『Ep46: Vulnerability Prioritization: Why 98.5% of CVEs Are Never Exploited』のカバーアート

Ep46: Vulnerability Prioritization: Why 98.5% of CVEs Are Never Exploited

Ep46: Vulnerability Prioritization: Why 98.5% of CVEs Are Never Exploited

無料で聴く

ポッドキャストの詳細を見る

【Amazonプライム会員限定】今ならプレミアムプランが4か月 月額99円。

10月19日まで。※適用条件あり

Roughly 98.5% of all known CVEs have never been exploited. In this episode I break down a conversation between Jeremiah Grossman and Robert Hansen of Root Evidence, and host Raphael Mudge, on the Down the Rabbit Hole podcast, and what it means for how you prioritize a patch queue. I cover CVSS score versus exploitation evidence, how to use CISA's free KEV catalog, why the vulnerability management industry has no incentive to tell you the truth, and what separates a junior-sounding answer from a senior one in a security interview.

In this episode:

  • (00:00) The scan report that isn't as urgent as it looks
  • (01:03) The 98.5% number and the mechanic analogy
  • (02:01) Why the industry defaulted to patch everything
  • (03:00) The 36-hour outage from a perfect-10 patch
  • (03:48) CVSS score vs. exploitation evidence vs. insurance-claims data
  • (05:08) What it sounds like when someone understands this in an interview
  • (06:15) Why the industry has no brakes, and the AI-hype myth
  • (07:49) Your homework

Links:

  • Down the Rabbit Hole, episode 722, "Vulnerability Math Ain't Mathing"
  • CISA's Known Exploited Vulnerabilities (KEV) catalog
  • FIRST.org, the CVSS specification
  • Full written breakdown
  • Our cybersecurity career guide
  • Breaking into cybersecurity with no experience
  • Third-party risk and the AI bug-report flood

Not financial or legal advice. Figures cited reflect Root Evidence's analysis as discussed on the source podcast episode.

I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.

--

Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:

Listen to Byte Sized Security

--

Support this Podcast with a Tip:

Support Byte Sized Security

--

If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast.

Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

adbl_web_anon_alc_button_suppression_t1
まだレビューはありません