Supply Chain Vulnerabilities Are Accelerating

▶ Watch (0:12)

2025 saw roughly 48,000 new CVEs. Over 25,000 were disclosed in the first half alone. 38% scored critical or high on CVSS. Zero-day exploitation accelerated: 28% of exploits launched within 24 hours of disclosure, down from a month previously. AI weaponizes proofs-of-concept instantly. Yet the top two weaknesses remain cross-site scripting and SQL injection. OWASP Top 10 added a category for software supply chain failures.

Patching Alone Cannot Keep Up

▶ Watch (3:44)

Fewer than 50% of organizations have visibility beyond direct dependencies. Transitive dependency sprawl buries vulnerabilities in layers. Package A depends on B, B on C, C on a vulnerable package. Fixing requires every upstream author to patch and release. Inside an organization, patching demands testing, compliance approvals, and release cycles that take weeks. Ownership blurs: the library maintainer may not consume the library, so they have no incentive to patch.

WAF Mitigates the Gap

▶ Watch (9:18)

A web application firewall inspects HTTP traffic at L7 and blocks malicious payloads. Migo Security research found WAFs mitigate 48% of CVEs out-of-box. With fine-tuning to a specific stack – PHP rules for PHP, Node rules for Node – coverage reaches 80–90%. Virtual patching distributes a fix across the entire infrastructure instantly. Anomaly scoring gives a graded response instead of binary block. Paranoia levels trade false positives for depth of protection.

The Future: Dynamic Rules and Active Monitoring

▶ Watch (36:43)

Static rules fail when AI generates dynamic payloads that mutate to bypass regexes. WAFs need rules that evolve based on evaluation feedback. Rules must be specialized for lambda, microservices, messaging, and WebAssembly. Perimeter defense is not going away but the perimeter itself is shifting. Deploying a WAF and hoping for the best is not a strategy. Audit logs and metrics must be watched continuously. Learn, change rules, deploy again. That cycle is the only way to get actual value.

Notable Quotes

28% of the exploits were launched within 24 hours. José Carlos Chávez · ▶ Watch (3:12)

The top two weakness remain being cross-site scripting and SQL injection. José Carlos Chávez · ▶ Watch (4:09)

You cannot patch all CVEs reported in your system despite what your scanners says. José Carlos Chávez · ▶ Watch (42:16)

Deploying a WAF and hope for the best is not enough. Like hope is not a strategy. José Carlos Chávez · ▶ Watch (44:02)

Most of the internet and most of the software that is being created in the industry rely on the building blocks, which is open source software. José Carlos Chávez · ▶ Watch (5:26)

Key Takeaways

  • WAFs mitigate 48% of CVEs out-of-box and up to 90% with stack-specific tuning.
  • Transitive dependencies and ownership conflicts make patching too slow for supply chain threats.
  • Active monitoring of WAF metrics and dynamic rule updates are essential to keep up with AI-driven attacks.

About the Speaker(s)

José Carlos Chávez is a Security Software Engineer at Okta, an OWASP Coraza co-leader and a Mathematics student at the University of Barcelona. He enjoys working in Security, compiling to WASM, designing APIs and building distributed systems. While not working with code, you can find him sipping on kombuchas or enjoying his children.