A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle @FIRSTdotorg
A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 1 hour ago
Art Manion (Tharros Labs, US), Jay Jacobs (Empirical Security, US)

In this talk, we build the case for an identity-first redesign of vulnerability records. Instead of open prose and after-market labels, each record should be anchored to the minimal, machine-verifiable set of assertions that unambiguously denote the same vulnerability across sources and time. We will connect familiar pain points (conflicting assertions, ambiguously defined affected products, flawed cross-repository joins, incomplete records and metric-driven shortcuts), to their root causes and the challenges facing us as we try to establish the identity of a vulnerability. We will explore the inherent tension between being human-meaningful, machine-usable, secure and decentralized, and how that is compounded by the analyst's natural limitations during the vulnerability discovery process. Our goal is an identity contract that is small, testable, and publisher-anchored that enables local discovery, deduplication, and practical adoption.

---

Art Manion spends a lot of time working on various aspects of technical cybersecurity vulnerabilities including coordinated disclosure, measurement, management, information systems, risk assessment, and public policy. Art has led and contributed to vulnerability-related efforts the Forum of Incident Response and Security Teams (FIRST), the CVE Program, ISO/IEC JTC 1/SC 27, the Open Source Security Foundation (OpenSSF), and the National Telecommunications and Information Administration (NTIA, US). Art is the Deputy Director of Tharros Labs and previously managed vulnerability analysis at the CERT Coordination Center (CERT/CC).

Jay Jacobs is a Co-founder and Data Scientist at Empirical Security and Data Scientist Emeritus at Cyentia Institute. Jay is also the lead data scientist for the Exploit Prediction Scoring System (EPSS) and co-chair of the EPSS special interest group at FIRST. He also serves as the chair of the Consumer Working Group within the CVE program. Prior to his current roles, he was the Chief Data Scientist at Cyentia for several years and produced dozens of data-driven industry reports. He also served as the lead data scientist at Verizon working on the Data Breach Investigations report from 2010-2015 and he also served on the board of directors for the Society of Information Risks Analysts (SIRA) where he co-founded the non-profit dedicated to advancing risk management practices.
A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases StrugglePreparing Vulnerability Management for the Post-Quantum Era: From Legacy Cryptography Crypto-AgilitySocial Engineering in the Age of AI: Rethinking Security Awareness TrainingBuilding the Blueprint: Designing Effective Storyboards for Cybersecurity Tabletop ExercisesThe Dependency Mirage: Hidden Vulnerabilities in Your Compiled BinariesTransforming Vulnerability Management with Advanced Dependency Knowledge GraphsA Researcher Centric Approach to Coordinated Vulnerability DisclosureHow to Answer “What’s Affected?” in Open SourceSysmon Deep Dive: Real Detection Scenarios You Can ReproduceThe PR3TACK Initiative: Building the World’s First Preemptive Tactics & Countermeasures KnowledgebasGuardians of the HypervisorBest Practices for Data Privacy Breach Response: Lessons Learned from Social Media Case Studies
FIRST |

A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER