heise online reports from Open Source Summit Europe in Prague that FINOS executive director Gabriele Columbro presented initial results from the OSERA Risk Navigator project, part of the Open-Source Enterprise Resiliency Alliance effort to help banks and other highly regulated organizations close security gaps in open source software. The article describes how a patch can take weeks, months or years to travel from a source repository into a bank’s production environment, and how institutions often clone, patch and re-sync software themselves without telling upstream, leaving components in a publicly unknown state. It says AI tools such as Claude Mythos have put the patching backlog on bank executives’ agendas by finding vulnerabilities in hours rather than months, and that Risk Navigator uses SBOMs to identify which files and libraries are vulnerable, prioritises remediation using CVSS, EPSS and CISA KEV data, and summarises the corrections so they can be planned operationally.
OSERA's Risk Navigator targets the open source patches that never reach banks
heise online reports from Open Source Summit Europe in Prague that FINOS executive director Gabriele Columbro presented initial results from the OSERA Risk Navigator project, part of the Open-Source Enterprise Resiliency Alliance effort to help banks and other highly regulated organizations close security gaps in open source software. The article describes how a patch can take weeks, months or years to travel from a source repository into a bank's production environment, and how institutions often clone, patch and re-sync software themselves without telling upstream, leaving components in a publicly unknown state. It says AI tools such as Claude Mythos have put the patching backlog on bank executives' agendas by finding vulnerabilities in hours rather than months, and that Risk Navigator uses SBOMs to identify which files and libraries are vulnerable, prioritises remediation using CVSS, EPSS and CISA KEV data, and summarises the corrections so they can be planned operationally.
Source: Heise