Getting Secure Beyond CVE Scanning
This is not a post meant to bash CVEs, especially with the recent drama around the issues at the NVD. Instead, I’m arguing that CVEs are the baseline for supply chain security, not the end goal. Are CVE's really the best we can do? Why SCA Scanners Built Upon CVEs What Outcome are we looking for? What are some different approaches? Predictions on the future Latio Updates: This week I planned on further exploring API security or CNAPP, but I find myself returning to SCA after meeting with two vendors, Phylum and Tidelift. Phylum raised a $15 million series A in 2022, and Tidelift a $27 million series C (later expanded to 33.5) at around the same time. After meeting with these companies, I was wondering two things: Why have I come across neither company before in researching application security tools? Should supply chain security mean more than CVE scanning and remediation workflows? Phylum shared some data with me that led me to question my sanity, having spent so much of my career on
This is not a post meant to bash CVEs, especially with the recent drama around the issues at the NVD. Instead, I’m arguing that CVEs are the baseline for supply chain security, not the end goal. Are CVE's really the best we can do? Why SCA Scanners Built Upon CVEs What Outcome are we looking for? What are some different approaches? Predictions on the future Latio Updates: This week I planned on further exploring API security or CNAPP, but I find myself returning to SCA after meeting with two vendors, Phylum and Tidelift. Phylum raised a $15 million series A in 2022, and Tidelift a $27 million
Explore this link on the map →