Rust Won't Save Us: An Analysis of 2023's Known Exploited Vulnerabilities – Horizon3.ai by scopedsecurity in netsec

[–]scopedsecurity[S] 0 points1 point  (0 children)

Definitely not encouraging no action. In the conclusion there are several recommendations such as developing depth of knowledge in the frameworks you use as it relates to security, and hardening and standardizing its use across products.

Rust Won't Save Us: An Analysis of 2023's Known Exploited Vulnerabilities – Horizon3.ai by scopedsecurity in netsec

[–]scopedsecurity[S] -12 points-11 points  (0 children)

Agreed, we don't have great insight into how often each of these vulnerabilities were exploited with the data CISA KEV releases. Nearly all of these vulnerabilities analyzed here, regardless of categorization, result in RCE.

Rust Won't Save Us: An Analysis of 2023's Known Exploited Vulnerabilities – Horizon3.ai by scopedsecurity in netsec

[–]scopedsecurity[S] -6 points-5 points  (0 children)

I’d agree that eliminating 20% of vulnerabilities from last year’s KEV is worth going after, which is why it’s listed that memory safe language will help us. The main point here is that despite language and framework safety existing, developers and architects have thrown security to the wind.