2026 Event
1:30 pm - 2:10 pm, Wednesday, October 14
Known Vulnerability, Unknown to Your Scanner: How Matching Failures Get Exploited
About

Vulnerability scanners cannot reliably agree on which software is vulnerable. When CPE strings are malformed, PURL identifiers inconsistently populated, or version normalization diverges across tools, the same exploitable library gets flagged by one scanner and silently passed by another. Fragmentation across NVD, CVE.org, OSV, and EUVD compounds the problem. This talk reframes scanner disagreement as an exploitable property, presents empirical false negative rates across ecosystems and scanners, and releases faultline, an open-source tool surfacing per-package confidence scores from inter-scanner agreement.

 

Get in touch
Get in touch
Customer Service
For any and all inquiries please click the button below
Speaking Opportunities

Interested in speaking at the event?

InfoSec World
Stay
Informed
Join our mailing list for the latest news on InfoSec World 2026.