📣 At #VulnCon 2025, the OpenSSF community showed up strong—leading 16+ sessions & driving convos on vuln metadata, CRA, SBOMs, and more.
Catch CRob's key takeaways blog 👉 https://openssf.org/blog/2025/04/14/key-takeaways-from-vulncon-2025-insights-from-the-openssf-community/
OpenSSF’s CRob shares key takeaways from VulnCon 2025, highlighting community-driven collaboration, OSS security insights, the impact of the EU CRA, and the growing importance of vulnerability metadata and supply chain transparency.
I've had a bunch of people ask me why I wasn't at #VulnCon, so I wrote a blog post about it
TL;DR - I don't think VulnCon should exist
Follow me for more security hot takes
https://opensourcesecurity.io/2025/04-why-i-didnt-go-to-vulncon/
VulnCon 2025 is over. I didn’t go. A bunch of people have asked me why, and rather than keep my answer to a small group, I thought it would make sense to write something public about it all. The TL;DR is I went to a different conference that I thought was a better use of my time. The conference I went to was Cyphercon and BSides Milwaukee. They are regional conferences in Wisconsin. Good people, great shows, a lot of fun and learning. Yeah, it was technically the week before VulnCon, but I lack the fortitude to do two conferences back to back. Some people can, I tip my hat to those folks. I’m not one of them. I should be clear though, this isn’t the only reason. I also don’t think VulnCon should exist (more on that at the end).
At #VulnCon, NIST revealed that the NVD is scrapping its consortium plan, walking back last year’s promise of reform, while pitching new tools that critics say won't meaningfully address the backlog or transparency problem.
https://socket.dev/blog/vulncon-2025-nvd-scraps-consortium-plan #CVE #CyberSecurity #VulnCon2025
Day 1 of “CVE/FIRST VulnCon 2025” is here!
Today’s agenda for all 5 tracks: https://first.org/conference/vulncon2025/program#d20250407
#CWE #VulnerabilityManagement #Vulnerability #CVE #FIRST #VulnCon
Day 1 of “CVE/FIRST VulnCon 2025” is here!
Today’s agenda for all 5 tracks: https://first.org/conference/vulncon2025/program#d20250407
#VulnerabilityManagement #Vulnerability #CVE #FIRST #VulnCon
🔐 #OpenSSF is sponsoring #VulnCon 2025, happening April 7-10 at the McKimmon Center in Raleigh, NC!
Join the community! Virtual admission through April 4: https://www.first.org/conference/vulncon2025/