Forecasting Vulnerability Sightings Under Data Scarcity: Modeling Sparse and Bursty Cyber Threat ... @FIRSTdotorg
Forecasting Vulnerability Sightings Under Data Scarcity: Modeling Sparse and Bursty Cyber Threat ...  @FIRSTdotorg
Uploaded June 2026 | Updated September 2026, 1 hour ago
Alexandre Dulaunoy (CIRCL, LU), Cédric Bonhomme (CIRCL, FR)

Forecasting vulnerability activity is challenging: sightings such as PoCs, scanner detections, or Fediverse mentions are sparse, noisy, and highly bursty. We present experiments on predicting short-term sighting trends for individual vulnerabilities using real-world data and multiple statistical approaches. Classical SARIMAX models struggle under data scarcity, while Poisson regression and simple logistic/decay functions yield more stable and interpretable results. Building on the VLAI severity model, we outline practical techniques CTI teams can apply today to anticipate spikes in attention and better prioritize vulnerabilities despite limited historical data.

---

Alexandre Dulaunoy encountered his first computer in the eighties, and he disassembled it to know how the thing works. While pursuing his logical path towards information security and free software, he worked as senior security network consultant at different places (e.g. Ubizen, now Cybertrust). He co-founded a startup called Conostix, which specialised in information security management. For the past 6 years, he was the manager of global information security at SES, a leading international satellite operator. He is now working at CIRCL in the research and operational fields. He is also a lecturer in information security at Paul-Verlaine University in Metz and the University of Luxembourg. He is also the lead developer of various open source tools including cve-search and member of the MISP core team. Besides his activities in cyber-security, he's also fond of generally fixing anything that's broken around the office.

Cédric Bonhomme is a seasoned computer scientist with a deep passion for computer security and privacy. From 2010 to 2017, he worked as an R&D Engineer at a research center, specializing in Multi-Agent Systems and Cybersecurity. Since 2017, he has been an integral part of CIRCL, actively contributing to CSIRT operations and the development of innovative open-source software projects. Currently, he serves as the lead developer of Vulnerability-Lookup, driving advancements in vulnerability research and management.
Forecasting Vulnerability Sightings Under Data Scarcity: Modeling Sparse and Bursty Cyber Threat ...IC5 – Integrated CERT Cyber Communications, Collaboration & Coordination FrameworkHow NOT to be Your Adversarys Best Friend - Doing What Matters...CSIRTeaming: Forging Resilient Incident Management Teams with Psychological SafetyMind the Match: Why Vulnerability Matching Is Harder Than You ThinkOpenTide: From Raw Intelligence to Structured Threat-Informed DetectionsThe Vulnerability Ecosystem’s Vendor Bias — Exposed by Open SourceRouting Security for Enterprises: Secure Your Supply ChainEmbracing the Era of Transparency: Automating VEX Application for Scalable, Context-Aware SecurityAttack or Noise?: Tracking and Evaluating the Impact of Internet-Wide Survey ScannersAI Is Writing Your Bug Reports. Can You Tell?Dark Silicon: Unmasking GPU Threats in the Age of AI
FIRST |

Forecasting Vulnerability Sightings Under Data Scarcity: Modeling Sparse and Bursty Cyber Threat ...

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER