Home / Companies / Endor Labs / Blog / November 2023

November 2023 Summaries

5 posts from Endor Labs

Filter
Month: Year:
Post Summaries Back to Blog
Artificial intelligence (AI) is increasingly being discussed for its potential applications and the risks associated with its integration into digital ecosystems without adequate security and privacy measures. To address these challenges, organizations and governments are developing guidelines, such as the "Guidelines for Secure AI System Development" released by the U.S. Cybersecurity Infrastructure Security Agency (CISA) and the U.K.'s National Cyber Security Centre (NCSC). This publication highlights the unique aspects of AI security, including novel vulnerabilities like adversarial machine learning and the shared responsibility model between AI providers and users. It offers tactical recommendations for secure AI design, development, deployment, and operations, stressing the importance of practices like threat modeling, supply chain security, and continuous monitoring. By incorporating principles such as Secure-by-Design and emphasizing transparency and accountability, the guidance aims to ensure AI systems are developed with security integrated throughout their lifecycle. The guidelines also align with global efforts like the Bletchley Declaration on AI Safety, aiming to balance the benefits of AI with the need to manage its risks effectively.
Nov 30, 2023 2,389 words in the original blog post.
Open source software (OSS) plays a significant role in modern digital landscapes, composing a large portion of codebases used in various applications, infrastructure, and national security systems. Despite its widespread use, the security measures for OSS have not evolved, leading to vulnerabilities that pose risks to digital infrastructure. Research highlights alarming metrics, such as outdated components and known vulnerabilities in a majority of codebases, emphasizing the need for improved security practices. Organizations are encouraged to adopt fundamental measures like maintaining a detailed inventory of OSS assets, using tools like Software Composition Analysis to identify vulnerabilities, and implementing risk-informed component selection. Additionally, understanding project health through initiatives like the OpenSSF Scorecard can help assess the security posture of OSS projects. By focusing on these areas, organizations can mitigate risks associated with OSS, ensure better security, and protect against potential threats from software supply chain attacks.
Nov 16, 2023 1,001 words in the original blog post.
Endor Labs, recognized by CRN as a 2023 Stellar Startup in the Security category, has developed a Code and Pipeline Governance Platform that addresses challenges in application security by focusing on open source software and CI/CD pipeline security. The platform mitigates the inefficiencies developers face with security alerts and tool integration, by reducing vulnerabilities and enhancing performance through improved dependency selection. It also aids compliance with emerging standards like the Software Bill of Materials (SBOMs) and VEX generation. Endor Labs, founded by industry veterans and supported by prominent investors, is noted for its innovative solutions that address unique IT industry needs, helping organizations to manage risks without sacrificing productivity. This distinction by CRN highlights the company's role in providing cutting-edge solutions that contribute to the success of the IT channel.
Nov 13, 2023 713 words in the original blog post.
Endor Labs' tutorial on prioritizing open-source software (OSS) vulnerabilities focuses on using reachability analysis to identify and address the most critical issues. The method involves scanning for OSS vulnerabilities and operational risks, utilizing program analysis to pinpoint which risks are reachable, and illustrating these risks through call paths from code to vulnerable functions. By evaluating factors such as severity, Exploit Prediction Scoring System (EPSS), patch availability, and reachability, the process helps filter thousands of vulnerabilities down to the most urgent five. The tutorial was initially published on November 9, 2023, and later updated on August 25, 2025, emphasizing the evolving nature of OSS security practices.
Nov 09, 2023 273 words in the original blog post.
Endor Labs is set to participate in BlackHat 2026 in Las Vegas, where they are emphasizing the challenges and importance of open-source security, particularly for Python and AI applications, in the wake of incidents like Log4j. They highlight the difficulties organizations face in identifying vulnerable Python dependencies and offer solutions through their software supply chain platform, which now includes container scanning. Recently published materials by Endor Labs include the third-annual Dependency Management Report, which discusses trends in open-source security for guiding SDLC security strategies in 2024, and they also report on multiple vulnerabilities that have been fixed in the Node.js runtime.
Nov 06, 2023 179 words in the original blog post.