
Absolute AppSec
Episode 330 - w/ Jeevan Singh - Vulnerability Jail
In this special episode of Absolute AppSec, we cover a topic which started as a solution proposed by Rippling Security's Jeevan Singh: Vulnerability Jail. As Jeevan describes it: "In this new AI world, we have seen many more vulnerabilities, and we struggled to get Engineering to fix them all in a timely fashion. This changed when we created Vulnerability Jail. If any vulnerability goes over SLA, your team is placed in Jail, preventing them from merging PRs into the main/default branches. We implemented Vulnerability Jail, updated our SLAs and got buy-in from Eng Leadership for our new Vulnerability Management program. As a result, we have now fixed the same number of vulnerabilities in one month as the team did in the previous year. The speed is still accelerating."" What do we think of the Stick approach to Vuln Management? What are the solutions to the rapid production by AI as well as the vulnpocalypse, Alex Gaynor's term to describe the way that "new technological innovation enables (or indirectly results in) finding a very large number of vulnerabilities in pre-existing software, which renders all previous assumptions and beliefs about the volume of extant vulnerabilities incorrect." Will "Vulnerability Jail" save us from the vulnpocalypse? Episode sponsored by GuardSquare (guardsquare.com)

