From Discovery to Fix: What 10,000 Open Source Projects Reveal About CVE Remediation @FIRSTdotorg
From Discovery to Fix: What 10,000 Open Source Projects Reveal About CVE Remediation  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 13 hours ago
Mor Weinberger (Echo, IL)

We analyzed CVE remediation patterns across 10,000 open‑source projects to understand a critical problem: the mean time to repair (MTTR) for vulnerabilities as they propagate through the ecosystem. Our research reveals a sobering reality — CVEs fixed upstream take weeks or months to reach downstream containers, creating massive security‑exposure windows in Kubernetes environments.

In this talk, we'll present our findings showing how CVE fixes flow (or stall) through different ecosystem layers — from upstream projects to package managers to base images to final containers. You'll see real data on remediation delays, bottlenecks, and the compounding effect of layered dependencies.

But we won't stop at the problem. The second half focuses on practical solutions. We'll demonstrate remediation strategies that actually work at scale, from automated patch backporting to in‑place image patching with tools like Copa. You'll learn how to build workflows that dramatically reduce MTTR, including dependency‑automation patterns and risk‑based prioritization.

Attendees will leave with both a data‑driven understanding of the CVE remediation challenge and a practical playbook for fixing it, complete with automation templates and proven patterns from the field.

---

Mor Weinberger is a Staff Software Engineer specializing in analyzing cloud-native security and supply chain threats. His efforts have uncovered a variety of emerging threats, including unsecured environments and platforms, as well as cryptomining campaigns. Additionally, he has collaborated with the Center for Internet Security (CIS) to develop guidelines for software supply chains and an open-source security tool to address these challenges.
From Discovery to Fix: What 10,000 Open Source Projects Reveal About CVE RemediationLightning Talks!Anti-Forensics - You are Doing it Wrong (Believe Me, Im an IR Consultant)What Can Cybersecurity Incident Responders Learn from Real-World Crises?Enhancing Incident Response with AWS CIRT, MSSPs, and ISVsEpisode 55: Merike Kaeo, FIRSTCON26 Program ChairProactive EDR Against Adaptive Evasion: Countering Self‑Modifying Agentic MalwareProduction Is the New Attack Surface: Why Post-Deployment Endpoint Detection Is Now CriticalOROCHIFY - An Assist to Product Developers in Manufacturing Industry to Find VulnerabilitiesRemediation-Aware Reachability: Patching Containers, Prioritizing with Agentic-CTI, and Scaling...Threat Hunting with Python & PandasEpisode 56: Mor Weinberger and Lior Kaplan, FIRSTCON26 Speakers
FIRST |

From Discovery to Fix: What 10,000 Open Source Projects Reveal About CVE Remediation

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER