Event

Mastering OSS Security: Validating Vulnerabilities with Code-Level Reachability Analysis

Date
August 22, 2024
Time
4:00 pm - 4:45 pm CEST
Event Type
Virtual

Discover how to transform your approach to vulnerability assessment by focusing on those vulnerabilities that matter most in your codebase. This webinar explains how to use reachability analysis and other parameters such as EPSS etc. to manage & prioritize vulnerabilities and cut unnecessary noise.

Key takeaways :

  • Prioritizing vulnerabilities in OSS dependencies: Accurately identify and mitigate vulnerabilities at the code level to reduce unnecessary alerts.
  • Using call graphs in vulnerability analysis: Leverage call graphs to trace execution paths and identify reachable vulnerabilities within your code.
  • Refining vulnerability detection: Evaluate most critical vulnerabilities based on severity, EPSS and patch availability.

Join us for a dynamic session full of insights, practical tips, and real-time Q&A to improve your security programs.

Want to stay in the loop?

Sign up for our newsletter.

Claude Fable 5: Mythos-grade hype, record cheating, and a few hall-of-fame entries
Average results with 59.8% on functional solves and just 19.0% on security solves
Read more
Recall, not reasoning: how AI coding agents cheat security benchmarks
Recall, not reasoning: how AI coding agents cheat security benchmarks
Read more
Endor Labs + Cursor: Building the security foundation for agentic coding
Endor Labs + Cursor: Building the security foundation for agentic coding
Read more
Introducing Full Stack Reachability: Container Scanning That Actually Reduces Noise
Cut container vulnerability noise by up to 90% with full-stack reachability analysis spanning application and container image OS layers.
Read more
Classic Vulnerabilities Meet AI Infrastructure: Why MCP Needs AppSec
MCP servers inherit classical vulnerabilities like command injection, path traversal, and SSRF. Here's why LLMs and MCP deserve the same security practices as traditional applications.
Read more
How Fake Font Packages Abused npm as a CDN
101 packages disguised as font files distributed 34 TiB of data via npm's infrastructure—with a total of 4.3 PiB transferred via downloads.
Read more