Hello! I am submitting a proposal for the July 30th "CVE in an Era of AI-Enabled Vulnerability Discovery" virtual conference.
Format: Lightning talk (5 minutes)
Theme alignment: Helping consumers make reliable remediation and prioritization decisions at greater speed and scale. Secondary: improving how vulnerability information moves through the ecosystem.
Speaker: Jerry Gamblin, RogoLabs
Abstract
Record CVE publication volume is routinely framed as a crisis: the "vulnpocalypse," the "CVE flood," "drowning in vulnerabilities." Emerging AI discovery and triage tools are about to make that framing much louder, pushing publication rates well past anything we've seen. If the community continues to treat every new record as a unit of catastrophe, the narrative will only get darker as the program gets better.
This talk argues the opposite. Catalog growth reflects expanded CNA coverage, better vendor transparency, and highly capable discovery tooling. The doom vocabulary is not just inaccurate; it is actively harmful across the entire ecosystem:
- For Leaders & Policymakers: It signals failure at exactly the moment the vulnerability management program is succeeding and scaling.
- For Vendors & CNAs: It disincentivizes transparency. If every published CVE adds to "the problem," organizations are implicitly punished for disclosure.
- For Defenders: It pushes practitioners toward fatalism. "You can't keep up" fuels checkbox compliance and burnout.
Raw counts were never the unit of work. Prioritization frameworks and statistical modeling tools like EPSS, KEV, and SSVC exist precisely so volume does not equal workload. AI and classic ML on the consumption side scale right alongside AI on the discovery side. More CVEs mean more visibility into risk that already existed, not more risk. A bigger map is not a bigger territory.
Takeaway
A concrete vocabulary shift the community can adopt before the next massive growth curve arrives: retire "vulnpocalypse," replace "flood" with "coverage growth," and replace "keeping up with CVEs" with "prioritizing from CVEs." Ultimately, we must stop measuring ecosystem health by raw publication counts, and start measuring it by the gap between active exploitation and remediation.
Contact
Hello! I am submitting a proposal for the July 30th "CVE in an Era of AI-Enabled Vulnerability Discovery" virtual conference.
Format: Lightning talk (5 minutes)
Theme alignment: Helping consumers make reliable remediation and prioritization decisions at greater speed and scale. Secondary: improving how vulnerability information moves through the ecosystem.
Speaker: Jerry Gamblin, RogoLabs
Abstract
Record CVE publication volume is routinely framed as a crisis: the "vulnpocalypse," the "CVE flood," "drowning in vulnerabilities." Emerging AI discovery and triage tools are about to make that framing much louder, pushing publication rates well past anything we've seen. If the community continues to treat every new record as a unit of catastrophe, the narrative will only get darker as the program gets better.
This talk argues the opposite. Catalog growth reflects expanded CNA coverage, better vendor transparency, and highly capable discovery tooling. The doom vocabulary is not just inaccurate; it is actively harmful across the entire ecosystem:
Raw counts were never the unit of work. Prioritization frameworks and statistical modeling tools like EPSS, KEV, and SSVC exist precisely so volume does not equal workload. AI and classic ML on the consumption side scale right alongside AI on the discovery side. More CVEs mean more visibility into risk that already existed, not more risk. A bigger map is not a bigger territory.
Takeaway
A concrete vocabulary shift the community can adopt before the next massive growth curve arrives: retire "vulnpocalypse," replace "flood" with "coverage growth," and replace "keeping up with CVEs" with "prioritizing from CVEs." Ultimately, we must stop measuring ecosystem health by raw publication counts, and start measuring it by the gap between active exploitation and remediation.
Contact