Vulnerability haruspicy: picking out risk signals from scoring system entrails

Vulnerability scoring frameworks promise clarity but often deliver confusion. CVSS (Common Vulnerability Scoring System) bends messy math into neat curves, EPSS (Exploit Prediction Scoring System) leans on opaque models, and SSVC (Stakeholder-Specific Vulnerability Categorization) relies on structured intuition. 

Tod Beardsley explores the strengths and flaws of these systems, asking whether they improve risk decisions or simply rationalize them. Expect smart analysis, best practices (and astrology jokes!) along the way.

Explore related resources:

Meet Our Speakers

todb

Vice President of Security Research

Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.


Related Resources

Talks
Rewriting the rules of exposure management
HD Moore examines why traditional vulnerability management tools continue to fail and why vendor hype and competing frameworks only add to the noise
Talks
There and back again: discovering OT devices across protocol gateways with Rob King
Rob King discusses the security implications of the convergence of IT and OT, with deep dives into OT protocols and device discovery.
Talks
Charting the SSH multiverse with HD Moore (BSidesSF 2025)
Watch runZero founder HD Moore, explore the multitude of SSH implementations, their specific weaknesses, and real-world exposures.
Talks
NSEC keynote: a pirate's guide to snake oil & security - HD Moore
Watch HD's keynote at NSEC, where you are taken on a satirical voyage through the crowded world of vulnerability management.

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.