2026
About
University of Twente
My work sits at the intersection of cybersecurity and artificial intelligence, with a focus on vulnerability prioritization, threat knowledge representation, and automated reasoning over CVEs, CWEs, and MITRE ATT&CK.
I am especially interested in practical research that helps defenders understand which weaknesses matter most in realistic attack paths and how AI can support that process.
CTO One-Pager
Research overview
CTO One-Pager
A brief overview of the CTO is available as a PDF.
Curriculum Vitae
Updated academic CV
Stefano Simonetto CV
The latest CV is available as a PDF and reflects the current publication list, including the two recently added papers shown below.
Selected Publications
Papers and research outputs
A selection of recent work. For the most complete list, use the Google Scholar search above or visit the University of Twente research profile.
2026
Knowing your weaknesses is your greatest strength: Mapping CVE to CWE by leveraging CWE hierarchy and LLMs
2026
Making the most of fragmented supervision for sentence-to-TTP mapping
2025
ThreatCompass: A tool for identifying and mapping security issues to TTPs
2025
Beyond CVEs: Mapping weaknesses in unstructured threat intelligence text
2025
What matters most in vulnerabilities? Key term extraction for CVE-to-CWE mapping with LLMs
2024
Text2Weak: mapping CVEs to CWEs using description embeddings analysis
2024
Comprehensive threat analysis and systematic mapping of CVEs to MITRE framework
2023
Strengthening cloud applications: A deep dive into kill chain identification, scoring, and automatic penetration testing
2023
Are we reasoning about cloud application vulnerabilities in the right way?
Supervision
Student support and mentoring
I have supervised 11 Bachelor's students and supervised or co-supervised 3 Master's students on topics spanning vulnerability analysis, attack techniques, IoT security, automated pentesting, and anomaly detection.
Bachelor's Supervision
- Bridging the Gap: From CWEs to TTPs in Cybersecurity Attack Kill Chains
- Software Updates in Internet of Things Devices: Monolithic vs. Containerized
- Docker: Advantages and Security Implications of a Python Client-Linux Application
- Technical and Security Challenges of Cloud-Based Storage Management for IoT Devices
- Tracking the Evolution: Uncovering Concept Drift in Vulnerability Descriptions Over Time
- From Descriptions to Decisions: Classifying Vulnerabilities by Information Sufficiency
Master's Supervision
- IoC to TTP and identifying malware attack techniques in cyber threat intelligence
- Multiagent-Vuln-Assist: multi-agent support for automated pentesting in Dockerized applications
- Anomaly detection in API calls to web services using deep learning
Teaching
Courses and academic contributions
My teaching combines lecture design, delivery, and hands-on lab support across software security, distributed systems, IoT, embedded ML, and pervasive computing.
Software Security
Contributed to the design and delivery of class material on insecure configurations and secure coding practices.
Distributed Systems
Supported lectures and lab sessions on distributed systems principles, architectures, and system design fundamentals.
Internet of Things
Designed and delivered lectures on IoT security, communication protocols, and edge-to-cloud design, and developed teaching material from scratch for the first course edition.
Embedded Machine Learning
Delivered lab sessions and practical guidance on deploying machine learning models on constrained devices.
Pervasive Computing
Designed and delivered a lecture on security in pervasive computing, covering threats and protections across the ISO/OSI layers.
Contact
Get in touch
Email: s.simonetto@utwente.nl