Uploaded August 2026 | Updated September 2026, 13 hours ago
Mor Weinberger (Echo, IL)
We analyzed CVE remediation patterns across 10,000 open‑source projects to understand a critical problem: the mean time to repair (MTTR) for vulnerabilities as they propagate through the ecosystem. Our research reveals a sobering reality — CVEs fixed upstream take weeks or months to reach downstream containers, creating massive security‑exposure windows in Kubernetes environments.
In this talk, we'll present our findings showing how CVE fixes flow (or stall) through different ecosystem layers — from upstream projects to package managers to base images to final containers. You'll see real data on remediation delays, bottlenecks, and the compounding effect of layered dependencies.
But we won't stop at the problem. The second half focuses on practical solutions. We'll demonstrate remediation strategies that actually work at scale, from automated patch backporting to in‑place image patching with tools like Copa. You'll learn how to build workflows that dramatically reduce MTTR, including dependency‑automation patterns and risk‑based prioritization.
Attendees will leave with both a data‑driven understanding of the CVE remediation challenge and a practical playbook for fixing it, complete with automation templates and proven patterns from the field.
---
Mor Weinberger is a Staff Software Engineer specializing in analyzing cloud-native security and supply chain threats. His efforts have uncovered a variety of emerging threats, including unsecured environments and platforms, as well as cryptomining campaigns. Additionally, he has collaborated with the Center for Internet Security (CIS) to develop guidelines for software supply chains and an open-source security tool to address these challenges.
Mor Weinberger (Echo, IL)
We analyzed CVE remediation patterns across 10,000 open‑source projects to understand a critical problem: the mean time to repair (MTTR) for vulnerabilities as they propagate through the ecosystem. Our research reveals a sobering reality — CVEs fixed upstream take weeks or months to reach downstream containers, creating massive security‑exposure windows in Kubernetes environments.
In this talk, we'll present our findings showing how CVE fixes flow (or stall) through different ecosystem layers — from upstream projects to package managers to base images to final containers. You'll see real data on remediation delays, bottlenecks, and the compounding effect of layered dependencies.
But we won't stop at the problem. The second half focuses on practical solutions. We'll demonstrate remediation strategies that actually work at scale, from automated patch backporting to in‑place image patching with tools like Copa. You'll learn how to build workflows that dramatically reduce MTTR, including dependency‑automation patterns and risk‑based prioritization.
Attendees will leave with both a data‑driven understanding of the CVE remediation challenge and a practical playbook for fixing it, complete with automation templates and proven patterns from the field.
---
Mor Weinberger is a Staff Software Engineer specializing in analyzing cloud-native security and supply chain threats. His efforts have uncovered a variety of emerging threats, including unsecured environments and platforms, as well as cryptomining campaigns. Additionally, he has collaborated with the Center for Internet Security (CIS) to develop guidelines for software supply chains and an open-source security tool to address these challenges.










