
Getting Vulnerability Management Back on the Rails - Patrick Garrity - ESW #356
About this episode
NVD checked out, then they came back? Maybe?
Should the xz backdoor be treated as a vulnerability?
Is scan-driven vulnerability management obsolete when it comes to alerting on emerging threats?
What were some of the takeaways from the first-ever VulnCon?
EPSS is featured in over 100 security products, but is it properly supported by those that benefit from it?
How long do defenders have from the moment a vulnerability is disclosed to patch or mitigate it before working exploits are ready and in the wild?
There's SO much going on in the vulnerability management space, but we'll try to get to the bottom of some of in in this episode. In this interview, we talk to Patrick Garrity about the messy state of vulnerability management and how to get it back on the rails.
Segment Resources:
Show Notes: https://securityweekly.com/esw-356
Get every episode summarized
Each time Enterprise Security Weekly (Video) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Enterprise Security Weekly (Video)
Breaking in with CrashFix, supply chain security, and CMMC phase 1 - Anna Pham,...
Enterprise Security Weekly (Video)
OT Security/business resilience, lack of incentives for securing software & the...
Enterprise Security Weekly (Video)
Bringing intelligence to assets, new White House cybersecurity strategy, and the...
Enterprise Security Weekly (Video)
Hardware-level zero trust, don't trust AI with your employees, and the news - Ma...
Enterprise Security Weekly (Video)