Uploaded June 2026 | Updated September 2026, 1 hour ago
Alexandre Dulaunoy (CIRCL, LU), Cédric Bonhomme (CIRCL, FR)
Forecasting vulnerability activity is challenging: sightings such as PoCs, scanner detections, or Fediverse mentions are sparse, noisy, and highly bursty. We present experiments on predicting short-term sighting trends for individual vulnerabilities using real-world data and multiple statistical approaches. Classical SARIMAX models struggle under data scarcity, while Poisson regression and simple logistic/decay functions yield more stable and interpretable results. Building on the VLAI severity model, we outline practical techniques CTI teams can apply today to anticipate spikes in attention and better prioritize vulnerabilities despite limited historical data.
---
Alexandre Dulaunoy encountered his first computer in the eighties, and he disassembled it to know how the thing works. While pursuing his logical path towards information security and free software, he worked as senior security network consultant at different places (e.g. Ubizen, now Cybertrust). He co-founded a startup called Conostix, which specialised in information security management. For the past 6 years, he was the manager of global information security at SES, a leading international satellite operator. He is now working at CIRCL in the research and operational fields. He is also a lecturer in information security at Paul-Verlaine University in Metz and the University of Luxembourg. He is also the lead developer of various open source tools including cve-search and member of the MISP core team. Besides his activities in cyber-security, he's also fond of generally fixing anything that's broken around the office.
Cédric Bonhomme is a seasoned computer scientist with a deep passion for computer security and privacy. From 2010 to 2017, he worked as an R&D Engineer at a research center, specializing in Multi-Agent Systems and Cybersecurity. Since 2017, he has been an integral part of CIRCL, actively contributing to CSIRT operations and the development of innovative open-source software projects. Currently, he serves as the lead developer of Vulnerability-Lookup, driving advancements in vulnerability research and management.
Alexandre Dulaunoy (CIRCL, LU), Cédric Bonhomme (CIRCL, FR)
Forecasting vulnerability activity is challenging: sightings such as PoCs, scanner detections, or Fediverse mentions are sparse, noisy, and highly bursty. We present experiments on predicting short-term sighting trends for individual vulnerabilities using real-world data and multiple statistical approaches. Classical SARIMAX models struggle under data scarcity, while Poisson regression and simple logistic/decay functions yield more stable and interpretable results. Building on the VLAI severity model, we outline practical techniques CTI teams can apply today to anticipate spikes in attention and better prioritize vulnerabilities despite limited historical data.
---
Alexandre Dulaunoy encountered his first computer in the eighties, and he disassembled it to know how the thing works. While pursuing his logical path towards information security and free software, he worked as senior security network consultant at different places (e.g. Ubizen, now Cybertrust). He co-founded a startup called Conostix, which specialised in information security management. For the past 6 years, he was the manager of global information security at SES, a leading international satellite operator. He is now working at CIRCL in the research and operational fields. He is also a lecturer in information security at Paul-Verlaine University in Metz and the University of Luxembourg. He is also the lead developer of various open source tools including cve-search and member of the MISP core team. Besides his activities in cyber-security, he's also fond of generally fixing anything that's broken around the office.
Cédric Bonhomme is a seasoned computer scientist with a deep passion for computer security and privacy. From 2010 to 2017, he worked as an R&D Engineer at a research center, specializing in Multi-Agent Systems and Cybersecurity. Since 2017, he has been an integral part of CIRCL, actively contributing to CSIRT operations and the development of innovative open-source software projects. Currently, he serves as the lead developer of Vulnerability-Lookup, driving advancements in vulnerability research and management.










