A dashboard displays a vulnerability funnel with stages: low, internet-facing, fix available, and exploitable, showing decreasing counts. Below, a list details vulnerabilities with categories like Jira, use, exploit, and fix, using color-coded indicators.

Filter Out the Noise And Focus on the Vulnerabilities that Actually Matter

Denise Ashur September 29, 2023

Filter Out the Noise And Focus on the Vulnerabilities that Actually Matter

We’re excited to release an important capability for our Runtime Vulnerability management. Starting today, you can view an end-to-end funnel of your vulnerabilities, apply critical filters to your vulnerabilities data and answer these tough questions within seconds: 

  • Is the package loaded into memory or actively in use?
  • Is the package exposed to the Internet?
  • Is remote execution possible?
  • Is there active ingress or egress traffic related to the package?
  • Does the package have access to sensitive data?
  • Is there an available exploit for the vulnerability?
  • Is a vendor-supplied fix available?

You can now customize your vulnerability reports and filter vulnerabilities that are in use, Internet facing, have a fix available and are exploitable – helping you rapidly filter and prioritize the alerts that actually matter to your organization. 

Use Upwind’s Vulnerability Funnel to run custom reports by vulnerability, image or resource type and streamline your remediation by getting highly personalized alert information to the right members of your security team, in record time. 

Contents

Further Reading

org chart - dark mode

The Org Chart is The Wrong Security Boundary

The department model of dividing companies into groups earned its place. Finance gets the finance applications, engineering gets the repositories, HR gets the HRIS, and the boundaries hold because software was bought per function and used per function. Identity and access management platforms, such as Active Directory and Okta, were built around exactly that. Groups…
behind-the-curtain-part-03

What’s Behind the Curtain? AWS Bedrock AgentCore Runtime Tear Down – Part III

Recap In Part I and Part II, we: Networking and VPC Mode Network Isolation Testing The microVM is assigned an IPv6 address matching the value in the JWT. Across multiple runs, all addresses shared the same 2600:1f18::/32 prefix, but cross-microVM communication always failed. We attempted to reach the host EC2 IMDS by manipulating the route…
behind-the-curtain-part-02

What’s Behind the Curtain? AWS Bedrock AgentCore Runtime Tear Down – Part II

Recap In Part I, we explored the AgentCore Runtime microVM from the inside and discovered we weren't alone - four platform binaries were running alongside our code, and one of them was quietly shipping logs to an AWS-internal S3 bucket. We left off with a question: what can we learn from these internal components, and…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS