This year, we’re introducing an additional day (23 September) to more broadly cover All the (Vulnerability) Things. The expanded scope of Day 1 will provide a forum for the European vulnerability community to network and discuss vulnerability management, the anticipated AI vulnpocalypse, the realities of building a VDP, legal and policy considerations, and more.
All times are Luxembourg local, that is Central European Summer Time (CEST, UTC+2). Subject to change!
Day 1: 23 September
Day 2: 24 September
Day 3: 25 September
| Time | Talk |
|---|---|
| 9:30 | Opening remarks VulnOptiCON Program Committee |
| 10:00 | Day 1 Keynote: AI Innovations for Vulnerability Management Jaya Baloo, AISLE |
| 11:00 | Johannes Clos, ENISA |
| 11:30 | GCVE: Rebooting Vulnerability Tracking for an Open Security Ecosystem Alexandre Dulaunoy and Cedric Bonhomme, CIRCL |
| Time | Talk |
|---|---|
| 9:00 | Opening remarks VulnOptiCON Program Committee |
| 9:15 | Day 2 Keynote: Signal and Noise: What A Decade In Forecasting Science Has Taught Me Regina Joseph |
| 10:00 | Pick a Number Anyway: Measuring the SBOM... Andrey Lukashenkov, Vulners |
| Time | Talk |
|---|---|
| 9:00 | Opening remarks VulnOptiCON Program Committee |
| 16:30 | Closing remarks VulnOptiCON Program Committee |
Regina Joseph
Before the results of an Intelligence Advanced Research Projects and Activity (IARPA) experiment that ran from 2011-2015 testing human forecasting ability, few believed that consistent and replicable accuracy was possible. Since the celebrated findings of that experiment, e.g., the discovery of superforecasters as well as the identification of technical systems, processes and behaviors correlated with better foresight, a pipeline of forecasting experiments (and their consequences) has revealed the complexity of what it takes to build a solid forecasting community. This research also exposed the unique challenges in applying the technologies of prediction in critical decision-making environments. As both a researcher and superforecaster veteran of IARPA’s multiple experiments in anticipatory intelligence---as well as her own forecasting research programs with European and US federal entities and private sector organizations---Regina Joseph will share apocryphal stories from the superforecaster frontlines, as well as insights on how to construct a high quality forecasting cohort.
Andrey Lukashenkov, Vulners
Andrey Lukashenkov works on vulnerability management at Vulners, a bootstrapped and profitable vulnerability-intelligence company. His work sits at the seam where software inventories meet vulnerability data - SBOM enrichment, component-to-vulnerability matching, exploitation signals, and the data-quality problems that quietly undermine every scanner and dashboard downstream. Technical by background and curious by default, he has unlimited access to the Vulners database and uses it to chase down whatever question he is stuck on that week, publishing the results to more than 20,000 practitioners on LinkedIn and, increasingly, from conference stages across Europe. A first-principles thinker with a consistent bias: distrust hype, insist on measurement, prefer engineering over demos. Happy to argue about any of it over coffee.
Alexandre Dulaunoy and Cedric Bonhomme, CIRCL
The vulnerability ecosystem has become critical infrastructure for defenders, vendors, researchers, and open source maintainers. Yet the way identifiers and vulnerability data are assigned, published, and distributed still reflects a centralized model that does not always match the speed, diversity, and realities of today’s security landscape.
This talk introduces GCVE, a new approach to vulnerability identification and tracking designed to support a more open, decentralized, and resilient ecosystem. GCVE rethinks how vulnerability numbers can be allocated, how trusted actors can publish advisories, and how vulnerability information can be synchronized without creating unnecessary bottlenecks or dependency on a single central authority.
Through the lens of open source security, the talk will explain why this matters: maintainers need lightweight processes, defenders need timely and structured data, and the community needs a model that encourages participation rather than gatekeeping. It will also show how GCVE and its associated tooling can help make vulnerability tracking more transparent, interoperable, and adaptable.
Rather than presenting only a new identifier format, this session will explore a broader idea: how we can build vulnerability tracking as shared public infrastructure for the security community.