Seven days of passive listening at BSides, Black Hat and DEF CON: 673 open networks, one beacon flooder, and what it takes to count devices honestly. I have wanted to build one of these for a long time. A little screen on my bag that tells me what the air around me is actually made ... Read more
My schedule, a new role at Empirical Security, and the CVE and vulnerability talks worth your time. It is almost the first week of August, which means it is time to point myself at the desert one more time. BSides Las Vegas, Black Hat, and DEF CON all land back to back, and for me ... Read more
We are halfway through 2026, so it is time for the mid-year CVE check-in. The short version: the volume curve has gone vertical while exploitation has not. This review covers everything published in the first half of 2026 (Jan 1 Jun 30, 2026), the volume, the severity, what is actually being exploited, and who ... Read more
I play golf. I am not good at golf. But I have a Garmin Approach R10 launch monitor, a Python interpreter, and too much free time, so naturally I spent way more time building a dashboard to analyze my swing data than I did actually swinging a club. The result is jgamblin/golf, a self-hosted analytics ... Read more
I spend a significant amount of my time thinking about EPSS, CVSS, and the inherent gaps in how we prioritize vulnerabilities. We all know the drill: a 9.8 CRITICAL that remains unexploited shouldn t jump the line ahead of a 7.5 HIGH that is being actively used in the wild. Closing that gap between theoretical severity ... Read more
2025 set a new baseline with 48,185 published CVEs. While the sheer volume is climbing, the median CVSS score remained surprisingly stable. We are seeing a distinct shift toward web application flaws (specifically in the CMS ecosystem) and a wider distribution of vendors, proving that vulnerabilities are spreading deeper into the supply chain. This massive growth ... Read more
I m incredibly excited to finally share something I ve been pouring my heart into at RogoLabs. For those of you who caught my talk at BSidesLV, you got a sneak peek, but today it s official: CNAScorecard.org is live! For years, the CVE program has been our shared language for identifying vulnerabilities. But lately, we ve all felt ... Read more
It s that time of year again! The first week of August means my annual trip to the desert for Security Summer Camp —the whirlwind of BSides Las Vegas, Black Hat, and DEF CON. It s always an exhausting but amazing week, and I can t wait to dive in, catch up with everyone, and talk about what I ve ... Read more
2024 brought unprecedented growth in CVE data, so I figured it would be appropriate to start the new year by exploring these statistics and highlighting some of the more intriguing data points. CVEs By The Numbers We ended 2024 with 40,009 published CVEs, up over 38% from the 28,818 CVEs published in 2023. CVEs By Month Month ... Read more
The Common Vulnerabilities and Exposures (CVE) program, launched in late October 1999, has not only marked its presence but has become a pivotal force in shaping how we perceive and manage cybersecurity threats. A Journey Through Time The CVE program emerged as a beacon, standardizing how vulnerabilities are identified, shared, and mitigated. From its inception ... Read more