Program Overview

CVE/FIRST VulnCon 2024 & Annual CNA Summit

Agenda is subject to change. The time zone reflected in the agenda is Eastern Standard Time. All sessions and social activities will take place at the McKimmon Conference and Training Center.

Virtual Attendance: All presentations will be  TLP:CLEAR  and streamed for those interested in virutal participation. Virtual registration is available within the registration form. Streaming will be delivered over Zoom.

Registration Hours

Registration will be located in the main lobby of the McKimmon Conference and Training Center. Please have a copy of your ID or registration confirmation readily available to assist with badge collection. Registration will open at 07:30 all three days.

Monday, March 25th

Track 1Track 2Track 3
08:30 – 09:00
 US

Welcome Remarks

Peter Allor (Red Hat, US)

TLP:CLEAR
09:00 – 10:00
 US

Supply Chain Security: The Office of the National Cyber Director Perspective (presentation features a virtual speaker)

Andrew Pasternak (USG, US)

TLP:CLEAR
10:00 – 10:30
 KR

A Legislation Guide for Keeping pace with Cybersecurity Paradigm Shift toward Vulnerability (presentation features a virtual speaker)

Tae Seung Lee (Korea Internet & Security Agency, KR)

TLP:CLEAR
11:00 – 12:00
 AU

The Trials and Tribulations of Bulk Converting CVEs to OSV

Andrew Pollock (Google Open Source Security Team, AU)

TLP:CLEAR
 IL

Why Can't We All Just Get Along? Bridging the Gap in Vulnerability Prioritization Standards

Yotam Perkal (Rezilion, IL)

TLP:CLEAR
 US

Revising the CVE CNA Operational Rules: AMA

Art Manion (ANALYGENCE Labs, US)

TLP:CLEAR
13:00 – 14:00
 US

Crossing the Streams - How Downstream Can Understand Upstream Vulns

Christopher Robinson (Intel, US); Madison Oliver (GitHub, US)

TLP:CLEAR
 US

SBOMs – The Missing Link

Cassie Crossley (Schneider Electric, US)

TLP:CLEAR
 US

CVSS SIG Past, Present & Future + CVSS v4.0 Beyond the Numbers: Improving Qualitative Aspects of Vulnerability Disclosure

Nick Leali (Cisco and CVSS SIG Chair, US)

TLP:CLEAR

13:00 – 14:30

14:00 – 15:00
 US

A Roadmap for Your OSS Security Lifecyle Journey to Protect Customers

Lisa Bradley, Sarah Evans (Dell, US)

TLP:CLEAR
 PL

Understanding Red Hat's SBOM - The Future of Software Transparency

Przemyslaw Roguski (Red Hat, PL)

TLP:CLEAR
14:30 – 15:00
 US

Building a Better Database: How GitHub Structures Their Advisory Database to Drive Developer Outcomes

Jon Moroney (GitHub, US)

TLP:CLEAR
15:30 – 16:30
 US

Seeing the Vulnerable Forest Through the Exploited Trees

Jay Jacobs (Cyentia, US)

TLP:CLEAR
 US

CVE Is The Worst Vulnerability Framework (Except For All The Others)

Benjamin Edwards, Sander Vinberg (Bitsight, US)

TLP:CLEAR
 US

Panel Discussion: Enabling Accurate, Decentralized Root Cause Mapping at Scale

Alec Summers, Chris Levendis (The MITRE Corporation, US); Deana O'Meara (NVIDIA, US); Erin Alexander (CISA, US)

TLP:CLEAR
16:30 – 17:00
 US

Day 1: Wrap Up & Lessons Learned

Peter Allor (Red Hat, US); Josh Dembling (Intel, US)

TLP:CLEAR
17:00 – 19:00

Networking After Party Sponsored by Nucleus

TLP:CLEAR

Tuesday, March 26th

Track 1Track 2Track 3
08:30 – 09:00
 US

Daily Updates & Announcements

Peter Allor (Red Hat, US)

TLP:CLEAR
09:00 – 10:00
 BE

Vulnerability Coordination in the EU

Johannes Clos (ENISA, BE)

TLP:CLEAR
10:00 – 10:30
 JP

Pushing Coordinated Vulnerability Disclosure forward in Asia Pacific

Tomo Ito (JPCERT/CC, JP)

TLP:CLEAR
10:30 – 11:00

Break

11:00 – 12:00
 IT ES

Nestlé Unified Vulnerability Management Approach

Angelo Punuriero (Nestlé, IT); Jenifer Jimenez, Martin Karel (Nestlé, ES)

TLP:CLEAR
 MX

Democratizing Exploitability Data with OpenVEX

Adolfo Garcia Veytia (Stacklok, MX)

TLP:CLEAR
 US

Adventures in Vulnerability Coordination

Daniel Larson, Iain Deason (CISA, US)

TLP:CLEAR
12:00 – 13:00

Lunch

13:00 – 14:00
 DE

Finding, Managing, Preventing Vulnerabilities: An Automotive Perspective (presentation features virtual speakers)

Andreas Weichslgartner, Joyabrata Ghosh, Vineeth Bharadwaj (CARIAD SE, DE)

TLP:CLEAR
 MX US

Panel Discussion: Don’t be Vexed by VEX - VEXperts Panel (presentation features a virtual speaker)

Adolfo Garcia Veytia (Stacklok, MX); Art Manion (ANALYGENCE Labs, US); Christopher Robinson (Intel, US); Justin Murphy (CISA, US)

TLP:CLEAR
 US

EPSS: Challenges and Opportunities Going Forward + EPSS AMA

Jay Jacobs (Cyentia, US); Sasha Romanosky (RAND Corporation, US)

TLP:CLEAR

13:00 – 14:30

14:00 – 15:00
 US

China's New Vuln System

Dakota Cary (Atlantic Council, SentinelOne, US)

TLP:CLEAR
 US

CSAF/VEX: Improved Security Data

Martin Prpic (Red Hat, US)

TLP:CLEAR
14:30 – 15:00
 FR US

Effective Vulnerability Management for Over 400 Projects at the Eclipse Foundation (presentation features a virtual speaker)

Marta Rybczynska (Eclipse Foundation, FR); Michael Winser (Eclipse Foundation, US)

TLP:CLEAR
15:00 – 15:30

Break

15:30 – 16:30
 US

The CWE Program: Current State and Road Ahead

Alec Summers (The MITRE Corporation, US)

TLP:CLEAR
 US

VeXing Vulnerabilities: NVIDIA's Dynamic Approach to OSS Security

Jessica Butler, Amy Rose (NVIDIA, US)

TLP:AMBER
 US

Panel Discussion: This One Time at CVD Camp

Art Manion (ANALYGENCE Labs, US); Deana O'Meara (NVIDIA, US); Madison Oliver (GitHub, US); Christopher Robinson (Intel, US)

TLP:CLEAR
16:30 – 17:00
 US

Day 2: Wrap Up & Lessons Learned

Peter Allor (Red Hat, US); Josh Dembling (Intel, US)

TLP:CLEAR
17:00 – 19:00

Networking After Party Sponsored by OpenSSF

TLP:CLEAR

Wednesday, March 27th

Track 1Track 2Track 3
09:00 – 10:00
 US

What It Takes to Lead America’s Vulnerability Management Team

Bob Lord, Lindsey Cerkovnik, Sandy Radesky (CISA, US); Chris Hughes (Aquia, US); Patrick Garrity (VulnCheck, US)

TLP:CLEAR
10:00 – 10:30
 IN

CNA Challenges From a National CERT Perspective

Mohd. Akram Khan, Seema Khanum (CERT.IN, IN)

TLP:CLEAR
11:00 – 12:00
 IL

From SBOM to VEX - Discovering What's in the Box and How Badly it Can Hurt You

Ben Hirschberg (ARMO, IL)

TLP:CLEAR
 DE

Black and Blue, or White and Gold? - Minimizing Vulnerability Scoring Discrepancies due to Limited Information (presentation features a virtual speaker)

Michael Schueler (Cisco, DE)

TLP:CLEAR

NVD Symposium

TLP:CLEAR
13:00 – 14:00
 US

CISA’s Known Exploited Vulnerabilities (KEV) Catalog

Tod Beardsley (CISA, US); Elizabeth Cardona (CISA)

TLP:CLEAR
 US

Panel Discussion - The Risks of Requiring Premature Vulnerability Disclosures

Kathleen Noble (Intel, US); Tanvi Chopra (Venable, US); Rob Spiger (Microsofy, US); Michael Woolslayer (HackerOne, US)

TLP:CLEAR
 US

CNA Feedback Session to the CVE Program

Mz Megazone (F5, Inc., US)

TLP:CLEAR
14:00 – 15:00
 US

Information Sharing to Mitigate Emerging Vulnerabilities

Joshua Justice, Tyler Curry (Health-ISAC, US)

TLP:CLEAR
 US

Elevating Security Standards: Intel's Integration of Common Security Advisory Framework into Tooling Processes and Future Roadmap

Julia DeWeese, Mike Wiles (Intel, US)

TLP:CLEAR
 US AU

Panel Discussion: It is a Tale as Old as Time…. a CNA, the NVD, and a CVE Consumer Walk Into a Bar. Hilarity Ensues, Right?

Christopher Robinson (Intel, US); Andrew Pollock (Google Open Source Security Team, AU); Madison Oliver (GitHub, US); Tanya Brewer (NIST, US)

TLP:CLEAR
15:30 – 16:30
 US

Reducing Ratio of Reserved But Public CVEs

Shelby Cunningham (GitHub, US)

TLP:CLEAR
 US

Firmware Supply Chain Security BoF

Jerry Bryant (Intel, US)

TLP:CLEAR

CANCELLED

TLP:CLEAR
16:30 – 17:00
 US

Conference Closing Remarks

Peter Allor (Red Hat, US); Josh Dembling (Intel, US)

TLP:CLEAR