Vulnrichment Playground @FIRSTdotorg
Vulnrichment Playground  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 1 hour ago
Art Manion (Tharros Labs, US), Lindsey Cerkovnik (CISA, US)

The CISA Vulnrichment project has demonstrated how a CVE Program authorized data publisher (ADP) can provide additional information to CVE Records, supporting a more consistent baseline that includes SSVC, KEV, CVSS, and CWE. Beyond this baseline, Vulnrichment allows CISA to experiment with different types of information, assessing costs, value to consumers, and potential policy recommendations. What additional information should Vulnrichment provide? Or stop providing? What if Vulnrichment disagrees with CNA-provided information? This presentation will review "Vulnrichment Year 2" and explore new enrichment options.

---

Art Manion spends a lot of time working on various aspects of technical cybersecurity vulnerabilities including coordinated disclosure, measurement, management, information systems, risk assessment, and public policy. Art has led and contributed to vulnerability-related efforts the Forum of Incident Response and Security Teams (FIRST), the CVE Program, ISO/IEC JTC 1/SC 27, the Open Source Security Foundation (OpenSSF), and the National Telecommunications and Information Administration (NTIA, US). Art is the Deputy Director of Tharros Labs and previously managed vulnerability analysis at the CERT Coordination Center (CERT/CC).

Lindsey Cerkovnik is the Chief of CISA’s Vulnerability Response & Coordination (VRC) Branch. Her team is responsible for CISA’s Coordinated Vulnerability Disclosure

(CVD) process, the Known Exploited Vulnerabilities (KEV) catalog, and CISA’s Stakeholder Specific Vulnerability Categorization (SSVC) process. Lindsey and her team help to maintain, support, and advance the global vulnerability ecosystem by funding and overseeing the CVE and CVE Numbering Authority (CNA) programs, leading the production and dissemination of machine-readable vulnerability enrichment information, and engaging in valuable technical collaboration with the vulnerability research community.
Vulnrichment PlaygroundBenchmarking Your Constituency: A Practical Framework for CERTs with Results from Academic SectorBillions of Indicators, Zero Action: How We Fixed ThatCritical SaaS, Critical Blind Spots: A Detection Engineers Field Guide to SaaS AttacksThe Hidden Cost of CVEs: Can CSAF and VEX Change the Equation?The SOC Of The Future… The Future Is NowOne SOC, The Whole SOC, and Nothing But The SOC, So Help MeEiffel: A Tool to Oversee Incident Response From the HeightsProtecting Customers Through Smarter OSS ManagementOperationalizing AIBOMs: Extending Vulnerability Management to AI Models and DatasetsMalice in the Modules - How NPM Became a Supply-Chain Battleground?One Bad OSINT Can Ruin Everything: How Secure is Your CTI RAG System, and Can You Minimize the Risk?
FIRST |

Vulnrichment Playground

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER