
Episode #11
Is It Easier to Write a Vulnerability Than to Find One?
Static analysis tools used to be right about as often as a coin flip. Kathleen Goeschel, Principal Product Security Engineer at Red Hat, spent years using machine learning to fix that, and now she's watching large language models change both sides of the fight. How fast vulnerable code gets written, and how fast it gets found. Goeschel walks through how she trained machine learning models on aggregated scanner alerts, software metrics, and prior CVEs to cut false positives in static analysis, and the surprising finding that code churn alone predicted real vulnerabilities better than most of the signals built for that purpose. Read the blog post and follow us on LinkedIn !




