Taming the Scanner Storm: How VEX Brings Context to Vulnerability Data @FIRSTdotorg
Taming the Scanner Storm: How VEX Brings Context to Vulnerability Data  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 6 hours ago
Jessica Butler (NVIDIA, US)

Modern vulnerability management programs are flooded with scanner findings, many tied to open‑source components that have no available vendor fix or have already been deemed not exploitable by the vendor. This lack of trustworthy context leads to noisy reports and wasted developer effort on issues that cannot yet—or need not—be resolved. This session introduces a system that overlays vendor VEX (Vulnerability Exploitability eXchange) data onto container OS scan results to separate actionable upgrades from unaffected or unresolved vulnerabilities across all severity levels. By enabling consistent reporting and clarity, it helps teams focus on what they can fix today while maintaining visibility into what remains pending from upstream vendors.

The session will walk through a two‑stage VEX pipeline: (1) continuous ingestion and normalization of vendor VEX from distributions such as Ubuntu and Red Hat, and (2) rules‑based VEX synthesis to determine the appropriate response for internal teams and customers. By combining these layers, the system assigns VEX‑informed status and recommended actions for about 94% of vulnerabilities, significantly reducing manual triage.

Attendees will learn practical strategies for integrating vendor VEX data into vulnerability management workflows to cut through scanner noise, improve reporting accuracy, and accelerate fix adoption across engineering teams.

---

Jessica Butler is a Senior Product Security Engineer at NVIDIA, where she scales vulnerability detection and remediation across complex software and AI ecosystems. She leads automation of vendor VEX ingestion and overlays exploitability context onto scan results—turning raw data into actionable insights for engineering teams and customers. Jessica partners with scanning vendors to optimize how VEX intelligence enhances container image security at scale. She also integrates NVIDIA’s Vulnerability Analysis for Containers into internal workflows, applying AI-driven, evidence-based techniques to reduce analyst toil and improve decision quality. She is passionate about pragmatic security automation that bridges standards, tools, and real-world developer practices.
Taming the Scanner Storm: How VEX Brings Context to Vulnerability DataEpisode 62: Tim Brown, Team8, former SolarWinds CISO, FIRSTCON26 KeynoteUnmasking MSC FilesImproving Security Across Nations with FIRST: Dr. Lisa Bradley, FIRST PSIRT SIG MemberFlipping the Criticality Funnel, A Practical Path to Real PrioritizationForecasting Vulnerability Sightings Under Data Scarcity: Modeling Sparse and Bursty Cyber Threat ...IC5 – Integrated CERT Cyber Communications, Collaboration & Coordination FrameworkHow NOT to be Your Adversarys Best Friend - Doing What Matters...CSIRTeaming: Forging Resilient Incident Management Teams with Psychological SafetyMind the Match: Why Vulnerability Matching Is Harder Than You ThinkOpenTide: From Raw Intelligence to Structured Threat-Informed DetectionsThe Vulnerability Ecosystem’s Vendor Bias — Exposed by Open Source
FIRST |

Taming the Scanner Storm: How VEX Brings Context to Vulnerability Data

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER