#firstcon26 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #firstcon26, aggregated by home.social.
-
🎙️ New FIRST Impressions Podcast Episode: John Hollenberger (Fortinet)
Recorded live at FIRSTCON26, John Hollenberger of Fortinet explores how organizations can make tabletop exercises more realistic, and ultimately more valuable.
In this episode, John introduces ChaosStack, an approach that recreates the stress, competing priorities, and decision fatigue teams experience during real cyber incidents. The discussion explores how better exercises lead to stronger teamwork, better decision-making, and greater organizational resilience.
As a Founding Supporter and Launch Partner of the *FIRST CORE Program*, Fortinet's commitment extends beyond technology to strengthening cybersecurity capacity around the world. Through FIRST CORE, supporters help expand incident response capabilities, education, and community building in regions where resources are limited—helping make the global cybersecurity community stronger together.
🎧 Listen now for practical insights on preparing your team for the moments that matter most.
https://media.first.org/podcasts/FIRST_Impressions-chaosstack.mp3#FIRSTCON26 #FIRSTImpressions #Cybersecurity #IncidentResponse #TabletopExercises #Fortinet #FIRSTCORE #CyberResilience #SecurityLeadership
-
🎙️New FIRST Impressions Podcast Episode: Tim Brown (Team8)
Recorded live at #FIRSTCON26 following his opening keynote, Tim Brown, CISO-in-Residence at Team8 and former SolarWinds CISO, shares an incredibly candid conversation about leading through one of cybersecurity's most consequential incidents.
From the technical realities of incident response to the often-overlooked human impact of prolonged crisis, Tim discusses resilience, recovery, leadership, and why taking care of your team is just as important as protecting your infrastructure.
Whether you're an incident responder, security leader, or simply interested in the people behind cybersecurity, this episode offers thoughtful lessons that extend far beyond technology.
🎧 Tune in to hear one of FIRSTCON26's keynote speakers reflect on leadership, resilience, and finding growth through adversity.
https://media.first.org/podcasts/FIRST_Impressions-timbrown.mp3
#FIRSTCON26 #FIRSTImpressions #Cybersecurity #IncidentResponse #Leadership #Team8 #CISO #Resilience #SecurityLeadership
-
New on the FIRST blog: Jon Baker, VP, Threat-Informed Defense, AttackIQ, and Co-founder of MITRE's Center for Threat-Informed Defense, on why "how fast can we patch" is no longer the right question.
At #FIRSTCON26 in Denver, Jon's session introduced MITRE INFORM, the open-source threat-informed defense maturity model, walking attendees through a self-assessment and practical steps to move from reactive to measurable defense.
In this companion post, he builds that into a fuller operating model:
🎯 Threat-informed defense as the foundation: aligning to real adversary behavior, not generic best practice
📊 MITRE INFORM to measure and mature the program
💳 Threat debt as the shared scoreboard across Security, IT, and the business
🔄 CTEM as the continuous discipline that pays it downRead more: https://go.first.org/xaqpW
-
🎙️ New FIRST Impressions Podcast Episode: Chris Butera (CISA)
Recorded live at #FIRSTCON26 in Denver, this episode features Chris Butera, acting Executive Assistant Director for Cybersecurity at CISA, the local host of the conference.
Chris joins the podcast to discuss the future of the #CVEprogram, software supply chain security, AI-specific SBOMs, end-of-support risk management, and the importance of strong collaboration between government and industry.
If you’re interested in vulnerability management, AI security, supply chain resilience, or the evolving cybersecurity ecosystem, this is an episode you won’t want to miss!
🎧 Tune in to hear how CISA is helping shape the future of cyber defense and vulnerability coordination across the global community.
#FIRSTCON26 #FIRSTImpressions #CISA #Cybersecurity #CVE #SBOM #AISecurity #SupplyChainSecurity #VulnerabilityManagement
https://media.first.org/podcasts/FIRST_Impressions-butera26.mp3 -
New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?Two independent data sets, isolated from one another, revealed strikingly similar problems:
📄 IRPs too dense for anyone to actually use in a crisis
⚠️ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
📊 Severity triage that doesn't reflect real business impact
🧭 Unclear decision authority when it matters most
👤 Key personnel unavailable, with no backup empowered to act
🗣️ Discussions that never resolve into an actual decision
✅ Actions assigned but never tracked
📢 Communication breakdowns, especially with non-technical stakeholdersRead more: https://go.first.org/nqUbz
-
📬 FIRST's Q2FY26 Newsletter is here! Here's a look at what's inside:
🎉 #FIRSTCON26 Recap
A look back on the 38th Annual Conference in Denver — five days, 100+ presentations, and lively networking that reflected the event's collaborative spirit. Outgoing PC Chair Merike Kaeo delivered an outstanding program, and Martijn van der Heide now takes the reins to prepare #FIRSTCON27 in Bangkok.
🗳️ AGM & Board Elections
The Annual General Meeting confirmed a refreshed Board: Serge Droz, Carlos Leonardo, and Olivier Caleff re-elected, Mona Elisabeth Østvang returns after a year away, and Logan Wilkins joins for the first time.
👩💻 Women of FIRST Mentorship ProgramA new 6–9 month mentorship pilot launches in Q3 2026 — interest survey closes July 20.
🏅 Member Spotlight: Art Manion & Jay Jacobs
Two of the driving forces behind FIRST's vulnerability management work: Jay Jacobs (co-Chair, EPSS SIG) and Art Manion (Chair, VRDX-SIG and Vulnerability Coordination SIG). Their contributions to CVSS and EPSS have given the community core frameworks for vulnerability assessment and prioritization, and both have been key organizers of VulnCon — most recently leading a session in Scottsdale titled "A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle."
🕰️ New SIG Alert: Time Security
With the Unix epoch overflow arriving January 19, 2038 — plus an NTP rollover as soon as 2036 and a GPS week rollover later in 2038 — the new Time Security SIG is coordinating the community's response. Now 60+ participants strong, its work is already feeding into ITU-T and IEEE standards efforts.
🛡️Additional SIG Updates
✅ Metrics SIG released v1.1, completing metrics coverage across all five CSIRT Services Framework areas
✅ DNS Abuse SIG published v1.3 of the DNS Abuse Techniques Matrix — the first update since 2023
✅ Insider Threat SIG held its inaugural in-person meetup in Denver
✅ EPSS v5 went live June 15 with improved calibration and new exploit-detection signals
✅ Policy SIG published a brief on AI's impact across the cybersecurity ecosystem🌍 Capacity Building
FIRST launched a new initiative under the G7-ECOWAS Platform for Advancing Cybersecurity, working with ECOWAS and GIZ to support regional cyber confidence-building measures across West Africa.
Read more 👉 https://go.first.org/AXSBi
-
New on the FIRST blog: Eric Zielinski, CISO at Jumpmind and #FIRSTCON26 speaker, on why most AI governance programs document the outside of a black box and call it governed.
Highlights:
🔍 Explainability under incident pressure: auditors and boards want to understand why the model got it wrong, not just confirmation that the output was logged
🧬 Data and model poisoning: training-time compromise of weights is a supply-chain attack on your detection stack, and it only shows up under internal inspection
🤖 Prompt injection against security agents: MITRE ATLAS AML.T0051, a risk anywhere an AI agent reads attacker-controlled content, from a malicious log entry to a poisoned ticket📊 Interpretability Maturity Score: a 0 to 5 evidence ratchet, from fully opaque to continuous CI/CD-integrated circuit analysis
🗂️ Registry: an eight-section YAML schema, one entry per model, machine-readable and diffable in Git
🚦 Circuit Risk Score: combines risk tier, interpretability maturity, and decision consequence into four action bands, from standard approval to not-deployable, backed by ten binding hard rulesCIRCUIT is released under Apache 2.0 and builds on prior open work from NIST, MITRE, OWASP, and CSA. Jumpmind is CIRCUIT's first adopter, not its owner. No single organization owns it, and any team can adopt, extend, and govern it collectively. It crosswalks to NIST AI RMF, the EU AI Act, ISO 42001, SR 11-7, SOC 2, and MITRE ATLAS, and ships with a 29-question "Show Me Your Circuits" vendor questionnaire.
Read more: https://go.first.org/6tBji
#cybersecurity -
Working in cyber in 2026, we spend so much of our time connecting through screens. But every year, #FIRSTCON reminds us that the strongest partnerships are still built face to face.
You can exchange emails for years, join countless video calls, and collaborate across continents, but there's something irreplaceable about sharing a meal, raising a glass, and getting to know the person behind the job title. Those moments build the trust that matters when the pressure is on. When an incident strikes, you're not reaching out to a stranger, you're calling a friend.
Our #FIRSTCON26 recap reflects on the conversations, connections, and community that made this year's conference in Denver so memorable.
Read the full blog here: https://www.first.org/blog/20260703-When-FIRSTCON26-Rode-into-Denver
#FIRSTCON26 #CyberSecurity #IncidentResponse #Community #FIRST
-
New on the FIRST blog: Vishal Thakur, Regional Manager of CSIRT Operations at Atlassian, on why the most damaging techniques in the wild often have no home in any defensive framework until after they've already been used. He presented at #FIRSTCON26 alongside co-author David Wearing.
Highlights:
Atom Table abuse. Revix's "kill-all-VMs" tactic. Both real, both weaponized, both caused damage in the wild, and neither had a place in MITRE ATT&CK before the fact.
These techniques aren't rare. They just don't make it into the catalogue until after someone's already been hit by them.
🎯 Pre-Positioning: sleeper threats seeded long before the "hands-on-keyboard" phase
🛡️ Resilience Erosion: flags how backups or patch cycles could be quietly targeted
🏛️ Governance & Cognitive Manipulation: threats aimed at policy, procurement, and analyst judgmentWhat PR3TACK brings:
📊 Seed Matrix v1.0: 17 tactic categories, from Execution to Digital Exhaust Manipulation
🎚️ Every technique tiered by feasibility: High (PoC demonstrated), Medium (technically reasoned), Low (early research)
🧭 An interactive Navigator to search, filter, and map techniques to your own environmentThey are opening PR3TACK to the wider community. CSIRTs can apply to join the Members Team or Core Team, and researchers can apply as PR3TACK Affiliated Researchers to help validate and submit new TTPs.
Read more: https://go.first.org/TUmTi
-
That’s a wrap on the 38th Annual FIRST Conference in Denver. What an incredible week out west! Six days of learning, connection, and exploration with incident response professionals from around the globe. 🏔️✨
From hands‑on training to keynotes, SIGs, BoFs, lightning talks, and a buzzing exhibit hall, this year’s program delivered insights and collaboration at every turn. And of course, the conference social event brought the whole community together in true Colorado style. 🤝🌄
Thank you to everyone who joined us at altitude to strengthen global coordination and help shape the future of incident response. #FIRSTCON26
Next stop: Bangkok 🌏 Save the date for the 39th Annual FIRST Conference — we’ll see you in Thailand, June 13-18, 2027. ✨
-
🎉 #FIRSTCON26 has wrapped in Denver, Colorado!
The 38th Annual FIRST Conference brought together incident response teams, CERTs, government agencies, and security leaders from around the world to do what this community does best: collaborate, share intelligence, and make the ecosystem stronger.
Highlights:
✅ FIRST released its mid-year 2026 vulnerability forecast, projecting approximately 66,000 CVEs by year-end — a 46% overage against the initial annual forecast, driven largely by AI-assisted vulnerability discovery
✅ Chris Butera, Acting Executive Assistant Director for CISA's Cybersecurity Division opened the conference drawing a direct parallel between soccer team coordination and how the security community needs to operate: fast movement, shared trust, and partners who know the play before it develops
✅ Former US National Cyber Director Chris Inglis pushed back on rigid defense models, making the case for coalition defense — private sector, infrastructure providers, and governments operating together, not in parallel
✅ EPSS deployed its v2026.06.15 refresh, delivering updated exploitation probability scores for every public CVE
✅ New and critical security frameworks, tools, SIGs, and research insights aimed at automating defense and managing AI risk were showcased during the event
FIRST also welcomed its newly elected Board of Directors for the 2026–2027 term, appointing Logan Wilkins (Cisco, US) and welcoming back returning board member Mona Elisabeth Østvang (mnemonic, NO). Olivier Caleff was also re-elected as Chair of the Board of Directors, beginning his second term in the role.
A huge thank you to everyone who attended, presented, and sponsored.
Sessions will be available on YouTube in the coming weeks.
Read more: https://go.first.org/RKxUj
-
The final day of the 38th Annual FIRST Conference is here. 🌄
It’s been a week of learning, connection, and exploration at altitude — and today we wrap up with the last round of sessions and takeaways to bring home.
Thank you, Denver, for an incredible week.🤍
-
#FIRSTCON26 may be closing down, but we're already winding up for next year! #FIRSTCON27 The 39th Annual FIRST Conference: "Guardians of the Global Network: Uniting Resilience", will be held in Bangkok, Thailand, June 13-18, 2027. We're gathering our Program Committee members now, so if you have interest in helping select the program sessions, apply at: https://www.first.org/conference/2027/
-
Your voice helps strengthen the global IR community.
Share your thoughts in the #FIRSTCON26 survey and help us keep improving year after year. 🏔️🤝📝
-
Day 4 brings another full day of sessions, SIGs, BoFs, and global collaboration.
The conversations happening here in Denver are pushing incident response forward in real, meaningful ways. One more day to go — let’s make it count. 🛡️✨
-
Day 3 is here, and it’s a big one. 🌄
We’ve got an afternoon keynote to spark new thinking, and tonight’s Conference Social Event brings the whole community together.
Join us as we will unwind and connect against the Denver skyline! Be ready to throw on a cowboy hat and say, "Yeehaw!"🤠
-
⭐ Tip your hat to our Silver Sponsor, @Group-IB steady on the trail and helpin’ keep #FIRSTCON26 rollin’.🤠
-
Howdy, FIRSTies! 🤠
Have you saddled up and subscribed to the #FIRSTImpressionsPodcast yet? Available on Apple Podcasts, Google Podcasts, and Spotify! Every year, the trail bosses themselves, Chris John Riley and Martin McKeay, sit down with #FIRSTCON sponsors and speakers to swap stories, share insights, and preview the biggest conversations in cybersecurity.
From the wild frontier of AI security to hard-earned lessons from the incident response trail, the podcast rounds up some of the best content from this year's conference. 🤠🐎
🔗 Tune in here for the #FIRSTCON26 content: https://www.first.org/newsroom/news/first-impressions/
#FIRSTCON26 #FIRSTImpressions #Cybersecurity #Denver #PeakDefense
-
Day 2 is rolling in with clear skies and a packed agenda.
From technical deep dives to management‑level discussions, today is all about exploring new ground and strengthening global coordination across the IR community.
Denver is delivering the energy. 🏔️⚡
-
Great conversations at #FIRSTCON26 so far! Come say hello to the @volexity team at Booth 7 & see how to rapidly resolve your investigations and find what other tools are missing.
-
FIRST has released its highly anticipated 2026 Mid-Year Vulnerability Forecast at #FIRSTCON26 in Denver.
If you're a CISO, security leader, or vulnerability management practitioner, this is a must-read. Actual #CVE disclosures are running a staggering 46.3% higher than projected, putting the industry on pace for a historic ~66,000 CVEs this year.
Here's what's inside:⛈️ The "Rain vs. Flood" Phenomenon — Understand why raw CVE volume is skyrocketing (driven by AI-assisted discovery and a 449% surge in GHSA volume), while actual real-world exploitability risk remains flat.
🗺️ A 4-Step Navigation Framework — Exact strategic actions for managing exposure, leveraging threat intelligence overlays like EPSS and CISA KEV, and compressing Mean Time to Remediate (MTTR).
📊 An Open-Source Methodology — FIRST has made the full methodology, live data reports, and Python forecasting scripts openly available for security teams to use and build on.
A huge thank you to Éireann Leverett, FIRST Liaison and Lead Member of FIRST's Vulnerability Forecasting Team, Jerry Gamblin, FIRST EPSS SIG Member, and the entire FIRST Vulnerability Forecasting Team for their work on this report.
🔗 Read more: https://go.first.org/Fi2t8
-
Day 1 begins the main program here in Denver! 🌄
We’re starting strong with our Opening Keynote this morning, followed by a full slate of sessions — and tonight’s Sponsor Showcase Reception brings everyone together to connect and explore.
A big week of incident response is officially underway. ✨
-
Cheers to our Sunday Welcome Reception Sponsor, @Cisco for setting the tone for an incredible week in Denver.
The mountains aren’t the only thing elevating us tonight. 🌄🥂✨
-
🤠🧵 Big thanks to our Lanyard Sponsor, @circl_lu for keepin’ the FIRSTCON26 community connected on the trail. 🤠 #FIRSTCON26 🔗https://go.first.org/FXZ3s
-
Sunday in Denver kicks off with hands‑on training as we ease into the mountains and dive straight into skill‑building. A full day of learning, sharpening techniques, and getting ready for a big week ahead at the 38th Annual FIRST Conference. 🌄🛡️ #FIRSTCON26 🔗https://go.first.org/FXZ3s
-
📰 CSO covered CISA's new Binding Operational Directive 26-04, which tells federal agencies to patch smarter, not harder. The directive moves beyond #CVSS severity scores toward a four-factor risk model that weighs internet exposure, KEV listing, whether exploitation can be automated, and how much control an attacker gains after exploitation.
FIRST EPSS SIG member and RogoLabs founder Jerry Gamblin commented, "BOD 26-04 is a massive step in the right direction and validates what data-driven teams already know: Patching every CVSS High or Critical is mathematically impossible. By formalizing the use of the KEV catalog alongside advanced predictive data like #EPSS, CISA is helping drive the industry toward practical, risk-based operational maturity."
Hear more from CISA next week at #FIRSTCON26.
-
Giddy up #FIRSTCON26 — It's almost time to ride into town. We can't wait to see you in Denver. Keep an eye out for these WANTED FIRSTies, and mind the sheriff! 🤠
Sunday, June 14 🐎
Newbie Session: 17:30 – 18:00
Welcome Reception: 18:00 – 20:00Code of Conduct: https://www.first.org/about/policies/code-of-conduct
-
⏰ The EU #CyberResilienceAct is coming, and for manufacturers, the clock is already ticking⏰
In the latest episode of the #FirstImpressionsPodcast, Mars Cheng of TXOne Networks explains what organizations need to know about one of the most significant cybersecurity regulations to emerge in recent years.
From 24-hour vulnerability reporting requirements to secure-by-design expectations and product certification obligations, the #CRA introduces sweeping requirements for organizations that want to sell digital products in the European market.
If you're involved in #productsecurity, #vulnerabilitymanagement, compliance, or cybersecurity leadership, this conversation is for you!
🎧 Listen now to preview of Mars' upcoming #FIRSTCON26 presentation: https://media.first.org/podcasts/FIRST_Impressions-mars2026.mp3
-
We’re headed west! The 38th Annual FIRST Conference kicks off in Denver next week, June 14–19.
Join incident response professionals from around the world as we explore new ideas, share expertise, and shape the future of IR together. 🏔️✨ #FIRSTCON26