Paul's Security Weekly (Audio) cover image

Paul's Security Weekly (Audio)

How do we patch the right things? - Josh Bressers - PSW #840

Aug 22, 2024
Josh Bressers, a knowledgeable figure in vulnerabilities and exploits, dives into the complexities of patch management. He discusses the limitations of tools like MITRE ATT&CK and CVSS in accurately prioritizing vulnerabilities. The conversation emphasizes the importance of context in patching decisions and addresses the challenges of tracking incidents that lack CVEs. Bressers shares insights on the balance between urgent patches and asset criticality, highlighting personal anecdotes that shed light on navigating the evolving cybersecurity landscape.
02:58:57

Episode guests

Podcast summary created with Snipd AI

Quick takeaways

  • Organizations must prioritize patches based on nuanced risk assessments, going beyond just CVSS scores which may not reflect true vulnerabilities.
  • The ransomware attack in Flint, Michigan showcases the vulnerability of municipal infrastructures to cyber threats amid existing crises.

Deep dives

Prioritizing Patching and Remediation

The discussion emphasizes the importance of prioritizing patches and remediation efforts in cybersecurity. It draws on various frameworks and tools that assist in determining which vulnerabilities need immediate attention, including MITRE ATT&CK, CVSS, EPSS, and SysaCav. The conversation reveals that simply relying on a CVSS score may not be sufficient, as environmental and organizational factors play a significant role in assessing the true risk posed by a vulnerability. There is a call for organizations to develop a more nuanced understanding of risk, beyond just the metrics provided by these tools.

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode