< Agenda

Is this the CVE-nd? Inside the Vulnerability Data Crisis

15:30 (30 minutes) · Room 1A · Talk · Intermediate · Security

Samuel Dynes
Samuel DynesSenior Software Engineer - Arqit

This talk explores a growing crisis in the vulnerability intelligence ecosystem. The number of reported CVEs (Common Vulnerabilities and Exposures) keeps rising, while the agencies responsible for tracking them, CISA (Cybersecurity and Infrastructure Security Agency) and the NVD (National Vulnerability Database), are being weakened by political cuts. As a result, traditional vulnerability management tools are quietly failing, and their users don't even know it. At the same time, security researchers are finding it increasingly difficult to disclose vulnerabilities responsibly, exacerbating the long-standing tension at the heart of the CVE programme: balancing the interests of software vendors and researchers. Finally, we look at the latest disruption hitting the community: AI-assisted vulnerability discovery. As automated tooling begins generating CVEs at unprecedented scale, and with hugely variable quality, it is placing even more strain on an already creaking ecosystem. So all of this begs the question: is this the CVE-nd for vulnerability intelligence as we know it? And how do we as developers cope with a increasingly fragmented security space?

Samuel Dynes

Software engineer and security enthusiast who has been working on or around vulnerability management for his entire career. When not sitting in front of a work laptop he’s a big fan of CTF’s, reading about things with no application to real life and a little bit of weightlifting