UTC -8 America/Los_Angeles

Vulnerability Haruspicy: Picking Out Risk Signals from Scoring System Entrails

07

Thursday

Aug 07, 2025

2:00 PM - 2:30 PM

3950 S Las Vegas Blvd, Las Vegas, NV 89119 ( Islander E & I, Level 0 - North Convention Center )

This talk will dig into the strengths, weaknesses, and absurdities of CVSS, EPSS, and SSVC, comparing them to the reality of how security teams actually handle vulnerabilities. This talk will explore where these models help, where they mislead, and whether any of them are meaningfully better than rolling a D20 saving throw vs exploitation. Expect debate, disagreements, and plenty of astrology jokes.