Program

VulnOptiCON 2026

This year, we’re introducing an additional day (23 September) to more broadly cover All the (Vulnerability) Things. The expanded scope of Day 1 will provide a forum for the European vulnerability community to network and discuss vulnerability management, the anticipated AI vulnpocalypse, the realities of building a VDP, legal and policy considerations, and more.

All times are Luxembourg local, that is Central European Summer Time (CEST, UTC+2). Subject to change!

Day 1: 23 September

Day 2: 24 September

Day 3: 25 September


Day 1

Time Talk
9:30 Opening remarks
VulnOptiCON Program Committee
10:00 Day 1 Keynote: AI Innovations for Vulnerability Management
Jaya Baloo, AISLE
11:00 Johannes Clos, ENISA
11:30 GCVE: Rebooting Vulnerability Tracking for an Open Security Ecosystem
Alexandre Dulaunoy and Cedric Bonhomme, CIRCL

Day 2

Time Talk
9:00 Opening remarks
VulnOptiCON Program Committee
9:15 Day 2 Keynote: Signal and Noise: What A Decade In Forecasting Science Has Taught Me
Regina Joseph
10:00 Pick a Number Anyway: Measuring the SBOM...
Andrey Lukashenkov, Vulners

Day 3

Time Talk
9:00 Opening remarks
VulnOptiCON Program Committee
16:30 Closing remarks
VulnOptiCON Program Committee

Day 2 Keynote: Signal and Noise: What A Decade In Forecasting Science Has Taught Me

Regina Joseph

Regina Joseph

Before the results of an Intelligence Advanced Research Projects and Activity (IARPA) experiment that ran from 2011-2015 testing human forecasting ability, few believed that consistent and replicable accuracy was possible. Since the celebrated findings of that experiment, e.g., the discovery of superforecasters as well as the identification of technical systems, processes and behaviors correlated with better foresight, a pipeline of forecasting experiments (and their consequences) has revealed the complexity of what it takes to build a solid forecasting community. This research also exposed the unique challenges in applying the technologies of prediction in critical decision-making environments. As both a researcher and superforecaster veteran of IARPA’s multiple experiments in anticipatory intelligence---as well as her own forecasting research programs with European and US federal entities and private sector organizations---Regina Joseph will share apocryphal stories from the superforecaster frontlines, as well as insights on how to construct a high quality forecasting cohort.


Pick a Number Anyway: Measuring the SBOM...

Regina Joseph

Andrey Lukashenkov, Vulners

Andrey Lukashenkov works on vulnerability management at Vulners, a bootstrapped and profitable vulnerability-intelligence company. His work sits at the seam where software inventories meet vulnerability data - SBOM enrichment, component-to-vulnerability matching, exploitation signals, and the data-quality problems that quietly undermine every scanner and dashboard downstream. Technical by background and curious by default, he has unlimited access to the Vulners database and uses it to chase down whatever question he is stuck on that week, publishing the results to more than 20,000 practitioners on LinkedIn and, increasingly, from conference stages across Europe. A first-principles thinker with a consistent bias: distrust hype, insist on measurement, prefer engineering over demos. Happy to argue about any of it over coffee.


GCVE: Rebooting Vulnerability Tracking for an Open Security Ecosystem

Alexandre Dulaunoy and Cedric Bonhomme, CIRCL

The vulnerability ecosystem has become critical infrastructure for defenders, vendors, researchers, and open source maintainers. Yet the way identifiers and vulnerability data are assigned, published, and distributed still reflects a centralized model that does not always match the speed, diversity, and realities of today’s security landscape.

This talk introduces GCVE, a new approach to vulnerability identification and tracking designed to support a more open, decentralized, and resilient ecosystem. GCVE rethinks how vulnerability numbers can be allocated, how trusted actors can publish advisories, and how vulnerability information can be synchronized without creating unnecessary bottlenecks or dependency on a single central authority.

Through the lens of open source security, the talk will explain why this matters: maintainers need lightweight processes, defenders need timely and structured data, and the community needs a model that encourages participation rather than gatekeeping. It will also show how GCVE and its associated tooling can help make vulnerability tracking more transparent, interoperable, and adaptable.

Rather than presenting only a new identifier format, this session will explore a broader idea: how we can build vulnerability tracking as shared public infrastructure for the security community.