This presentation was held at #BSidesBUD2026 IT security conference on 29 April 2026. Short description of the talk: Most published CVEs never become meaningful risks—but the security industry still treats every new disclosure as a fire to put out. This talk explores what makes a vulnerability truly exploitable by examining the economics of offensive research, the limitations of CVSS, EPSS and other scoring systems, and the real-world conditions required for exploitation. Attendees will learn how attackers prioritize n-days, how AI accelerates exploit development, and why exploitability depends far more on environment and business value than on scores alone. About the speaker: Eryx is an enthusiast in Cybersecurity and OpenSource. Currently working as Staff Security Engineer at Lyft he leads the vulnerability management program, handling the strategy to identify and fix code, infrastructure and endpoint vulnerabilities at scale. His career includes roles in backend/frontend development, consulting, software architecture, and management. He loves sharing knowledge in the academy and at community events, locally or globally. His academic background includes a BSc from Instituto Politecnico Nacional (Mexico) and an MSc from the University of Southampton (UK). During his free time he enjoys doing a good BBQ, drinking craft beers or organizing tech events. https://bsidesbud.com All rights reserved. #bsidesbud2026 #iot #malware