VEX - Cutting through the Noise in Software Supply Chain Security
UA2.114 (Baudoux) | Day 1 | 17:30 - 17:45 | Speakers: Rao Lakkakula, Georg Kunz
Abstract
Security teams are currently drowning in vulnerability data, but the Vulnerability Exploitability eXchange (VEX) offers a solution by providing machine-readable clarity on which exploits actually matter. This technology is rapidly evolving from a "nice-to-have" efficiency tool into a critical compliance enabler for the EU Cyber Resilience Act (CRA), which mandates effective vulnerability handling for the European market.
In this session, Georg and Rao present the findings from the VEX Industry Collaboration Working Group, a group of industry leaders driving the development and application of VEX. The group identified a set of challenges and gaps hampering adoption, ranging from the different evolving technical directions in VEX formats to practical barriers such as discovery and distribution of VEX documents, immature tooling, and education. Rao and Georg will outline a shared path forward, advocating for the creation of a common distribution system, development of necessary tooling, and establishing a forum for collaboration between industry partners and open source projects to drive adoption and education.
Speakers
Rao Lakkakula is the Director at Microsoft leading Open Source Strategy & Ecosystems group. With over 25 years of expertise in security and software development, Rao has held various roles in Engineering, Security, Open Source and Risk management. His previous experience includes leadership positions at world largest companies such as JPMorgan Chase, Climate Corp, Amazon, and also several startups. Rao currently serves on the Linux Foundation Research Advisory Board and previously served as Founding Board Member of the Open-Source Security Foundation (OpenSSF) from 2020 to 2024.
Georg is a Director of Open Source Software in Ericsson's Open Source Program Office. He currently serves on the Technical Advisory Council of the OpenSSF, co-chairs the OpenSSF Best Practices WG, and is a member of the Steering Committee of the TODO Group. At Ericsson, Georg is responsible for open source engagement strategy and contribution policies.
Links
External Links
Notice: The placeholder video image is licensed under CC BY-SA 4.0. The original image can be found hereChanges made to the image are: Cropped the image to a new ratio, part of the image was cut off.
