Uploaded May 2026 | Updated September 2026, 1 hour ago
Jessica Butler (NVIDIA, US), Kristina Joos (NVIDIA, US)
As organizations accelerate AI adoption, managing software vulnerabilities in sprawling open-source ecosystems has become increasingly complex. Traditional vulnerability scanning alone cannot match the speed and scale of modern AI software supply chains. This session explores how open standards and automated Vulnerability Exploitability eXchange (VEX) integration are transforming vulnerability management with precise, machine‑readable insights. We’ll show how VEX documents, built on open specifications, can be directly associated with software release artifacts, ensuring traceable context that persists across the release lifecycle. By collaborating with leading scanning vendors, we’re streamlining VEX ingestion into vulnerability management workflows—enabling automated filtering of exploitable vulnerabilities at scan time without additional user effort. This standards‑based integration reduces false positives, improves prioritization, and keeps focus squarely on real, exploitable risks. Attendees will dive into the architecture behind VEX automation, the open ecosystem standards that power it, and practical steps to implement these capabilities in their own environments. A live demo will showcase end‑to‑end automation in action—turning raw vulnerability data into actionable intelligence for secure, production‑grade AI deployments. Participants will leave with a clear blueprint for adopting open, automated, and scalable vulnerability management practices that enhance both resilience and speed in the AI era.
---
Jessica Butler is a Senior Product Security Engineer at NVIDIA, where she scales vulnerability detection and remediation across complex software and AI ecosystems. She leads automation of vendor VEX ingestion and overlays exploitability context onto scan results—turning raw data into actionable insights for engineering teams and customers. Jessica partners with scanning vendors to optimize how VEX intelligence enhances container image security at scale. She also integrates NVIDIA’s Vulnerability Analysis for Containers into internal workflows, applying AI-driven, evidence-based techniques to reduce analyst toil and improve decision quality. She is passionate about pragmatic security automation that bridges standards, tools, and real-world developer practices.
Kristina Joos is a Product Manager at NVIDIA working diligently to accelerate AI adoption in enterprises, focusing on OSS security management. Before this, Kristina was a product manager for NVIDIA's NGC catalog, facilitating SDK access for developers.
Jessica Butler (NVIDIA, US), Kristina Joos (NVIDIA, US)
As organizations accelerate AI adoption, managing software vulnerabilities in sprawling open-source ecosystems has become increasingly complex. Traditional vulnerability scanning alone cannot match the speed and scale of modern AI software supply chains. This session explores how open standards and automated Vulnerability Exploitability eXchange (VEX) integration are transforming vulnerability management with precise, machine‑readable insights. We’ll show how VEX documents, built on open specifications, can be directly associated with software release artifacts, ensuring traceable context that persists across the release lifecycle. By collaborating with leading scanning vendors, we’re streamlining VEX ingestion into vulnerability management workflows—enabling automated filtering of exploitable vulnerabilities at scan time without additional user effort. This standards‑based integration reduces false positives, improves prioritization, and keeps focus squarely on real, exploitable risks. Attendees will dive into the architecture behind VEX automation, the open ecosystem standards that power it, and practical steps to implement these capabilities in their own environments. A live demo will showcase end‑to‑end automation in action—turning raw vulnerability data into actionable intelligence for secure, production‑grade AI deployments. Participants will leave with a clear blueprint for adopting open, automated, and scalable vulnerability management practices that enhance both resilience and speed in the AI era.
---
Jessica Butler is a Senior Product Security Engineer at NVIDIA, where she scales vulnerability detection and remediation across complex software and AI ecosystems. She leads automation of vendor VEX ingestion and overlays exploitability context onto scan results—turning raw data into actionable insights for engineering teams and customers. Jessica partners with scanning vendors to optimize how VEX intelligence enhances container image security at scale. She also integrates NVIDIA’s Vulnerability Analysis for Containers into internal workflows, applying AI-driven, evidence-based techniques to reduce analyst toil and improve decision quality. She is passionate about pragmatic security automation that bridges standards, tools, and real-world developer practices.
Kristina Joos is a Product Manager at NVIDIA working diligently to accelerate AI adoption in enterprises, focusing on OSS security management. Before this, Kristina was a product manager for NVIDIA's NGC catalog, facilitating SDK access for developers.










