Silent Patching: Harnessing LLMs to Detect Hidden Vulnerabilities

No ratings

Presented at RSAC 2025 by

Silent patching is when security vulnerabilities are patched without disclosure. This presents a blind spot for software supply chain security as security teams rely on public vulnerability databases like CVE or NVD. This session will introduce a novel approach to leveraging AI to scan public changelog data and identify hundreds of silently patched vulnerabilities.