Managing Risk of Open Source Libraries using Mandiant Vulnerability Intelligence

Опубликовано: 08 Декабрь 2022
на канале: Nucleus Security
218
9

Today nearly every organization has a growing internal software development team to ensure the business remains competitive. With a global shortage of software engineering talent that is showing no signs of improving, and increasing demands for software teams to ship code faster, the use of open-source libraries has grown tremendously over the last decade.

Open-source libraries enable development teams to quickly deploy new functionality with minimal effort, however, they also introduce new application security risks that must be managed. Many vulnerability scanning tools will identify and monitor open source libraries for vulnerabilities, however, the volume of findings, combined with the lack of context about the vulnerabilities, makes it increasingly difficult to determine which vulnerabilities should be fixed, and what their priorities are.

In this talk Stephen Carter discusses the value of vulnerability intelligence correlated to open-source library vulnerabilities, and how our customers have been able to minimize the time their development teams spend researching vulnerabilities and enable them to focus on updating the libraries that matter most.