Beyond CVEs: Uncovering the Hidden Threat of End‑of‑Life Software

00:00
/
00:00
Security teams are conditioned to chase CVEs—but what about the vulnerabilities that aren’t patchable, or aren’t even disclosed? In this talk, we’ll explore how End-of-Life (EOL) software creates a dangerous blind spot in modern security programs. From packages quietly abandoned by maintainers to high-risk libraries with no upgrade path, we’ll examine how unsupported components persist across CI/CD pipelines, SBOMs, and production environments—often long after they’ve been forgotten.
