CyberWire Daily

New sandbox escape looks awfully familiar.

Mar 28, 2025
Chris Wysopal, the Founder and Chief Security Evangelist of Veracode, delves into the alarming increase in the average fix time for security flaws, shedding light on how modern technology complicates the issue. He reveals that many organizations are sitting on critical security debt for over a year. The conversation also touches on significant vulnerabilities affecting both Firefox and Chrome. Additionally, the RedCurl gang's first foray into ransomware adds a chilling twist to current cyber threats, while innovative automation in cybersecurity is showcased.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Rising Security Debt

  • Average fix time for software security flaws is increasing, impacting 75% of organizations.
  • This "security debt" grows as software complexity rises, hindering timely remediation.
INSIGHT

Mismatched Priorities

  • Developers often prioritize fixing easier vulnerabilities over critical ones, regardless of severity.
  • This mismatched prioritization exacerbates security risks.
ADVICE

Manage Security Debt

  • Allocate specific resources for vulnerability remediation and balance them against new feature development.
  • Plan for security debt management to reduce accumulating risks.
Get the Snipd Podcast app to discover more snips from this episode
Get the app