Product Announcementspmonaghan (Veracode, Inc.) asked a question.

🌟 SCA update: APIs now include KEV data

A few months ago, as part of on-going efforts to help customers prioritize what to fix, Veracode added EPSS scores to its SCA results. These scores estimate the probability that a hacker will exploit a vulnerability in the next 30 days. While forecasting future exploits is important, it is also necessary to understand what has happened in the past, which is why earlier this week the SCA team added an Exploit Observed field to SCA’s results. This field will be set to true whenever a vulnerability has already been exploited or whenever exploit code has been made public. Another field will indicate the source of this information. Initially, the only source will be CISA's Known Exploited Vulnerabilities (KEV) catalog, but next year, Veracode will add more sources, such as exploit-DB. All of this exploit information is now available in the Issues APIs for SCA Agent results and the Findings API for SCA Upload results. Veracode will add exploitation data to reports and user interfaces next year. Please see this page in Veracode Docs for more details. Thank you.


DTran and lucas.ferreira like this.

Topics (10)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.