- Vulnerability management past the CVSS score
Quick recap. The Cloud Security Office Hours session focused on open discussions about cloud security challenges, particularly around vulnerability management and the evolving landscape of prioritizing and remediating vulnerabilities. Participants shared experiences and strategies for handling vulnerabilities, including the limitations of CVSS scores, the importance of asset context, and the role of tools like Wiz and Orca. The conversation touched on the difficulties of patching at scale, the impact of legacy systems, and the potential of shifting left and reducing attack surfaces. There was also discussion about the use of AI in development, secure coding practices, and the challenges of verifying AI-generated code. The group highlighted the value of community, networking, and learning from each other's experiences in cloud security. New members were welcomed, and the session ended with appreciation for the knowledge shared among participants.
Show 8 discussion topics
Cloud Security Office Hours Meeting
The meeting began with casual conversation about Metallica playing at 10 AM and participants sharing their locations across the East Coast. Shawn welcomed everyone to Cloud Security Office Hours and noted that this was an open session for networking and asking questions. He encouraged new attendees to introduce themselves by coming on camera and sharing their background in cloud security, though no formal introductions were completed in the provided transcript segment.
New Member Welcome and Networking
The meeting focused on welcoming new members, particularly Kevin, who introduced himself as a SOC analyst looking to transition into cloud security. Shawn emphasized the group's supportive environment and encouraged participants to ask questions and network with each other, highlighting the success stories of members like Alhaji. Tyler noted the high representation of female participants in the group, which is rare in cybersecurity, and the community celebrated this diversity.
AWS Billing and Vulnerability Updates
The group discussed several topics, including a concerning AWS billing error that Shawn discovered, which initially showed a $70,000 charge before being corrected to $39,000. Neil explained the current state of CVE vulnerability enrichment, noting that NVD stopped enriching vulnerabilities two years ago and now only enriches those relevant to the federal government, while vendors have shifted to relying more on CNA scores for metadata. Neil announced an upcoming webinar on July 22nd with Ashley Burrell from Orca to discuss vulnerability management, and mentioned that about 90% of vulnerabilities now have CVSS scores from CNAs, though only 10-20% have CPE information.
CPE and Vulnerability Management Approaches
Neil explained CPE (Common Platform Enumeration) and discussed approaches to vulnerability management, including the use of CNA scores, NVD and CISA resources, and enrichment with additional data like the CISA KEV list. He described the SSVC approach as a decision matrix that prioritizes vulnerabilities based on external exposure, known exploitation, automatability, and impact, noting that CISA's Binding Operational Directive 20-04 implements this framework. Neil also mentioned the trend toward minimalism in security, where removing unnecessary components reduces the number of vulnerabilities to manage.
Vulnerability Prioritization and Risk Assessment
The group discussed vulnerability prioritization and risk assessment approaches. Nathaneal expressed concerns about combining multiple metrics and trusting single vendors like GitHub, while Jay explained that different vulnerability scoring models like CVSS, EPSS, and KEV all aim to address similar challenges, with the key being proper environmental and temporal context. Shawn highlighted how the window between vulnerability discovery and exploitation has dramatically shrunk from weeks to hours or minutes, emphasizing the importance of focusing on attack surface and reachable endpoints rather than just identifying vulnerabilities.
Vulnerability Management Evolution Discussion
The group discussed the evolution of vulnerability management, with Shawn and Jay noting its convergence with attack surface management to address security issues at scale. Don shared insights about how vulnerability management strategies vary by industry, particularly in financial services, and emphasized the importance of scaling remediation efforts. Neil and Jay debated the current state of vulnerability management, with Neil arguing that despite challenges, existing approaches still provide real benefits, while Jay suggested that adding guardrails and defense-in-depth measures could improve efficiency without abandoning current practices.
Vulnerability Management Strategy Discussion
Pavel advocated for bulk vulnerability fixes using automated agents rather than individual tickets, citing a recent example of a 200-day unaddressed vulnerability in Cursor. Tyler emphasized the complexity of vulnerability management, particularly for large organizations with heterogeneous infrastructure, and highlighted the challenges of patching, including potential breaks in production workloads. Jay challenged the premise of constant patching, suggesting a need to rethink security approaches and considering alternatives like developing custom code or using reliable partners, while Tyler argued that custom development could introduce new vulnerabilities and that environmental controls like WAFs have limitations.
Vulnerability Management Approaches Discussion
The meeting focused on vulnerability management approaches and tools for securing code, particularly in the context of large organizations versus smaller ones. Tyler shared IBM's use of Concert Secure Coder to scan pull requests for vulnerabilities, while Nathaneal discussed implementing Wiz and other tools for tracking AI model usage and applying traditional security controls to new infrastructure. The group explored how different organizational scales affect vulnerability management strategies, with Jay noting that smaller, more agile organizations have advantages over large legacy systems like SAP ERP. The discussion concluded with plans for future sessions, including a potential presentation on business process threat modeling and an upcoming discussion about an AI model scoring system.
