Sign up now
Reserve your spot
Schedule
Want to stay in the loop?
Sign up for our newsletter.
Why does a “simple upgrade” often take so long, and why's it *so hard* to get development teams to do it?
Fix Faster is a hands-on workshop for AppSec and Product Security practitioners that want to address security issues faster and more effectively.
This beginner-to-intermediate training is your chance to step into a developer’s shoes. Through live demonstrations, interactive discussions, and guided exercises, we’ll simulate project-based challenges—walking into unfamiliar, legacy codebases and working through realistic constraints to remediate vulnerabilities. Participants will face real-world scenarios across Java and Python ecosystems, gaining firsthand experience in remediating known vulnerabilities in open source software. With more empathy for "upgrade hell", you can better partner with your dev teams to help your org reduce risk faster.
We'll cover:
Agenda:
1:30 - 2:00 PM - Check-in & Welcome
2:00 - 4:00 PM - Workshop Fix Faster
4:00 - 5:00 PM - Happy Hour
This workshop is for AppSec and Product Security practitioners looking to bridge the gap between AppSec and development by gaining empathy for the developer experience. You must currently be in one of these roles, but you don't need any specialized knowledge—just curiosity and a willingness to learn.
Sign up for our newsletter.
Integrate Microsoft Defender for Cloud with Endor Labs for reachability analysis and attack path visibility — available natively within the Defender for Cloud console. Prioritize what to fix without switching tools.
Click to read
The Cyber Resilience Act (CRA) sets mandatory security requirements for hardware and software. This blog covers key compliance objectives, challenges with OSS vulnerabilities, and best practices for maintaining security throughout the product life cycle.
Click to read
Get key insights from the 2024 Dependency Management webinar with Darren Meyer and Henrik Plate. We discuss how to prioritize vulnerabilities, navigate breaking changes, and leverage public vulnerability databases effectively.
Click to read
This blog covers key steps to simplify FedRAMP vulnerability management, helping you reduce risks and meet compliance timelines. It also provides practical tips to empower developers and streamline fixes for a smoother FedRAMP process.
Click to read
GitHub Actions are open source dependencies - secure them accordingly! Learn how to effectively manage the security risks associated with GitHub Actions with a proactive approach focusing on three key areas: visibility, hardening, and dependency management.
Click to read
Explore the five key categories of reachability and their practical applications in AppSec and development. Learn the differences between SCA and container scanning, and understand how various tools like Function-Level Reachability, Package Baselining, and Internet Reachability play crucial roles in identifying and prioritizing security risks.
Click to read
Innovate Cybersecurity Summit - Nashville
Click to view
Innovate Cybersecurity Summit, Scottsdale
Click to view