Events Archives - Phoenix Security
Category: Events
- 5th August 2026
Phoenix Security Launches the Exploit Hunt: A Threat-Model-Led AI Red Team That Attacks Your Code and Proves the Exploit
Phoenix Security releases Exploit Hunt at Black Hat USA 2026 — an AI red team that takes targets from a live threat model and reports a finding only after writing and validating a runnable proof-of-concept exploit. Available in Phoenix Purple now.
Francesco Cipollone
- 5th August 2025
AI Meets Application Security: Phoenix Security Steals the Show at OWASP London
Phoenix Security lit up OWASP London with a powerful session on ASPM, threat-centric AI agents, and risk-based remediation strategies. Human-first, AI-second isn’t just a philosophy — it’s the future of DevSecOps.
- 27th April 2025
ASPM at Two Speeds: Remediation Strategies for Every Security Journey & CVE/NVD Collapse
The journey of securing an organization’s application landscape varies dramatically, depending on where a company stands in its maturity. Early-stage startups with small security teams face challenges not only with vulnerabilities but also with scaling their security processes in line with their growth. On the flip side, established enterprises struggle with managing complex environments, prioritizing remediation, and dealing with vast amounts of vulnerabilities while staying ahead of sophisticated threats.
For startups, the focus is clear—establish visibility and ensure core security practices are in place. Application Security Posture Management (ASPM) tools provide a straightforward, automated approach to detecting vulnerabilities and enforcing policies. These solutions help reduce risk quickly without overburdening small security teams.
Mature organizations, on the other hand, are tackling a different set of problems. With the sheer number of vulnerabilities and an increasingly complicated threat landscape, enterprises need to fine-tune their approach. The goal shifts toward intelligent remediation, leveraging real-time threat intelligence and advanced risk prioritization. ASPM tools at this stage do more than just detect vulnerabilities—they provide context, enable proactive decision-making, and streamline the entire remediation process.
The emergence of AI-assisted code generation has further complicated security in both environments. These tools, while speeding up development, are often responsible for introducing new vulnerabilities into applications at a faster pace than traditional methods. The challenge is clear: AI-generated code can hide flaws that are difficult to catch in the rush of innovation. Both startups and enterprises need to adjust their security posture to account for these new risks. ASPM platforms, like Phoenix Security, provide automated scanning of code before it hits production, ensuring that flaws don’t make it past the first line of defense.
Meanwhile, organizations are also grappling with the backlog crisis in the National Vulnerability Database (NVD). A staggering number of CVEs remain unprocessed, leaving many businesses with limited data on which to base their patching decisions. While these delays leave companies vulnerable, Phoenix Security steps in by cross-referencing CVE data with known exploits and live threat intelligence, helping organizations stay ahead despite the lag in official vulnerability reporting.
Whether just starting their security program or managing a complex infrastructure, organizations need a toolset that adapts with them. Phoenix Security enables businesses of any size to prioritize vulnerabilities based on actual risk, not just theoretical impact, helping security teams navigate the evolving threat landscape with speed and accuracy.
Francesco Cipollone
- 6th February 2025
Event Recap: Phoenix ASPM + OWASP NYC – WTH is Reachability analysis Path to 0 real critical
Are never-ending critical alerts leaving you scrambling? Explore how reachability analysis identifies vulnerabilities that truly matter, saving your teams from needless patch frenzies. This session, hosted by the OWASP NYC Chapter, uncovers the latest insights in ASPM, remediation techniques, and application security best practices. Attendees learn how to streamline vulnerability management through practical examples, advanced risk scoring, and live demonstrations of container-based architectures. Expect lively discussions, real-world success stories, and expert tips on targeting only the exploitable weaknesses—rather than chasing every single alert in your backlog.
Francesco Cipollone
- 3rd February 2025
Modern AppSec Webinar Recap: Tackling Vulnerabilities, Regulatory Shifts, and Root Cause Analysis an ASPM perspective
The cybersecurity landscape is evolving rapidly, demanding a threat-centric, risk-based approach to vulnerability management. With the U.S. favoring voluntary guidelines and Europe enforcing stricter regulations, organizations must navigate compliance while focusing on real exploitability over CVE volume. This blog delves into ASPM, cloud security, and regulatory intelligence, exploring how businesses can move beyond the traditional patch-and-pray model to address root cause vulnerabilities before they become critical risks.
Francesco Cipollone
- 21st July 2024
Infosecurity Europe 2024: What a great event to reconnect with friends, community, sign books
Discover the highlights of Phoenix Security’s participation at Infosecurity Europe 2024, including community engagement, innovative talks on ASPM and vulnerability management, and a successful book signing event.
Francesco Cipollone
- 8th May 2023
Shift Smart, Shift Left, Shift Everywhere: a comprehensive approach to vulnerability management in application security
Shift Left has been the classical approach to application security, shifting smart by involving the business and adopting a risk-based approach is the next frontier
Francesco Cipollone
- 3rd May 2023
Application Security Weekly: Francesco Cipollone on shifting smart and shifting everywhere
Francesco Cipollone Talks on Application Security Weekly on shifting left and shifting smart and how to move from SLA based approach into a risk-based
Francesco Cipollone
- 5th December 2022
AppSec Phoenix LIVE STREAM @ BLACK HAT Europe – Fireside Chat on Application & Cloud Security
Phoenix Security will be at black hat Europe with Application and cloud security unified into an actionable risk-based contextual view.
We will host a raffle on the day and announce the winners on both days. Ask us about Phoenix Security, decipher the cypher and win a special prize. Decipher the code, come and win the special price
Francesco Cipollone
- 13th November 2022
APPSEC PHOENIX CVE, CWE, CONTEXT IS QUEEN, VULNERABILITY PRIORITIZATION IS QUEEN talk at Open Security Summit London
Phoenix Security CEO Francesco Cipollone will be talking at the Open Security Summit in London. Vulnerability tooling is increasing, security advisories are faster, and teams are leaner. Have we lost the battle of vulnerabilities, is the shift left and the view that ‘security is everyone’s problem working?
Francesco Cipollone
- 13th November 2022
APPSEC PHOENIX CVE, CWE, CONTEXT IS QUEEN, VULNERABILITY PRIORITIZATION IS QUEEN talk at London DevSecOps
Phoenix Security CEO Francesco Cipollone will be talking at the London DevSecOps meetup.Vulnerability tooling is increasing, security advisories are faster, and teams are leaner. Have we lost the battle of vulnerabilities, is the shift left and the view that ‘security is everyone’s problem working?
Francesco Cipollone
- 11th November 2022
APPSEC PHOENIX WILL BE LIVESTREAMING AT BLACK HAT FIRESIDE CHAT ON APPLICATION AND CLOUD SECURITY
Francesco Cipollone