Third Party
A new AI model called Mythos promises to find vulnerabilities faster than any human team. But what does that actually mean for the security leaders responsible for managing third-party risk? In this special episode, Jeffrey Wheatman is joined by Bob Maley, Ferhat Dikbiyik, and Black Kite co-founder and CTO Candan Bolukbas to break down what Mythos and Project Glasswing actually change, and what they don't. The numbers are already alarming. Forty-eight thousand CVEs published in 2025. A 43-day mean time to patch. An exploitation window that has gone negative, meaning threat actors are exploiting vulnerabilities an average of seven days before defenders even know they exist. Mythos accelerates vulnerability discovery, but as the team makes clear, discovering more vulnerabilities faster only matters if you have a program built to handle it. In this episode, you will learn: * What Mythos and Project Glasswing actually are and why the hype may be outpacing the reality * Why the vulnerability deluge is already unmanageable with traditional CVSS-based prioritization * How the 135-day embargo window affects your third-party exposure * Why fourth-party risk, meaning what your vendors run rather than just who they are, is becoming the real blind spot * What SBOMs have to do with the future of supply chain vulnerability management * The three things security leaders should do right now to prepare their programs This is not a theoretical conversation. It's the one your program needs before the window closes.
19 afleveringen
Reacties
0Wees de eerste die een reactie plaatst
Meld je nu aan en word lid van de Third Party community!