cd /news/ai-safety/first-unveils-vulnopticon-2026-to-ad… · home topics ai-safety article
[ARTICLE · art-103980] src=first.org ↗ pub= topic=ai-safety verified=true sentiment=· neutral

FIRST Unveils VulnOptiCON 2026 to Address the Future of Vulnerability, Threats and Cybersecurity Risk

The Forum of Incident Response and Security Teams (FIRST) announced VulnOptiCON 2026, a three-day technical colloquium scheduled for September 23-25, 2026, in Luxembourg, to address vulnerability tracking, exploitation predictability, and AI-related security risks. The event comes as CVE disclosures exceed a record-breaking 66,000 this year, according to FIRST. Keynote speakers include Jaya Baloo, COO & CISO at AISLE, and Regina Joseph, a behavioral scientist and forecasting expert.

read4 min views2 publishedAug 20, 2026
FIRST Unveils VulnOptiCON 2026 to Address the Future of Vulnerability, Threats and Cybersecurity Risk
Image: First (auto-discovered)

Global security practitioners convene to advance vulnerability tracking and exploitation predictability, and explore security risks of Artificial Intelligence (AI)

Luxembourg – AUGUST 20, 2026 - The Forum of Incident Response and Security Teams (FIRST), today announced VulnOptiCON 2026, a FIRST Technical Colloquium taking place on September 23-25, 2026, in Luxembourg. The event is an evolution of Vuln4Cast, expanding to cover broader vulnerability ecosystem topics and more fully serve European vulnerability data and management communities. The event arrives at a pivotal moment this year, as CVE disclosures exceed a record-breaking 66,000, making it critical that the industry understand how best to manage risk.

This year’s conference expands to a three-day format, uniting security practitioners, vulnerability researchers, academics, and data scientists to share practical tips for how to put vulnerability, configuration, or exploit data to work before a crisis hits. The theme will be “The A-Eyes See All.” Limited tickets are available now for EUR 404 and attendees are encouraged to register as soon as possible.

"In cybersecurity, our greatest enemy isn't the bug, it's the uncertainty about how many more are waiting. And right now, the vulnerabilities community is facing an unprecedented level of uncertainty and change due to the introduction of AI discovery and exploitation,” said Éireann Leverett, FIRST Liaison and Lead Member of FIRST’s Vulnerability Forecasting Team. “Our goal is to make this year’s VulnOptiCON as interactive as possible, so that as a community, we can inform and strengthen each other’s outcomes, adopt and adapt new ways of thinking, and uncover new opportunities.”

Agenda Highlights #

The conference brings together a unique cross-section of global cybersecurity leadership including representatives from government and international cybersecurity agencies, such as CISA, NCSC UK, and ENISA, regional CSIRTs including CIRCL, academic research institutions such as the University of Twente, pioneering security and AI startups, and end-user organisations. The conference programme will be keynoted by:

  • A world-renowned cybersecurity leader ranked among the top 100 CISOs. Jaya is COO & CISO at AISLE, the former CISO of Rapid7 and Avast, and a former WEF Expert in Quantum and Cybersecurity. Her keynote presentation will address how artificial intelligence is fundamentally reshaping how vulnerabilities are discovered, exploited, and remediated, detailing actionable strategies for defenders to enhance their posture.Jaya Baloo- A leading behavioral scientist and applied forecasting expert. Regina will share field-tested strategies on building high-performing, high-pressure forecasting units capable of predicting threat behavior before crises occur.Regina Joseph

Featured sessions include:

Global & Open Ecosystems:* GCVE: Rebooting Vulnerability Tracking for an Open Security Ecosystem*– FeaturingAlexandre DulaunoyandCedric Bonhomme(CIRCL).Forecasting & Metrics:* Measuring and Forecasting Exploitation Conditions*– FeaturingRuben Bos(Volerian).Policy & Program Futures:* You, Me, and CVE: What Does the Future Hold for the CVE Program?– Featuring an international panel of policy leaders, includingLindsey Cerkovnik(CISA),Nuno Rodrigues Carvalho(ENISA),Jeroen van der Ham-de-Vos(University of Twente), andJen Ellis(NextJenSecurity).Data & Observable Evidence: The CVE Panopticon: What Happens When The Prisoners Set The Standards?– FeaturingJerry Gamblin(Empirical Security)Next-Gen Threat Detection: Detecting What Cannot Be Named*– FeaturingNatalie Kilber(Haste).

Complete program details and registration for VulnOptiCON 2026 are available at https://vulnopticon.org/.

“Shifting from reactive patching to informed forecasting takes more than data for today’s researchers and specialists. It requires practitioners willing to pressure-test new methods and compare notes to strengthen each other’s outcomes, said Chris Gibson, CEO of FIRST. “VulnOptiCON 2026 is invested in providing a space that examines real-world threats to forecasting and data management, including how AI is changing not just what vulnerabilities look like but also how security teams find, verify, and act on them.”

The VulnOptiCON event follows the Vuln4Cast tradition of highlighting a different European city each year. The 2026 event will be held in Luxembourg, in partnership with the Computer Incident Response Centre Luxembourg (CIRCL), who are sponsoring the venue, technical support, and catering for the event. Special thanks to them and the event’s Platinum sponsor, Brinqa, Gold sponsor, ENISA, and Bronze sponsor, Vulners for making the event possible.

FIRST invites the community to join the conversation leading up to and during the conference by following and using #VulnOptiCON for the latest speaker announcements and program updates.

Also available in PDF Issued on behalf of FIRST. For further information, please contact FIRST Press.

About FIRST

FIRST aspires to bring together incident response and security teams from every country across the world to ensure a safe internet for all. Founded in 1990, the Forum of Incident Response and Security Teams (FIRST) consists of internet emergency response teams from more than 868 member teams, 211 individual members, and 5 associates spanning corporations, government bodies, universities and other institutions across 117 countries in the Americas, Asia, Europe, Africa, and Oceania. For more information and to see the full calendar of events, visit: FIRST.Org.

Connect with FIRST on social media via BlueSky, GitHub, LinkedIn, Mastodon, Meta, X and YouTube.

Thu, 20 Aug 2026 04:00:00 +0000

── more in #ai-safety 4 stories · sorted by recency
── more on @first 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/first-unveils-vulnop…] indexed:0 read:4min 2026-08-20 ·