Uploaded May 2026 | Updated September 2026, 12 hours ago
Art Manion (Tharros Labs, US), Caitlin Condon (VulnCheck, US), David Welch (HeroDevs, US), Shelby Cunningham (GitHub, US)
2025 was a year of attention-grabbing malware campaigns targeting the open-source supply chain. From a campaign that affected a single package (tj-actions/changed-files) to massive supply chain compromises like the Shai Hulud attacks against npm, vulnerability management teams need ways to keep track of compromised packages that provides accurate information in a timely fashion. While CVE rules prohibit the use of CVE for tracking general-purpose malicious code, the rules do allow issuing a CVE ID to a legitimate package infected with malware. This raises a question: Is CVE the best way to track these supply chain compromises? This panel discusses situations in which CVE helped to facilitate tracking of a single-package supply chain attack, while acknowledging the drawbacks that arise when CVE rules are applied to campaigns that affect hundreds of packages
---
Art Manion spends a lot of time working on various aspects of technical cybersecurity vulnerabilities including coordinated disclosure, measurement, management, information systems, risk assessment, and public policy. Art has led and contributed to vulnerability-related efforts the Forum of Incident Response and Security Teams (FIRST), the CVE Program, ISO/IEC JTC 1/SC 27, the Open Source Security Foundation (OpenSSF), and the National Telecommunications and Information Administration (NTIA, US). Art is the Deputy Director of Tharros Labs and previously managed vulnerability analysis at the CERT Coordination Center (CERT/CC).
Caitlin Condon is the VP of research at VulnCheck, where she works on initial access intelligence, emerging threat response, and coordinated vulnerability disclosure with some of the kindest, most talented researchers and analysts around. She previously led research and Metasploit development at Rapid7. Caitlin also chairs the CVE Program's Researcher Working Group (RWG), which you should totally join if you’re a researcher or bug bounty CNA!
David Welch is a seasoned industry leader with 20+ years of experience. Passionate about open source software, security, and compliance, he brings a unique perspective to the evolving tech landscape. As Chief Architect at HeroDevs, David spearheads the technical direction of the Never-Ending Support program, delivering Long-Term Support for end-of-life open-source projects.
Shelby Cunningham has been an advisory curator for the GitHub Advisory Database (GHAD) for five years. Her duties include, but are not limited to, organizing and publishing vulnerability information for the GHAD and gathering vulnerability information from project maintainers on GitHub to submit to the CVE list. Shelby has supported best security practices in the open source software community by advising projects that are part of the GitHub Secure Open Source Fund. In 2025, she responded to multiple incidents involving compromise of legitimate packages in ecosystems supported by the GHAD.
Art Manion (Tharros Labs, US), Caitlin Condon (VulnCheck, US), David Welch (HeroDevs, US), Shelby Cunningham (GitHub, US)
2025 was a year of attention-grabbing malware campaigns targeting the open-source supply chain. From a campaign that affected a single package (tj-actions/changed-files) to massive supply chain compromises like the Shai Hulud attacks against npm, vulnerability management teams need ways to keep track of compromised packages that provides accurate information in a timely fashion. While CVE rules prohibit the use of CVE for tracking general-purpose malicious code, the rules do allow issuing a CVE ID to a legitimate package infected with malware. This raises a question: Is CVE the best way to track these supply chain compromises? This panel discusses situations in which CVE helped to facilitate tracking of a single-package supply chain attack, while acknowledging the drawbacks that arise when CVE rules are applied to campaigns that affect hundreds of packages
---
Art Manion spends a lot of time working on various aspects of technical cybersecurity vulnerabilities including coordinated disclosure, measurement, management, information systems, risk assessment, and public policy. Art has led and contributed to vulnerability-related efforts the Forum of Incident Response and Security Teams (FIRST), the CVE Program, ISO/IEC JTC 1/SC 27, the Open Source Security Foundation (OpenSSF), and the National Telecommunications and Information Administration (NTIA, US). Art is the Deputy Director of Tharros Labs and previously managed vulnerability analysis at the CERT Coordination Center (CERT/CC).
Caitlin Condon is the VP of research at VulnCheck, where she works on initial access intelligence, emerging threat response, and coordinated vulnerability disclosure with some of the kindest, most talented researchers and analysts around. She previously led research and Metasploit development at Rapid7. Caitlin also chairs the CVE Program's Researcher Working Group (RWG), which you should totally join if you’re a researcher or bug bounty CNA!
David Welch is a seasoned industry leader with 20+ years of experience. Passionate about open source software, security, and compliance, he brings a unique perspective to the evolving tech landscape. As Chief Architect at HeroDevs, David spearheads the technical direction of the Never-Ending Support program, delivering Long-Term Support for end-of-life open-source projects.
Shelby Cunningham has been an advisory curator for the GitHub Advisory Database (GHAD) for five years. Her duties include, but are not limited to, organizing and publishing vulnerability information for the GHAD and gathering vulnerability information from project maintainers on GitHub to submit to the CVE list. Shelby has supported best security practices in the open source software community by advising projects that are part of the GitHub Secure Open Source Fund. In 2025, she responded to multiple incidents involving compromise of legitimate packages in ecosystems supported by the GHAD.










