SecurityBrief Ireland - Technology news for CISOs & cybersecurity decision-makers
Ireland
FIRST launches VulnOptiCON 2026 in Luxembourg on AI

FIRST launches VulnOptiCON 2026 in Luxembourg on AI

Mon, 24th Aug 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

FIRST has launched VulnOptiCON 2026 in Luxembourg, rebranding and expanding its Vuln4Cast gathering into a three-day conference.

The event will focus on vulnerability tracking, exploit forecasting and the role of artificial intelligence in both cyber defence and attack activity. The programme is aimed at security practitioners, researchers, academics and data scientists working across vulnerability data and management.

The launch comes as Common Vulnerabilities and Exposures disclosures have passed 66,000 this year, increasing pressure on security teams to assess which flaws are most likely to be exploited and how to prioritise their response.

Hosted in partnership with CIRCL, Luxembourg's national computer security incident response team, the conference will bring together speakers from public agencies, research groups and private sector organisations. The programme includes representatives from CISA, NCSC UK, ENISA, NVIDIA and CIRCL.

The event is built around the theme "The A-Eyes See All", reflecting a programme that explores how AI is affecting vulnerability discovery, exploitation and remediation, as well as how security teams are using forecasting methods to anticipate threats.

FIRST has positioned the conference as a broader forum than Vuln4Cast, which focused on vulnerability forecasting. The expanded format adds sessions on open vulnerability ecosystems, policy questions around the CVE programme, observable evidence in vulnerability data and newer approaches to threat detection.

Keynote speakers include Jaya Baloo, Chief Operating Officer and Chief Information Security Officer at AISLE, and Regina Joseph, behavioural scientist and applied forecasting researcher. Baloo is scheduled to address the effect of AI on how vulnerabilities are found and exploited, while Joseph will speak on building forecasting teams that can predict threat behaviour under pressure.

Other sessions include a discussion on rebooting vulnerability tracking for an open security ecosystem, featuring Alexandre Dulaunoy and Cedric Bonhomme of CIRCL, and a session on measuring and forecasting exploitation conditions featuring Ruben Bos of Volerian.

A separate panel on the future of the CVE programme will include Lindsey Cerkovnik of CISA, Nuno Rodrigues Carvalho of ENISA, Jeroen van der Ham-de-Vos of the University of Twente and Jen Ellis of NextJenSecurity. Another session, led by Jerry Gamblin of Empirical Security, will examine standards and governance in vulnerability data.

The gathering also reflects a wider debate in the cybersecurity industry over whether existing systems for cataloguing and scoring vulnerabilities are keeping pace with the volume of disclosures and attackers' changing methods. Security teams increasingly rely on prioritisation models rather than patching every disclosed flaw immediately, pushing forecasting and exploit prediction further into the mainstream.

Luxembourg is the latest European host city for the event series. CIRCL is supporting the venue, technical operations and catering, while Brinqa, ENISA and Vulners are among the sponsors.

FIRST describes itself as a global association of incident response and security teams, with more than 868 member teams, 211 individual members and five associates across 117 countries spanning companies, government bodies, universities and other institutions.

Éireann Leverett, FIRST Liaison and Lead Member of FIRST's Vulnerability Forecasting Team, said the event is intended to help security teams respond to a changing threat landscape shaped by AI and rising uncertainty in vulnerability research.

"In cybersecurity, our greatest enemy isn't the bug, it's the uncertainty about how many more are waiting. And right now, the vulnerabilities community is facing an unprecedented level of uncertainty and change due to the introduction of AI discovery and exploitation," Leverett said.

He added: "Our goal is to make this year's VulnOptiCON as interactive as possible, so that as a community, we can inform and strengthen each other's outcomes, adopt and adapt new ways of thinking, and uncover new opportunities."

Chris Gibson, Chief Executive Officer of FIRST, said the event would examine the practical shift from patching to prediction.

"Shifting from reactive patching to informed forecasting takes more than data for today's researchers and specialists. It requires practitioners willing to pressure-test new methods and compare notes to strengthen each other's outcomes," Gibson said.

He added: "VulnOptiCON 2026 is invested in providing a space that examines real-world threats to forecasting and data management, including how AI is changing not just what vulnerabilities look like but also how security teams find, verify, and act on them."