Vulnerabilities Without CVEs: Governing the Dark Matter of Internal and Unknown Software @FIRSTdotorg
Vulnerabilities Without CVEs: Governing the Dark Matter of Internal and Unknown Software  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 46 minutes ago
Josh Skorich (Spektion, US)

Vulnerability management programs are optimized for what can be named and matched: a product, a version, a CVE. But real environments contain significant software that exists outside practical CVE coverage: legacy tools from defunct vendors, obscure utilities embedded in base images, regional software without CNA relationships, and abandoned projects that still run in production. If a scanner can't fingerprint it, your pipeline produces no finding, no ticket, no owner. The risk is invisible by design.

This talk presents an endpoint-telemetry approach to finding and governing that blind spot, born from a career in red teaming where the most interesting findings were rarely in software with CVE coverage. Using host-level runtime events (process execution, privilege context, network connections), we can identify software that scanners miss and surface pre-CVE risk: exploit-relevant behaviors observable in production before any advisory exists. Think of the output as synthetic CVEs for software that the ecosystem doesn't cover. I'll walk through concrete examples, show what host telemetry can and cannot prove, and discuss how these findings integrate into existing VM workflows alongside traditional CVE-based results.

---

Josh Skorich is Founder and CTO at Spektion, working on runtime-based security for production environments. He spent over a decade in red teaming and adversary simulation, leading offensive security programs across financial systems, critical infrastructure, and cloud environments. His focus is bringing operational security reality into scalable, repeatable vulnerability governance.
Vulnerabilities Without CVEs: Governing the Dark Matter of Internal and Unknown SoftwareEpisode 61: Chris Butera, CISA, FIRSTCON26 Speakernx Compromise - AI as an Attack VectorAutomating CNA CVE Reporting and Monthly Bulletins at AtlassianClosing RemarksArtemis: How CERT PL Improves the Security of the Polish InternetImproving Security Across Nations with FIRST: Carlos Leonardo, FIRST Board of Directors MemberOne Poisoned Artifact Can Steer Your AI: How Robust Are Your LLM-Assisted Security Workflows?The Vulnerability Identity CrisisSpeeding Up Vulnerability Triage: Automating Context Retrieval with AI AgentsPanel: Tips and Tricks to Run a CSIRT in Low-income and Fragile ContextsEngaging with the Media to Foster Cybersecurity Resilience
FIRST |

Vulnerabilities Without CVEs: Governing the Dark Matter of Internal and Unknown Software

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER