Pulse 16: Severity is NOT Probability cover art

Pulse 16: Severity is NOT Probability

Pulse 16: Severity is NOT Probability

Listen for free

View show details

CISA added a Linux kernel flaw to its Known Exploited Vulnerabilities list on May 1. CVSS 7.8. Federal agencies got two weeks to patch. Working exploit code in three languages.

The 9.8s your scanner pushed to the top of the dashboard last week were probably nobody's target.

This is the CVSS trap. Severity is not probability. CVSS is not a risk score. And almost every founder-led company has stepped in it.

First episode of a six-week series on the gap between what you measure and what gets exploited.

Full edition: signal.echocyber.io

Take the Signal Score: echocyber.io/assessment

adbl_web_anon_alc_button_suppression_c
No reviews yet