• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Twitter Mentions More Effective Than CVSS at Reducing Exploitability

You are here: Home / General Cyber Security News / Twitter Mentions More Effective Than CVSS at Reducing Exploitability
January 20, 2022

Monitoring Twitter mentions of vulnerabilities may possibly be two times as productive as CVSS scores at encouraging corporations prioritize which bugs to patch first, according to new analysis.

Kenna Security’s latest report, Prioritization to Prediction, Volume 8: Measuring and Reducing Exploitability, was compiled with enable from the Cyentia Institute.

It verified what lots of security industry experts have been indicating for some time: the sheer volume of CVEs learned these days signifies businesses must get superior at prioritizing which vulnerabilities to resolve.

✔ Approved Seller From Our Partners
Malwarebytes Premium 2022

Protect yourself against all threads using Malwarebytes. Get Malwarebytes Premium with 60% discount from a Malwarebytes official seller SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Despite the fact that an regular of 55 bugs have been learned every day in 2021, the fantastic information is that only 4% posed a high risk to corporations, according to the exploration. It went further more, claiming that 62% of the vulnerabilities analyzed had a less than a 1% chance of exploitation, although only 5% exceeded a 10% probability.

To arrive at its findings, Kenna Security used an field-devised Exploit Prediction Scoring Process (EPSS), which uses CVE data and serious-earth exploit details to forecast “whether and when” vulnerabilities will be exploited in the wild.

Not all vulnerability administration approaches are made equal, argued Kenna Security co-founder and CTO, Ed Bellis.

“Prioritizing vulnerabilities with exploit code is 11 situations additional efficient than CVSS scores in minimizing exploitability. Mentions on Twitter, surprisingly, also have a much much better signal-to-sound ratio than CVSS (about two times superior),” he wrote.

“We also acquired that, offered the option, it’s much extra helpful to improve vulnerability prioritization than boost remediation ability … but performing both can attain a 29-instances reduction in exploitability.”

Bellis concluded that prioritizing bugs through exploitability rather than technological CVSS scores is “the system of the future” and one that US authorities security experts surface to be taking.

“The information exhibits that having this much more calculated method of prioritizing exploitability above CVSS scores is the way to go and the recent Cybersecurity and Infrastructure Security Company (CISA) directive agrees,” he argued.


Some pieces of this post are sourced from:
www.infosecurity-magazine.com

Previous Post: «Cyber Security News Eleven Arrested in Bust of Prolific Nigerian BEC Gang
Next Post: Applications Open for Next NCSC for Startups Cohort Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Phishers Using Ukraine Invasion to Solicit Cryptocurrency
  • FBI Launches Virtual Assets Unit
  • The Total Economic Impact™ of IBM Security MaaS360 with Watson
  • Unified endpoint management solutions 2021-22
  • Misconfigured Firebase Databases Exposing Data in Mobile Apps
  • Six myths of SIEM
  • US Passes “Game-Changing” Cyber Incident Reporting Legislation
  • How a platform approach to security monitoring initiatives adds value
  • Popular NPM Package Updated to Wipe Russia, Belarus Systems to Protest Ukraine Invasion
  • Reporting Mandates to Clear Up Feds’ Hazy Look into Threat Landscape – Podcast

Copyright © TheCyberSecurity.News, All Rights Reserved.