Phoenix Security Features – October 2023 – Risk-based formula, Magnitude, Application Security & Vulnerability Management Improvement

The Cloud Security and AppSec teams at Phoenix Security are pleased to bring you another set of new Phoenix Security features and improvements for vulnerability management across application and cloud security engines. This release is full of key additions and progress across multiple areas of the platform.

We are sure that you’ll find these quite interesting!

  • Asset and Vulnerability Management
    • Cyber Risk Navigation Graph
    • Improved Vulnerability Triage with Grouping
    • Improved CISA KEV Identification and Filtering
    • Link Finding to Scanner’s Page
    • Improved Exploitability and Fixability Data
  • Risk-based Posture Management
    • Risk Exception and Mitigation Flow
    • Edit Component Asset Selection Rules
  • Integrations
    • Microsoft Defender for Endpoint
    • Added Lacework Cloud support
    • Added Item Type option to ADO integration
  • Other Improvements
    • Improved Cloud Account Visualisation
    • User control of Notifications and Email Alerts
    • And Many More


Asset and Vulnerability Management

Cyber Risk Navigation Graph

As organisations model their cybersecurity landscape in Phoenix Security, getting a birds-eye view of the overall set of applications and environments becomes increasingly important. With the new navigation graph, it’s now easier to get an overview of your applications, environments and their components. From there, you can quickly find the one of interest, jump to its details, or edit it.

Improved Vulnerability Triage with Grouping

One of the core areas of Phoenix Security’s user interface is its Vulnerabilities screen. Here users can find every single finding affecting their assets, search and filter, and act on them by opening tickets or requesting risk exceptions.

However, sometimes, getting lost amongst many similar findings can be easy, especially when the same vulnerability affects multiple assets. However, with the new views introduced to the Vulnerability screen, users can group findings by their vulnerability definition (e.g. CVE or scanner vulnerability ID) or by the location affected by the asset where location can be a more specific place within a wider asset (e.g. a file and line within a repository).

Improved CISA KEV Identification and Filtering

Phoenix Security is constantly checking your vulnerabilities against the CISA Known Exploited Vulnerabilities catalogue in order to flag those assets affected by any of these vulnerabilities.

With this new release we are surfacing this information for individual findings and making sure that users can quickly find them by including system-generated tags to support flexible filtering.

Link Finding to Scanner’s Page

Continuing with the theme of improved triaging capabilities, at Phoenix, we want to ensure that users have quick and easy access to all the vulnerability details they might need. More often than not, these details are available within the platform. Still, sometimes, users might want to have a look at the original vulnerability report in the scanner’s own user interface.

This is why we have started to include links to the vulnerability’s scanner page within the Phoenix user interface and in the details of the tickets open from the platform.

Improved Exploitability and Fixability Data

One of the key features of the Phoenix platform is its ability to provide additional details and context for the vulnerabilities reported by external scanners. When it comes to exploitability and fixability, we are going beyond the scanner data and extracting additional intelligence from the CISA-KEV catalogue and the vulnerability’s CVSS vector.

This ensures that exploitability and fixability details are as accurate as possible.

Risk-based Posture Management

Risk Exception and Mitigation Flow

Management of False Positive exceptions, with request/approval flow, has been part of Phoenix for quite some time now. In this release, we take risk exceptions management to the next level by introducing Risk Mitigation alongside the existing false positive option.

The new exception options allow users to partially mitigate vulnerability risks and define an expiration date for the mitigation. This allows for much more fine-grained control over the extent and duration of the exception.

Furthermore, we are releasing bulk acceptance and rejection functionality alongside the creation of bulk exception requests – which was already possible in Phoenix. This will allow security approvers to deal with groups of requests requiring similar treatment easily.

Edit Component Asset Selection Rules

With the release of the asset multi-assignment functionality, now it’s possible to edit existing asset selection (or aggregation) rules without the inconvenience of being unable to see previously selected assets during the process.

So far, it was possible to achieve the update effect by creating a new rule and deleting the old one. Now, users can edit existing rules directly and modify the conditions that match the right subset of assets for their applications and environments.

Integrations

Microsoft Defender for Endpoint

In this iteration we are extending the scope of our native integration with Microsoft/Azure vulnerability sources by adding Microsoft Defender for Endpoint to our extensive list of integrations. Check out the Microsoft detailed article for all the features and integration.

Added Lacework Cloud support

Another addition to our native integration capabilities is Lacework Cloud scanning.

In this case, users don’t have to configure a new integration since Lacework uses the same API credentials for Container and Cloud vulnerabilities. The scanner integration will now offer both container and cloud targets for vulnerability fetching if Lacework is scanning them. Check out the detailed article on Lacework integration.

Added Item Type option to ADO integration

Azure DevOps ticketing functionality allows users to create different types of “items” to represent traceable actions. By default, the type of item is “Issue”, but in some cases, organisations use a different type, whether from the standard catalogue or a custom one.

Now, Phoenix supports this use case by allowing users to define the type of ADO item that represents issue tickets. This new field is optional and returns to the default “Issue” type if left blank. Check out the Microsoft detailed article for all the features and integration.

Other Improvements

Improved Cloud Account Visualisation

Even though cloud account IDs are an everyday item in the life of many security engineers, it is much easier to identify cloud accounts by their friendly name or label.

With this release, and whenever the information is available from the source scanner, Phoenix platform always displays the account’s label in lists and filters – while internally working with the unique IDs that are required for accurate identification.

User control of Notifications and Email Alerts

At Phoenix, we are always mindful of the notifications that everybody gets every day. That’s why our email notifications and alerts have a conservative frequency.

However, sometimes that’s not enough, and users want to be able to disable notifications.

We release the first step by allowing users to disable notifications through their user profile configuration.

Other Improvements

  • Improved risk calculation and vulnerability selection for False Positive/Risk Mitigation flow to cover some edge cases.
  • Improved findings selection logic for non-fixable vulnerabilities to cover some edge cases.
  • Improved the Vulnerability density factor for asset risk calculation to cover some edge cases.
  • Now users can edit the Default Application and Environments to better suite their usage of these default asset holders.
  • Keep issue tickets updated when vulnerabilities are closed or Risk Mitigated, with details of the changes happening in the Phoenix platform.
  • Improved filtering by date ranges, with open and closed ranges at both ends.

Get in control of your Application Security posture and Vulnerability management

Alfonso brings experience running international teams for multi-million dollar, technologically advanced projects for Telefónica, IBM and Vodafone. Alfonso joins with two decades of experience working for tech leaders, including at Dell EMC, Yahoo! and Intershop.

Discuss this blog with our community on Slack

Join our AppSec Phoenix community on Slack to discuss this blog and other news with our professional security team

From our Blog

Phoenix Security has completed its SOC 2 Type 2 report, reinforcing our ISO 27001 and data privacy commitments. Our Actionable ASPM helps teams cut noise and ship fixes that matter, powered by reachability analysis, contextual deduplication, and human-aligned AI agents. Customers like ClearBank, Bazaarvoice, and Integral Ad Science report double-digit reductions in criticals and massive time savings. If you need verifiable trust and faster remediation across code-to-cloud, Phoenix Security turns risk data into a single, prioritized backlog that engineering actually executes.
Francesco Cipollone
Most enterprises drown in vulnerability data yet starve for attribution. By mapping ownership, location, exposure, and business impact, Phoenix Security’s ASPM turns that swamp into a laser‑focused task list. Only then do three autonomous agents—Researcher, Analyzer, and Remediator—kick in, collaborating to recommend fixes and workflow automation that 10× security‑engineering output. Skip the context and you’ll waste money, requests, tokens, carbon, and human patience on hallucinated advice. For startups, the focus is clear—establish visibility and ensure core security practices are in place. Application Security Posture Management (ASPM) tools provide a straightforward, automated approach to detecting vulnerabilities and enforcing policies. These solutions help reduce risk quickly without overburdening small security teams. Mature organizations, on the other hand, are tackling a different set of problems. With the sheer number of vulnerabilities and an increasingly complicated threat landscape, enterprises need to fine-tune their approach. The goal shifts toward intelligent remediation, leveraging real-time threat intelligence and advanced risk prioritization. ASPM tools at this stage do more than just detect vulnerabilities—they provide context, enable proactive decision-making, and streamline the entire remediation process. The emergence of AI-assisted code generation has further complicated security in both environments. These tools, while speeding up development, are often responsible for introducing new vulnerabilities into applications at a faster pace than traditional methods. The challenge is clear: AI-generated code can hide flaws that are difficult to catch in the rush of innovation. Both startups and enterprises need to adjust their security posture to account for these new risks. ASPM platforms, like Phoenix Security, provide automated scanning of code before it hits production, ensuring that flaws don’t make it past the first line of defense. Meanwhile, organizations are also grappling with the backlog crisis in the National Vulnerability Database (NVD). A staggering number of CVEs remain unprocessed, leaving many businesses with limited data on which to base their patching decisions. While these delays leave companies vulnerable, Phoenix Security steps in by cross-referencing CVE data with known exploits and live threat intelligence, helping organizations stay ahead despite the lag in official vulnerability reporting. Whether just starting their security program or managing a complex infrastructure, organizations need a toolset that adapts with them. Phoenix Security enables businesses of any size to prioritize vulnerabilities based on actual risk, not just theoretical impact, helping security teams navigate the evolving threat landscape with speed and accuracy.
Francesco Cipollone
Shai Hulud weaponised npm’s trust model: stolen maintainer creds, poisoned tarballs, and stealthy GitHub Actions that exfiltrate secrets and persist in CI. 500+ packages were touched in days, starting with @ctrl/tinycolor. This analysis maps the blast radius and delivers a practical remediation plan—pin versions, block direct npm with a proxy, rotate tokens, and strip backdoor workflows—grounded in ASPM and reachability.
Francesco Cipollone
A coordinated npm compromise hit @ctrl/tinycolor and dozens of related packages. The payload auto-trojanizes maintainers’ projects, scans for GitHub/NPM/cloud creds using TruffleHog, plants a backdoor GitHub Actions workflow, and exfiltrates to a webhook. This piece breaks down the attack chain and lays out decisive DevSecOps and ASPM actions to contain and harden.
Francesco Cipollone
Derek

Derek Fisher

Head of product security at a global fintech

Derek Fisher – Head of product security at a global fintech. Speaker, instructor, and author in application security.

Derek is an award winning author of a children’s book series in cybersecurity as well as the author of “The Application Security Handbook.” He is a university instructor at Temple University where he teaches software development security to undergraduate and graduate students. He is a speaker on topics in the cybersecurity space and has led teams, large and small, at organizations in the healthcare and financial industries. He has built and matured information security teams as well as implemented organizational information security strategies to reduce the organizations risk.

Derek got his start in the hardware engineering space where he learned about designing circuits and building assemblies for commercial and military applications. He later pursued a computer science degree in order to advance a career in software development. This is where Derek was introduced to cybersecurity and soon caught the bug. He found a mentor to help him grow in cybersecurity and then pursued a graduate degree in the subject.

Since then Derek has worked in the product security space as an architect and leader. He has led teams to deliver more secure software in organizations from multiple industries. His focus has been to raise the security awareness of the engineering organization while maintaining a practice of secure code development, delivery, and operations.

In his role, Jeevan handles a range of tasks, from architecting security solutions to collaborating with Engineering Leadership to address security vulnerabilities at scale and embed security into the fabric of the organization.

Jeevan Singh

Jeevan Singh

Founder of Manicode Security

Jeevan Singh is the Director of Security Engineering at Rippling, with a background spanning various Engineering and Security leadership roles over the course of his career. He’s dedicated to the integration of security practices into software development, working to create a security-aware culture within organizations and imparting security best practices to the team.
In his role, Jeevan handles a range of tasks, from architecting security solutions to collaborating with Engineering Leadership to address security vulnerabilities at scale and embed security into the fabric of the organization.

James

James Berthoty

Founder of Latio Tech

James Berthoty has over ten years of experience across product and security domains. He founded Latio Tech to help companies find the right security tools for their needs without vendor bias.

christophe

Christophe Parisel

Senior Cloud Security Architect

Senior Cloud Security Architect

Chris

Chris Romeo

Co-Founder
Security Journey

Chris Romeo is a leading voice and thinker in application security, threat modeling, and security champions and the CEO of Devici and General Partner at Kerr Ventures. Chris hosts the award-winning “Application Security Podcast,” “The Security Table,” and “The Threat Modeling Podcast” and is a highly rated industry speaker and trainer, featured at the RSA Conference, the AppSec Village @ DefCon, OWASP Global AppSec, ISC2 Security Congress, InfoSec World and All Day DevOps. Chris founded Security Journey, a security education company, leading to an exit in 2022. Chris was the Chief Security Advocate at Cisco, spreading security knowledge through education and champion programs. Chris has twenty-six years of security experience, holding positions across the gamut, including application security, security engineering, incident response, and various Executive roles. Chris holds the CISSP and CSSLP certifications.

jim

Jim Manico

Founder of Manicode Security

Jim Manico is the founder of Manicode Security, where he trains software developers on secure coding and security engineering. Jim is also the founder of Brakeman Security, Inc. and an investor/advisor for Signal Sciences. He is the author of Iron-Clad Java: Building Secure Web Applications (McGraw-Hill), a frequent speaker on secure software practices, and a member of the JavaOne Rockstar speaker community. Jim is also a volunteer for and former board member of the OWASP foundation.

Join our Mailing list!

Get all the latest news, exclusive deals, and feature updates.

The IKIGAI concept
x  Powerful Protection for WordPress, from Shield Security
This Site Is Protected By
ShieldPRO