Security News

Cybersecurity news aggregator

INFO News SC Media

Vulnerability Management is Broken: How to Reduce Risk (Not Just CVEs) in Containers - WC #1

Read Full Article →

Share Full episode and show notes Vulnerability Management Vulnerability Management is Broken: How to Reduce Risk (Not Just CVEs) in Containers – WC #1 Drowning in CVEs? Learn why traditional vulnerability management fails and how reducing attack surface, prioritization, and minimal container images can dramatically improve real risk reduction. Thank you to our sponsor for this webcast, Minimus! Still chasing thousands of vulnerabilities? Learn how modern security teams are reducing risk at the source: register for upcoming webcasts at https://scworld.com/webcasts. June 25, 2026 Full Segment Notes Drowning in CVEs? Learn why traditional vulnerability management fails and how reducing attack surface, prioritization, and minimal container images can dramatically improve real risk reduction. Thank you to our sponsor for this webcast, Minimus! Still chasing thousands of vulnerabilities? Learn how modern security teams are reducing risk at the source: register for upcoming webcasts at https://scworld.com/webcasts Key Moments 0:00 - Introduction & Topic: Risk vs CVEs 02:30 - Why Vulnerability Volume Is Exploding 05:00 - Containers vs Traditional Patching 07:30 - Dev vs Security Friction Explained 10:30 - Why Only 10% of Vulnerabilities Get Fixed 13:00 - Prioritization, Exploitability & Reality 16:00 - Why CVSS Alone Isn’t Enough 18:30 - The Problem with “Noise” in Security 21:00 - Rethinking Vulnerability Management 23:00 - Minimus Approach: Minimal Containers 25:30 - Reducing Attack Surface at the Source 27:30 - Mean Time to CVE Explained 30:00 - Why Less Software = Less Risk 32:30 - Developer Experience & Better Signal 35:00 - Real Example: Faster Patch Turnaround 38:00 - Hardening vs Reduction Explained 41:00 - Why Old Vulnerabilities Keep Reappearing 44:30 - Dependency Hell & Supply Chain Risk 47:30 - How Adoption Actually Works 50:00 - Security + Dev Collaboration Model 52:00 - Key Takeaways & Final Thoughts Host Adrian Sanabria @sawaba https://adriansanabria.com Show More Stay in the Know, No Smoke and Mirrors – Join Our Newsletter Get expert insights and technical breakdowns straight to your inbox. Join Now Related Segments Vulnerability Management Turing, BODS, Struwwelpeter, EO-14409, VBScript, Pixemsmash, Cloudflare, Aaran Leylan – SWN #592 Vulnerability Management Navigating Shadow AI in the Enterprise, Verizon’s SECOND 2026 report, and the news – Ankita Gupta – ESW #464 Vulnerability Management TSME, ARCH, Maine, Fable, PANOS, Doug’s Grandma, Vienna Sausages, Aaran Leyland – SWN #590 Related Content MSSP MSSPs, MSPs get a scalable path to vCISO and vulnerability management services Vulnerability Management Closing the ‘risk window’: Why real-time remediation is the new security standard Vulnerability Management Patched Samsung KNOX kernel flaw (CVE-2026-20971) detailed You can skip this ad in 5 seconds

Share this article