This year, we’re adding a day (aptly named Day 1, on 23 September) to more broadly cover All the (Vulnerability) Things. The expanded scope of Day 1 will provide a forum for the European vulnerability community to network and discuss vulnerability management, the anticipated AI vulnpocalypse, the realities of building a VDP, legal and policy considerations, and more.
All times are Luxembourg local, that is, Central European Summer Time (CEST, UTC+2).
Reminder! Day 1 is in a different location than Days 2 and 3. See Hotel and Venues.
Jump to: Day 1 (23 September), Day 2 (24 September), Day 3 (25 September)
Maison des Arts et des Étudiants - Grande Salle - Place de l'Université Belval, Esch-sur-Alzette
| 9:00 | Venue open |
| 9:30 |
Opening remarks FIRST VulnOptiCON Program Committee |
| 10:00 |
Day 1 Keynote: AI Innovations for Vulnerability Management Jaya Baloo, AISLE |
| 11:00 |
Establishing a Unified Model for EU Vulnerability Services Johannes Clos, ENISA |
| 11:30 |
GCVE: Rebooting Vulnerability Tracking for an Open Security Ecosystem Alexandre Dulaunoy, CIRCL |
| 12:00 |
Would You Let an AI Close That Ticket? Earning a Security Team's Trust in Exposure Management Ron Dovich, Brinqa |
| 12:30 | Lunch |
| 13:30 |
TBC |
| 15:00 | Break |
| 15:30 |
Drowning in Disclosure: The Operational Reality of Vulnerability Response Katie Noble, Intel |
| 16:00 |
I Reject Your Reality and Substitute My Own: Two Years of Vulnerability Discovery with LLM Agents Erick Galinkin, NVIDIA |
| 16:30 |
Broken, Reachable, and Harmful: Rethinking Vulnerabilities Jay Jacobs, Empirical Security |
| 17:00 | End of Day 1 |
Luxembourg Mariott Hotel Alfa
| 8:30 | Venue open |
| 9:00 |
Opening remarks VulnOptiCON Program Committee |
| 9:15 |
Day 2 Keynote: Signal and Noise: What A Decade In Forecasting Science Has Taught Me Regina Joseph |
| 10:00 |
The CVE Panopticon: What Happens When The Prisoners Set The Standards? Jerry Gamblin, Empirical Security |
| 10:30 | Break |
| 16:30 |
Beyond Remediation: Integrating Countermeasures into Vulnerability Management Angelo Punturiero, Nestlé; Martin Karel, Nestlé; Alexia Sorel, Nestlé |
| 11:20 |
Measuring and Forecasting Exploitation Conditions Ruben Bos, Volerion |
| 12:00 | Lunch |
| 13:00 |
You, Me, and CVE: What Does the Future Hold for the CVE Program? Jen Ellis, NextJen Security |
| 14:30 |
What Does NCSC (UK) Actually Do With Vulnerability Data? NCSC (UK) |
| 15:00 | Break |
| 15:30 |
SoK: Understanding the state of IoT-specific vulnerabilities via CVE characterization with LLIoT Tina Rezaei, University of Twente |
| 16:15 |
Exploitation Saturation and Designing for Detection Éireann Leverett, Concinnity Risks |
| 17:00 | End of Day 2 |
| 18:00 | Social Event |
Luxembourg Mariott Hotel Alfa
| 8:30 | Venue open |
| 9:00 |
Opening remarks VulnOptiCON Program Committee |
| 9:15 |
Hard on the Outside, Soft in the Middle: How Many Clicks to Post Quantum? Davi Ottenheimer |
| 10:00 |
Group Therapy—Come and Share Your Fear and Pain Relating to AI and Vulns Alexandre Dulaunoy, CIRCL |
| 10:45 | Break |
| 11:15 |
Detecting What Cannot Yet Be Named —Can We Optimize the Vulnerability Ecoystem? Natalie Kilber, Haste |
| 11:45 |
Ben Edwards, Empirical Security |
| 12:15 |
Cassie Crossley, VulNow |
| 12:30 | Lunch |
| 13:30 |
Lightning Debates —Bring Us Your Topics! Jen Ellis, NextJen Security |
| 14:20 |
On the Mineshaft Gap: Infinite Vulnerabilities, One Deadline, Zero Public Messaging Trey Darley, Proper Tools SRL |
| 14:45 |
Pick a Number Anyway: Measuring the SBOM → CRA Article 14 Pipeline When Your Tools Disagree by Half Andrey Lukashenkov, Vulners |
| 15:00 | Break |
| 15:30 |
The Missing Map: Crowdsourcing Better CPEs for Vulnerability Management with cpe.gcve.eu Alexandre Dulaunoy, CIRCL |
| 16:00 |
VulnOptiCON 2027, The Next Episode Everyone |
| 16:15 |
Closing Remarks VulnOptiCON Program Commitee |
| 16:30 | Fin |
Jaya Baloo, AISLE
Jaya Baloo is a globally recognized cybersecurity leader, consistently ranked among the top 100 CISOs and top 100 security influencers worldwide. She is a leading expert in cybersecurity and quantum readiness. Baloo brings extensive CISO experience to her role as COO & CISO at AISLE, an AI & Cybersecurity startup she co-founded. With over 12 years of leadership in cybersecurity, she previously served as CISO at Rapid7 and Avast, and prior to that at KPN, the Netherlands' largest telecommunications provider. She served as an Expert in Quantum and Cybersecurity for the World Economic Forum and advised Europol's European Cybercrime Centre (EC3). She was also formerly the Vice Chair of the EU Quantum Flagship and on the board of the Dutch news service, the NOS. Jaya Baloo currently sits on the audit committee of TIN Capital, a cybersecurity fund, and serves as a board member of Yubico, the Cyber Threat Alliance (CTA), & the DIVD and is on the CTREX Board for the Monetary Authority of Singapore. Baloo also lectures as a faculty member at Singularity University. In 2019, she was selected as one of the 50 most inspiring women in the Netherlands by Inspiring Fifty. Baloo's distinguished career includes an honorary doctorate from the University of Twente in 2022, awarded in recognition of her inspiring leadership and contributions to cybersecurity advancements.
Johannes Clos, ENISA
As the Cyber Resilience Act’s reporting obligations begin to apply and ENISA rolls out the Single Reporting Platform, this session offers a timely deep dive into how ENISA is scaling its EU Vulnerability Services, including the European Vulnerability Database (EUVD), support to Member States’ coordinated vulnerability disclosure processes, and a growing operational role in the global vulnerability management ecosystem. The session will show how ENISA together with the EU CSIRTs network transforms vulnerability information into actionable guidance, prioritised mitigation, and more effective risk reduction across critical systems and supply chains. The talk will also examine lessons learned from real-world implementation, the importance of global interoperability and cooperation, and how AI is reshaping vulnerability discovery, potential exploitation, and faster remediation.
Johannes Kaspar Clos discovered an interest in computers initially through his passion for audio engineering and signal processing. Encountering the power of applied cryptography got him interested in information security and the political implications of technology. After receiving his diploma in computer science from TU Darmstadt, he followed initial research at Fraunhofer-Gesellschaft and University of Newcastle and worked as a network security engineer. In 2010, he joined CERT-Bund, Germany's national CSIRT section at the Federal Office for Information Security's (BSI). While supporting the team with building up its vulnerability coordination capacity, abuse automation, and strategic development, he cultivated a passion for CSIRT collaboration. Today, he is working for ENISA’s Incident and Vulnerability ServicesJ section where his tasks include the implementation of the EU vulnerability services catalogue.
|
Alexandre Dulaunoy, CIRCL |
Cedric Bonhomme, CIRCL |
The vulnerability ecosystem has become critical infrastructure for defenders, vendors, researchers, and open source maintainers. Yet the way identifiers and vulnerability data are assigned, published, and distributed still reflects a centralized model that does not always match the speed, diversity, and realities of today’s security landscape. This talk introduces GCVE, a new approach to vulnerability identification and tracking designed to support a more open, decentralized, and resilient ecosystem. GCVE rethinks how vulnerability numbers can be allocated, how trusted actors can publish advisories, and how vulnerability information can be synchronized without creating unnecessary bottlenecks or dependency on a single central authority. Through the lens of open source security, the talk will explain why this matters: maintainers need lightweight processes, defenders need timely and structured data, and the community needs a model that encourages participation rather than gatekeeping. It will also show how GCVE and its associated tooling can help make vulnerability tracking more transparent, interoperable, and adaptable. Rather than presenting only a new identifier format, this session will explore a broader idea: how we can build vulnerability tracking as shared public infrastructure for the security community.
Alexandre encountered his first computer in the eighties, and he disassembled it to know how the thing works. While pursuing his logical path towards information security and free software, he worked as senior security network consultant at different places (e.g. Ubizen, now Cybertrust). He co-founded a startup called Conostix specialized in information security management, and the past 6 years, he was the manager of global information security at SES, a leading international satellite operator. He is now working at the Luxembourgian Computer Security Incident Response Team (CSIRT) called CIRCL in the research and operational fields. He is also lecturer in information security at Paul-Verlaine University in Metz and the University of Luxembourg. Alexandre enjoys working on projects where there is a blend of “free information”, innovation and a direct social improvement. When not gardening binary streams, he likes facing the reality of ecosystems while gardening or doing photography.
TBC
Katie Noble, Intel
Modern PSIRTs face a growing imbalance between vulnerability demand and defensive capacity. Teams must triage an endless stream of reports of varying quality, coordinate remediation across complex products and supply chains, respond to active exploitation, and satisfy expanding regulatory obligations, all with finite resources and, regrettably, finite hours in the day. Releasing a patch is only part of the challenge. Patch fatigue, deployment complexity, incomplete data, disclosure deadlines, and competing business priorities can prevent vulnerability activity from producing meaningful risk reduction. Emerging technologies may accelerate vulnerability discovery, but finding more problems does not magically create more engineers to fix them. This talk examines how PSIRTs can forecast demand, identify operational bottlenecks, prioritize work based on exploitation and impact, and measure defensive capacity rather than celebrate ever-growing vulnerability counts. The central question is not how many vulnerabilities an organization can process, but whether limited resources are being directed toward the actions most likely to reduce real-world harm.
Katie serves as a CVE Program Board, Bug Bounty Community of Interest Founder, and Hacking Policy Council Founding member. She is a passionate defensive cybersecurity community activist, she is regularly involved is community driven projects and is most happy when she is able to effect positive progress in cyber defense. In her day job Katie Noble serves as a Director of PSIRT, specializing in Global Secretarial Policy and Industry Engagement and Bug Bounty, at a fortune 50 Technology Company. Prior to joining private sector, Katie spent over 15 years in the US Government. Most recently as the Section Chief of Vulnerability Management and Coordination at the Department of Homeland Security, Cyber and Infrastructure Security Agency (CISA). Her team is credited with the coordination and public disclosure of 20,000+ cybersecurity vulnerabilities within a two-year period. During her government tenure, in roles spanning Intelligence Analyst for the National Intelligence Community to Senior Policy Advisor for White House led National Security Council Cyber programs, Katie’s work directly impacted decision making for government agencies in the United States, United Kingdom, Canada, and Australia.
Erick Galinkin, NVIDIA
Suddenly, automated vulnerability discovery has become the eldritch monster stalking the security community. While policymakers and tech startups have proffered countless opinions about regulatory regimes, security teams must deal with the reality that the maxim "attackers are people too" does not necessarily hold any longer. This session offers practical guidance for defenders—and probably attackers—on the capabilities of agentic systems to autonomously discover vulnerabilities and conduct operations, and how they have evolved. Where defenders have attempted to incorporate language models, this session offers gentle reminders and at least one hot take about how to limit risk.
Erick Galinkin is a Research Scientist at NVIDIA, where he spends his time attacking AI systems, defending AI systems, and occasionally trying to determine which of those two things he is doing. His work focuses on the security of large language model-powered systems, and he currently chairs the AI Working Groups for both the CVE and CWE programs. Previously, he led AI research at Rapid7 after working his way through enough different cybersecurity roles to develop opinions about most of them. Erick holds a PhD in Computer Science from Drexel University, where his dissertation explored autonomous cyber defense through game theory, decision theory, and reinforcement learning, as well as an MS in Applied and Computational Mathematics from Johns Hopkins University. When not trying to make computers behave themselves, Erick is a father to three boys, which has provided extensive practical experience with intelligent agents that do not reliably follow instructions.
Jay Jacobs, Empirical Security
Ask security practitioners to define "vulnerability" and you will get a variety of answers that look roughly the same yet fall short in roughly the same places. The definitions aren't wrong, they work well on most cases well enough, but they break down on the edge cases, where the disputes live. This talk looks at the disputed CVEs (especially the high profile ones) and shows how these are just a failure in precise language and definition. A vulnerability is a disposition: a capacity for a security failure that exists in a system, that is waiting to be discovered and have the conditions for exploitation manifest that security failure. Understanding vulnerability as a disposition rather than just a weakness, flaw or an event changes how we classify hard cases, how we describe vulnerabilities, measure risk, and how we should be reporting and naming them.
Jay Jacobs is a Co-founder and Data Scientist at Empirical Security and Data Scientist Emeritus at Cyentia Institute. Jay is also the lead data scientist for the Exploit Prediction Scoring System (EPSS), a co-chair of the EPSS special interest group at FIRST and chair of the Consumer Working Group within the CVE program. He is also a co-founder of the Society for Information Risk Analysts (SIRA), a not-for-profit association dedicated to advancing risk management practices where he served on the board of directors for several years.
Regina Joseph
Before the results of an Intelligence Advanced Research Projects and Activity (IARPA) experiment that ran from 2011-2015 testing human forecasting ability, few believed that consistent and replicable accuracy was possible. Since the celebrated findings of that experiment, e.g., the discovery of superforecasters as well as the identification of technical systems, processes and behaviors correlated with better foresight, a pipeline of forecasting experiments (and their consequences) has revealed the complexity of what it takes to build a solid forecasting community. This research also exposed the unique challenges in applying the technologies of prediction in critical decision-making environments. As both a researcher and superforecaster veteran of IARPA’s multiple experiments in anticipatory intelligence—as well as her own forecasting research programs with European and US federal entities and private sector organizations&emdash;Regina Joseph will share apocryphal stories from the superforecaster frontlines, as well as insights on how to construct a high quality forecasting cohort.
A data scientist specialising in the analysis of vulnerability data and focused on applying data-driven approaches to support risk-informed decision-making.
Éireann Leverett, Concinnity Risks
There's a limit to how many CVEs are necessary to exploit a product successfully, and we think of this as exploitation saturation. We believe it is an ecosystem limiter on how many CVEs will see active exploitation, and needs a community consensus definition. Another limit that will be useful is how quickly we can write detection signatures for new CVEs and exploits. We want to explore this with the community to stay ahead of the game.
Éireann Leverett works on the parts of cyber risk that refuse to behave: the fat tails, the correlated losses, and the vulnerabilities nobody has found yet. As Founder and CTO of Concinnity Risks he builds the Extortion Loss Model, a ransomware catastrophe model on the Oasis framework that prices extortion loss across 245 countries. He leads the Vulnerability Forecasting Team at FIRST.org, Founded the Ransomware and Cyber Insurance SIGs there, and has published on actuarial methods for cyber, entity resolution, and ransomware economics. He is a cyber risk entrepreneur, and long term DFIR professional. With an Edinburgh BEng and Cambridge MPhil; he can occasionally found arguing that the set of vulnerabilities in a program is countably infinite. He once placed second in an Éireann Leverett impersonation contest.
Davi Ottenheimer
A CDN reported in late 2025 that more than half its traffic uses hybrid key agreement and wrote a story about being halfway to post-quantum. We started measuring origin servers to check and found the headlines about adoption are an inflated client-side figure distracting from a near-zero origin deployment. Over the past year https://pqprobe.com/dashboard/nis2 has been tracking EU origin infrastructure (NIS2 essential entities, named vendors, BSI C5 attested cloud providers) with a rescore on every probe, producing a trajectory map to compare with the snapshots. This talk presents the latest trajectory data: where things started, the slope over time, and what the observed remediation velocity implies for the CNSA 2.0 and BSI deadlines of 2027, 2030, and 2035. Data is segmented by industry and state. The forecast is a remediation rate for the known, dated exposure (HNDL) across a stable population, scored against each regulatory deadline. We focus on where and why a slope will go flat, where and when it degraded, and which areas are moving fast enough to hit the looming deadlines.
Davi Ottenheimer operates a new EU-based security research and consulting practice focused on AI harness safety and post-quantum cryptography readiness. He builds and operates a PQC tool and grading platform that tracks migration posture across NIS2 Annex I and II sectors in Europe. Previously as head of security for Inrupt (Tim Berners-Lee's future vision for the Web) he released the "Charlie" secure personal assistant running the Solid protocol, designed for TEE-based models. Before that he was head of security at MongoDB, where he built field level encryption, the company's CVE Numbering Authority and coordinated disclosure program, and established their CISO function. His current research examines insecure-by-default patterns, data integrity breaches, and the gap between post-quantum adoption claims and measurable deployment. He has presented at security conferences across Europe and North America for twenty years and has been part of the BSides community since its founding. He bloviates at flyingpenguin.com.
|
Claus Cramon-Houmann, Infosec Librarian |
Alexandre Dulaunoy, CIRCL |
Art Manion, Tharros |
There's been a lot of hype and fear, uncertainty, and doubt (FUD) around rapidly evolving AI capabilities to discover and exploit vulnerabilities. Despite the huge amount of misreporting, misunderstanding, and uncertainty, the aggregate impact of LLMs over the last 12+ months IS a significant step change for defenders. We're only just beginning to see the new reality; however, as defenders, we must quickly adjust to it and mitigate the shifting risk landscape. Mythos and various other AI models have created enough noise to overwhelm even large and well-resourced corporations. We're now starting to see signs of meaningful change in conversations and activity to tackle this. This requires substantially reframing current understandings, baselines for security behaviour and processes, budgets and risk management frameworks. What does a machine-speed response look like? Can such a response be useful, and if so, how and when? Come join our group therapy session on this timely issue of AI pain and uncertainty in the vulnerability ecosystem. We'll have a frank, guided discussion with as many participants as want to join in, kicked-off by Claus and Alexandre sharing their own experiences, concerns, and response plans. Bring your perspectives on the emerging realities, predictions of what is to come, and suggestions for ideas and architecture to respond to the evolving risk.
Natalie Kilber, Haste
Real-world exploitation rarely hinges on a single vulnerability. In practice, attackers construct layered attack chains — combining memory corruption, privilege escalation, container escapes, and logic flaws — to achieve their intended impact. This talk examines why the "single CVE" mental model understates actual attack complexity, and why that complexity, paradoxically, creates detection opportunity. The ultimate goal is to discuss if the vulnerability ecosystem can be optimized for faster zero day anaylsis and transfer into signatures. We explore how behavioral and anomaly-based detection operates independently of signature knowledge: rather than asking what vulnerability is being exploited, it asks what the system is doing that it shouldn't be. Process lineage, unexpected syscall sequences, lateral movement patterns, and anomalous inter-process communication all surface attacker behavior regardless of whether the underlying flaw has a CVE number attached to it. The central challenge of zero-day detection is one of elimination: known exploit types, known attack chains, and known indicators of compromise can all be ruled out through conventional detection, but will be part of the attack chain. What remains — behavior that is anomalous but matches no known pattern — is where zero-day candidates live. We discuss what it takes to shrink the window between exploitation and discovery - showing three interlocking problems:
-
First, the adequacy of behavioral/threat detection as a primary paradigm: does it represent a sufficiently developed methodology — in telemetry fidelity, baselining, and cross-layer signal/IoC/attack chain correlation — to close the gap that signature-based approaches leave structurally open?
-
Second, the upstream question of whether the vulnerability ecosystem itself can be reformed to accelerate the transition from zero-day discovery to actionable signature: disclosure practices, patch cadence, CVE taxonomy, and exploit broker market dynamics all shape how long an unknown flaw remains uncharacterized, and structural interventions at any of these points could compress that window before detection is even attempted.
-
Third, the organizational and epistemic conditions required for effective zero-day detection in practice — specifically, the institutional willingness to treat unattributed anomalies as threat hypotheses rather than noise or uncertainties, and the taxonomy and process investment for the vulnerability ecosystem.
Running beneath all three is a foundational epistemological tension: zero-day detection is, by definition, the problem of detecting what cannot yet be named.
Natalie Kilber is the CEO of Haste, a stealth startup securing the future of compute. She brings more than 16+ years of experience spanning research, industrial control systems, cloud, and technology sectors, with a focus on emergent technologies, product development, and threat hunting. Before founding Haste, Natalie held roles at HARMAN, Microsoft, Siemens Energy, MHP – A Porsche Company, and several startups. She also serves as an external evaluator for EU research funding programs covering quantum, AI, and cybersecurity, and is a frequent speaker at international conferences. Natalie studied physics and computer science at the University of Stuttgart and quantum physics at Cardiff University, and holds a BA from Hult International Business School. She holds multiple industry certifications, including GCFA, CAISP (Certified AI Security Practitioner), Microsoft certifications, and speaks nine languages. Outside of work, she enjoys electric skateboarding, fast cars, cross-country jumping, and anything that involves a little adrenaline.
Trey Darley, Proper Tools SRL
As J. B. S. Haldane observed in his famous 1926 essay: "You can drop a mouse down a thousand-yard mine shaft; and, on arriving at the bottom, it gets a slight shock and walks away, provided that the ground is fairly soft. A rat is killed, a man is broken, a horse splashes." The structural question this talk surfaces is: what happens to this Internet when it gets dropped down a thousand-yard mine shaft sometime in the next decade? Leverett and van der Ham-de Vos recently proved software vulnerabilities are countably infinite. They then reassured us that exploits are not, as fewer than ~6% of CVEs are ever exploited, and only a small subset aimed at market-share monocultures does most of the damage. Their Exploitation Exposure, E = abundance × deployment-share × P(exploit), is the firewall between an infinite problem and a manageably finite one.
Consider one instance of their own CWE-190 (signed overflow past INT_MAX): the 2038 timestamp boundary in Kerberos, beneath the Active Directory identity fabric of nearly every enterprise on Earth. Enterprises deploy AD as a monoculture deliberately — one single trust root is the value proposition — which means the very deployment share that maximises the exposure term also makes remediation a global, fixed-date, flag-day transition rather than a patch. What makes this CWE-190 different is that it is deterministic (time is the trigger; no attacker required) and ubiquitous (one representation, maximal reach) — and there the Abundance Frame's firewall fails: it measures reach, but has no term for whether remediation can be coordinated once reach is known. For this class, ecosystem coordination is the binding constraint. Microsoft has spent more than a decade telling the world to disable NTLM, a self-paced, deadline-free migration that remains impossible in brownfield environments. The Kerberos transition, by contrast, is externally dated, all-at-once, and has no public transition messaging yet. That gap is governance capacity, measured in the wild — Haldane's carrying capacity past which the institutional form no longer supports the function. The whole point of a flag day is lost if you keep it a secret. The mouse walks away from the mineshaft but the horse splashes.
Step back far enough and this isn't a vulnerability in the abundance sense at all. The Internet's coherence rests on what amounts to a vast distributed proof — interlocking RFCs and other standards whose local semantics compose into global interoperability, with the running network as the constructive witness that the proof holds. 2038 stresses that proof at a layer beneath the explicit standards: a coherence invariant — that any two systems' time-dependent validations agree under shared assumptions — that partial migration silently breaks pairwise, holding for some pairs and failing for others depending on who has remediated. The system stays up; it just becomes progressively harder to reason about, coordinate across, and defend. Boehm and Baran proved in 1964 that the network survives the independent loss of half its nodes; no one has retested that resilience against correlated failure at present scale — which is precisely the question the looming mineshaft asks. AI sharpens the forecast twice over: it grows the population (helpful assistants emitting time_t at scale) and migrates it (remediation-by-rewrite trading known open-source or commercial attack surface for unknown bespoke surface). And the brownfield we are asked to upgrade already hosts footholds multiple uncoordinated actors consider strategic, so "remediate for 2038" is also "disturb contested substrate." In this talk I'll ask how we forecast a class that is correlated, self-masking, coherence-level, and contested.
The talk closes with a helpful refresher on Roseannadanna's Law: "It's always something — if it's not one thing, it's another."
Trey is an independent adviser, recovering sysadmin, facilitator, and writer based in Brussels. He has spent more than twenty-five years working on systems that matter beyond the organisations that operate them. He began close to the machinery: embedded computers, telecommunications equipment, networks, test laboratories, and infrastructure expected to keep working in difficult conditions. Over time, the work moved outward—from individual systems to the organisations responsible for them, and then to the standards, institutions, and communities that allow many organisations to act together.
Andrey Lukashenkov, Vulners
By the time we meet at VulnOptiCon, the EU Cyber Resilience Act's Article 14 reporting obligations will have been operational for roughly two weeks. The regulation describes a continuous machine-readable pipeline: component identifier (SBOM) → matched vulnerability (Art. 3(40)) → exploitable in your operational context (Art. 3(41)) → actively exploited (Art. 3(42)) → 24-hour CSIRT and ENISA early warning. Policy text describes the output. The engineering (and VulnOptiCon) question is: what is the failure rate at each hop, and what does the bucket at the end actually contain?
This talk walks every hop on a single real container SBOM (insecure-app: 11,725 SBOM entries → 677 packages with PURLs → three ecosystems: deb, Python, Go) and puts empirical numbers on each:
-
Matching disagreement. Same SBOM, several scanners, varied overlap, and not always in the direction you'd expect. Different identifier paths (CPE vs. PURL), different advisory databases, and different matching logic produce different defensible answers on the same components. The disagreement isn't noise; it's a measurement of which corner of the ecosystem each tool can see.
-
Multi-source divergence in one component. Article 13(7) and Commission Guidance §211 push you toward multi-database monitoring, but the databases don't speak the same identifier dialect, and some have no version filtering at all. Querying the same component across PURL-native, CPE-native, and EUVD-proxy sources returns different sets, and the differences are systematic: each database's coverage model leaves its own shape in the result.
-
Scanner blind spots in properly versioned code. Even when an SBOM identifier is clean - no pseudo-versions, no escaped slashes, no scoped-name pathologies - the PURL → CPE translation inside the scanner can lose the namespace, and the component drops out of NVD-based tooling entirely. The blind spot lives in the translation, not in the source data; properly versioned does not mean reliably matched.
The novel contribution for VulnOptiCon is not the pipeline (Article 14 describes that). It is the measurement layer over the pipeline, anchored on the empirical numbers above, with explicit failure-rate metrics at each hop. I will argue that the right CRA defense is not the final reporting bucket - it is the process. The talk's stated posture: "Sources will contradict. You will have to be opinionated. Your CRA defense is in the process, not the number. This is not a finish line. It's a treadmill."
The talk assumes you already know CVSS, EPSS, KEV, VEX, SBOM, and PURL and that you have already been frustrated by what happens when you try to make them cooperate.
Andrey Lukashenkov works on vulnerability management at Vulners, a bootstrapped and profitable vulnerability-intelligence company. His work sits at the seam where software inventories meet vulnerability data - SBOM enrichment, component-to-vulnerability matching, exploitation signals, and the data-quality problems that quietly undermine every scanner and dashboard downstream. Technical by background and curious by default, he has unlimited access to the Vulners database and uses it to chase down whatever question he is stuck on that week, publishing the results to more than 20,000 practitioners on LinkedIn and, increasingly, from conference stages across Europe. A first-principles thinker with a consistent bias: distrust hype, insist on measurement, prefer engineering over demos. Happy to argue about any of it over coffee.
CPE records are a critical building block of vulnerability management, but in practice they are often incomplete, inconsistent, duplicated, or difficult to map to real-world products. Vendors rename products, projects move between organizations, open-source components appear under multiple identifiers, and the same software may be represented through several names, aliases, CPEs, or package URLs. These inconsistencies create noise for vulnerability scanners, asset inventories, SBOM tooling, CSIRTs, vendors, and analysts: missed vulnerabilities, false positives, duplicated work, and fragile enrichment pipelines. This talk introduces cpe.gcve.eu, a collaborative catalog for vendors, products, CPEs, and PURLs, together with its open-source backend, gcve-eu/cpe-editor. The goal is to move CPE maintenance from opaque, isolated correction processes toward a transparent, reusable, and community-driven workflow. We will explain how the platform supports browsing and searching vendor/product records, proposing new entries and corrections, documenting synonyms and renames, linking CPEs with PURLs, moderating changes, exporting datasets, and integrating the data through APIs. The talk will also discuss the design choices behind the project: deterministic identifiers, documented data formats, proposal workflows, moderation, relationship tracking, and practical reuse by vulnerability intelligence platforms. More broadly, it presents cpe.gcve.eu as an attempt to fix one of the least glamorous but most operationally painful problems in vulnerability management: naming things correctly.