Your Software IS - NOT Vulnerable - CSAF, VEX, and the Future of Advisories
Offered By: Black Hat via YouTube
Course Description
Overview
Explore the future of software security advisories in this 24-minute Black Hat conference talk. Delve into the challenges organizations face as security advisories become more prevalent, particularly with the rise of Software Bill of Materials (SBOMs). Learn about the increasing occurrence of "false positives" in vulnerability reports and the importance of distinguishing between exploitable and non-exploitable vulnerabilities. Discover how the Common Security Advisory Framework (CSAF) and Vulnerability Exploitability eXchange (VEX) are shaping the landscape of security information processing and prioritization. Gain insights from experts Allan Friedman and Thomas Schmidt on how to navigate the evolving risk landscape and effectively manage the growing influx of security information in software development and usage.
Syllabus
Your Software IS/NOT Vulnerable: CSAF, VEX, and the Future of Advisories
Taught by
Black Hat
Related Courses
Attack on Titan M, Reloaded - Vulnerability Research on a Modern Security ChipBlack Hat via YouTube Attacks From a New Front Door in 4G & 5G Mobile Networks
Black Hat via YouTube AAD Joined Machines - The New Lateral Movement
Black Hat via YouTube Better Privacy Through Offense - How to Build a Privacy Red Team
Black Hat via YouTube Whip the Whisperer - Simulating Side Channel Leakage
Black Hat via YouTube