Uploaded May 2026 | Updated September 2026, 1 hour ago
Art Manion (Tharros Labs, US), Jay Jacobs (Empirical Security, US)
In this talk, we build the case for an identity-first redesign of vulnerability records. Instead of open prose and after-market labels, each record should be anchored to the minimal, machine-verifiable set of assertions that unambiguously denote the same vulnerability across sources and time. We will connect familiar pain points (conflicting assertions, ambiguously defined affected products, flawed cross-repository joins, incomplete records and metric-driven shortcuts), to their root causes and the challenges facing us as we try to establish the identity of a vulnerability. We will explore the inherent tension between being human-meaningful, machine-usable, secure and decentralized, and how that is compounded by the analyst's natural limitations during the vulnerability discovery process. Our goal is an identity contract that is small, testable, and publisher-anchored that enables local discovery, deduplication, and practical adoption.
---
Art Manion spends a lot of time working on various aspects of technical cybersecurity vulnerabilities including coordinated disclosure, measurement, management, information systems, risk assessment, and public policy. Art has led and contributed to vulnerability-related efforts the Forum of Incident Response and Security Teams (FIRST), the CVE Program, ISO/IEC JTC 1/SC 27, the Open Source Security Foundation (OpenSSF), and the National Telecommunications and Information Administration (NTIA, US). Art is the Deputy Director of Tharros Labs and previously managed vulnerability analysis at the CERT Coordination Center (CERT/CC).
Jay Jacobs is a Co-founder and Data Scientist at Empirical Security and Data Scientist Emeritus at Cyentia Institute. Jay is also the lead data scientist for the Exploit Prediction Scoring System (EPSS) and co-chair of the EPSS special interest group at FIRST. He also serves as the chair of the Consumer Working Group within the CVE program. Prior to his current roles, he was the Chief Data Scientist at Cyentia for several years and produced dozens of data-driven industry reports. He also served as the lead data scientist at Verizon working on the Data Breach Investigations report from 2010-2015 and he also served on the board of directors for the Society of Information Risks Analysts (SIRA) where he co-founded the non-profit dedicated to advancing risk management practices.
Art Manion (Tharros Labs, US), Jay Jacobs (Empirical Security, US)
In this talk, we build the case for an identity-first redesign of vulnerability records. Instead of open prose and after-market labels, each record should be anchored to the minimal, machine-verifiable set of assertions that unambiguously denote the same vulnerability across sources and time. We will connect familiar pain points (conflicting assertions, ambiguously defined affected products, flawed cross-repository joins, incomplete records and metric-driven shortcuts), to their root causes and the challenges facing us as we try to establish the identity of a vulnerability. We will explore the inherent tension between being human-meaningful, machine-usable, secure and decentralized, and how that is compounded by the analyst's natural limitations during the vulnerability discovery process. Our goal is an identity contract that is small, testable, and publisher-anchored that enables local discovery, deduplication, and practical adoption.
---
Art Manion spends a lot of time working on various aspects of technical cybersecurity vulnerabilities including coordinated disclosure, measurement, management, information systems, risk assessment, and public policy. Art has led and contributed to vulnerability-related efforts the Forum of Incident Response and Security Teams (FIRST), the CVE Program, ISO/IEC JTC 1/SC 27, the Open Source Security Foundation (OpenSSF), and the National Telecommunications and Information Administration (NTIA, US). Art is the Deputy Director of Tharros Labs and previously managed vulnerability analysis at the CERT Coordination Center (CERT/CC).
Jay Jacobs is a Co-founder and Data Scientist at Empirical Security and Data Scientist Emeritus at Cyentia Institute. Jay is also the lead data scientist for the Exploit Prediction Scoring System (EPSS) and co-chair of the EPSS special interest group at FIRST. He also serves as the chair of the Consumer Working Group within the CVE program. Prior to his current roles, he was the Chief Data Scientist at Cyentia for several years and produced dozens of data-driven industry reports. He also served as the lead data scientist at Verizon working on the Data Breach Investigations report from 2010-2015 and he also served on the board of directors for the Society of Information Risks Analysts (SIRA) where he co-founded the non-profit dedicated to advancing risk management practices.










