Uploaded May 2026 | Updated September 2026, 20 minutes ago
Johnny Shaieb (IBM, US)
This paper is a cause-and-effect narrative that examines the historical events, key individuals, challenges, and vulnerability analyses that contributed to the development of vulnerability repositories—both lists and databases—forming the foundation for the “Common Vulnerabilities and Exposures (CVE)” and later the “National Vulnerability Database (NVD)”. This narrative follows a cause-and-effect progression, beginning with the very first message sent over ARPANET, which caused a buffer overflow and served as a catalyst for the development of modern vulnerability tracking. As the nascent ARPANET developed, operating system pioneers began documenting vulnerabilities with meticulous care, restricting awareness to legitimate users only. However, cultural moments such as the film WarGames (1983) and cyber incidents like the Morris Worm (1988), The Cuckoo’s Egg (1989), and Solar Sunrise (1998) began to erode this cautious approach, highlighting the need for full public disclosure of vulnerabilities stored in a centralized database. To provide an authoritative account of seldom-told stories and historical events, a combination of virtual interviews, phone calls, emails, messaging, questionnaires, and white paper discussions were conducted with the following thought leaders: Scott Moore, Jay Jacobs, Brian Martin, Steve Christey, Peter Mell, Dr. David Mann, Andre Frech, Dr. Eugene Spafford, Dr. Matt Bishop, Elias Levy, Art Manion, Dr. Cliff Stoll, Dr. Leonard Kleinrock, and Dr. John Hale.
---
Johnny Shaieb is currently working on his PhD at the University of Tulsa, where his dissertation focuses on vulnerability database history and scoring. He is the Chief Architect of IBM’s Cyber Threat Exposure Management practice, an elite unit specializing in penetration testing, adversary simulation, and vulnerability management. His cybersecurity journey began in 1998 at WorldCom after earning a bachelor’s in management information systems from Oklahoma State University. He later pursued a master’s in Telecommunications at OSU and a second master’s in Computer Science at the University of Tulsa, focusing on NSA CyberCorps security.
With over 25 years of experience, Johnny has honed his offensive security skills through academic and professional endeavors. Since 2011, he has taught ethical hacking at institutions like Houston Community College and created the "Hac-King-Do" framework for free ethical hacker training. At IBM, he patented a methodology to automate hacker research and co-founded the X-Force Red Hacker internship with "Space Rogue" to recruit top cybersecurity talent.
Johnny Shaieb (IBM, US)
This paper is a cause-and-effect narrative that examines the historical events, key individuals, challenges, and vulnerability analyses that contributed to the development of vulnerability repositories—both lists and databases—forming the foundation for the “Common Vulnerabilities and Exposures (CVE)” and later the “National Vulnerability Database (NVD)”. This narrative follows a cause-and-effect progression, beginning with the very first message sent over ARPANET, which caused a buffer overflow and served as a catalyst for the development of modern vulnerability tracking. As the nascent ARPANET developed, operating system pioneers began documenting vulnerabilities with meticulous care, restricting awareness to legitimate users only. However, cultural moments such as the film WarGames (1983) and cyber incidents like the Morris Worm (1988), The Cuckoo’s Egg (1989), and Solar Sunrise (1998) began to erode this cautious approach, highlighting the need for full public disclosure of vulnerabilities stored in a centralized database. To provide an authoritative account of seldom-told stories and historical events, a combination of virtual interviews, phone calls, emails, messaging, questionnaires, and white paper discussions were conducted with the following thought leaders: Scott Moore, Jay Jacobs, Brian Martin, Steve Christey, Peter Mell, Dr. David Mann, Andre Frech, Dr. Eugene Spafford, Dr. Matt Bishop, Elias Levy, Art Manion, Dr. Cliff Stoll, Dr. Leonard Kleinrock, and Dr. John Hale.
---
Johnny Shaieb is currently working on his PhD at the University of Tulsa, where his dissertation focuses on vulnerability database history and scoring. He is the Chief Architect of IBM’s Cyber Threat Exposure Management practice, an elite unit specializing in penetration testing, adversary simulation, and vulnerability management. His cybersecurity journey began in 1998 at WorldCom after earning a bachelor’s in management information systems from Oklahoma State University. He later pursued a master’s in Telecommunications at OSU and a second master’s in Computer Science at the University of Tulsa, focusing on NSA CyberCorps security.
With over 25 years of experience, Johnny has honed his offensive security skills through academic and professional endeavors. Since 2011, he has taught ethical hacking at institutions like Houston Community College and created the "Hac-King-Do" framework for free ethical hacker training. At IBM, he patented a methodology to automate hacker research and co-founded the X-Force Red Hacker internship with "Space Rogue" to recruit top cybersecurity talent.










