© Mapbox, © OpenStreetMap
Jessy Ayala

Jessy Ayala

PhD Student at UC Irvine

Irvine, California, United States

Actions

Jessy is a PhD student at UC Irvine studying problems where software engineering meets security. In particular, Jessy is interested in investigating and addressing software supply chain security concerns from various angles. In his free time, Jessy enjoys writing music and training jiu-jitsu, and has competed in events hosted by ADCC, IBJJF, and UFC.

Area of Expertise

  • Information & Communications Technology

Topics

  • Emerging Cybersecurity Topics
  • Artificial Intelligence and Machine Learning for Cybersecurity
  • Security
  • DevSecOps
  • Information Security

Poison Was the Cure: A Glimpse Into OSS Vulnerability Disclosure Practices

In open-source software (OSS), software vulnerabilities are at an all-time high. We conduct a study focusing on security advisories and bug bounty reports as perspectives for exploring OSS vulnerability disclosure practices. Findings reveal challenges in keeping pace with review rates, the absence of CVEs in the National Vulnerability Database, and subjective determination in filing CVE requests for vulnerabilities; thus, hindering the spread of alerts to affected projects. Furthermore, a majority of projects do not implement easy-to-configure software vulnerability management features. We offer actionable recommendations to enhance OSS project security, focusing on improving review rates, reinforcing CVE integration, and promoting robust vulnerability disclosure practices. Overall, we reveal gaps in the current OSS security landscape to provide valuable insights for practitioners, developers, and the broader OSS community.

MINT: A Fresh Take on Early Vulnerability Triage

Recently, OSS maintainers have received an influx of vulnerability reports that have become time-consuming to triage. Some reports look technically plausible, but lack clear evidence, exaggerate severity, omit reproduction steps, or reference files, functions, and project behavior that do not exist. As AI-assisted vulnerability reporting becomes more prevalent, this type of noise can consume scarce maintainer time and delay responses to legitimate security issues. This session presents MINT, a Maintainer-INformed Triage framework for helping OSS projects evaluate noisy vulnerability reports. Rather than replacing maintainer judgment or attempting deep vulnerability discovery, MINT supports early triage by checking report actionability and whether the report is grounded in the target repository. Attendees will learn how maintainer practices can inform security tooling and how repository-grounded triage summaries can help projects prioritize credible reports while reducing review burden.

Highlighting the Uniqueness and Prevalence of OSS AI/ML Vulnerabilities

This session explores the uniqueness and prevalence of vulnerabilities in open-source AI/ML projects, drawing on empirical data from bug bounty reports. We examine how AI/ML vulnerabilities differ from traditional OSS issues, why they are harder to fix, and how other gaps in disclosure pipelines (e.g., missing NVD entries) impact ecosystem security. The talk highlights key challenges, such as patching rates and taxonomy mismatches, and proposes research directions to improve vulnerability visibility, remediation, and tooling support. Attendees will gain overarching insights into emerging security risks of AI/ML OSS vulnerabilities and high-level actionable strategies to strengthen the ecosystem.

CNCF-Hosted Co-located Events North America 2026 Sessionize Event Upcoming

November 2026 Salt Lake City, Utah, United States

OpenSSF Community Day Korea 2025 Sessionize Event

November 2025 Seoul, South Korea

Jessy Ayala

PhD Student at UC Irvine

Irvine, California, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top