Company
Date Published
Author
Daniel Berman
Word count
1297
Language
English
Hacker News points
None

Summary

The Snyk company has introduced EPSS (Exploit Prediction Scoring System) to its security intelligence, which estimates the likelihood of a vulnerability being exploited in the next 30 days, assigning it a probability score between 0% and 100%. This system is designed to address limitations of existing industry standards like CVSS, providing a more comprehensive risk assessment model by considering additional contextual factors. EPSS scores are updated daily, and Snyk plans to incorporate this system into its new risk assessment model that will also consider CVSS and other contextual risk factors, aiming for a more holistic approach to prioritization and issue management.