On-Demand Webinar
In the Wild with VulnCheck
June Topic: BOD 26-04, Decoded: What It Means for Federal Agencies and Everyone Else
CISA's BOD 26-04 sets accelerated remediation timelines for federal agencies — but the framework applies to any security team trying to cut through vulnerability noise.
In the Wild with VulnCheck is a monthly, research-driven webinar focused on how vulnerabilities, exploits, and attacker tradecraft are actually showing up in real environments, hosted by Kimber Duke, Principal Product Manager, and Patrick Garrity, Security Researcher, from VulnCheck.
In the Wild with VulnCheck is a monthly, research-driven webinar focused on how vulnerabilities, exploits, and attacker tradecraft are actually showing up in real environments, hosted by Kimber Duke, Principal Product Manager, and Patrick Garrity, Security Researcher, from VulnCheck.
In this month's session, we discussed what the directive requires, where the gaps are, and how exploitation intelligence helps teams on both sides of the equation.
We also covered:
We also covered:
- What BOD 26-04 requires and how SSVC-based prioritization works in practice
- Where CISA's Vulnrichment leaves gaps and how to fill them
- How VulnCheck KEV surfaces exploitation evidence days, months, or years ahead of CISA KEV
- Why this framework matters for private sector security teams, not just federal agencies
Past Topics:
January 28th: Tales from the Exploit Mines
February 25th: Inside the Exploitation Files
March 25th: Expectations vs Reality
April 29th: CISA, NIST, and Mythos — oh my
May 27th: Fuzzers to Frameworks: Hot takes on the new AI-Powered Vulnerability Discovery Stack
June 24th: BOD 26-04, Decoded: What It Means for Federal Agencies and Everyone Else
Future Dates:
July 29th: TBD
August 26th: TBD


