Open Source Conference Luxembourg

Cédric Bonhomme

Cédric Bonhomme is a computer scientist with a strong focus on cybersecurity, privacy, and open-source software. From 2010 to 2017, he worked as an R&D Engineer specializing in Multi-Agent Systems and cybersecurity. Since 2017, he has been part of CIRCL (Computer Incident Response Center Luxembourg), contributing to CSIRT operations and developing open-source security tools and infrastructure.

He is the lead developer of Vulnerability-Lookup, an open-source platform for vulnerability intelligence, and works on vulnerability data, security automation, and AI/ML applied to cybersecurity. His work also includes GCVE, open vulnerability identifiers, and VulnTrain, a collection of open datasets and models for vulnerability analysis.


Session

10-07
16:30
30min
Digital Sovereignty Starts with Vulnerability Data
Cédric Bonhomme

Digital sovereignty is often discussed in terms of cloud infrastructure, data hosting, or dependence on large technology providers. But there is a more uncomfortable question when it comes to cybersecurity: who owns vulnerability data?

Who controls the infrastructure, identifiers, databases, enrichment, and models that we rely on to understand vulnerabilities? Organizations such as MITRE, CISA and CVE Program provide critical public infrastructure for the cybersecurity ecosystem, but how much of our vulnerability intelligence ultimately depends on external organizations and services?

Vulnerability information is a fundamental building block of cybersecurity, yet organizations increasingly depend on external platforms, proprietary databases, closed scoring systems, and AI services to collect, enrich, and interpret it.

This talk explores what digital sovereignty can mean for vulnerability intelligence. Using the open-source Vulnerability-Lookup ecosystem as a case study, we will look at open vulnerability data, GCVE, decentralized sources, and open AI models and datasets developed with VulnTrain. The goal is to examine what it takes to build a security intelligence stack that can be independently operated, understood, reproduced, and extended.

The central question is simple: can we build vulnerability intelligence that we can actually own?

Topic: CyberSecurity
CyberSecurity