# Modern Vulnerability Management

[Watch Now](/content/resources/webinars/modern-vulnerability-management#onDemand/index.html)

As applications continue to rely on large and complex open source dependency chains, security teams face growing challenges in identifying, prioritizing, and addressing risks effectively. Explore why traditional approaches to vulnerability management are struggling to keep pace with the realities of modern software development. In this fireside chat, industry experts examine the underlying issues and discuss practical strategies for managing vulnerabilities in today’s fast-moving software ecosystems.

Modern Vulnerability Management

Modern Vulnerability Management

Dave Welch, Chief Software Architect • HeroDevs AND Brian Fox, CTO • Sonatype AND Christopher Robinson, Chief Security Architect • OpenSSF

Watch now

Feb 23 2026 | 49 mins

Modern vulnerability management is breaking down, not because teams aren't scanning, but because the system itself no longer supports reliable remediation.

End-of-life (EOL) dependencies are becoming a structural flaw in modern enterprise stacks. Once a release line is out of maintenance, upstream fixes stop, turning ordinary CVEs into permanent exposure. With 5–15% of components in enterprise dependency graphs already EOL, organizations face a growing blind spot where advisory coverage degrades and risks are undercounted.

In this session featuring experts from Sonatype, HeroDevs, and OpenSSF, we unpack the 2025 data behind avoidable vulnerability consumption, failing vulnerability intelligence, and the structural risks of abandoned software.

Join us to explore real-world telemetry on:
- The Persistence of Fixable Risks: Why most vulnerable components being downloaded today already have safer versions available.
- The "Forever Risk" of EOL: How end-of-life dependencies transform manageable vulnerabilities into permanent security debts.
- The AI Multiplier: Why AI-assisted development often amplifies the consumption of outdated and vulnerable components.
- Beyond "Scan and Patch": Practical strategies for when traditional remediation paths are closed.

This is a practical conversation for leaders navigating vulnerability risk that can’t simply be patched away.

## Featured Speakers

### Dave Welch
Chief Software Architect, Herodevs

### Brian Fox
CTO, Sonatype

### Christopher Robinson
Chief Security Architect, OpenSSF
