Security Bugs and Vulnerability - The Vulnerability Landscape

Cyber security is an arms race between offensive and defensive capabilities, and unfortunately, we are losing this battle. As users, we want better technology doing cooler things enabling us to do more. But the more we have, the more we rely on it, and the more complex these systems become. Complexity is the enemy of security. In fact, complexity is a nemesis of security, which is one of the main reasons why we’re losing this arms race. I’m going to get you up to speed on security bugs and vulnerabilities and how they affect your security. A security bug and a vulnerability are actually the same thing. So they’re synonyms for each other. So if I say security bug or vulnerability, it’s the same thing. And it’s an error. It’s an error written into software that creates a potential for a threat agent, such as a hacker, to exploit it. So an example might be the recent Heartbleed bug which you may have heard about because it was on mainstream news. This is a bug in something ...