home.social

#vulncon26 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vulncon26, aggregated by home.social.

fetched live
  1. The CVE funding disruption exposed a single point of failure in the infrastructure that underpins global vulnerability management. In this Help Net Security interview, ENISA's Nuno Rodrigues Carvalho, #VulnCon26 speaker, breaks down what needs to change.

    📖 Read more: go.first.org/bSrxK

    #CyberDefense #cybersecurity #CVE

  2. The CVE funding disruption exposed a single point of failure in the infrastructure that underpins global vulnerability management. In this Help Net Security interview, ENISA's Nuno Rodrigues Carvalho, #VulnCon26 speaker, breaks down what needs to change.

    📖 Read more: go.first.org/bSrxK

    #CyberDefense #cybersecurity #CVE

  3. New on the FIRST blog: Jenn Gile, Co-Founder of OpenSourceMalware and #VulnCon26 speaker, on why malicious open source packages don't fit the traditional vulnerability intelligence model.

    The response motion looks familiar. A malicious package appears in a public registry, a record lands in OSV, tools fire an alert, and someone opens a ticket. But the data and the playbook don't actually match the threat.

    🔍 Vulnerabilities are passive. They wait to be exploited.
    ⚡ Malicious packages are active. They execute on install.
    🔧 Vulnerabilities have a fixed version.
    🚫 Malicious packages ARE the latest version.

    That mismatch leaves three investigative gaps vulnerability databases weren't built to fill:

    📦 Payload: what the malware did and which files were affected.
    👤 Threat actor: C2 infrastructure and accounts reused across campaigns.
    🔗 Campaign: how one package connects to broader activity.

    Case in point: the axios account takeover on March 30, 2026. OSV surfaces three IOCs. The campaign has at least nine, two of them shared with other malicious assets.

    Jenn's argument: malicious packages need their own intelligence track, built around a different set of questions.

    📖 Read more: go.first.org/BwFfv

    #cybersecurity #infosec #VulnerabilityManagement

  4. New on the FIRST blog: Jenn Gile, Co-Founder of OpenSourceMalware and #VulnCon26 speaker, on why malicious open source packages don't fit the traditional vulnerability intelligence model.

    The response motion looks familiar. A malicious package appears in a public registry, a record lands in OSV, tools fire an alert, and someone opens a ticket. But the data and the playbook don't actually match the threat.

    🔍 Vulnerabilities are passive. They wait to be exploited.
    ⚡ Malicious packages are active. They execute on install.
    🔧 Vulnerabilities have a fixed version.
    🚫 Malicious packages ARE the latest version.

    That mismatch leaves three investigative gaps vulnerability databases weren't built to fill:

    📦 Payload: what the malware did and which files were affected.
    👤 Threat actor: C2 infrastructure and accounts reused across campaigns.
    🔗 Campaign: how one package connects to broader activity.

    Case in point: the axios account takeover on March 30, 2026. OSV surfaces three IOCs. The campaign has at least nine, two of them shared with other malicious assets.

    Jenn's argument: malicious packages need their own intelligence track, built around a different set of questions.

    📖 Read more: go.first.org/BwFfv

    #cybersecurity #infosec #VulnerabilityManagement

  5. 📰 Maria Korolov, CSO Online covered NIST's major shift in CVE handling announced at #VulnCon26, as the National Vulnerability Database buckles under a 30,000+ backlog and submissions grow 263% since 2020.

    FIRST CEO Chris Gibson weighs in on the vulnerability velocity crisis, with FIRST projecting 59,427 CVEs in 2026 and realistic scenarios cracking 100,000 amid the rise of AI-powered discovery tools like Anthropic's Mythos.

    Harold Booth, Supervisory Computer Scientist, NIST outlined the agency's pivot to prioritize KEV-listed and critical software CVEs while turning to LLMs, AI agents, and RPA to tackle the backlog.

    Jay Jacobs, Co-Founder & Data Scientist, Empirical Security, FIRST EPSS-SIG Co-Chair, CVE Consumer WG Chair shares optimism that AI-driven automation can help NIST keep pace, noting that even if it isn't Mythos, "something is going to come out next week."

    Read more: go.first.org/9k8UO

    #cybersecurity #infosec #VulnerabilityManagement

  6. 📰 Maria Korolov, CSO Online covered NIST's major shift in CVE handling announced at #VulnCon26, as the National Vulnerability Database buckles under a 30,000+ backlog and submissions grow 263% since 2020.

    FIRST CEO Chris Gibson weighs in on the vulnerability velocity crisis, with FIRST projecting 59,427 CVEs in 2026 and realistic scenarios cracking 100,000 amid the rise of AI-powered discovery tools like Anthropic's Mythos.

    Harold Booth, Supervisory Computer Scientist, NIST outlined the agency's pivot to prioritize KEV-listed and critical software CVEs while turning to LLMs, AI agents, and RPA to tackle the backlog.

    Jay Jacobs, Co-Founder & Data Scientist, Empirical Security, FIRST EPSS-SIG Co-Chair, CVE Consumer WG Chair shares optimism that AI-driven automation can help NIST keep pace, noting that even if it isn't Mythos, "something is going to come out next week."

    Read more: go.first.org/9k8UO

    #cybersecurity #infosec #VulnerabilityManagement

  7. 📰 Kevin Poireault, Infosecurity Magazine, sat down with FIRST CEO Chris Gibson at #VulnCon26 in Scottsdale, AZ, unpacking the AI-driven vulnerability tsunami reshaping #VulnerabilityManagement, with mean time to exploit now measured in hours, not weeks.

    Gibson makes the case for global collaboration over fragmentation, welcomes ENISA joining CISA and MITRE as a Top-Level Root CNA, and predicts Anthropic and OpenAI will become CVE Numbering Authorities by year-end.

    Read more: go.first.org/lM4sa

    #CVE #CyberDefense #cybersecurity #infosec

  8. 📰 Kevin Poireault, Infosecurity Magazine, sat down with FIRST CEO Chris Gibson at #VulnCon26 in Scottsdale, AZ, unpacking the AI-driven vulnerability tsunami reshaping #VulnerabilityManagement, with mean time to exploit now measured in hours, not weeks.

    Gibson makes the case for global collaboration over fragmentation, welcomes ENISA joining CISA and MITRE as a Top-Level Root CNA, and predicts Anthropic and OpenAI will become CVE Numbering Authorities by year-end.

    Read more: go.first.org/lM4sa

    #CVE #CyberDefense #cybersecurity #infosec

  9. 🎉 The CVE/FIRST #VulnCon26 & Annual CNA Summit has wrapped, and what a week it was.

    500+ security professionals from around the world gathered in Scottsdale, AZ to advance the #VulnerabilityManagement ecosystem, with sessions led by leaders from CISA, ENISA, NIST, Google, Microsoft, NVIDIA, Cisco, Dell, and dozens more.

    Highlights:
    ✅ CISA reaffirmed the CVE program as a top agency priority and called on AI companies to play a larger role going forward
    ✅ CWE is becoming a more integral part of vulnerability disclosure, with root-cause mapping gaining wider adoption
    ✅ New product launches on the show floor, including Volerion's Vulnerability Intelligence Platform, NetRise Provenance, and a major Red Hat security data overhaul
    ✅ Key updates from CVE Working Groups, the EPSS SIG, and Women of FIRST

    Speaker sessions will be available on-demand for virtual attendees in the FIRST Events app, as well as FIRST's YouTube channel in the coming weeks.

    A huge thank you to everyone who attended, presented, sponsored, and supported this event.

    This community is what makes the vulnerability management ecosystem stronger!

    Read more: go.first.org/WabqC

    #CyberDefense #cybersecurity #infosec

  10. 🎉 The CVE/FIRST #VulnCon26 & Annual CNA Summit has wrapped, and what a week it was.

    500+ security professionals from around the world gathered in Scottsdale, AZ to advance the #VulnerabilityManagement ecosystem, with sessions led by leaders from CISA, ENISA, NIST, Google, Microsoft, NVIDIA, Cisco, Dell, and dozens more.

    Highlights:
    ✅ CISA reaffirmed the CVE program as a top agency priority and called on AI companies to play a larger role going forward
    ✅ CWE is becoming a more integral part of vulnerability disclosure, with root-cause mapping gaining wider adoption
    ✅ New product launches on the show floor, including Volerion's Vulnerability Intelligence Platform, NetRise Provenance, and a major Red Hat security data overhaul
    ✅ Key updates from CVE Working Groups, the EPSS SIG, and Women of FIRST

    Speaker sessions will be available on-demand for virtual attendees in the FIRST Events app, as well as FIRST's YouTube channel in the coming weeks.

    A huge thank you to everyone who attended, presented, sponsored, and supported this event.

    This community is what makes the vulnerability management ecosystem stronger!

    Read more: go.first.org/WabqC

    #CyberDefense #cybersecurity #infosec

  11. Our last day in Scottsdale and the momentum is still going strong — this community doesn’t slow down. #VulnCon26🦎✨#CVEProgram #CVSS 🔗go.first.org/WWSDp

  12. Our last day in Scottsdale and the momentum is still going strong — this community doesn’t slow down. #VulnCon26🦎✨#CVEProgram #CVSS 🔗go.first.org/WWSDp

  13. Afternoon sessions are heating up (and not just because we’re in the desert). #VulnCon26🔥🦎 #CVEProgram #CVSS 🔗go.first.org/WWSDp

  14. Afternoon sessions are heating up (and not just because we’re in the desert). #VulnCon26🔥🦎 #CVEProgram #CVSS 🔗go.first.org/WWSDp

  15. Coffee in hand, ideas flowing, community buzzing — that’s the #VulnCon26 morning vibe. 🌵✨ #CVEProgram #CVSS 🔗go.first.org/WWSDp

  16. Coffee in hand, ideas flowing, community buzzing — that’s the #VulnCon26 morning vibe. 🌵✨ #CVEProgram #CVSS 🔗go.first.org/WWSDp

  17. Breakouts are buzzing at #VulnCon26 — real talk, real challenges, real solutions. Exactly what this ecosystem needs. 🌵💬#vulnerabilitymanagement #IncidentResponse 🔗go.first.org/WWSDp

  18. Breakouts are buzzing at #VulnCon26 — real talk, real challenges, real solutions. Exactly what this ecosystem needs. 🌵💬#vulnerabilitymanagement #IncidentResponse 🔗go.first.org/WWSDp

  19. Help Net Security interviewed Art Manion, Tharros, FIRST Liaison Member, FIRST VRDX-SIG Chair, CVE Board Member, CVE SPWG Chair, on why vulnerability databases keep failing us, and what the community needs to do about it.

    Highlights:

    - Stop treating this as a data problem, it's first an architecture problem
    - There is no minimum set of assertions that can confirm two systems describe the same vulnerability
    - CVSS scores are pulling attention away from the harder work of real risk assessment
    - 50%+ of vendor names in NVD's CPE data have naming inconsistencies, if you can't identify the product, nothing else matters
    - Before writing new specs or building new tools, the community needs shared terms and principles

    This research is part of ongoing collaborative work with Jay Jacobs, Co-Founder & Data Scientist, Empirical Security, FIRST EPSS-SIG Co-Chair, CVE Consumer WG Chair.

    Catch Art and Jay live at #VulnCon26: 'A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle' — April 14, 1:30–2:30 PM MST.

    📖 Read the full interview: go.first.org/jnofT

    #cybersecurity #CVE
    #infosec #VulnerabilityManagement

  20. Help Net Security interviewed Art Manion, Tharros, FIRST Liaison Member, FIRST VRDX-SIG Chair, CVE Board Member, CVE SPWG Chair, on why vulnerability databases keep failing us, and what the community needs to do about it.

    Highlights:

    - Stop treating this as a data problem, it's first an architecture problem
    - There is no minimum set of assertions that can confirm two systems describe the same vulnerability
    - CVSS scores are pulling attention away from the harder work of real risk assessment
    - 50%+ of vendor names in NVD's CPE data have naming inconsistencies, if you can't identify the product, nothing else matters
    - Before writing new specs or building new tools, the community needs shared terms and principles

    This research is part of ongoing collaborative work with Jay Jacobs, Co-Founder & Data Scientist, Empirical Security, FIRST EPSS-SIG Co-Chair, CVE Consumer WG Chair.

    Catch Art and Jay live at #VulnCon26: 'A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle' — April 14, 1:30–2:30 PM MST.

    📖 Read the full interview: go.first.org/jnofT

    #cybersecurity #CVE
    #infosec #VulnerabilityManagement

  21. There’s something special about seeing the VM ecosystem come together in one place. #VulnCon26 is where collaboration happens. 🤠🌅 #vulnerabilitymanagement 🔗go.first.org/WWSDp

  22. There’s something special about seeing the VM ecosystem come together in one place. #VulnCon26 is where collaboration happens. 🤠🌅 #vulnerabilitymanagement 🔗go.first.org/WWSDp

  23. Nothing like Scottsdale views + cybersecurity brainpower. #VulnCon26 is off to a strong start. 🌅✨#vulnerabilitymanagement 🔗go.first.org/WWSDp

  24. Nothing like Scottsdale views + cybersecurity brainpower. #VulnCon26 is off to a strong start. 🌅✨#vulnerabilitymanagement 🔗go.first.org/WWSDp

  25. Kicking off #VulnCon26 in Scottsdale — the VM community is officially in the house! Let’s spark ideas and build something stronger together. 🌵✨ #CVEProgram #CVSS 🔗go.first.org/WWSDp

  26. Kicking off #VulnCon26 in Scottsdale — the VM community is officially in the house! Let’s spark ideas and build something stronger together. 🌵✨ #CVEProgram #CVSS 🔗go.first.org/WWSDp

  27. What if the key to better vulnerability management isn't just patching faster, but understanding why vulnerabilities keep coming back? 🔍

    Help Net Security connected with #VulnCon26 speaker Alec Summers, MITRE CVE/CWE Project Lead, Principal Cybersecurity Engineer, and FIRST Member, to explore how CWE mapping is becoming a strategic layer of the vulnerability management stack.

    🎤 Catch Alec's upcoming presentations at VulnCon26 next week and read the full Q&A here: go.first.org/BZzAf

    #CVE #cybersecurity
    #infosec #VulnerabilityManagement

  28. What if the key to better vulnerability management isn't just patching faster, but understanding why vulnerabilities keep coming back? 🔍

    Help Net Security connected with #VulnCon26 speaker Alec Summers, MITRE CVE/CWE Project Lead, Principal Cybersecurity Engineer, and FIRST Member, to explore how CWE mapping is becoming a strategic layer of the vulnerability management stack.

    🎤 Catch Alec's upcoming presentations at VulnCon26 next week and read the full Q&A here: go.first.org/BZzAf

    #CVE #cybersecurity
    #infosec #VulnerabilityManagement

  29. Today (March 25th) is the very last day to book within the #VulnCon26 hotel room block. Future you will be glad you clicked “reserve.” 🌵🏨

    🔗go.first.org/WWSDp

    #LastCall #Scottsdale

  30. Today (March 25th) is the very last day to book within the #VulnCon26 hotel room block. Future you will be glad you clicked “reserve.” 🌵🏨

    🔗go.first.org/WWSDp

    #LastCall #Scottsdale

  31. You asked, and we delivered (again)! 🎉 The hotel room block for #VulnCon26 has been extended once more—you now have until March 25th to lock in your stay. 🌵🏨 Don’t miss your chance to stay close to all the action! 🔗go.first.org/WWSDp

    #Scottsdale #RoomBlockExtended

  32. You asked, and we delivered (again)! 🎉 The hotel room block for #VulnCon26 has been extended once more—you now have until March 25th to lock in your stay. 🌵🏨 Don’t miss your chance to stay close to all the action! 🔗go.first.org/WWSDp

    #Scottsdale #RoomBlockExtended

  33. Good news, desert travelers — the room block just got extended! You now have until March 20th to reserve your stay. 🌵🌞🏨🔗go.first.org/WWSDp
    #VulnCon26 #Scottsdale #RoomBlockExtended

  34. Good news, desert travelers — the room block just got extended! You now have until March 20th to reserve your stay. 🌵🌞🏨🔗go.first.org/WWSDp
    #VulnCon26 #Scottsdale #RoomBlockExtended

  35. #VulnCon26 Checklist
    Registration ✅
    Flights Booked ✅
    Hotel Room Reserved 👀 …wait, you booked your room, right?

    The discounted rate expires on March 14th, so do your future self a favor and book now 😉👉🔗 go.first.org/o0mK5

  36. #VulnCon26 Checklist
    Registration ✅
    Flights Booked ✅
    Hotel Room Reserved 👀 …wait, you booked your room, right?

    The discounted rate expires on March 14th, so do your future self a favor and book now 😉👉🔗 go.first.org/o0mK5

  37. 🌵🤠 Wrangle up! #VulnCon26's early‑bird rate and hotel room block both ride off into the sunset on March 14th. Saddle up and get everything locked in before it’s gone. 🔗go.first.org/WWSDp