Last for day 1 of #vulnopticon is @jayjacobs on our understanding of, definition of and need to rethink what a vulnerability is
Btw he also invented and maintains #EPSS

Last for day 1 of #vulnopticon is @jayjacobs on our understanding of, definition of and need to rethink what a vulnerability is
Btw he also invented and maintains #EPSS
ENISA is working towards becoming a too-level root on par w CISA and MITRE says @johannesklos at #vulnopticon
Next at #vulnopticon is Johannes Klos of ENISA on the expanding role of ENISA in the vulnerability ecosystem
Jaya shares some final takeaways:
At #vulnopticon
And wrt Sandboxes: MAKE SURE THEY WORK, because most don’t.
At #vulnopticon , @Jaya says you need to be able to detect at the earliest possible moment where your AI usage starts to go wrong (evil, misalignment, compromise, poisoning, etc)
The bigger a model is (on parameters), the more likely it is to be an evil or sneaky bastard, @Jaya Baloo quoting their chief AI person at #vulnopticon
At #vulnopticon , @Jaya says that vulnerability reporting HAS to be of sufficient quality, if it isn’t it makes the jobs and lives of maintainers much harder and they drown in the volume of potential slop grenades
Vulnerability identification is much higher than last year, but the exploitation is behind 2025!
The AI vulnerability identification industry/movement needs to transform says @Jaya, because how can a tiny startup like Aisle dominate 5/8 categories in this Berkeley leaderboard
At #vulnopticon
The 2026 #VerizonDBIR -> shift from phishing and lack of MFA to exploitation of vulnerabilities observed says @Jaya at #vulnopticon
AND the AI-CC showed significant vulnerability identification and patching in the competition
The Jaggedness of the AI model market per country
Via @Jaya at #vulnopticon
@Jaya is on stage at #vulnopticon to keynote with “AI innovations for vulnerability management”
Exciting!