The DefectDojo Blog

Practitioner writing on vulnerability management, from the team that builds DefectDojo.

How-tos, product deep dives, and hard lessons from running security programs at scale. Written by the people who ship the platform, not a content team.

LatestUpdated Aug 18, 2026

Latest

The newest writing from the team: what we are shipping, what we are seeing in the field, and what it means for your program.

SecuritySep 23, 2026, 11:06:14 AM You've been lied to about security

You have been lied to about security. Not by the attackers. By the people selling you the fix.

GREG ANDERSONGREG ANDERSON
Getting Started with DefectDojo in 10 Minutes or Less Vulnerability ManagementSep 7, 2026, 9:00:00 AM Getting Started with DefectDojo in 10 Minutes or Less

Getting started with a new security platform can feel like a project in itself. Adding new scans, setting up reporting, and making sense of myriad new features is an involved and time-consuming process, especially without disrupting your current workflows. I was prepared for the same difficulties when I began using DefectDojo, but I’ve been pleasantly surprised to learn that they take a different approach: instead of asking you to change your processes to adapt to their tools, their tools adapt to your existing processes.

Dan GoelzDan Goelz
Your Triage Work is Now an Export: SBOMs and VEX from DefectDojo Pro Vulnerability ManagementSep 1, 2026, 8:00:03 AM Your Triage Work is Now an Export: SBOMs and VEX from DefectDojo Pro

Sooner or later, someone will ask for your SBOM. A customer's procurement team, an assessor working through a compliance framework, or a downstream pipeline that will not deploy without one. Producing a component list at build time is the easy half. The more important part is the follow-up question: which of these components are actually vulnerable, and what are you doing about it?

Chris AzumaChris Azuma
DefectDojo Sensei Now Fixes Your Cloud Too: CSPM for AWS, Azure, and GCP Cloud SecurityAug 27, 2026, 10:15:00 AM DefectDojo Sensei Now Fixes Your Cloud Too: CSPM for AWS, Azure, and GCP

Since we launched Sensei last year, it’s primarily done one job: scan your repositories, find what's wrong, and open the pull request that fixes it. Today that loop extends to your cloud.

MATT TESAUROMATT TESAURO
The Vulnerability Explorer: EPSS, KEV, and Root Cause Analysis in One View Vulnerability ManagementAug 25, 2026, 8:45:00 AM The Vulnerability Explorer: EPSS, KEV, and Root Cause Analysis in One View

Your scanners report findings. Your team fixes vulnerabilities. Those are not the exact same thing, and the gap between them is where security teams spend an enormous amount of time.

GREG ANDERSONGREG ANDERSON