home.social

#vulncon26 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vulncon26, aggregated by home.social.

fetched live
  1. The CVE funding disruption exposed a single point of failure in the infrastructure that underpins global vulnerability management. In this Help Net Security interview, ENISA's Nuno Rodrigues Carvalho, #VulnCon26 speaker, breaks down what needs to change.

    📖 Read more: go.first.org/bSrxK

    #CyberDefense #cybersecurity #CVE

  2. The CVE funding disruption exposed a single point of failure in the infrastructure that underpins global vulnerability management. In this Help Net Security interview, ENISA's Nuno Rodrigues Carvalho, #VulnCon26 speaker, breaks down what needs to change.

    📖 Read more: go.first.org/bSrxK

    #CyberDefense #cybersecurity #CVE

  3. The CVE funding disruption exposed a single point of failure in the infrastructure that underpins global vulnerability management. In this Help Net Security interview, ENISA's Nuno Rodrigues Carvalho, #VulnCon26 speaker, breaks down what needs to change.

    📖 Read more: go.first.org/bSrxK

    #CyberDefense #cybersecurity #CVE

  4. The CVE funding disruption exposed a single point of failure in the infrastructure that underpins global vulnerability management. In this Help Net Security interview, ENISA's Nuno Rodrigues Carvalho, #VulnCon26 speaker, breaks down what needs to change.

    📖 Read more: go.first.org/bSrxK

    #CyberDefense #cybersecurity #CVE

  5. The CVE funding disruption exposed a single point of failure in the infrastructure that underpins global vulnerability management. In this Help Net Security interview, ENISA's Nuno Rodrigues Carvalho, #VulnCon26 speaker, breaks down what needs to change.

    📖 Read more: go.first.org/bSrxK

    #CyberDefense #cybersecurity #CVE

  6. New on the FIRST blog: Jenn Gile, Co-Founder of OpenSourceMalware and #VulnCon26 speaker, on why malicious open source packages don't fit the traditional vulnerability intelligence model.

    The response motion looks familiar. A malicious package appears in a public registry, a record lands in OSV, tools fire an alert, and someone opens a ticket. But the data and the playbook don't actually match the threat.

    🔍 Vulnerabilities are passive. They wait to be exploited.
    ⚡ Malicious packages are active. They execute on install.
    🔧 Vulnerabilities have a fixed version.
    🚫 Malicious packages ARE the latest version.

    That mismatch leaves three investigative gaps vulnerability databases weren't built to fill:

    📦 Payload: what the malware did and which files were affected.
    👤 Threat actor: C2 infrastructure and accounts reused across campaigns.
    🔗 Campaign: how one package connects to broader activity.

    Case in point: the axios account takeover on March 30, 2026. OSV surfaces three IOCs. The campaign has at least nine, two of them shared with other malicious assets.

    Jenn's argument: malicious packages need their own intelligence track, built around a different set of questions.

    📖 Read more: go.first.org/BwFfv

    #cybersecurity #infosec #VulnerabilityManagement

  7. New on the FIRST blog: Jenn Gile, Co-Founder of OpenSourceMalware and #VulnCon26 speaker, on why malicious open source packages don't fit the traditional vulnerability intelligence model.

    The response motion looks familiar. A malicious package appears in a public registry, a record lands in OSV, tools fire an alert, and someone opens a ticket. But the data and the playbook don't actually match the threat.

    🔍 Vulnerabilities are passive. They wait to be exploited.
    ⚡ Malicious packages are active. They execute on install.
    🔧 Vulnerabilities have a fixed version.
    🚫 Malicious packages ARE the latest version.

    That mismatch leaves three investigative gaps vulnerability databases weren't built to fill:

    📦 Payload: what the malware did and which files were affected.
    👤 Threat actor: C2 infrastructure and accounts reused across campaigns.
    🔗 Campaign: how one package connects to broader activity.

    Case in point: the axios account takeover on March 30, 2026. OSV surfaces three IOCs. The campaign has at least nine, two of them shared with other malicious assets.

    Jenn's argument: malicious packages need their own intelligence track, built around a different set of questions.

    📖 Read more: go.first.org/BwFfv

    #cybersecurity #infosec #VulnerabilityManagement

  8. New on the FIRST blog: Jenn Gile, Co-Founder of OpenSourceMalware and #VulnCon26 speaker, on why malicious open source packages don't fit the traditional vulnerability intelligence model.

    The response motion looks familiar. A malicious package appears in a public registry, a record lands in OSV, tools fire an alert, and someone opens a ticket. But the data and the playbook don't actually match the threat.

    🔍 Vulnerabilities are passive. They wait to be exploited.
    ⚡ Malicious packages are active. They execute on install.
    🔧 Vulnerabilities have a fixed version.
    🚫 Malicious packages ARE the latest version.

    That mismatch leaves three investigative gaps vulnerability databases weren't built to fill:

    📦 Payload: what the malware did and which files were affected.
    👤 Threat actor: C2 infrastructure and accounts reused across campaigns.
    🔗 Campaign: how one package connects to broader activity.

    Case in point: the axios account takeover on March 30, 2026. OSV surfaces three IOCs. The campaign has at least nine, two of them shared with other malicious assets.

    Jenn's argument: malicious packages need their own intelligence track, built around a different set of questions.

    📖 Read more: go.first.org/BwFfv

    #cybersecurity #infosec #VulnerabilityManagement

  9. New on the FIRST blog: Jenn Gile, Co-Founder of OpenSourceMalware and #VulnCon26 speaker, on why malicious open source packages don't fit the traditional vulnerability intelligence model.

    The response motion looks familiar. A malicious package appears in a public registry, a record lands in OSV, tools fire an alert, and someone opens a ticket. But the data and the playbook don't actually match the threat.

    🔍 Vulnerabilities are passive. They wait to be exploited.
    ⚡ Malicious packages are active. They execute on install.
    🔧 Vulnerabilities have a fixed version.
    🚫 Malicious packages ARE the latest version.

    That mismatch leaves three investigative gaps vulnerability databases weren't built to fill:

    📦 Payload: what the malware did and which files were affected.
    👤 Threat actor: C2 infrastructure and accounts reused across campaigns.
    🔗 Campaign: how one package connects to broader activity.

    Case in point: the axios account takeover on March 30, 2026. OSV surfaces three IOCs. The campaign has at least nine, two of them shared with other malicious assets.

    Jenn's argument: malicious packages need their own intelligence track, built around a different set of questions.

    📖 Read more: go.first.org/BwFfv

    #cybersecurity #infosec #VulnerabilityManagement

  10. New on the FIRST blog: Jenn Gile, Co-Founder of OpenSourceMalware and #VulnCon26 speaker, on why malicious open source packages don't fit the traditional vulnerability intelligence model.

    The response motion looks familiar. A malicious package appears in a public registry, a record lands in OSV, tools fire an alert, and someone opens a ticket. But the data and the playbook don't actually match the threat.

    🔍 Vulnerabilities are passive. They wait to be exploited.
    ⚡ Malicious packages are active. They execute on install.
    🔧 Vulnerabilities have a fixed version.
    🚫 Malicious packages ARE the latest version.

    That mismatch leaves three investigative gaps vulnerability databases weren't built to fill:

    📦 Payload: what the malware did and which files were affected.
    👤 Threat actor: C2 infrastructure and accounts reused across campaigns.
    🔗 Campaign: how one package connects to broader activity.

    Case in point: the axios account takeover on March 30, 2026. OSV surfaces three IOCs. The campaign has at least nine, two of them shared with other malicious assets.

    Jenn's argument: malicious packages need their own intelligence track, built around a different set of questions.

    📖 Read more: go.first.org/BwFfv

    #cybersecurity #infosec #VulnerabilityManagement

  11. 📰 Maria Korolov, CSO Online covered NIST's major shift in CVE handling announced at #VulnCon26, as the National Vulnerability Database buckles under a 30,000+ backlog and submissions grow 263% since 2020.

    FIRST CEO Chris Gibson weighs in on the vulnerability velocity crisis, with FIRST projecting 59,427 CVEs in 2026 and realistic scenarios cracking 100,000 amid the rise of AI-powered discovery tools like Anthropic's Mythos.

    Harold Booth, Supervisory Computer Scientist, NIST outlined the agency's pivot to prioritize KEV-listed and critical software CVEs while turning to LLMs, AI agents, and RPA to tackle the backlog.

    Jay Jacobs, Co-Founder & Data Scientist, Empirical Security, FIRST EPSS-SIG Co-Chair, CVE Consumer WG Chair shares optimism that AI-driven automation can help NIST keep pace, noting that even if it isn't Mythos, "something is going to come out next week."

    Read more: go.first.org/9k8UO

    #cybersecurity #infosec #VulnerabilityManagement

  12. 📰 Maria Korolov, CSO Online covered NIST's major shift in CVE handling announced at #VulnCon26, as the National Vulnerability Database buckles under a 30,000+ backlog and submissions grow 263% since 2020.

    FIRST CEO Chris Gibson weighs in on the vulnerability velocity crisis, with FIRST projecting 59,427 CVEs in 2026 and realistic scenarios cracking 100,000 amid the rise of AI-powered discovery tools like Anthropic's Mythos.

    Harold Booth, Supervisory Computer Scientist, NIST outlined the agency's pivot to prioritize KEV-listed and critical software CVEs while turning to LLMs, AI agents, and RPA to tackle the backlog.

    Jay Jacobs, Co-Founder & Data Scientist, Empirical Security, FIRST EPSS-SIG Co-Chair, CVE Consumer WG Chair shares optimism that AI-driven automation can help NIST keep pace, noting that even if it isn't Mythos, "something is going to come out next week."

    Read more: go.first.org/9k8UO

    #cybersecurity #infosec #VulnerabilityManagement

  13. 📰 Maria Korolov, CSO Online covered NIST's major shift in CVE handling announced at #VulnCon26, as the National Vulnerability Database buckles under a 30,000+ backlog and submissions grow 263% since 2020.

    FIRST CEO Chris Gibson weighs in on the vulnerability velocity crisis, with FIRST projecting 59,427 CVEs in 2026 and realistic scenarios cracking 100,000 amid the rise of AI-powered discovery tools like Anthropic's Mythos.

    Harold Booth, Supervisory Computer Scientist, NIST outlined the agency's pivot to prioritize KEV-listed and critical software CVEs while turning to LLMs, AI agents, and RPA to tackle the backlog.

    Jay Jacobs, Co-Founder & Data Scientist, Empirical Security, FIRST EPSS-SIG Co-Chair, CVE Consumer WG Chair shares optimism that AI-driven automation can help NIST keep pace, noting that even if it isn't Mythos, "something is going to come out next week."

    Read more: go.first.org/9k8UO

    #cybersecurity #infosec #VulnerabilityManagement

  14. 📰 Maria Korolov, CSO Online covered NIST's major shift in CVE handling announced at #VulnCon26, as the National Vulnerability Database buckles under a 30,000+ backlog and submissions grow 263% since 2020.

    FIRST CEO Chris Gibson weighs in on the vulnerability velocity crisis, with FIRST projecting 59,427 CVEs in 2026 and realistic scenarios cracking 100,000 amid the rise of AI-powered discovery tools like Anthropic's Mythos.

    Harold Booth, Supervisory Computer Scientist, NIST outlined the agency's pivot to prioritize KEV-listed and critical software CVEs while turning to LLMs, AI agents, and RPA to tackle the backlog.

    Jay Jacobs, Co-Founder & Data Scientist, Empirical Security, FIRST EPSS-SIG Co-Chair, CVE Consumer WG Chair shares optimism that AI-driven automation can help NIST keep pace, noting that even if it isn't Mythos, "something is going to come out next week."

    Read more: go.first.org/9k8UO

    #cybersecurity #infosec #VulnerabilityManagement

  15. 📰 Maria Korolov, CSO Online covered NIST's major shift in CVE handling announced at #VulnCon26, as the National Vulnerability Database buckles under a 30,000+ backlog and submissions grow 263% since 2020.

    FIRST CEO Chris Gibson weighs in on the vulnerability velocity crisis, with FIRST projecting 59,427 CVEs in 2026 and realistic scenarios cracking 100,000 amid the rise of AI-powered discovery tools like Anthropic's Mythos.

    Harold Booth, Supervisory Computer Scientist, NIST outlined the agency's pivot to prioritize KEV-listed and critical software CVEs while turning to LLMs, AI agents, and RPA to tackle the backlog.

    Jay Jacobs, Co-Founder & Data Scientist, Empirical Security, FIRST EPSS-SIG Co-Chair, CVE Consumer WG Chair shares optimism that AI-driven automation can help NIST keep pace, noting that even if it isn't Mythos, "something is going to come out next week."

    Read more: go.first.org/9k8UO

    #cybersecurity #infosec #VulnerabilityManagement

  16. 📰 Kevin Poireault, Infosecurity Magazine, sat down with FIRST CEO Chris Gibson at #VulnCon26 in Scottsdale, AZ, unpacking the AI-driven vulnerability tsunami reshaping #VulnerabilityManagement, with mean time to exploit now measured in hours, not weeks.

    Gibson makes the case for global collaboration over fragmentation, welcomes ENISA joining CISA and MITRE as a Top-Level Root CNA, and predicts Anthropic and OpenAI will become CVE Numbering Authorities by year-end.

    Read more: go.first.org/lM4sa

    #CVE #CyberDefense #cybersecurity #infosec

  17. 📰 Kevin Poireault, Infosecurity Magazine, sat down with FIRST CEO Chris Gibson at #VulnCon26 in Scottsdale, AZ, unpacking the AI-driven vulnerability tsunami reshaping #VulnerabilityManagement, with mean time to exploit now measured in hours, not weeks.

    Gibson makes the case for global collaboration over fragmentation, welcomes ENISA joining CISA and MITRE as a Top-Level Root CNA, and predicts Anthropic and OpenAI will become CVE Numbering Authorities by year-end.

    Read more: go.first.org/lM4sa

    #CVE #CyberDefense #cybersecurity #infosec

  18. 📰 Kevin Poireault, Infosecurity Magazine, sat down with FIRST CEO Chris Gibson at #VulnCon26 in Scottsdale, AZ, unpacking the AI-driven vulnerability tsunami reshaping #VulnerabilityManagement, with mean time to exploit now measured in hours, not weeks.

    Gibson makes the case for global collaboration over fragmentation, welcomes ENISA joining CISA and MITRE as a Top-Level Root CNA, and predicts Anthropic and OpenAI will become CVE Numbering Authorities by year-end.

    Read more: go.first.org/lM4sa

    #CVE #CyberDefense #cybersecurity #infosec

  19. 📰 Kevin Poireault, Infosecurity Magazine, sat down with FIRST CEO Chris Gibson at #VulnCon26 in Scottsdale, AZ, unpacking the AI-driven vulnerability tsunami reshaping #VulnerabilityManagement, with mean time to exploit now measured in hours, not weeks.

    Gibson makes the case for global collaboration over fragmentation, welcomes ENISA joining CISA and MITRE as a Top-Level Root CNA, and predicts Anthropic and OpenAI will become CVE Numbering Authorities by year-end.

    Read more: go.first.org/lM4sa

    #CVE #CyberDefense #cybersecurity #infosec

  20. 📰 Kevin Poireault, Infosecurity Magazine, sat down with FIRST CEO Chris Gibson at #VulnCon26 in Scottsdale, AZ, unpacking the AI-driven vulnerability tsunami reshaping #VulnerabilityManagement, with mean time to exploit now measured in hours, not weeks.

    Gibson makes the case for global collaboration over fragmentation, welcomes ENISA joining CISA and MITRE as a Top-Level Root CNA, and predicts Anthropic and OpenAI will become CVE Numbering Authorities by year-end.

    Read more: go.first.org/lM4sa

    #CVE #CyberDefense #cybersecurity #infosec

  21. 🎉 The CVE/FIRST #VulnCon26 & Annual CNA Summit has wrapped, and what a week it was.

    500+ security professionals from around the world gathered in Scottsdale, AZ to advance the #VulnerabilityManagement ecosystem, with sessions led by leaders from CISA, ENISA, NIST, Google, Microsoft, NVIDIA, Cisco, Dell, and dozens more.

    Highlights:
    ✅ CISA reaffirmed the CVE program as a top agency priority and called on AI companies to play a larger role going forward
    ✅ CWE is becoming a more integral part of vulnerability disclosure, with root-cause mapping gaining wider adoption
    ✅ New product launches on the show floor, including Volerion's Vulnerability Intelligence Platform, NetRise Provenance, and a major Red Hat security data overhaul
    ✅ Key updates from CVE Working Groups, the EPSS SIG, and Women of FIRST

    Speaker sessions will be available on-demand for virtual attendees in the FIRST Events app, as well as FIRST's YouTube channel in the coming weeks.

    A huge thank you to everyone who attended, presented, sponsored, and supported this event.

    This community is what makes the vulnerability management ecosystem stronger!

    Read more: go.first.org/WabqC

    #CyberDefense #cybersecurity #infosec

  22. 🎉 The CVE/FIRST #VulnCon26 & Annual CNA Summit has wrapped, and what a week it was.

    500+ security professionals from around the world gathered in Scottsdale, AZ to advance the #VulnerabilityManagement ecosystem, with sessions led by leaders from CISA, ENISA, NIST, Google, Microsoft, NVIDIA, Cisco, Dell, and dozens more.

    Highlights:
    ✅ CISA reaffirmed the CVE program as a top agency priority and called on AI companies to play a larger role going forward
    ✅ CWE is becoming a more integral part of vulnerability disclosure, with root-cause mapping gaining wider adoption
    ✅ New product launches on the show floor, including Volerion's Vulnerability Intelligence Platform, NetRise Provenance, and a major Red Hat security data overhaul
    ✅ Key updates from CVE Working Groups, the EPSS SIG, and Women of FIRST

    Speaker sessions will be available on-demand for virtual attendees in the FIRST Events app, as well as FIRST's YouTube channel in the coming weeks.

    A huge thank you to everyone who attended, presented, sponsored, and supported this event.

    This community is what makes the vulnerability management ecosystem stronger!

    Read more: go.first.org/WabqC

    #CyberDefense #cybersecurity #infosec

  23. 🎉 The CVE/FIRST #VulnCon26 & Annual CNA Summit has wrapped, and what a week it was.

    500+ security professionals from around the world gathered in Scottsdale, AZ to advance the #VulnerabilityManagement ecosystem, with sessions led by leaders from CISA, ENISA, NIST, Google, Microsoft, NVIDIA, Cisco, Dell, and dozens more.

    Highlights:
    ✅ CISA reaffirmed the CVE program as a top agency priority and called on AI companies to play a larger role going forward
    ✅ CWE is becoming a more integral part of vulnerability disclosure, with root-cause mapping gaining wider adoption
    ✅ New product launches on the show floor, including Volerion's Vulnerability Intelligence Platform, NetRise Provenance, and a major Red Hat security data overhaul
    ✅ Key updates from CVE Working Groups, the EPSS SIG, and Women of FIRST

    Speaker sessions will be available on-demand for virtual attendees in the FIRST Events app, as well as FIRST's YouTube channel in the coming weeks.

    A huge thank you to everyone who attended, presented, sponsored, and supported this event.

    This community is what makes the vulnerability management ecosystem stronger!

    Read more: go.first.org/WabqC

    #CyberDefense #cybersecurity #infosec

  24. 🎉 The CVE/FIRST #VulnCon26 & Annual CNA Summit has wrapped, and what a week it was.

    500+ security professionals from around the world gathered in Scottsdale, AZ to advance the #VulnerabilityManagement ecosystem, with sessions led by leaders from CISA, ENISA, NIST, Google, Microsoft, NVIDIA, Cisco, Dell, and dozens more.

    Highlights:
    ✅ CISA reaffirmed the CVE program as a top agency priority and called on AI companies to play a larger role going forward
    ✅ CWE is becoming a more integral part of vulnerability disclosure, with root-cause mapping gaining wider adoption
    ✅ New product launches on the show floor, including Volerion's Vulnerability Intelligence Platform, NetRise Provenance, and a major Red Hat security data overhaul
    ✅ Key updates from CVE Working Groups, the EPSS SIG, and Women of FIRST

    Speaker sessions will be available on-demand for virtual attendees in the FIRST Events app, as well as FIRST's YouTube channel in the coming weeks.

    A huge thank you to everyone who attended, presented, sponsored, and supported this event.

    This community is what makes the vulnerability management ecosystem stronger!

    Read more: go.first.org/WabqC

    #CyberDefense #cybersecurity #infosec

  25. 🎉 The CVE/FIRST #VulnCon26 & Annual CNA Summit has wrapped, and what a week it was.

    500+ security professionals from around the world gathered in Scottsdale, AZ to advance the #VulnerabilityManagement ecosystem, with sessions led by leaders from CISA, ENISA, NIST, Google, Microsoft, NVIDIA, Cisco, Dell, and dozens more.

    Highlights:
    ✅ CISA reaffirmed the CVE program as a top agency priority and called on AI companies to play a larger role going forward
    ✅ CWE is becoming a more integral part of vulnerability disclosure, with root-cause mapping gaining wider adoption
    ✅ New product launches on the show floor, including Volerion's Vulnerability Intelligence Platform, NetRise Provenance, and a major Red Hat security data overhaul
    ✅ Key updates from CVE Working Groups, the EPSS SIG, and Women of FIRST

    Speaker sessions will be available on-demand for virtual attendees in the FIRST Events app, as well as FIRST's YouTube channel in the coming weeks.

    A huge thank you to everyone who attended, presented, sponsored, and supported this event.

    This community is what makes the vulnerability management ecosystem stronger!

    Read more: go.first.org/WabqC

    #CyberDefense #cybersecurity #infosec

  26. Our last day in Scottsdale and the momentum is still going strong — this community doesn’t slow down. #VulnCon26🦎✨#CVEProgram #CVSS 🔗go.first.org/WWSDp

  27. Our last day in Scottsdale and the momentum is still going strong — this community doesn’t slow down. #VulnCon26🦎✨#CVEProgram #CVSS 🔗go.first.org/WWSDp

  28. Our last day in Scottsdale and the momentum is still going strong — this community doesn’t slow down. #VulnCon26🦎✨#CVEProgram #CVSS 🔗go.first.org/WWSDp

  29. Our last day in Scottsdale and the momentum is still going strong — this community doesn’t slow down. #VulnCon26🦎✨#CVEProgram #CVSS 🔗go.first.org/WWSDp

  30. Our last day in Scottsdale and the momentum is still going strong — this community doesn’t slow down. #VulnCon26🦎✨#CVEProgram #CVSS 🔗go.first.org/WWSDp

  31. Afternoon sessions are heating up (and not just because we’re in the desert). #VulnCon26🔥🦎 #CVEProgram #CVSS 🔗go.first.org/WWSDp

  32. Afternoon sessions are heating up (and not just because we’re in the desert). #VulnCon26🔥🦎 #CVEProgram #CVSS 🔗go.first.org/WWSDp

  33. Afternoon sessions are heating up (and not just because we’re in the desert). #VulnCon26🔥🦎 #CVEProgram #CVSS 🔗go.first.org/WWSDp

  34. Afternoon sessions are heating up (and not just because we’re in the desert). #VulnCon26🔥🦎 #CVEProgram #CVSS 🔗go.first.org/WWSDp

  35. Afternoon sessions are heating up (and not just because we’re in the desert). #VulnCon26🔥🦎 #CVEProgram #CVSS 🔗go.first.org/WWSDp

  36. Coffee in hand, ideas flowing, community buzzing — that’s the #VulnCon26 morning vibe. 🌵✨ #CVEProgram #CVSS 🔗go.first.org/WWSDp

  37. Coffee in hand, ideas flowing, community buzzing — that’s the #VulnCon26 morning vibe. 🌵✨ #CVEProgram #CVSS 🔗go.first.org/WWSDp

  38. Coffee in hand, ideas flowing, community buzzing — that’s the #VulnCon26 morning vibe. 🌵✨ #CVEProgram #CVSS 🔗go.first.org/WWSDp

  39. Coffee in hand, ideas flowing, community buzzing — that’s the #VulnCon26 morning vibe. 🌵✨ #CVEProgram #CVSS 🔗go.first.org/WWSDp

  40. Coffee in hand, ideas flowing, community buzzing — that’s the #VulnCon26 morning vibe. 🌵✨ #CVEProgram #CVSS 🔗go.first.org/WWSDp

  41. Breakouts are buzzing at #VulnCon26 — real talk, real challenges, real solutions. Exactly what this ecosystem needs. 🌵💬#vulnerabilitymanagement #IncidentResponse 🔗go.first.org/WWSDp

  42. Breakouts are buzzing at #VulnCon26 — real talk, real challenges, real solutions. Exactly what this ecosystem needs. 🌵💬#vulnerabilitymanagement #IncidentResponse 🔗go.first.org/WWSDp

  43. Breakouts are buzzing at #VulnCon26 — real talk, real challenges, real solutions. Exactly what this ecosystem needs. 🌵💬#vulnerabilitymanagement #IncidentResponse 🔗go.first.org/WWSDp

  44. Breakouts are buzzing at #VulnCon26 — real talk, real challenges, real solutions. Exactly what this ecosystem needs. 🌵💬#vulnerabilitymanagement #IncidentResponse 🔗go.first.org/WWSDp

  45. Breakouts are buzzing at #VulnCon26 — real talk, real challenges, real solutions. Exactly what this ecosystem needs. 🌵💬#vulnerabilitymanagement #IncidentResponse 🔗go.first.org/WWSDp

  46. Help Net Security interviewed Art Manion, Tharros, FIRST Liaison Member, FIRST VRDX-SIG Chair, CVE Board Member, CVE SPWG Chair, on why vulnerability databases keep failing us, and what the community needs to do about it.

    Highlights:

    - Stop treating this as a data problem, it's first an architecture problem
    - There is no minimum set of assertions that can confirm two systems describe the same vulnerability
    - CVSS scores are pulling attention away from the harder work of real risk assessment
    - 50%+ of vendor names in NVD's CPE data have naming inconsistencies, if you can't identify the product, nothing else matters
    - Before writing new specs or building new tools, the community needs shared terms and principles

    This research is part of ongoing collaborative work with Jay Jacobs, Co-Founder & Data Scientist, Empirical Security, FIRST EPSS-SIG Co-Chair, CVE Consumer WG Chair.

    Catch Art and Jay live at #VulnCon26: 'A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle' — April 14, 1:30–2:30 PM MST.

    📖 Read the full interview: go.first.org/jnofT

    #cybersecurity #CVE
    #infosec #VulnerabilityManagement

  47. Help Net Security interviewed Art Manion, Tharros, FIRST Liaison Member, FIRST VRDX-SIG Chair, CVE Board Member, CVE SPWG Chair, on why vulnerability databases keep failing us, and what the community needs to do about it.

    Highlights:

    - Stop treating this as a data problem, it's first an architecture problem
    - There is no minimum set of assertions that can confirm two systems describe the same vulnerability
    - CVSS scores are pulling attention away from the harder work of real risk assessment
    - 50%+ of vendor names in NVD's CPE data have naming inconsistencies, if you can't identify the product, nothing else matters
    - Before writing new specs or building new tools, the community needs shared terms and principles

    This research is part of ongoing collaborative work with Jay Jacobs, Co-Founder & Data Scientist, Empirical Security, FIRST EPSS-SIG Co-Chair, CVE Consumer WG Chair.

    Catch Art and Jay live at #VulnCon26: 'A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle' — April 14, 1:30–2:30 PM MST.

    📖 Read the full interview: go.first.org/jnofT

    #cybersecurity #CVE
    #infosec #VulnerabilityManagement

  48. Help Net Security interviewed Art Manion, Tharros, FIRST Liaison Member, FIRST VRDX-SIG Chair, CVE Board Member, CVE SPWG Chair, on why vulnerability databases keep failing us, and what the community needs to do about it.

    Highlights:

    - Stop treating this as a data problem, it's first an architecture problem
    - There is no minimum set of assertions that can confirm two systems describe the same vulnerability
    - CVSS scores are pulling attention away from the harder work of real risk assessment
    - 50%+ of vendor names in NVD's CPE data have naming inconsistencies, if you can't identify the product, nothing else matters
    - Before writing new specs or building new tools, the community needs shared terms and principles

    This research is part of ongoing collaborative work with Jay Jacobs, Co-Founder & Data Scientist, Empirical Security, FIRST EPSS-SIG Co-Chair, CVE Consumer WG Chair.

    Catch Art and Jay live at #VulnCon26: 'A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle' — April 14, 1:30–2:30 PM MST.

    📖 Read the full interview: go.first.org/jnofT

    #cybersecurity #CVE
    #infosec #VulnerabilityManagement

  49. Help Net Security interviewed Art Manion, Tharros, FIRST Liaison Member, FIRST VRDX-SIG Chair, CVE Board Member, CVE SPWG Chair, on why vulnerability databases keep failing us, and what the community needs to do about it.

    Highlights:

    - Stop treating this as a data problem, it's first an architecture problem
    - There is no minimum set of assertions that can confirm two systems describe the same vulnerability
    - CVSS scores are pulling attention away from the harder work of real risk assessment
    - 50%+ of vendor names in NVD's CPE data have naming inconsistencies, if you can't identify the product, nothing else matters
    - Before writing new specs or building new tools, the community needs shared terms and principles

    This research is part of ongoing collaborative work with Jay Jacobs, Co-Founder & Data Scientist, Empirical Security, FIRST EPSS-SIG Co-Chair, CVE Consumer WG Chair.

    Catch Art and Jay live at #VulnCon26: 'A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle' — April 14, 1:30–2:30 PM MST.

    📖 Read the full interview: go.first.org/jnofT

    #cybersecurity #CVE
    #infosec #VulnerabilityManagement

  50. Help Net Security interviewed Art Manion, Tharros, FIRST Liaison Member, FIRST VRDX-SIG Chair, CVE Board Member, CVE SPWG Chair, on why vulnerability databases keep failing us, and what the community needs to do about it.

    Highlights:

    - Stop treating this as a data problem, it's first an architecture problem
    - There is no minimum set of assertions that can confirm two systems describe the same vulnerability
    - CVSS scores are pulling attention away from the harder work of real risk assessment
    - 50%+ of vendor names in NVD's CPE data have naming inconsistencies, if you can't identify the product, nothing else matters
    - Before writing new specs or building new tools, the community needs shared terms and principles

    This research is part of ongoing collaborative work with Jay Jacobs, Co-Founder & Data Scientist, Empirical Security, FIRST EPSS-SIG Co-Chair, CVE Consumer WG Chair.

    Catch Art and Jay live at #VulnCon26: 'A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle' — April 14, 1:30–2:30 PM MST.

    📖 Read the full interview: go.first.org/jnofT

    #cybersecurity #CVE
    #infosec #VulnerabilityManagement

  51. There’s something special about seeing the VM ecosystem come together in one place. #VulnCon26 is where collaboration happens. 🤠🌅 #vulnerabilitymanagement 🔗go.first.org/WWSDp

  52. There’s something special about seeing the VM ecosystem come together in one place. #VulnCon26 is where collaboration happens. 🤠🌅 #vulnerabilitymanagement 🔗go.first.org/WWSDp

  53. There’s something special about seeing the VM ecosystem come together in one place. #VulnCon26 is where collaboration happens. 🤠🌅 #vulnerabilitymanagement 🔗go.first.org/WWSDp

  54. There’s something special about seeing the VM ecosystem come together in one place. #VulnCon26 is where collaboration happens. 🤠🌅 #vulnerabilitymanagement 🔗go.first.org/WWSDp

  55. There’s something special about seeing the VM ecosystem come together in one place. #VulnCon26 is where collaboration happens. 🤠🌅 #vulnerabilitymanagement 🔗go.first.org/WWSDp

  56. Nothing like Scottsdale views + cybersecurity brainpower. #VulnCon26 is off to a strong start. 🌅✨#vulnerabilitymanagement 🔗go.first.org/WWSDp

  57. Nothing like Scottsdale views + cybersecurity brainpower. #VulnCon26 is off to a strong start. 🌅✨#vulnerabilitymanagement 🔗go.first.org/WWSDp

  58. Nothing like Scottsdale views + cybersecurity brainpower. #VulnCon26 is off to a strong start. 🌅✨#vulnerabilitymanagement 🔗go.first.org/WWSDp

  59. Nothing like Scottsdale views + cybersecurity brainpower. #VulnCon26 is off to a strong start. 🌅✨#vulnerabilitymanagement 🔗go.first.org/WWSDp

  60. Nothing like Scottsdale views + cybersecurity brainpower. #VulnCon26 is off to a strong start. 🌅✨#vulnerabilitymanagement 🔗go.first.org/WWSDp