Uploaded May 2026 | Updated September 2026, 3 hours ago
Karel Knibbe (Volerion, NL), Ruben Bos (Volerion, NL)
CVSS is standardized, yet difficult to apply in practice. Traditional CVSS enrichment starts by mentally constructing an attack scenario, but that context is abstracted away by the final vector. In addition to this, many vulnerabilities have multiple plausible exploitation paths, but workflows lack the ability to choose the most severe candidate. Without first considering all plausible scenarios, it is unclear which scenario the final vector should be based on, and "worst case" becomes an assumption rather than fact. In an attempt to represent multiple possibilities with a single score, analysts often end up mixing metric choices drawn from different scenarios, producing a hybrid vector that does not faithfully represent any single attack. These shortcomings drive inconsistency, inaccuracy, and lack auditability. This talk presents a transparent, multi-scenario scoring method based on attack graphs, thereby eliminating all three.
---
Ruben Bos is co-founder of Volerion, where he and co-founder Karel Knibbe use AI to improve the quality, consistency, and timeliness of CVE data. Ruben studied software engineering and holds a cum laude Bachelor’s degree in Cyber Security. He has over a decade of experience in bug bounty and penetration testing, including winning multiple live hacking events hosted by companies such as Meta and Intel. Over the past two years, he has focused on high-accuracy CVSS automation and vulnerability enrichment, progressing from direct vector prediction to guided walkthrough approaches and ultimately to a graph-based method that models exploitation as explicit scenarios and derives CVSS vectors programmatically.
Karel Knibbe (Volerion, NL), Ruben Bos (Volerion, NL)
CVSS is standardized, yet difficult to apply in practice. Traditional CVSS enrichment starts by mentally constructing an attack scenario, but that context is abstracted away by the final vector. In addition to this, many vulnerabilities have multiple plausible exploitation paths, but workflows lack the ability to choose the most severe candidate. Without first considering all plausible scenarios, it is unclear which scenario the final vector should be based on, and "worst case" becomes an assumption rather than fact. In an attempt to represent multiple possibilities with a single score, analysts often end up mixing metric choices drawn from different scenarios, producing a hybrid vector that does not faithfully represent any single attack. These shortcomings drive inconsistency, inaccuracy, and lack auditability. This talk presents a transparent, multi-scenario scoring method based on attack graphs, thereby eliminating all three.
---
Ruben Bos is co-founder of Volerion, where he and co-founder Karel Knibbe use AI to improve the quality, consistency, and timeliness of CVE data. Ruben studied software engineering and holds a cum laude Bachelor’s degree in Cyber Security. He has over a decade of experience in bug bounty and penetration testing, including winning multiple live hacking events hosted by companies such as Meta and Intel. Over the past two years, he has focused on high-accuracy CVSS automation and vulnerability enrichment, progressing from direct vector prediction to guided walkthrough approaches and ultimately to a graph-based method that models exploitation as explicit scenarios and derives CVSS vectors programmatically.










