Breaking
March 12, 2025

Businesses are struggling to address vulnerabilities hidden in phantom dependencies udinmwenefosa@gmail.com (Efosa Udinmwen) | usagoldmines.com


  • Hidden dependencies pose unseen risks in modern software systems, says report
  • Function-level analysis slashes unnecessary vulnerability fixes by 90%
  • Advisory delays leave systems exposed to potential exploitations

As organizations increasingly rely on third-party components and open source libraries to accelerate development processes, experts have warned addressing the security risks associated with these dependencies has become a significant priority.

Endor Labs’ 2024 Dependency Management Report explores the evolving challenges in managing software dependencies and vulnerabilities, and analysis of seven programming languages (Java, Python, Rust, Go, C#, .NET, Kotlin, and Scala) found fewer than 9.5% of vulnerabilities in 2024 were considered ‘real threats’.

“A lot of organizations are struggling with managing dependency risks,” noted Darren Meyer, staff research engineer at Endor Labs. “They’re drowning in vulnerability alerts, many of which don’t represent relevant risk; researching the alerts is expensive for security teams (and software teams), and trying to fix everything is even more expensive.”

Dependency management

Managing dependencies is not a simple task as most software projects rely on multiple layers of dependencies, including first-party code libraries, frameworks, and operational dependencies that support production environments, creating a web of interconnected components – and any vulnerability within this web could expose an organization to significant security risks.

The use of third-party components, particularly open source software, is a common practice in modern software development because it reduces the time developers need to spend writing foundational code, offering pre-built functionalities that accelerate development cycles – but also brings unique security challenges due to vulnerabilities in these external components.

Many security issues stem from “phantom dependencies,” or hidden components that are not explicitly documented in the software’s code, and can introduce vulnerabilities that traditional tools fail to detect.

These vulnerabilities aren’t helped by the fact that nearly 70% of advisories issued by vulnerability management platforms, such as NIST’s NVD, are published after the corresponding security patch is released, with a median delay of 25 days.

Endor also claims that almost half of the advisories in public vulnerability databases lack code-level details, while only 2% provide function-specific vulnerability information, making it difficult for security teams to determine whether known vulnerabilities can be exploited in their applications.

In addition, Endor analysis from 1,250 updates from vulnerable to non-vulnerable versions shows that 24% of fixes require a major version update while 6% of vulnerabilities could be fixed with minor or patch-level updates.

Endor therefore argues that not all vulnerabilities pose the same level of risk, with organizations being advised to focus on the most reachable and exploitable vulnerabilities, as only about 9.5% of vulnerabilities in dependencies are exploitable at the function level.

Reachability analysis, which determines whether a vulnerable function in a dependency is called by the application’s code, emerges as one of the most effective methods for reducing the noise in vulnerability reporting. By focusing on vulnerabilities that have a clear path to being exploited, organizations can reduce their remediation efforts by nearly 90%, according to the report.

You may also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

This nightmarish $35K computer is powered by a lab-grown human brain | usagoldmines.com

Google Finds Fix for Chromecast 2nd Gen and Chromecast Audio Issue, Says Not to Factory Reset Kellen...

My Favorite Podcast App Now Has a Free Web Player Joel Cunningham | usagoldmines.com

The 10 Best Hidden AirTags Features Pranay Parab | usagoldmines.com

Apple rushed Apple Intelligence and now the company is stuck playing catch up | usagoldmines.com

Struggling with slow Google Messages photo transfers? Google says new update will make 'noticeable d...

JBL's new Bluetooth speakers bring all the upgrades I most wanted to see, and they're coming soon |...

Apple Photos could actually win you over in iOS 18.4 – here are 4 improvements that are coming rowan...

Google updates Chrome extension rules to ban affiliate link injection without user action or benefit...

iRobot says there is “substantial doubt” about it as a “going concern” Kevin Purdy | usagoldmines.co...

Tested: AMD’s new Ryzen 9 9950X3D absolutely dominates | usagoldmines.com

Addlink S93/A93 SSD review: Good value if you skip the heatsink | usagoldmines.com

Big March patch fixes dozens of security flaws in Windows and Office | usagoldmines.com

In wake of scandal, Google clamps down on Chrome shopping extensions | usagoldmines.com

Pokemon GO Gets a New Owner Kellen | usagoldmines.com

The Best New Features in Samsung One UI 7 David Nield | usagoldmines.com

What to Expect From Apple's Studio Display 2 Joe Rossignol | usagoldmines.com

$14,000 Mac Studio With 512GB RAM Facing Two-Week Delivery Delay Joe Rossignol | usagoldmines.com

Amazon Has All-Time Low Prices on AirTag 4-Pack ($64.49) and Apple Pencil Pro ($99) Mitchel Broussar...

UK cybersecurity sector could be worth £13bn, research shows | usagoldmines.com

Android 16 could bring an improved Samsung DeX-style desktop mode to more phones jamie.richards@futu...

ChatGPT just wrote the most beautiful short story, and I wonder what I'm even doing here lance.ulano...

Nvidia could unleash RTX 5060 and 5060 Ti GPUs on PC gamers tomorrow, but there’s no sign of rumored...

'There's a reason why we do it': The Wheel of Time showrunner responds to fans who are still upset o...

This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked | usago...

Hackers are abusing $TRUMP tokens to lure victims in to new phishing scam | usagoldmines.com

Quordle hints and answers for Thursday, March 13 (game #1144) | usagoldmines.com

NYT Strands hints and answers for Thursday, March 13 (game #375) | usagoldmines.com

NYT Connections hints and answers for Thursday, March 13 (game #641) | usagoldmines.com

Outdated ID verification myths put businesses at risk | usagoldmines.com

Microsoft’s Remote Desktop app becomes the Windows App | usagoldmines.com

Toyota tunes up bZ4x with new battery, more power Jonathan M. Gitlin | usagoldmines.com

Best home office monitors 2025: Displays that get the job done | usagoldmines.com

Best external drives 2025: Backup, storage, and portability | usagoldmines.com

Best laptops 2025: Premium, budget, gaming, 2-in-1s, and more | usagoldmines.com

Upgrade your desk with this triple monitor arm mount, now 20% off | usagoldmines.com

Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

New to Bluesky? Do these 7 things to make the most of it | usagoldmines.com

Aargh! Your USB flash drive is stuck in read-only. Here’s what to do | usagoldmines.com

Microsoft's Latest Update Patches 57 Security Vulnerabilities Emily Long | usagoldmines.com

This Solar-Powered, Subscription-Free Eufy Security Camera Is $100 Right Now Pradershika Sharma | us...

Apple Adds Disclosure About Delayed Siri Features to iPhone 16 Pages Joe Rossignol | usagoldmines.co...

New M4 MacBook Air Gets $50 Launch Day Discounts at Amazon, Available From $949 Mitchel Broussard | ...

Apple fixes dangerous zero-day used in attacks against iPhones and iPads | usagoldmines.com

This 10K power bank with built-in USB-C cable is only $20 (36% off) | usagoldmines.com

Whoa! This portable monitor is now $60, the lowest price we’ve seen | usagoldmines.com

Apple Upgrades CarPlay in Two Ways Joe Rossignol | usagoldmines.com

Samsung's Android XR headset could avoid the Apple Vision Pro's biggest mistake, according to this l...

Disney+ is making Andor free to stream on YouTube, and now you have no excuse not to watch the best ...

Many workers aren't sure how much their companies are set up to help them be productive | usagoldmi...

The Google Pixel 10 could get a big camera boost if this new leak is legit jamie.richards@futurenet....

Asus ROG Flow Z13 (2025) review: A gaming tablet outclassed by its rivals | usagoldmines.com

New MacBook Air, Mac Studio, iPads Now Available for In-Store Pickup Tim Hardwick | usagoldmines.com

Building a strong digital culture relies on investing in your people and your tech | usagoldmines.c...

Virgin Media O2 reveals £700m network transformation plan to boost reliability across the board | u...

Four key questions to strengthen your cyber threat detection strategy | usagoldmines.com

7 of my favorite upgrades in the all-new Roomba robovacs – plus 2 I'm worried about | usagoldmines....

The Samsung Galaxy S25 Edge is being tipped to come with a sweet Google Gemini deal | usagoldmines....

Daredevil: Born Again episode 3 contains another Marvel reference to Spider-Man, but it's got nothin...

Big Rivian update delivers hands-off driving to rival Tesla Autopilot –and a new 'Rally' mode | usa...

It's just a concept for now, but this RTX 5090 liquid-cooled gaming laptop is possibly the craziest ...

iPhone 17 Air Reportedly 9.5mm Thick Including Camera Bump Tim Hardwick | usagoldmines.com

Daredevil: Born Again episode 3's shocking final scene is a big misdirect, and I've got the evidence...

Chromecasts are still broken – but Google tells fuming owners not to factory reset their devices | ...

Monster Hunter Wilds best graphics settings for PS5, PS5 Pro, and Xbox Series X | usagoldmines.com

Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers alexblake.t...

ChatGPT wants to write your next novel, and readers and writers alike should be very worried john-an...

Monster Hunter Wilds best controller settings | usagoldmines.com

Fed up of adverts creeping into Windows 11? You won’t like Microsoft’s latest update, then, although...

France rejects controversial encryption backdoor provision chiara.castro@futurenet.com (Chiara Castr...

This renter-friendly smart lock fits over your existing door hardware, and costs less than you might...

iPhone 17 Pro to Use Advanced Cooling System for Better Performance Tim Hardwick | usagoldmines.com

UK workers are spending more than one day per week tracking down information | usagoldmines.com

You season 5: everything we know so far about the twisted Netflix show’s return | usagoldmines.com

iRobot is overhauling its entire robovac range, and for the first time in years I'm excited about a ...

Hitman: World of Assassination hits PSVR 2 soon, finally giving you a reason to dust off your headse...

New figures claim the smartwatch market just shrunk for the first time ever, and the Apple Watch Ult...

There’s a way to get Microsoft apps without a Microsoft subscription | usagoldmines.com

How AI can help the UK’s scale-ups realize the growth agenda | usagoldmines.com

T-Mobile rival is giving free ChatGPT Plus, worth hundreds, to its subscribers - but there's a catch...

I test AI agents for a living and these are the 5 reasons you should let tools like ChatGPT Deep Res...

I compared Manus AI to ChatGPT – now I understand why everyone is calling it the next DeepSeek erich...

Despite everything, US EV sales are up 28% this year Jonathan M. Gitlin | usagoldmines.com

Metallica Immersive Concert Experience Coming to Apple Vision Pro Juli Clover | usagoldmines.com

Apple Account Cards in Wallet Expanding to More Countries Juli Clover | usagoldmines.com

iPad Air M3 review roundup– should you buy Apple's new mid-range tablet? mark.wilson@futurenet.com (...

Pocket Casts makes its web player free, takes shots at Spotify and AI Kevin Purdy | usagoldmines.com

New Macs and iPads Begin Arriving to Customers Around the World Juli Clover | usagoldmines.com

Now HP printers are being bricked following firmware update | usagoldmines.com

Apple Vision Pro goes off to never never land with Metallica concert footage lance.ulanoff@futurenet...

OpenAI pushes AI agent capabilities with new developer API Benj Edwards | usagoldmines.com

X’s globe-trotting defense of ads on Nazi posts violates TOS, Media Matters says Ashley Belanger | u...

Google: We’re Working On That ‘Receiving Media’ Issue in Messages Tim | usagoldmines.com

Seven Home Improvement Projects You Can Get Done in One Day Jeff Somers | usagoldmines.com

Bluesky Now Lets You Hide DMs From Strangers Pranay Parab | usagoldmines.com

Texas measles outbreak spills into third state as cases reach 258 Beth Mole | usagoldmines.com

How whale urine benefits the ocean ecosystem Jennifer Ouellette | usagoldmines.com

Leaked GeForce RTX 5060 and 5050 specs suggest Nvidia will keep playing it safe Andrew Cunningham | ...

Apple patches 0-day exploited in “extremely sophisticated attack” Dan Goodin | usagoldmines.com

Microsoft’s Remote Desktop app is going away | usagoldmines.com

Leave a Reply