A CVE quagmire: Quality versus quantity

In this session, Tod Beardsley (runZero) and Jerry Gamblin (RogoLabs) dive into the "CVE Quagmire," exploring the tension between the sheer volume of vulnerability reports and the actual quality of the data provided. As the industry faces an average of over 160 new CVEs daily, the conversation shifts from fearing an AI-generated tsunami of bugs to addressing the long-standing issue of "human slop" and inconsistent metadata that has hindered security teams for decades.

The discussion highlights the critical need for machine-readable data and standardized scoring, particularly in complex environments like the Linux kernel. Gamblin explains how projects like cve.icu are bringing transparency to the program, while the upcoming CVE Schema 6.0 promises a quality era that could finally mandate the technical details necessary for automated discovery and remediation.

Meet Our Speakers

todb

VP of Security Research, runZero

Jerry Gamblin

Principal Engineer (Cisco)

Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.


Related Resources

Podcasts
Bug bounties in the age of AI
In this session, Tod Beardsley and Casey Ellis explore the evolving role of bug bounties in a world increasingly shaped by artificial intelligence.
Podcasts
The network edge: EOL and exploitation
Tod Beardsley is joined by Kimber Duke & Patrick Garrity of VulnCheck to discuss the critical intersection of EOL hardware and cybersecurity...
Podcasts
Mute the sirens: Prioritizing vulnerability noise
In this session, Tod Beardsley and Mark Lambert discuss the escalating challenge of managing vulnerability noise in the era of AI.
Podcasts
Force multiplied: Community-powered vuln detection
Tod Beardsley & Rishi Sharma discuss the origins of Nuclei, an open-source framework that has revolutionized how security teams validate...

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.