このエピソードについて
Dealing with vulns tends to be a discussion about prioritization. After all, there a tons of CVEs and dependencies with known vulns. It's important to figure out how to present developers with useful vuln info that doesn't overwhelm them. Francesco Cipollone shares how to redirect that discussion to focus on remediation and how to incorporate LLMs into this process without losing your focus or losing your budget.
In the news, supply chain security in Ruby and Rust, protecting package repositories, refining CodeQL queries for security, refactoring and Rust, an OWASP survey, and more!
Show Notes: https://securityweekly.com/asw-350
英語
アメリカ合衆国
文字起こし 🔗
Are you the producer of this podcast?
Add a podcast transcript
Need Audio-to-Text?
Transcribe with Listen411 in Just 60 Seconds
このポッドキャストの他のエピソード
At a time when the traditional approach to enterprise vulnerability management is no longer effective, security leaders are turning to AI agents to help identify, validate, and contain zero-day threats. Learn how Google Cloud Security is building autonomous detection engineering to help your organi…
Venus in Furs, Money Laundering, Agentic AI Hijinx, MCP, Thunderbastard, Aaran Leyland, and More on the Security Weekly News.
Show Notes: https://securityweekly.com/swn-620
Ear mite butterfly effects, Chuds, Agentic AI galore, CISA, Shiny Hunters, FreeBSD, Ghost Accounts, Pervs, Josh Marpet, and More on this episode of the Security Weekly News.
Show Notes: https://securityweekly.com/swn-619
Finding flaws with LLMs and agents is changing bug bounty programs. But it's not necessarily changing how orgs fix those flaws. Shlomie Liberow shares his experience across a decade of bounty programs and how they have changed for researchers and orgs. He explains why fixing the bug reported throug…
Interview with Christopher Crawley - The Value of SecOps This week, we talk to Chris Crawley about his new book, The Value of Cybersecurity Operations. Chris has been training teams on security operations for years, but found that students often struggled to justify the importance of secops trainin…
免責: このページに埋め込まれているポッドキャストとアートワークは Security Weekly Productions からのものであり、その所有者の所有物であり、Listen Notes, Inc. と提携または承認されていません。