At #VulnCon, NIST revealed that the NVD is scrapping its consortium plan, walking back last year’s promise of reform, while pitching new tools that critics say won't meaningfully address the backlog or transparency problem.

https://socket.dev/blog/vulncon-2025-nvd-scraps-consortium-plan #CVE #CyberSecurity #VulnCon2025

VulnCon 2025: NVD Scraps Industry Consortium Plan, Raising Q...

At VulnCon 2025, NIST scrapped its NVD consortium plans, admitted it can't keep up with CVEs, and outlined automation efforts amid a mounting backlog.

Socket

Day 2 of #VulnCon2025 has showcased the power of global cybersecurity collaboration. The energy in the hallways and networking spaces has been incredible—attendees sharing knowledge and solving challenges side by side, driving innovation and progress in vulnerability management.

Here are some highlights from today:

- Exploration of AI vulnerabilities and hands-on workshops like "Breaking the Bot: GenAI Web App Attack Surface & Exploitation"
- "Whose Vulnerability Is It Anyway?" panel examined conflicts between researchers, developers, operators, and leadership, offering strategies to bridge communication gaps for better security outcomes
- "Simulation Analysis of Vulnerability Assessment Using CVSS 4.0" presentation on innovative approaches from FIRST's members and SIG leaders

Special thank you to Qualys for hosting tonight's after party.

Check out what's on tap for Day 3 here: https://go.first.org/1jeVs

#cybersecurity #infosec #VulnerabilityManagement

Program Overview / CVE Program & FIRST VulnCon 2025

FIRST — Forum of Incident Response and Security Teams
Join us next week at #VULNCON2025 in Raleigh, North Carolina, where we’ll have a strong presence with these exciting sessions 🧵

Finite State is heading to #VulnCon2025!

Join us in Raleigh to talk risk management, vuln disclosure & software security. Stop by the booth to meet John & Jermaine & see how we help secure software supply chains.

Book a time with the team here 👉 https://info.finitestate.io/vulncon2025

VulnCon 2025 Event Page

Join us at VulnCon 2025, April 7-10

@CVE_Program @adulau @pombr I quote: "VulnCon 2025: One submission has been made for a panel on “Software Identity and the Vulnerability Management Ecosystem,” covering topics like CPE and Purl. That's not from me, but it could be! 👍 (will be there - remotely)

#vulncon2025 #cpe #purl

New Call for Papers Deadline for “VulnCon 2025” — January 31, 2025

#CVE Program and #FIRST will co-host #VulnCon2025 in Raleigh, North Carolina, USA, on April 7–10, 2025. Registration, both virtual & in-person, is open on the FIRST website

https://medium.com/@cve_program/new-call-for-papers-deadline-for-vulncon-2025-january-31-2025-92e59ab9f8d0
New Call for Papers Deadline for “VulnCon 2025” — January 31, 2025

The CVE Program and FIRST will co-host VulnCon 2025 at the McKimmon Center in Raleigh, North Carolina, USA, on April 7–10, 2025. The Call for Papers deadline has been extended until January 31, 2025…

Medium
Call for Papers & Call for Volunteers / VulnCon 2025

FIRST — Forum of Incident Response and Security Teams
📣 Less than 48 hours left to submit your CFP for VulnCon 2025, co-hosted by FIRST & CVE Program!
We’d love to see your proposals showcasing OpenSSF and its role in advancing vulnerability management.
👉 Submit now: https://www.first.org/conference/vulncon2025/cfp
#VulnCon2025
Call for Papers & Call for Volunteers / VulnCon 2025

FIRST — Forum of Incident Response and Security Teams
Submit your #CFP for #VulnCon2025 today to be a part of the 40+ action-packed sessions😎🔗 https://go.first.org/MPudV #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX #Raleigh
CVE Program & FIRST VulnCon 2025

FIRST — Forum of Incident Response and Security Teams
“VulnCon 2025” Call for Papers Closes January 15

The CVE Program and FIRST will co-host #VulnCon2025 at the McKimmon Center in Raleigh, North Carolina, USA, on April 7–10, 2025. Registration, both virtual and in-person, is open on the FIRST website

https://medium.com/@cve_program/vulncon-2025-call-for-papers-closes-january-15-0236298a7e0d
“VulnCon 2025” Call for Papers Closes January 15 - CVE Program Blog - Medium

The CVE Program and FIRST will co-host VulnCon 2025 at the McKimmon Center in Raleigh, North Carolina, USA, on April 7–10, 2025. The Call for Papers closes on January 15, 2025. See details here. The…

Medium