Boosted by andrewnez ("Andrew Nesbitt"):
joshbressers@infosec.exchange ("Josh Bressers") wrote:
This week on #OpenSourceSecurity I had a chat with @paulasadoorian about a tool he wrote called Fettle and a report he wrote that focuses on advisories instead of just the CVEs
We love making a huge deal about individual CVEs, but most of us have to deal with advisories that clump them together. It gets even weirder when you have to deal with firmware advisories
Paul is always fun to chat with and has some stories that are equal part amusing and scary