Blog

June 2026
Prioritizing the CVEs that are actually running

A scan returns thousands of CVEs sorted by severity, which doesn't tell you what to fix first. Ephor now ranks findings by what's deployed, exploitable, and fixable.

May 2026
Finding CVEs in images you haven't scanned yet

Scanners run on a schedule, so a vulnerable package can sit in an image for a full cycle before anyone notices. Here's how Ephor flags it from the SBOM in between.

March 2026
The $100K Gap in Kubernetes Security Tooling

Between free CLI scanners and six-figure enterprise platforms, there's nothing. I got tired of managing CVEs in spreadsheets and built what should have existed.