Navigation
Recherche
|
Traditional vulnerability assessment falls short on third-party risks
mardi 8 avril 2025, 13:02 , par BetaNews
As organizations increasingly rely on third-party vendors, open-source components, and cloud services to bolster efficiency and scalability, they also open themselves to risks. Historically they've relied on CVSS scores to measure the severity of risks, but a new report from Black Kite suggests that this method alone is not enough. 'Focusing solely on Common Vulnerability Scoring System (CVSS) scores is insufficient for risk management,' says Ferhat Dikbiyik, chief research and intelligence officer at Black Kite. 'CVSS is not a prioritization tool and cannot inform security teams whether a vulnerability is being exploited or the likelihood it will be weaponized. Further… [Continue Reading]
https://betanews.com/2025/04/08/traditional-vulnerability-assessment-falls-short-on-third-party-risk
Voir aussi |
56 sources (32 en français)
Date Actuelle
mer. 16 avril - 16:02 CEST
|