Static vs. Runtime Reachability: Insights from Latio’s On th...
Blog post from Socket
Latio's "On the Record" podcast delves into the significance of static and runtime reachability in vulnerability management, highlighting their roles in prioritizing exploitable vulnerabilities and optimizing application security workflows. With the surge in vulnerability disclosures in 2025, understanding which vulnerabilities are truly relevant is crucial for saving time and resources. The episode features insights from Martin Torp of Socket and Omer Yair of Raven.io, who discuss how reachability helps focus on relevant CVEs, noting that not all reachable vulnerabilities are exploitable due to potential safeguards. The podcast explains static reachability as analyzing code without execution, beneficial for early triage, and runtime reachability as observing live applications for accurate results with minimal performance impact. By combining both approaches, teams can gain a comprehensive understanding of exploitable vulnerabilities, enhancing the efficiency of AppSec programs, with discussions extending to language support, function-to-CVE mapping, and compliance frameworks.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.