In this session, Tod Beardsley (runZero) and Jerry Gamblin (RogoLabs) dive into the "CVE Quagmire," exploring the tension between the sheer volume of vulnerability reports and the actual quality of the data provided. As the industry faces an average of over 160 new CVEs daily, the conversation shifts from fearing an AI-generated tsunami of bugs to addressing the long-standing issue of "human slop" and inconsistent metadata that has hindered security teams for decades.
The discussion highlights the critical need for machine-readable data and standardized scoring, particularly in complex environments like the Linux kernel. Gamblin explains how projects like cve.icu are bringing transparency to the program, while the upcoming CVE Schema 6.0 promises a quality era that could finally mandate the technical details necessary for automated discovery and remediation.
Watch more sessions from runZero Day
| Session Title | Guests | |
|---|---|---|
| Watch Session | A CVE quagmire: Quality versus quantity | Jerry Gamblin, RogoLabs |
| Watch Session | Predicting exploitation: A practitioner's guide | Jay Jacobs, Empirical Security |
| Watch Session | Signal vs slop: Journalists on the evolution of research-driven reporting | Bill Brenner, CYBER.SEC.Community Dennis Fisher, Decipher Steve Ragan, 1Password |
| Watch Session | On the frontlines of investigative journalism in cybersecurity: An insider's perspective | Joseph Menn, Author & Investigative Journalist |
| Watch Session | From risk to resilience: Navigating OT security in a converged world | Mary Gannon, GuidePoint Security Patrick Gillespie, GuidePoint Security |
| Watch Session | Force multiplied: Community-powered vuln detection | Rishi Sharma, ProjectDiscovery |
| Watch Session | Mute the sirens: Prioritizing vulnerability noise | Mark Lambert, ArmorCode |
| Watch Session | The network edge: EOL and exploitation | Kimber Duke, VulnCheck Patrick Garrity, VulnCheck |
| Watch Session | Bug bounties in the age of AI | Casey Ellis, Bugcrowd |
| Watch Session | Perimeters and pathways: Protecting the complete attack surface | HD Moore, runZero Jared Atkinson, SpecterOps Zakir Durumeric, Censys |
| Watch Session | The infinite eye: How AI threat intelligence gives defenders an asymmetric edge | HD Moore, runZero Jonathan Cran, Mallory |
Get the latest news and expert insights delivered in your inbox.