In this episode of The Secure Disclosure, host Mackenzie Jackson welcomes Chris Hughes, founder of Resilient Cyber, Cyber Innovation Fellow at CISA, and a leading voice in cybersecurity. They dive into the increasingly chaotic landscape of software supply chain security, the operational failures of the National Vulnerability Database (NVD), and how AI is fundamentally reshaping vulnerability management.

The Open-Source Predicament

The discussion begins with the precarious state of the open-source software supply chain, which powers nearly all modern codebases. Chris explains that these critical components are often maintained by unpaid volunteers, making them attractive targets for attackers seeking high return on investment. Traditional scanning tools are failing to keep up with the velocity and volume of new code and evolving attack methods.

"the tools that we've used historically just haven't kept pace with the velocity and volume of code production, the evolution of the attack path and methodologies that attackers use."

Solving this problem requires a multi-faceted approach, including financial incentives for maintainers, modernized tooling, and a shift in how organizations prioritize security for developers. Security is often seen as a "soul-withering chore" by developers, who are incentivized for speed and features, not security performance.

NVD's Collapse and AI's Double-Edged Sword

The conversation pivots to the National Vulnerability Database (NVD), which is the de facto source for CVEs used by most security tools and organizations. The NVD is struggling to keep pace, with a massive backlog of unenriched vulnerabilities and an inability to scale with the exponential increase in reported CVEs, largely driven by AI.

"It's this weird circular logic where the answer to all the problems of AI is AI."

Yet, the human element crucial for verifying and enriching these vulnerabilities simply cannot keep up with the sheer volume.

AI is not just exacerbating existing problems; it is also creating new ones by empowering adversaries. While AI can help defenders find vulnerabilities faster, it also provides attackers with an unprecedented advantage in discovering and exploiting zero-days.

"I do think the attackers are going to have the advantage for some time here because they can just find an exploit,"

The Future of Security

The episode concludes by exploring the future of bug bounties and the pervasive issue of legacy systems. Even with AI's potential to uncover all vulnerabilities, patching them across the vast landscape of existing software remains a significant challenge. The concept of 100% security is a myth; instead, organizations must focus on risk management.

The episode wraps up with a chaotic round of "Would You Rather," where Chris is forced to choose between equally dreadful cybersecurity scenarios, including missing firewalls, permanent vulnerability freezes, and total AI "vibe coding."