Madness of Vulnerability Management in Modern Cloud, Container, How to Win the Battle...
CVE/FIRST VulnCon 2025 · Main Stage
Overview
The rapid adoption of cloud-native architectures, containers, and open-source components has profoundly transformed the landscape of vulnerability management, escalating its complexity to unprecedented levels. This talk, delivered by industry veterans Franchescoon "Franks" and James, delves into the "madness" of current vulnerability management practices, arguing that traditional, CVE-centric approaches are no longer effective. They contend that the sheer volume and dynamic nature of vulnerabilities in modern environments necessitate a radical shift towards a more intelligent, context-aware, and threat-centric strategy.

Key moments
- 0:00 Welcome, speaker intro, and agile presentation style.
- 3:00 Overarching goals: cloud's impact and prioritizing vulnerabilities.
- 4:20 How cloud complexity changed vulnerability management forever.
- 5:05 Shift-left scanning's unexpected complexity in modern environments.
- 6:50 Alarming statistics: 262K+ vulnerabilities and growing.
- 8:00 AI-generated code (vibe coding) to worsen vulnerability landscape.
Madness of Vulnerability Management in Modern Cloud, Container, How to Win the Battle...
Speakers: Franchescoon "Franks", Leader of Application and Cloud Security Programs (25+ years experience); James, Security Engineer at Lacatio (formerly at Reliquest and PagerDuty)
Conference: VulnCon
YouTube: https://www.youtube.com/watch?v=-LLAij7PZfY
Overview
The rapid adoption of cloud-native architectures, containers, and open-source components has profoundly transformed the landscape of vulnerability management, escalating its complexity to unprecedented levels. This talk, delivered by industry veterans Franchescoon "Franks" and James, delves into the "madness" of current vulnerability management practices, arguing that traditional, CVE-centric approaches are no longer effective. They contend that the sheer volume and dynamic nature of vulnerabilities in modern environments necessitate a radical shift towards a more intelligent, context-aware, and threat-centric strategy.
Franks, with over 25 years of experience leading application and cloud security programs, and James, a seasoned security engineer in cloud-native companies, bring a practitioner-to-practitioner perspective. They highlight the critical need to move beyond simply identifying vulnerabilities to understanding their true risk based on exploitability, reachability, and business context. The speakers aim to provide actionable insights for security professionals grappling with an ever-growing deluge of security findings, offering a roadmap to "win the battle" against the overwhelming tide of vulnerabilities.
This discussion is particularly pertinent for organizations struggling to maintain security posture amidst agile development cycles, extensive use of third-party libraries, and the emerging challenges posed by AI-generated code. The talk provides a compelling argument for a data-driven approach that prioritizes remediation efforts on the fraction of vulnerabilities that genuinely pose a threat, thereby enabling more efficient and impactful security operations.
Background
▶ Watch: Welcome, speaker intro, and agile presentation style. (0:00)
The journey of vulnerability management (VM) has undergone a dramatic transformation, particularly since 2015. In earlier days, VM was relatively straightforward, often involving network-based scanners checking system headers or using tools like Tenable to scan instances in vSphere or traditional data center environments. The scope was limited to base operating systems and known software versions, making remediation a more predictable process, often aligned with "Patch Tuesday" deployments.
However, the advent of cloud computing, containers, and widespread adoption of open-source software has fundamentally altered this landscape. The initial promise of "shift left" scanning, intended to fix vulnerabilities earlier in the development lifecycle, inadvertently exposed a "nightmarish complexity." No longer are security teams just concerned with the OS; they now contend with Software Composition Analysis (SCA), container vulnerabilities, and the intricate task of tracing these vulnerabilities as they move through deployment pipelines to production. Developers can now introduce a vast attack surface with just a few lines of code by importing open-source libraries like pydantic or OpenAI Agents SDK.
This explosion of vulnerabilities is not merely anecdotal; data from the NVD (National Vulnerability Database) shows a staggering 40x increase in vulnerabilities since 2015. The current count stands at over 262,000, with projections indicating a potential reach of one million vulnerabilities by 2031 if the current growth rate persists. This exponential growth vastly outpaces the modest 6% year-on-year increase in VM budgets and staffing. Compounding this challenge is the emergence of vibe coding, where Large Language Models (LLMs) generate code at an accelerating pace. While LLMs can be prompted for secure code, 90% of users do not, leading to an influx of potentially vulnerable code. Moreover, attackers are leveraging similar LLM capabilities to rapidly generate exploits, shrinking exploitation times for critical vulnerabilities from an average of 15 days to as little as 3 minutes, as seen with the JetBrains and Cloudflare incidents. This new reality demands a more sophisticated and agile approach to vulnerability management that can keep pace with both development and attack velocity.
Key Findings
▶ Watch: How cloud complexity changed vulnerability management forever. (4:20)
The core findings of the talk revolve around the fundamental disconnect between the current state of vulnerability management and the realities of modern cloud-native environments. The speakers assert that the traditional, volume-based approach to VM is broken, leading to alert fatigue for security teams and a lack of effective remediation by development teams.
Key findings include:
- Overwhelming Volume: The sheer number of vulnerabilities (262,000+ in NVD, a 40x increase since 2015) makes it impossible for security teams to address everything, especially with limited budgets and staff.
- Contextual Blindness: Traditional scanners often lack the necessary context about where vulnerabilities reside, whether they are actually exploitable, or if the affected component is even reachable in a production environment. This leads to generic "fix all by SLA" demands that developers ignore.
- Ineffective Asset Ownership: Identifying the true owner of an asset in dynamic cloud and container environments is incredibly difficult. Code changes hands, infrastructure is ephemeral, and legacy components often lack clear attribution, creating a significant barrier to remediation.
- Attacker Advantage: The rise of LLM-driven "vibe coding" for both development and exploitation has dramatically increased the speed and scale of attacks, with exploits emerging within minutes of vulnerability disclosure. Defenders are struggling to keep pace.
- The "Superstar Vulnerability" Cycle: Modern environments are plagued by a constant stream of high-profile vulnerabilities (e.g., TJ actions, Ingress Nightmare, Next.js auth bypass), each demanding immediate attention and diverting resources, making long-term strategic remediation difficult.
- The Solution Lies in Focus: The most critical finding is that organizations must shift from trying to fix all vulnerabilities to focusing on a fraction of issues that pose the highest real-world risk. This requires a threat-centric, data-driven approach that layers multiple dimensions of risk beyond basic CVSS scores.
Technical Deep Dive
▶ Watch: Shift-left scanning's unexpected complexity in modern environments. (5:05)
The "madness" of modern vulnerability management stems from several interconnected technical challenges. The shift from monolithic, on-premise architectures to highly distributed, ephemeral cloud-native environments has introduced layers of complexity that traditional VM tools and processes were never designed to handle.
One of the primary issues is the sheer volume and diversity of scan types. While shift-left scanning promised earlier detection, it uncovered a "nightmarish complexity." Security teams now deal with Software Composition Analysis (SCA) for open-source dependencies, container vulnerability scanning across base images and application layers, and static application security testing (SAST) and dynamic application security testing (DAST) for proprietary code. Each scanner often operates in isolation, producing its own set of findings, leading to a deluge of data that is difficult to normalize and prioritize.
The rapid adoption of open-source components, while accelerating development, has dramatically increased the attack surface. A single import statement for a Python library can introduce a "whole scope of vulnerabilities" that were previously hidden. This is exacerbated by vibe coding, where developers use LLMs to generate code, often without security-focused prompts. The speakers highlight that 90% of LLM-generated code is likely insecure, creating a continuous stream of new vulnerabilities. Attackers, too, leverage LLMs to generate sophisticated exploits rapidly, transforming vulnerability declaration into immediate exploitation opportunities, as demonstrated by ChatGPT's ability to create Remote Code Execution (RCE) payloads for newly disclosed flaws within minutes.
A significant conceptual hurdle is the traditional separation of application security and environment security (cloud/infrastructure security). While distinct in their focus, the talk emphasizes their deep correlation. A vulnerability in an application library can be exploited only if the underlying container and host environment are configured in a certain way and are reachable. A VM program that covers only one area is destined to fail. The problem is compounded by a lack of context. Scanners are often "blind to the context where things run," leading to security teams demanding developers "fix all of this stuff by SLA," a strategy universally ignored by development teams. This results in developer fatigue, executive shock over unaddressed vulnerabilities despite tool investments, and a constant cycle of "superstar vulnerabilities" (e.g., TJ Actions, Ingress Nightmare, Next.js Auth Bypass) that monopolize attention.
The core of effective remediation lies in asset ownership and attribution. In static data center environments, tracking assets with spreadsheets, while suboptimal, was feasible. In dynamic Kubernetes environments, with automatic orchestration, ephemeral containers, and multiple base OS and application OS layers, building a clear picture of asset ownership is "absolutely crushing." Different vulnerability scanners present data in frustratingly inconsistent ways (e.g., container process paths, unique names, inconsistent base image identification), making standardization a monumental task. Furthermore, the original committer of vulnerable code may no longer be with the company, and ownership lines blur as code moves through various teams (app team, front-end team, DevOps team) and tagging mechanisms change. The critical shift is from asking "how many problems do we have?" to "who owns what, how important is it, and is it reachable?"
Organizations often find themselves in an "endless building phase" trying to create custom solutions with Python scripts and spreadsheets, tasks better suited for dedicated business analysts or developers. Conversely, "buying" commercial platforms often leads to disappointment because "everyone's environment is a mess in a different way," and platforms lack the necessary customization. The real goal is not just discovery or prioritization, but genuine remediation and risk reduction.
To achieve this, the talk advocates focusing on a "fraction of vulnerabilities." This fraction is identified by layering multiple data points:
- Exploit Availability: Prioritizing vulnerabilities with verified exploits, leveraging resources like the CISA Known Exploited Vulnerabilities (KEV) catalog.
- EPSS (Exploit Prediction Scoring System): Reprioritizing based on the probability of exploitation.
- Criticality & Business Context: Assessing the impact of a vulnerability on critical business assets.
- Reachability Analysis: Determining if the vulnerability is accessible in the deployed environment.
Exploitability is defined beyond just the existence of a proof-of-concept. It considers whether the vulnerability is actively used by threat actors, easily automatable, has known attack vectors (e.g., RCE), and is supported by Cyber Threat Intelligence (CTI). The speakers emphasize that CVEs are not monolithic; their exploitability is highly contextual.
The concept of a "Pyramid of Priority" illustrates this layered approach: starting with raw vulnerability data (high volume), moving up to evidence of exploitation, then reachability (network, container, library), and finally the inherent threat type (vulnerability DNA). This funnel reduces the problem to a manageable few.
The speakers highlight the under-explored value of CWE (Common Weakness Enumeration) data. While CVEs describe specific instances, CWEs describe the underlying weakness. They argue that certain CWEs, particularly those leading to RCE, are inherently more attractive to attackers.
The "four horsemen" of effective vulnerability management in the cloud are introduced:
- Attribution: Clearly identifying who owns each asset.
- Lineage: Tracing how an asset transforms (e.g., code -> container image in registry -> running container on a node).
- Traceability: Understanding which application is built into which container and where it runs.
- Code-to-Cloud Reachability: The complete path from source code to runtime environment, assessing network and logical access.
Containers serve as the "hinge point" connecting application and environment security. A single container image can be scanned by multiple tools (SAST, SCA, container linter, CSPM) at different stages (code, registry, runtime), leading to redundant reports of the same underlying vulnerability. This necessitates contextual deduplication, a process that removes noise by tracing vulnerabilities back to the specific repository and library that needs fixing, ensuring remediation recommendations are precise.
The talk further elaborates on four methods of reachability analysis:
- Code Level: Is a vulnerable library actually loaded or executed within the application?
- Container Level: Is the vulnerable software loaded in a container that is actively running and potentially exposed?
- Network Level: Is the running container or host reachable from external networks or critical internal zones?
- CTI/Exploitation Evidence: Is there external intelligence indicating active exploitation of this specific vulnerability?
Beyond the traditional CVSS (Common Vulnerability Scoring System), which the speakers dismiss as "ancient Roman time" tools for modern risk assessment, they propose a four-dimensional risk model:
- CVSS Score: The inherent severity of the vulnerability.
- Business Context: The criticality of the application or asset where the vulnerability resides.
- Reachability Analysis: The combined assessment of code, container, and network reachability.
- Probability of Exploitation: Evidence of active exploitation, CTI, EPSS, and the inherent "DNA" of the vulnerability.
This leads to a shift from rigid Service Level Agreements (SLAs), which are "consistently getting breached," to a risk-based approach. Instead of dictating how to fix, security teams should set a "risk bar" for engineering teams, empowering them to decide the best remediation strategy (patching, library update, decommissioning). This treats engineers "like adults, not like toddlers" and fosters a more sustainable, collaborative security culture.
Finally, the talk introduces a deeper threat-centric approach by analyzing the "DNA" of exploitable vulnerabilities. By reclassifying NVD entries using LLM-based approaches to identify root cause and threat impact, patterns emerge. Trends show a reduction in vulnerabilities like cross-site scripting and denial of service, while Remote Code Execution (RCE) and memory corruption are consistently rising as preferred methods for zero-day exploits and ransomware attacks. Analysis of hundreds of ransomware-used vulnerabilities revealed that almost 40% shared these RCE/memory corruption characteristics. This intelligence allows security teams to predict which vulnerabilities are "more likely to be exploited, more likely to be triggered remotely," providing an additional flag for prioritization, especially when other threat intelligence is scarce.
Demo / Proof of Concept
▶ Watch: Alarming statistics: 262K+ vulnerabilities and growing. (6:50)
While the talk did not feature a live, interactive demonstration of specific tools or exploits, the speakers referenced their company's threat mapper and white papers detailing their methodology for classifying and visualizing threat intelligence and vulnerability DNA. They implied that such tools and methodologies are actively used to implement the contextual deduplication and four-dimensional risk assessment described. The discussion around LLM-based reclassification of NVD and the analysis of ransomware-used vulnerabilities serve as a conceptual proof-of-concept for their threat-centric approach, demonstrating how data can be leveraged to predict exploitation likelihood.
Defensive Implications
▶ Watch: AI-generated code (vibe coding) to worsen vulnerability landscape. (8:00)
The insights from this talk offer several critical defensive implications for organizations navigating the complexities of modern vulnerability management:
- Adopt a Threat-Centric Prioritization Model: Move beyond basic CVSS scores. Prioritize vulnerabilities based on their actual exploitability, reachability (network, code, container), business context, and the probability of exploitation (EPSS, CTI, vulnerability DNA). This allows security teams to focus efforts on the "fraction of vulnerabilities" that pose the highest real-world risk.
- Invest in Robust Asset Ownership and Traceability: Establish clear processes for attribution of assets in dynamic cloud environments. Implement lineage tracking from code to runtime and traceability of applications within containers. This is foundational for effective remediation, ensuring that issues can be assigned to the correct teams.
- Implement Contextual Deduplication: Combat scanner noise by deduplicating vulnerabilities across different stages of the software development lifecycle (code, registry, runtime). Solutions should trace vulnerabilities back to the specific, fixable component (e.g., a library in a particular repository), providing actionable recommendations rather than raw scanner outputs.
- Leverage CWE Data and Threat Intelligence: Utilize CWE (Common Weakness Enumeration) to understand the underlying weakness type, particularly focusing on high-impact categories like Remote Code Execution (RCE) and memory corruption, which are strongly correlated with active exploitation and ransomware. Integrate open-source and proprietary Cyber Threat Intelligence (CTI) to identify actively exploited vulnerabilities.
- Shift from SLAs to Risk Targets: Empower engineering teams by setting clear "risk bars" rather than rigid, often-missed SLAs. Allow teams the autonomy to choose the most effective remediation strategy (patching, library updates, decommissioning, mitigation) to meet the defined risk posture. This fosters ownership and better collaboration.
- Embrace "Shift Left" with Context: While scanning registries before deployment is ideal for preventing vulnerable images from reaching runtime, organizations must also be prepared to manage vulnerabilities that emerge or are discovered in already deployed, running environments. A holistic approach covers both pre-runtime blocking and post-deployment management, with context being key in both scenarios.
Key Takeaways
- Modern VM is Overwhelmed: The explosion of vulnerabilities (40x increase since 2015), cloud complexity, and "vibe coding" make traditional, volume-based vulnerability management unsustainable.
- Prioritize with Context: Effective prioritization moves beyond simple CVSS scores to a threat-centric, data-driven approach considering exploitability, reachability (network, code, container), and business context.
- Asset Ownership is Foundational: Clear attribution, lineage, and code-to-cloud traceability are critical for assigning vulnerabilities to the correct teams and enabling timely remediation.
- Deduplicate with Intelligence: Implement contextual deduplication to reduce scanner noise, tracing vulnerabilities back to their fixable source (e.g., specific library in a repo) rather than reporting the same issue multiple times across the SDLC.
- Redefine Risk Beyond CVSS: Adopt a four-dimensional risk model that combines CVSS, business context, reachability analysis, and probability of exploitation, using CWEs and CTI to predict exploitation likelihood, especially for RCE and memory corruption.
- Empower Engineers with Risk Targets: Shift from rigid, often-missed SLAs to setting clear "risk bars," allowing engineering teams the autonomy to determine the most effective remediation strategies to meet desired risk levels.
About the Speaker(s)
Franchescoon "Franks" is a seasoned security professional with over 25 years of experience in the industry. He has led numerous application security and cloud security programs, bringing a deep, practitioner-level understanding of the challenges organizations face in managing vulnerabilities in complex environments. Franks emphasizes the importance of data-driven decision-making, stating that "you can't argue with data."
James is a security engineer who has worked at various cloud-native companies, including Reliquest and PagerDuty, where he was involved in FedRAMP authorization initiatives within highly cloud-native architecture stacks. He has extensive hands-on experience in the "weeds" of cloud vulnerability management. James now works at Lacatio, a company focused on helping engineers find security tools to streamline their work. His background as a "DevOps person at heart" provides a unique perspective on the operational challenges of security.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A competent practitioner talk on cloud-native vulnerability management that accurately diagnoses real operational pain — scanner sprawl, ephemeral asset ownership, CVSS theater, developer fatigue — and proposes a coherent multi-dimensional prioritization framework. The speakers clearly live in this problem space daily, and the 'four horsemen' construct (attribution, lineage, traceability, code-to-cloud reachability) is a useful organizing frame. The problem is this is essentially a well-packaged articulation of ideas the industry has been converging on for 2-3 years: EPSS + KEV + reachability + business context is the consensus playbook, not a novel contribution. No original data beyond…
Heather Calloway (CISO) — SOLID
A practitioner-level talk that correctly diagnoses why volume-based vulnerability management is failing in cloud-native environments and offers a coherent prioritization framework built around exploitability, reachability, and business context. The content is technically sound and operationally grounded, and the 'four horsemen' framing — attribution, lineage, traceability, code-to-cloud reachability — is the clearest articulation of what modern VM actually requires. But the talk stops at the program level and never crosses into governance territory. There is no discussion of how to resource this differently, how to make the case to a board or CFO when risk is being actively accepted, or…