In episode 99 of the Acceleration Economy Minute, Kieron Allen discusses Endor Labs and its new Dependency Management 2023 report. Endor Labs is on our Top 10 Shortlist of Cybersecurity leaders.
Highlights
00:44 — One of the key considerations in the report is the rise of Large Language Models (LLMs) and the ability of AI platforms powered by LLMs to classify malware risk. The report concludes that current LLMs can’t reliably assist in malware detection at scale; risk was accurately classified in just 5% of all cases.
01:15 — 45% of applications make no calls to security-sensitive APIs in their code base but, when dependencies are included, this drops to 5%. This demonstrates how organizations underestimate risk when they fail to analyze the use of APIs through open-source dependencies.
01:36 — Widespread implementation of ChatGPT and lack of historical data is a recipe for potential attacks. Endor Labs notes the “considerable harm” that can occur if the risks such new software introduces aren’t closely monitored. They can introduce malware and other risks in the software supply chain.




