No items found.
Event

Managing Open Source Vulnerabilities for PCI DSS Compliance

Date
June 18, 2024
Time
9:00am - 9:30am PT
Event Type
Virtual

PCI DSS version 4.0 contains a host of new practices that will become requirements on March 31, 2025. In this talk, we focus on a change that looks — at first glance — to be minor, but in reality could have significant implications for Application Security teams: the requirement to manage all internal vulnerabilities, regardless of criticality.

We’ll focus on how to address open source software (OSS) vulnerabilities, including:

  • What it means to “manage vulnerabilities”
  • Why OSS presents the greatest risk to compliance with this new requirement
  • The security tool problem preventing organizations from addressing OSS risk
  • Getting accurate dependency inventories and prioritizing remediation
  • Setting up guardrails to ensure developers select safe OSS dependencies
OpenAI Codex with GPT-5.6 Sol: competitive, zero cheating, one unique Django fix
OpenAI Codex with GPT-5.6 Sol: competitive, zero cheating, one unique Django fix
Read more
Endor Labs’ AI SAST Finds Zero Day Memory-Amplification DoS in Anthropic’s buffa library
Endor Labs’ AI SAST Finds CVE-2026-55407: Memory-Amplification DoS in buffa
Read more
Open source carries the world. Patching it at Mythos-scale can't fall to maintainers alone.
Read more
OpenAI Codex with GPT-5.6 Sol: competitive, zero cheating, one unique Django fix
OpenAI Codex with GPT-5.6 Sol: competitive, zero cheating, one unique Django fix
Read more
Endor Labs’ AI SAST Finds Zero Day Memory-Amplification DoS in Anthropic’s buffa library
Endor Labs’ AI SAST Finds CVE-2026-55407: Memory-Amplification DoS in buffa
Read more
Open source carries the world. Patching it at Mythos-scale can't fall to maintainers alone.
Read more

Want to stay in the loop?

Sign up for our newsletter.