The CVE Blind Spot: Defeating Hidden EOLs and Repo Jacking with Engineering Triage & Code Diet @FIRSTdotorg
The CVE Blind Spot: Defeating Hidden EOLs and Repo Jacking with Engineering Triage & Code Diet  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 2 hours ago
Kota Kanbe (Future Corporation, JP), Ryunosuke Tanai (Future Corporation, JP)

Standard vulnerability management relies heavily on CVEs. However, this creates a dangerous "Blind Spot": End-of-Life (EOL) OSS components often stop receiving CVE assignments even when critical vulnerabilities exist. Furthermore, abandoned components become prime targets for "Repo Jacking" and supply chain attacks.

---

Kota Kanbe is the creator of "Vuls," a globally recognized OSS vulnerability scanner with over 11.9k GitHub stars. As a Senior Architect at Future Corporation and leader of the FutureVuls team, he manages large-scale vulnerability data and complex supply chain risks. His contributions were recognized with the Google OSS Peer Bonus in 2022 and the Software Japan Award in 2019. A prominent speaker in the Japanese security community with extensive domestic experience, Kota has also brought his expertise to international stages such as BlackHat Asia Arsenal and HITCON. He is a leading advocate for a paradigm shift in vulnerability management, moving from traditional CVSS-based triage to risk-based prioritization through Reachability Analysis and SSVC. Drawing from his research on 20,000+ production components, Kota focuses on automating "Engineering Triage" to solve the real-world challenges of EOL management and supply chain bloat.

Ryunosuke Tanai is an Engineer at Future Corporation, currently contributing to the SRE domain of "FutureVuls," a cloud-based vulnerability management service. Since joining the company, he has been involved in the Technology Innovation Group (TIG) and the Cyber Security Innovation Group (CSIG), specializing in infrastructure, cloud services, and security. He is proficient in English, having completed a half-year study abroad program, and holds the Registered Information Security Specialist certification. He is also an active member of the tech community, frequently sharing his expertise on Datadog implementation and cloud architecture at conferences and through the Future Technical Blog.
The CVE Blind Spot: Defeating Hidden EOLs and Repo Jacking with Engineering Triage & Code DietAll Ransomware Economic Models are Wrong, But This One is UsefulCISA-ENISA Joint MessagingPanel: From Takedown to Touchpoint: An Inside Look at the Data-sharing Pipeline in the Victim ...Bringing Actionable Data to Internet DefendersUnlocking Insights: The Role of TI in Modern DFIR OperationsThe Quality Era of CVE: A Blueprint for Global Software SafetyBattle-Tested Incident Recovery: Lessons from the Front LinesThe AI Assistant’s Betrayal: One-Click for AI to Turn into the Perfect InsiderBoosting Vulnerability Intelligence: How Accurate CWE Mappings Transform ML Model PerformanceCan a General-Purpose LLM Do Tier-1 Triage?Improving Security Across Nations with FIRST: Esmeralda Kazia, FIRST Member
FIRST |

The CVE Blind Spot: Defeating "Hidden EOLs" and Repo Jacking with Engineering Triage & Code Diet

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER