The death and rebirth of vulnerability management (RSAC25)

Despite becoming a checkbox feature in major product suites, vulnerability management is fundamentally broken. The few remaining first-wave vulnerability scanners long ago shifted their investments and attention into adjacent markets to maintain growth, bolting on fragmented functionality that's added complexity without effectively securing today's attack surfaces. Meanwhile, security teams are left contending with massive blind spots and disparate tools that collectively fail to detect exposures that are commonly exploited by attackers. Our industry is ready for change.

Jeff Man and HD Moore explore the current state of vulnerability management, what’s required to truly prevent real-world incidents, new perspectives that are challenging the status quo, and innovative approaches that are finally overcoming decades old problems to usher in a new era of vulnerability management.

Segment Resources:

  • runZero offers a fully functional, free 21-day trial that converts into a free Community Edition license that is great for small environments and home networks.
  • Read more about runZero's recent launch, including new exposure management capabilities.
  • Watch a two-minute summary and deeper dive videos here
  • Tune into runZero's monthly research webcast, runZero Hour, to hear about the team's latest research findings and additional debate on all things exposure management.

Meet Our Speakers

HD Moore

Founder & CEO, runZero

Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.


Related Resources

Podcasts
Risky Biz Interview: Integrating runZero with Bloodhound
HD Moore talks to Patrick Gray about integrating runZero with Bloodhound-style graph databases, uses for driving runZero's tools with an AI and more.
Podcasts
Metasploit creator: why CVEs won’t save you in 2025
Kyser Clark (The Hacker’s Cache) talks with HD Moore (Founder & CEO, runZero) to discuss why relying on CVEs is putting organizations at risk in 2025.
Podcasts
CVE's emerging threats and horror movies
VulnCheck chat with Tod Beardsley about his time at CISA, cyber threats he's currently researching, the CVE program, its future - and horror movies.
Podcasts
Why your firewall might be your biggest risk, HD Moore (ITSP Magazine)
Listen as HD Moore breaks down where our security doctrines came from, why some became obsolete, and which ones still hold water.

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.