Changing the Vuln Conversation from Volume to Remediation - Francesco Cipollone - ASW #350
文章探讨了漏洞处理中的优先级问题及修复策略,建议利用大语言模型优化流程并降低成本。还涉及供应链安全、代码仓库保护等议题,并推荐相关播客。 2025-9-30 09:0:0 Author: sites.libsyn.com(查看原文) 阅读量:6 收藏

Sep 30, 2025

Dealing with vulns tends to be a discussion about prioritization. After all, there a tons of CVEs and dependencies with known vulns. It's important to figure out how to present developers with useful vuln info that doesn't overwhelm them. Francesco Cipollone shares how to redirect that discussion to focus on remediation and how to incorporate LLMs into this process without losing your focus or losing your budget.

In the news, supply chain security in Ruby and Rust, protecting package repositories, refining CodeQL queries for security, refactoring and Rust, an OWASP survey, and more!

Visit https://www.securityweekly.com/asw for all the latest episodes!

Show Notes: https://securityweekly.com/asw-350


文章来源: http://sites.libsyn.com/18678/changing-the-vuln-conversation-from-volume-to-remediation-francesco-cipollone-asw-350
如有侵权请联系:admin#unsafe.sh