March 1, 2023, 2:10 a.m. | Jay Jacobs, Sasha Romanosky, Octavian Suciuo, Benjamin Edwards, Armin Sarabi

cs.CR updates on arXiv.org arxiv.org

The number of disclosed vulnerabilities has been steadily increasing over the
years. At the same time, organizations face significant challenges patching
their systems, leading to a need to prioritize vulnerability remediation in
order to reduce the risk of attacks. Unfortunately, existing vulnerability
scoring systems are either vendor-specific, proprietary, or are only
commercially available. Moreover, these and other prioritization strategies
based on vulnerability severity are poor predictors of actual vulnerability
exploitation because they do not incorporate new information that might impact …

attacks challenges community data data-driven exploit insights order organizations patching poor predictions prioritization remediation risk severity systems vendor vulnerabilities vulnerability vulnerability prioritization vulnerability remediation

Offensive Security Engineering Technical Lead, Device Security

@ Google | Amsterdam, Netherlands

Senior Security Engineering Program Manager

@ Microsoft | Redmond, Washington, United States

Information System Security Analyst

@ Resource Management Concepts, Inc. | Dahlgren, Virginia, United States

Critical Facility Security Officer - Evening Shift

@ Allied Universal | Charlotte, NC, United States

Information System Security Officer, Junior

@ Resource Management Concepts, Inc. | Patuxent River, Maryland, United States

Security Engineer

@ JPMorgan Chase & Co. | Plano, TX, United States