The Hidden Cost of CVEs: Can CSAF and VEX Change the Equation? @FIRSTdotorg
The Hidden Cost of CVEs: Can CSAF and VEX Change the Equation?  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 1 hour ago
Lisa Olson (Microsoft, US)

The CRA is calling for disclosing many more classes of vulnerabilities and clearly articulating the exploit status of all known vulnerabilities in the entire supply chain. To execute successfully, the industry is going to have to work together to come up with the tooling necessary to make this possible. This talk will explore the challenges and opportunities for this industry collaboration.

---

Lisa Olson is a Principal Security Release Program Manager at Microsoft, where she has led the Patch Tuesday release process since 2013. A member of the CVE Board since 2018, Lisa is a passionate advocate for improving vulnerability communication through automation and machine-readable formats. Her work focuses on transforming how security information is shared to help organizations respond faster and more effectively.
The Hidden Cost of CVEs: Can CSAF and VEX Change the Equation?The SOC Of The Future… The Future Is NowOne SOC, The Whole SOC, and Nothing But The SOC, So Help MeEiffel: A Tool to Oversee Incident Response From the HeightsProtecting Customers Through Smarter OSS ManagementOperationalizing AIBOMs: Extending Vulnerability Management to AI Models and DatasetsMalice in the Modules - How NPM Became a Supply-Chain Battleground?One Bad OSINT Can Ruin Everything: How Secure is Your CTI RAG System, and Can You Minimize the Risk?Improving Security Across Nations with FIRST: Sametria McKinney, FIRST MemberClimbing Toward the Summit of Defense: Practical Methods for Strengthening CSIRT OrganizationsMonday Keynote: Perseverance, Growth and Success. The Sunburst Story from the CISO perspective.Evaluating Threat Intelligence Through Velocity
FIRST |

The Hidden Cost of CVEs: Can CSAF and VEX Change the Equation?

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER