#vulncon26 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vulncon26, aggregated by home.social.
-
The CVE funding disruption exposed a single point of failure in the infrastructure that underpins global vulnerability management. In this Help Net Security interview, ENISA's Nuno Rodrigues Carvalho, #VulnCon26 speaker, breaks down what needs to change.
📖 Read more: https://go.first.org/bSrxK
-
The CVE funding disruption exposed a single point of failure in the infrastructure that underpins global vulnerability management. In this Help Net Security interview, ENISA's Nuno Rodrigues Carvalho, #VulnCon26 speaker, breaks down what needs to change.
📖 Read more: https://go.first.org/bSrxK
-
New on the FIRST blog: Jenn Gile, Co-Founder of OpenSourceMalware and #VulnCon26 speaker, on why malicious open source packages don't fit the traditional vulnerability intelligence model.
The response motion looks familiar. A malicious package appears in a public registry, a record lands in OSV, tools fire an alert, and someone opens a ticket. But the data and the playbook don't actually match the threat.
🔍 Vulnerabilities are passive. They wait to be exploited.
⚡ Malicious packages are active. They execute on install.
🔧 Vulnerabilities have a fixed version.
🚫 Malicious packages ARE the latest version.That mismatch leaves three investigative gaps vulnerability databases weren't built to fill:
📦 Payload: what the malware did and which files were affected.
👤 Threat actor: C2 infrastructure and accounts reused across campaigns.
🔗 Campaign: how one package connects to broader activity.Case in point: the axios account takeover on March 30, 2026. OSV surfaces three IOCs. The campaign has at least nine, two of them shared with other malicious assets.
Jenn's argument: malicious packages need their own intelligence track, built around a different set of questions.
📖 Read more: https://go.first.org/BwFfv
-
New on the FIRST blog: Jenn Gile, Co-Founder of OpenSourceMalware and #VulnCon26 speaker, on why malicious open source packages don't fit the traditional vulnerability intelligence model.
The response motion looks familiar. A malicious package appears in a public registry, a record lands in OSV, tools fire an alert, and someone opens a ticket. But the data and the playbook don't actually match the threat.
🔍 Vulnerabilities are passive. They wait to be exploited.
⚡ Malicious packages are active. They execute on install.
🔧 Vulnerabilities have a fixed version.
🚫 Malicious packages ARE the latest version.That mismatch leaves three investigative gaps vulnerability databases weren't built to fill:
📦 Payload: what the malware did and which files were affected.
👤 Threat actor: C2 infrastructure and accounts reused across campaigns.
🔗 Campaign: how one package connects to broader activity.Case in point: the axios account takeover on March 30, 2026. OSV surfaces three IOCs. The campaign has at least nine, two of them shared with other malicious assets.
Jenn's argument: malicious packages need their own intelligence track, built around a different set of questions.
📖 Read more: https://go.first.org/BwFfv
-
📰 Maria Korolov, CSO Online covered NIST's major shift in CVE handling announced at #VulnCon26, as the National Vulnerability Database buckles under a 30,000+ backlog and submissions grow 263% since 2020.
FIRST CEO Chris Gibson weighs in on the vulnerability velocity crisis, with FIRST projecting 59,427 CVEs in 2026 and realistic scenarios cracking 100,000 amid the rise of AI-powered discovery tools like Anthropic's Mythos.
Harold Booth, Supervisory Computer Scientist, NIST outlined the agency's pivot to prioritize KEV-listed and critical software CVEs while turning to LLMs, AI agents, and RPA to tackle the backlog.
Jay Jacobs, Co-Founder & Data Scientist, Empirical Security, FIRST EPSS-SIG Co-Chair, CVE Consumer WG Chair shares optimism that AI-driven automation can help NIST keep pace, noting that even if it isn't Mythos, "something is going to come out next week."
Read more: https://go.first.org/9k8UO
-
📰 Maria Korolov, CSO Online covered NIST's major shift in CVE handling announced at #VulnCon26, as the National Vulnerability Database buckles under a 30,000+ backlog and submissions grow 263% since 2020.
FIRST CEO Chris Gibson weighs in on the vulnerability velocity crisis, with FIRST projecting 59,427 CVEs in 2026 and realistic scenarios cracking 100,000 amid the rise of AI-powered discovery tools like Anthropic's Mythos.
Harold Booth, Supervisory Computer Scientist, NIST outlined the agency's pivot to prioritize KEV-listed and critical software CVEs while turning to LLMs, AI agents, and RPA to tackle the backlog.
Jay Jacobs, Co-Founder & Data Scientist, Empirical Security, FIRST EPSS-SIG Co-Chair, CVE Consumer WG Chair shares optimism that AI-driven automation can help NIST keep pace, noting that even if it isn't Mythos, "something is going to come out next week."
Read more: https://go.first.org/9k8UO
-
📰 Kevin Poireault, Infosecurity Magazine, sat down with FIRST CEO Chris Gibson at #VulnCon26 in Scottsdale, AZ, unpacking the AI-driven vulnerability tsunami reshaping #VulnerabilityManagement, with mean time to exploit now measured in hours, not weeks.
Gibson makes the case for global collaboration over fragmentation, welcomes ENISA joining CISA and MITRE as a Top-Level Root CNA, and predicts Anthropic and OpenAI will become CVE Numbering Authorities by year-end.
Read more: https://go.first.org/lM4sa
-
📰 Kevin Poireault, Infosecurity Magazine, sat down with FIRST CEO Chris Gibson at #VulnCon26 in Scottsdale, AZ, unpacking the AI-driven vulnerability tsunami reshaping #VulnerabilityManagement, with mean time to exploit now measured in hours, not weeks.
Gibson makes the case for global collaboration over fragmentation, welcomes ENISA joining CISA and MITRE as a Top-Level Root CNA, and predicts Anthropic and OpenAI will become CVE Numbering Authorities by year-end.
Read more: https://go.first.org/lM4sa
-
🎉 The CVE/FIRST #VulnCon26 & Annual CNA Summit has wrapped, and what a week it was.
500+ security professionals from around the world gathered in Scottsdale, AZ to advance the #VulnerabilityManagement ecosystem, with sessions led by leaders from CISA, ENISA, NIST, Google, Microsoft, NVIDIA, Cisco, Dell, and dozens more.
Highlights:
✅ CISA reaffirmed the CVE program as a top agency priority and called on AI companies to play a larger role going forward
✅ CWE is becoming a more integral part of vulnerability disclosure, with root-cause mapping gaining wider adoption
✅ New product launches on the show floor, including Volerion's Vulnerability Intelligence Platform, NetRise Provenance, and a major Red Hat security data overhaul
✅ Key updates from CVE Working Groups, the EPSS SIG, and Women of FIRSTSpeaker sessions will be available on-demand for virtual attendees in the FIRST Events app, as well as FIRST's YouTube channel in the coming weeks.
A huge thank you to everyone who attended, presented, sponsored, and supported this event.
This community is what makes the vulnerability management ecosystem stronger!
Read more: https://go.first.org/WabqC
-
🎉 The CVE/FIRST #VulnCon26 & Annual CNA Summit has wrapped, and what a week it was.
500+ security professionals from around the world gathered in Scottsdale, AZ to advance the #VulnerabilityManagement ecosystem, with sessions led by leaders from CISA, ENISA, NIST, Google, Microsoft, NVIDIA, Cisco, Dell, and dozens more.
Highlights:
✅ CISA reaffirmed the CVE program as a top agency priority and called on AI companies to play a larger role going forward
✅ CWE is becoming a more integral part of vulnerability disclosure, with root-cause mapping gaining wider adoption
✅ New product launches on the show floor, including Volerion's Vulnerability Intelligence Platform, NetRise Provenance, and a major Red Hat security data overhaul
✅ Key updates from CVE Working Groups, the EPSS SIG, and Women of FIRSTSpeaker sessions will be available on-demand for virtual attendees in the FIRST Events app, as well as FIRST's YouTube channel in the coming weeks.
A huge thank you to everyone who attended, presented, sponsored, and supported this event.
This community is what makes the vulnerability management ecosystem stronger!
Read more: https://go.first.org/WabqC
-
Our last day in Scottsdale and the momentum is still going strong — this community doesn’t slow down. #VulnCon26🦎✨#CVEProgram #CVSS 🔗https://go.first.org/WWSDp
-
Our last day in Scottsdale and the momentum is still going strong — this community doesn’t slow down. #VulnCon26🦎✨#CVEProgram #CVSS 🔗https://go.first.org/WWSDp
-
Afternoon sessions are heating up (and not just because we’re in the desert). #VulnCon26🔥🦎 #CVEProgram #CVSS 🔗https://go.first.org/WWSDp
-
Afternoon sessions are heating up (and not just because we’re in the desert). #VulnCon26🔥🦎 #CVEProgram #CVSS 🔗https://go.first.org/WWSDp
-
Coffee in hand, ideas flowing, community buzzing — that’s the #VulnCon26 morning vibe. 🌵✨ #CVEProgram #CVSS 🔗https://go.first.org/WWSDp
-
Coffee in hand, ideas flowing, community buzzing — that’s the #VulnCon26 morning vibe. 🌵✨ #CVEProgram #CVSS 🔗https://go.first.org/WWSDp
-
Breakouts are buzzing at #VulnCon26 — real talk, real challenges, real solutions. Exactly what this ecosystem needs. 🌵💬#vulnerabilitymanagement #IncidentResponse 🔗https://go.first.org/WWSDp
-
Breakouts are buzzing at #VulnCon26 — real talk, real challenges, real solutions. Exactly what this ecosystem needs. 🌵💬#vulnerabilitymanagement #IncidentResponse 🔗https://go.first.org/WWSDp
-
Help Net Security interviewed Art Manion, Tharros, FIRST Liaison Member, FIRST VRDX-SIG Chair, CVE Board Member, CVE SPWG Chair, on why vulnerability databases keep failing us, and what the community needs to do about it.
Highlights:
- Stop treating this as a data problem, it's first an architecture problem
- There is no minimum set of assertions that can confirm two systems describe the same vulnerability
- CVSS scores are pulling attention away from the harder work of real risk assessment
- 50%+ of vendor names in NVD's CPE data have naming inconsistencies, if you can't identify the product, nothing else matters
- Before writing new specs or building new tools, the community needs shared terms and principlesThis research is part of ongoing collaborative work with Jay Jacobs, Co-Founder & Data Scientist, Empirical Security, FIRST EPSS-SIG Co-Chair, CVE Consumer WG Chair.
Catch Art and Jay live at #VulnCon26: 'A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle' — April 14, 1:30–2:30 PM MST.
📖 Read the full interview: https://go.first.org/jnofT
-
Help Net Security interviewed Art Manion, Tharros, FIRST Liaison Member, FIRST VRDX-SIG Chair, CVE Board Member, CVE SPWG Chair, on why vulnerability databases keep failing us, and what the community needs to do about it.
Highlights:
- Stop treating this as a data problem, it's first an architecture problem
- There is no minimum set of assertions that can confirm two systems describe the same vulnerability
- CVSS scores are pulling attention away from the harder work of real risk assessment
- 50%+ of vendor names in NVD's CPE data have naming inconsistencies, if you can't identify the product, nothing else matters
- Before writing new specs or building new tools, the community needs shared terms and principlesThis research is part of ongoing collaborative work with Jay Jacobs, Co-Founder & Data Scientist, Empirical Security, FIRST EPSS-SIG Co-Chair, CVE Consumer WG Chair.
Catch Art and Jay live at #VulnCon26: 'A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle' — April 14, 1:30–2:30 PM MST.
📖 Read the full interview: https://go.first.org/jnofT
-
There’s something special about seeing the VM ecosystem come together in one place. #VulnCon26 is where collaboration happens. 🤠🌅 #vulnerabilitymanagement 🔗https://go.first.org/WWSDp
-
There’s something special about seeing the VM ecosystem come together in one place. #VulnCon26 is where collaboration happens. 🤠🌅 #vulnerabilitymanagement 🔗https://go.first.org/WWSDp
-
Nothing like Scottsdale views + cybersecurity brainpower. #VulnCon26 is off to a strong start. 🌅✨#vulnerabilitymanagement 🔗https://go.first.org/WWSDp
-
Nothing like Scottsdale views + cybersecurity brainpower. #VulnCon26 is off to a strong start. 🌅✨#vulnerabilitymanagement 🔗https://go.first.org/WWSDp
-
Kicking off #VulnCon26 in Scottsdale — the VM community is officially in the house! Let’s spark ideas and build something stronger together. 🌵✨ #CVEProgram #CVSS 🔗https://go.first.org/WWSDp
-
Kicking off #VulnCon26 in Scottsdale — the VM community is officially in the house! Let’s spark ideas and build something stronger together. 🌵✨ #CVEProgram #CVSS 🔗https://go.first.org/WWSDp
-
What if the key to better vulnerability management isn't just patching faster, but understanding why vulnerabilities keep coming back? 🔍
Help Net Security connected with #VulnCon26 speaker Alec Summers, MITRE CVE/CWE Project Lead, Principal Cybersecurity Engineer, and FIRST Member, to explore how CWE mapping is becoming a strategic layer of the vulnerability management stack.
🎤 Catch Alec's upcoming presentations at VulnCon26 next week and read the full Q&A here: https://go.first.org/BZzAf
-
What if the key to better vulnerability management isn't just patching faster, but understanding why vulnerabilities keep coming back? 🔍
Help Net Security connected with #VulnCon26 speaker Alec Summers, MITRE CVE/CWE Project Lead, Principal Cybersecurity Engineer, and FIRST Member, to explore how CWE mapping is becoming a strategic layer of the vulnerability management stack.
🎤 Catch Alec's upcoming presentations at VulnCon26 next week and read the full Q&A here: https://go.first.org/BZzAf
-
Today (March 25th) is the very last day to book within the #VulnCon26 hotel room block. Future you will be glad you clicked “reserve.” 🌵🏨
-
Today (March 25th) is the very last day to book within the #VulnCon26 hotel room block. Future you will be glad you clicked “reserve.” 🌵🏨
-
You asked, and we delivered (again)! 🎉 The hotel room block for #VulnCon26 has been extended once more—you now have until March 25th to lock in your stay. 🌵🏨 Don’t miss your chance to stay close to all the action! 🔗https://go.first.org/WWSDp
-
You asked, and we delivered (again)! 🎉 The hotel room block for #VulnCon26 has been extended once more—you now have until March 25th to lock in your stay. 🌵🏨 Don’t miss your chance to stay close to all the action! 🔗https://go.first.org/WWSDp
-
Good news, desert travelers — the room block just got extended! You now have until March 20th to reserve your stay. 🌵🌞🏨🔗https://go.first.org/WWSDp
#VulnCon26 #Scottsdale #RoomBlockExtended -
Good news, desert travelers — the room block just got extended! You now have until March 20th to reserve your stay. 🌵🌞🏨🔗https://go.first.org/WWSDp
#VulnCon26 #Scottsdale #RoomBlockExtended -
Let's be vulnerable together 🤓 Join us at #VulnCon26 🔗https://go.first.org/syt8W #vulnerabilitymanagement #CVEProgram #CVSS
-
Let's be vulnerable together 🤓 Join us at #VulnCon26 🔗https://go.first.org/syt8W #vulnerabilitymanagement #CVEProgram #CVSS
-
#VulnCon26 Checklist
Registration ✅
Flights Booked ✅
Hotel Room Reserved 👀 …wait, you booked your room, right?The discounted rate expires on March 14th, so do your future self a favor and book now 😉👉🔗 https://go.first.org/o0mK5
-
#VulnCon26 Checklist
Registration ✅
Flights Booked ✅
Hotel Room Reserved 👀 …wait, you booked your room, right?The discounted rate expires on March 14th, so do your future self a favor and book now 😉👉🔗 https://go.first.org/o0mK5
-
🌵🤠 Wrangle up! #VulnCon26's early‑bird rate and hotel room block both ride off into the sunset on March 14th. Saddle up and get everything locked in before it’s gone. 🔗https://go.first.org/WWSDp