Your vulnerability remediation SLA starts a clock on every alert. On Redash, an open-source dashboarding tool we'll use as an example, that is 272 clocks. But only about 10% of them need action.
EPSS vs KEV: the 2% score on a ransomware CVE
On August 25 our weekly triage deferred a Starlette alert with a 2% EPSS score. On September 1 the same alert, same code, same 2% score, was the only advisory in a 127-alert backlog that had to be fixed that day. Nothing about the vulnerability changed in that week....
Why coding agents need help triaging dependency alerts
“Why not just prompt Claude Code or Copilot to triage dependency alerts per our security policy?” is the right question. A coding agent can read your code, trace a call path, and reason about whether a vulnerable function is reachable. That is the hardest part of alert...
How to Prioritize CVEs by Risk, Not Severity
In 24 hours we scored the same CVE three times against three different projects, and it came back DEFER on one and SCHEDULE on the other two. Every call was right. The scanner’s severity label read “high” all three times. What changed was the asset context, and with it...
Severity is no longer a triage input. Risk scoring you own is.
“I’m sorry, Dave. I’m afraid I can’t do that.” NIST said it more politely on April 15. The NVD change is permanent, not a temporary glitch. CVE volume has outpaced NIST’s analysis capacity. For 25 years, vulnerability-management programs assumed the National...
Building Evals for an AI Agent: From Zero to Consistency Testing
We’re building an AI agent that triages cloud security findings. It reads a finding from AWS Security Hub or Prowler, assesses the risk, and tells an engineer exactly what to do about it with specific AWS CLI commands they can run. The agent worked. We had 620 unit...
