Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Jerry Gamblin

@jgamblin@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

80 Followers
10 Following
49 Posts
Joined November 06, 2022
Website:
https://jerrygamblin.com
RogoLabs:
https://rogolabs.net
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 1w ago

If you sized your vulnerability management program on 2025's count, you're already a year behind.

September closed at 14,943 published CVEs. That's up 245.8% on September 2025, and it puts 2026 at 72,812 for the year so far, 105.9% ahead of the same nine months last year. Call it 267 a day.

Worth being precise about where that came from. The five busiest CNAs published 7,063 of the month's CVEs, 47.3%, and September 8 alone carried 1,559, with 965 of them from Microsoft. A lot of this is who is publishing, not what is breaking.

Median CVSS v3.x was 7.3 and the 75th percentile 8.1, across the 12,231 of 14,943 CVEs that have a v3.x score. Another 1,266 only have a v4.0 score and 1,446 have none.

Top weaknesses:
XSS (CWE-79): 1,119
Missing Authorization (CWE-862): 797
Improper Access Control (CWE-284): 610
SQL Injection (CWE-89): 494
Use After Free (CWE-416): 469

Last year's total is not a planning number anymore.

Source: NVD, excluding rejected CVEs
#CVE #VulnerabilityManagement #InfoSec

infosec.exchange
1
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 1mo ago

Last year's record is no longer a ceiling; at August's rate it is a midpoint.

August 2026 closed at 12,291 published CVEs against 3,628 in August 2025, +238.8%. Some of that is who is publishing rather than what is breaking: the five busiest assigners supplied 5,842 of the month, 47.5%, and a single scheduled Oracle release carried 889 CVEs on August 18. Strip that batch out, and August is still up 214.3% from last year.

That puts 2026 at 57,908 CVEs year-to-date, +86.5% year-over-year, running at 396 per day in August against 238 per day for the year so far. 2026 has already published more CVEs than all of 2025 (48,154) and is 9,754 ahead with four months left to count. Last month's post projected that crossing for August 13. It landed on August 10.

What number are you putting in the 2027 plan, and which year did you get it from?

Source: NVD, excluding rejected CVEs

3
0
2
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 1mo ago

"Do we have detection for this CVE?" is normally the first question after a CVE lands on CISA's KEV list. Six times in ten, nothing public can even tell you.

I checked the 554 KEV CVEs published in the last three years against Emerging Threats Open, SigmaHQ, and Elastic detection rules, counting a hit if a rule file cites the CVE ID. 329 have none. None of Apple's 31. None of Google's 24, every one of those a Chromium bug. Microsoft: 20 of 95.

The split tracks how a bug is reached, not how well it is defended. Network-reachable bugs get network signatures, and a signature carries the CVE number: Apache 9 for 9, then SolarWinds, Ivanti, and Fortinet all above 70%. Endpoint rules match attacker techniques instead, so a browser or kernel bug almost never carries its CVE, even when the EDR catches the attack.

The CVE is the identifier the due date arrives in, the identifier the auditor asks for, and the identifier your dashboard tracks. For 60% of these CVEs, there are no detection rules to track against.

3
0
2
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 4w ago

KEV used to be a patch list. Now, for most of what CISA adds, it is an IR list: was this box already owned?

48 of the 73 entries CISA has added to the KEV list since July 1 carry its forensic-triage flag. The 1,630 entries added before that date do not.

When I wrote about BOD 26-04 in June, the three-day clock was the argument. The catalog says the clock was the smaller half. The directive, issued June 10, replaced the flat KEV deadline with a risk table, and its top tier is three days plus what CISA calls "& forensic triage". The directive defines that: "carry out a forensic triage of the asset to assess whether the system is compromised." CISA cited the requirement in June entries, the per-entry flag starts July 1, and CISA publishes which entries carry it.

Your process is at least built for the patch half. The other half is a person opening up the box, preserving evidence, and deciding whether to call it an incident. Two thirds of new KEV entries now need somebody who can make that call inside three days.

BOD 26-04 binds federal agencies. You're outside it, and the flag is CISA's worst-case exposure call, which agencies settle asset by asset. It fires on internet-reachable, automatable, total-impact exploitation, and that's the profile where patching on day three still leaves day one unaccounted for.

If a flagged KEV entry landed on you this afternoon, who makes the was-it-already-compromised call: the patch owner, or IR?

1
0
3
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 1mo ago
NVD's April policy did not remove the enrichment work. It moved it. This chart is how you find out how much of it moved to you. The rule, published April 15: NVD enriches CVEs on CISA's KEV list, CVEs in software the federal government uses, and critical software under Executive Order 14028. Everything else is marked "not scheduled for immediate enrichment," which arrives in the API as Deferred and means no CPE. The CNA's own score usually still shows. The record does not look empty. Of the 51,219 CVEs published in 2026 that NVD has settled, 20,076 are Deferred. That is 39%. The useful part is that it is predictable. The rule is written about products. The result sorts by publisher. Patchstack, Wordfence and WPScan: 99% of their records Deferred. VulDB 70%, VulnCheck 52%, MITRE 47%, GitHub 27%. Microsoft, Chrome, Apple, Adobe and Mozilla: 0.0%. Take the three WordPress CNAs out and 12,608 Deferred CVEs remain. Severity does not change the answer: by the CNA's own score, Critical is Deferred at 46% and Low at 42%. So find the CNAs that publish most of your CVEs and read your own number off the chart. If you live on WordPress plugins or open-source packages, most of your CPE matching is now yours to do, and that is a staffing question before it is a tooling one. Run a Microsoft and Chrome estate and almost nothing changed. The KEV half of the rule is holding either way: 140 of the 141 KEV-listed CVEs from 2026 are enriched and none is Deferred. When NVD says Deferred, where does your CPE come from? #vulnerabilitymanagement #cybersecurity #CVE #NVD
1
0
1
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 2mo ago
CVSS is a severity label the industry treats like a priority list. A 9.8 tells you how bad a bug could be. It cannot tell you which 9.8 to do first. This year 4,719 CVEs carry a CVSS v3 score of 9.0 or higher. Half of them, 2,493, land on the identical 9.8, the arithmetic result of a remote, unauthenticated, full-impact vector. Nine distinct scores exist in the entire critical band. There is no 9.5 and no 9.7. That is the resolution you are triaging with. Rank the same 4,719 by EPSS percentile and the median lands at the 37th, so half the drop-everything tier ranks below 63% of all CVEs. Cut at the 90th percentile and 211 CVEs hold 49 of the 54 now on CISA's KEV list. One caveat: EPSS reads exploitation signal, and all 54 were listed before these scores were computed, so that is two sources agreeing, not a prediction. It still gives you an order. 9.8 does not. 2,493 CVEs this year share one score. If your tooling had to put them in a fix order tomorrow morning, what field would it sort on, and who would argue with you about it? #vulnerabilitymanagement #cybersecurity #CVE
4
2
4
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 1mo ago

@cR0w@infosec.exchange @nyanbinary@infosec.exchange Maybe not exactly what you asked for but I recently did this: https://www.linkedin.com/feed/update/urn:li:activity:7496228791048949761/

linkedin.com
1
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 2mo ago
Off to Vegas for Summer Camp. New role at Empirical Security (Head of Research, working on EPSS), a CVE panel at BSidesLV, a Black Hat luncheon on autonomous exploitation, and a curated list of the 18 CVE and vulnerability talks I would clear my calendar for across BSidesLV, Black Hat, and DEF CON. The data behind it: H1 2026 gave us 34,601 CVEs, but only 0.24% are in CISA KEV. That gap is the whole game. Full rundown: https://jerrygamblin.com/2026/07/22/hydrate-hack-repeat-security-summer-camp-2026/
jerrygamblin.com
3
0
2
1
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 2mo ago
The bugs that get exploited are not the bugs you see most. I mapped every CVE on CISA's Known Exploited Vulnerabilities list back to its weakness class. Two things stood out. First, a data-quality one. The organization that reports a bug fills in the weakness class only about a third of the time. On the exploited list, roughly two-thirds of the CNA-authored records leave the CWE blank, and it only reaches about 90% coverage because NVD and CISA's enrichment program (ADP) go back and add it. Pull the class from the CNA feed alone and it is nearly empty. Pull it from NVD or CISA and it is nearly complete. Same bugs, very different picture depending on who you ask. Now the finding. Using the enriched data, exploitation concentrates in two families. Memory corruption: out-of-bounds writes, use-after-free, buffer errors, type confusion. And code execution: OS command injection, code injection, deserialization. Add improper input validation and broken authentication, and you have most of the list. Notice what is missing. Cross-site scripting is the single most common weakness on the internet, tens of thousands of CVEs, and it barely registers here. CSRF does not make the top 12 at all. The classes that flood your feed by volume are not the ones attackers reach for. So "most common" and "most exploited" are nearly different lists, and the CWE data is only as complete as the source you pull it from. Ranking a backlog by volume, or by raw CVSS, points you at the wrong shelf. Which of these classes is your program actually resourced to find? #vulnerabilitymanagement #cybersecurity #CVE
3
0
1
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 1mo ago

CVSS fails the first test of a measurement: two people scoring the same bug should get roughly the same answer.

5,564 CVEs published in 2026 carry two official CVSS scores, the CNA's and NVD's (the roughly 12% of 2026's v3-scored CVEs NVD has re-scored so far). 55% land in different severity bands; they match exactly just 10.8% of the time. 1,043 are Critical to exactly one of their two scorers.

Which feed does your queue key on, and did anyone pick it on purpose? I'd bet most of us inherited the default.

1
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 7mo ago

Just wrapped up my talk at #BSidesGalway and officially launched VulnRadar!

I built this to show how any team can create a high-fidelity vulnerability intelligence capability for $0 in cloud spend. It’s about shifting from passive consumption to engineering autonomy.

The Highlights:

Serverless: Runs entirely on GitHub Actions with zero infrastructure overhead.

No APIs: Harvests directly from NVD, CVE List V5, and CISA KEV—no rate limits or auth headaches.

Contextual: Uses a simple watchlist.yaml to filter for the specific tech you actually run.

Actionable: Automatically creates GitHub Issues and triggers Slack/Discord alerts.

If you're here in Galway, let’s grab a coffee and talk shop! ☕

Code: https://github.com/RogoLabs/vulnradar

Slides: https://rogolabs.net/Talks/BSides-Galway-Open-Source-Intelligence.pdf

#CyberSecurity #InfoSec #OSINT #OpenSource #VulnerabilityManagement #RogoLabs #BSidesGalway

infosec.exchange
12
1
10
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 5mo ago

Version 2 of my CVE Intelligence TA for
Splunk is live on Splunkbase.

I’ve added EPSS probability, CISA KEV status, and SSVC data to the baseline for 327k+ vulnerabilities.

No API keys, zero-config, and pre-joined lookups for faster triage.

Full details and download: https://jerrygamblin.com/2026/04/18/prioritizing-what-matters-bringing-cve-intelligence-to-splunk/

Prioritizing What Matters: Bringing CVE Intelligence to Splunk
JerryGamblin.com

Prioritizing What Matters: Bringing CVE Intelligence to Splunk

I spend a significant amount of my time thinking about EPSS, CVSS, and the inherent gaps in how we prioritize vulnerabilities. We all know the drill: a 9.8 CRITICAL that remains unexploited shouldn…

6
0
4
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 2mo ago

July 2026 closed at 9,775 published CVEs against 3,776 in July 2025, +158.9%.

That puts 2026 at 45,626 CVEs year to date, +66.4% year over year, and 215 CVEs published a day so far this year. July 21 alone carried 1,474 of them, 1,097 of those from Oracle. All of 2025 came to 48,162. 2026 passes it in another 2,536 CVEs, in the second week of August.

1
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 5mo ago

When the NVD and GitHub disagree on a CVSS score, who do you trust?

I’m at #VulnCon and built Vuln Anarchy to visualize the scoring gap. This chart shows nearly 1,500 instances where the math doesn't align.

Live Data: https://rogolabs.github.io/vuln-anarchy/
Repo: https://github.com/RogoLabs/vuln-anarchy

infosec.exchange

Infosec Exchange

4
1
4
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 8mo ago

Finding CVEs that technically "don't exist" yet. 🕵️‍♂️

Ghost CVEs are live. A "Ghost CVE" is a vulnerability identifier that’s already popped up in the wild—think GitHub commits or security advisories—but is still listed as RESERVED or NOT_FOUND in official registries like NVD or MITRE.

It catches the threats that are already out there, even if the paperwork says they aren't. 📝💨

Admittedly, there are a lot more sources to add—this was just a quick weekend POV—but I plan on extending it soon.

Check out the latest ghost report here: https://github.com/RogoLabs/GhostCVEs/blob/main/reports/ghost_report.md

#InfoSec #ThreatIntel #OpenSource #GhostCVEs

github.com
8
0
4
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 2mo ago

When Cisco ended the life of Cisco Vulnerability Management (formerly Kenna Security), I knew it marked the end of my time there.

So today, I'm thrilled to share that I've joined Empirical Security as Head of Research.

Back to the data, back to building, back home.

https://research.empiricalsecurity.com/research/country-roads-take-me-home

research.empiricalsecurity.com
1
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 3mo ago
Stop triaging by bug class. Here are the 10 most common weakness types, lined up by the CVSS scores they actually get. The ranking looks sensible: injection and memory corruption up in the 7s and 8s (stack buffer overflow tops out at a median 8.5), the high-volume web classes down in the 5s and 6s. Folk wisdom, confirmed. Then look at the grey band in the middle. Every one of these ten classes, top to bottom, has a stack of vulnerabilities in the same 6.3 to 7.1 window. Pull a CVE scored 6.5 and it could be any of them. The class does not pin the score, and the score does not pin the class. And the ranking itself is soft. Within a single weakness type the middle 80% of scores spans three to four and a half points, so knowing a bug is "an XSS" or "a path traversal" tells you little about its severity. The category is not destiny either: out-of-bounds read is a memory bug like the top-ranked stack overflow, yet it sits near the bottom. So a "critical CWE" is not really a thing. The class shifts the odds, but severity lives in the specific bug. Which weakness class do you think your program over-weights, and which does it wave through? #vulnerabilitymanagement #cybersecurity #CVE
1
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 3mo ago

Mid-year CVE check-in: the first half of 2026 produced 35,364 CVEs. More than any full year before 2024, and more than the program's entire first decade (1999-2008) combined. One every 7.4 minutes.

The counterweight: only 85 of them (0.24%) are on CISA's KEV list. Volume keeps climbing; confirmed exploitation stays rare. The signal-to-noise problem is the story.

Full writeup + reproducible code: https://jerrygamblin.com/2026/07/01/3528/

CVE Mid-Year 2026 Check-In: Volume Vertical, Exploitation Rare
JerryGamblin.com

CVE Mid-Year 2026 Check-In: Volume Vertical, Exploitation Rare

We are halfway through 2026, so it is time for the mid-year CVE check-in. The short version: the volume curve has gone vertical while exploitation has not. This review covers everything published i…

1
0
1
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 6mo ago

The "Zero Day Clock" is a Masterclass in Bad Data Science.

I've heard this clock mentioned multiple times at #RSAC this week. It predicts an "exponential collapse" of the time-to-exploit (TTE) toward zero. It makes for a scary keynote slide, but the math is fundamentally broken.

The model suffers from:

Right-Censoring: It ignores that slow exploits for 2025 haven't happened yet, artificially forcing the "average" to zero.

Selection Bias: It only tracks the fastest 1.5% of vulnerabilities and ignores the "long tail."

Administrative Lag: It mistakes the growing NVD backlog for "attacker velocity."

We don’t need hyperbolic "scare-ware" statistics to justify our urgency. Defense is hard enough without distorting the data.

I’ve written a full technical audit on why this methodology fails a basic statistical peer review:

Technical Breakdown: https://gist.github.com/jgamblin/91f7843b62069616c951f32957c921cd

#RSAC #RSAC2026 #Infosec #CyberSecurity #DataScience #VulnerabilityManagement

infosec.exchange

Infosec Exchange

3
1
2
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 7mo ago

Vulnerability intel shouldn’t be a luxury.

Next week at @BSidesGalway, I’m launching VulnRadar:
✅ 100% Open Source
✅ Runs on free @github@infosec.exchange services
✅ NO API keys to manage

Good intel is a community necessity. Let’s make it the standard.

#BSidesGalway #CyberSecurity #OSS

infosec.exchange
3
0
1
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 6mo ago

March 2026 was a brutal month for vulnerabilities. 🛡️

Here is the damage:
• 6,246 new CVEs (+55.7% Over Last March)
• 169 new vulns per day 🤯
• 7.1 median CVSS severity (High)

The Top 3 Culprits:
🥇 XSS (730)
🥈 SQLi (325)
🥉 Missing Auth (292)

2026 is already up 27% YoY.

2
0
2
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 4mo ago

Launching LycosAI today.

The wilderness is encroaching. We are holding the line.

Deploying autonomous wolf packs at prefecture scale to secure the rural perimeter where legacy systems have failed.

lycosai.com

1
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 5mo ago

April 2026 CVE Stats:
🚨 5,820 New CVEs (+44% YoY)
📊 175/day avg
📈 YTD: 20,991 (+31% YoY)
🔥 Median CVSS: 7.0

Top CWEs:
1️⃣ XSS (588)
2️⃣ Path Traversal (238)
3️⃣ Missing Auth (235)
4️⃣ SQLi (218)

#InfoSec #CyberSecurity #CVE

infosec.exchange
1
0
1
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 7mo ago

RE: @gcve@social.circl.lu

GCVE now allows publishing.

social.circl.lu

gcve.eu: "Publishing Vulnerability Information with GCVE W…" - social.circl.lu

1
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 7mo ago

February 2026 CVE Growth Report:

YTD (February):
▸ 8,932 total CVEs (+12.4% vs 2025 YTD)
▸ 151 new vulnerabilities per day
▸ +982 more CVEs than 2025 through February

February alone:
▸ 4,619 CVEs (+25.7% vs February 2025)

1
0
1
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 7mo ago

The @openclaw project has exploded this month. 🛡️

Since I've given it deep local access, I’m tracking its security in real-time.

📈 92 Advisories
🚨 55 High/Critical
🔄 Hourly V5 sync

Link: https://github.com/jgamblin/OpenClawCVEs/
Plot twist: I had OpenClaw build the tracker for me. 🤖

GitHub

GitHub - jgamblin/OpenClawCVEs: Tracking OpenClaw CVEs

Tracking OpenClaw CVEs. Contribute to jgamblin/OpenClawCVEs development by creating an account on GitHub.

1
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 10mo ago

A professor reached out about my 3-year-old CVElk project—it was broken. Spent some time last night fixing it: 4 live data sources, 300K+ CVEs, modern Python CLI, auto-updates.

Always happy to fix old code if it helps! 🙏

github.com/jgamblin/CVElk

0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 11mo ago

2025 CVE Stats Update (October 31st, 2025)
Total Number of CVEs: 39,681
Average CVEs Per Day: 130.53
Average CVSS Score: 6.61
YOY Growth: 22.42% or +7,267 (32,414 CVEs in 2024)

0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 6mo ago

Paid $25 on eBay for a 1943 cryptography book. It arrived signed by LTC George R. Eckman, the Executive Officer of the Alsos Mission, the WWII task force that hunted Nazi nuclear scientists across Europe.

It's going to the U.S. Army Intelligence Hall of Fame. Some books belong in archives. 🔐

0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 1mo ago

I wore a $69 badge from @adafruit@fosstodon.org through BSides, Black Hat, and DEF CON. 10,501 radios, 673 open networks, and someone beaconing 77 fake access points across all 13 channels.

Plus the four rewrites it took to learn that counting addresses is not counting devices.

https://jerrygamblin.com/2026/08/10/10501-radios-in-seven-days-what-a-69-badge-heard-at-summer-camp/

jerrygamblin.com
0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 11mo ago

Forget cryptocurrency—let's talk real cryptography! If you're into ciphers and code-breaking, this special on the hidden messages of Mary, Queen of Scots, is a must-watch. https://www.pbs.org/video/cracking-the-queens-code-sp1wq9/

Secrets of the Dead | Cracking the Queen's Code | Season 22 | Episode 9
pbs.org

Secrets of the Dead | Cracking the Queen's Code | Season 22 | Episode 9

See how secret letters written by Mary, Queen of Scots, were finally decoded.

0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 10mo ago

🚨 BLACK FRIDAY DOORBUSTER 🚨

CVE.ICU just got a MASSIVE upgrade: EPSS, CISA KEV, & Risk Matrix.

Our unbeatable price remains: $0.00.

No credit card. No sales calls. Just vibes and vulnerabilities.

#BlackFriday #CyberSecurity #OpenSource

infosec.exchange
0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 6mo ago

@0x00string@infosec.exchange So many WordPress vulnerabilities!

0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 6mo ago

I just read this essay by Kenneth Reitz, and it’s a powerful, necessary look at the "hidden human cost" of the tech industry.

Kenneth pulls back the curtain on how Open Source can build a career while simultaneously draining a person's spirit. He captures the "identity fusion" that happens when we tie our entire self-worth to our code.

It’s a sentiment that has hit home for me in the past. At times, I've had to wrestle with that nagging internal voice that says, "I am only as valuable as my last project." It’s an exhausting mindset to break—the feeling that your worth has an expiration date unless you’re constantly shipping something new. Reading this was a vital reminder that we are more than our output.

A final note: Kenneth’s story reminds us that these pressures can sometimes reach an extreme. If you ever find yourself struggling with these feelings to the point of feeling unmanageable, seeking professional help is a sign of strength. We are humans first, developers second.

https://kennethreitz.org/essays/2026-03-18-open_source_gave_me_everything_until_i_had_nothing_left_to_give

Open Source Gave Me Everything Until I Had Nothing Left to Give
Kenneth Reitz

Open Source Gave Me Everything Until I Had Nothing Left to Give

I thought I was having a spiritual awakening. I was having a psychiatric emergency. I was at a tech conference in Sweden when it started. I hadn't slept in...

0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 3mo ago

For years, MITRE, the nonprofit that runs the CVE program, was its #1 issuer almost every month. Not anymore.

GitHub has been #1 every month of 2026. MITRE has slid to about #7.

0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 2mo ago

Everyone says the security world stops for Vegas. Your CVE queue never got the memo.

Ten years of Black Hat and DEF CON weeks, each against the twelve weeks around it: the median year lands 10% below its typical week, but half the years fall between 22% below and 30% above. Average rank: 6.3 out of 13, whereas a random week averages 7.0. No dip, and no spike either.

Who is actually on the vuln queue at your shop this week?

0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 3mo ago

A CVSS score is not a fact about a bug. It is an opinion with a decimal point.

Cross-site scripting is the most common bug on the internet. Here it is scored by 13 different organizations: the same weakness averages about a 3.4 at VulDB and about a 6.7 at Microsoft. Same bug class, same scoring system, more than a full severity band apart.

Most of that spread is really one organization. VulDB sits alone at the bottom while the other twelve cluster between 5.5 and 6.7. So the real question is why VulDB reads the same bugs so much lower.

The biggest reason is not the metric people argue about. It is whether an XSS leaks data at all. VulDB scores confidentiality impact as None on essentially every XSS, treating it as a bug that can alter a page but not read anything. Almost everyone else scores it Low: an XSS can read the page, lift a session token, scrape what the victim can see. That single call is worth about 1.4 points, the largest lever in the whole vector.

VulDB then stacks two more conservative calls on top: it marks XSS as not crossing a trust boundary (Scope:Unchanged) where most others mark it Changed, and it usually requires the attacker to already have some privilege. Each is worth about half as much as the confidentiality call. That is the twist: Scope is the metric the community argues about most for XSS, yet the quieter confidentiality call moves the score twice as far.

None of these orgs is being sloppy. They are applying the same defined metrics to a genuinely ambiguous bug and landing in different places, and no single dial orders them. The number just depends on who holds the pen.

When a CVE carries two different CVSS scores, which one does your program actually use?

#vulnerabilitymanagement #cybersecurity #CVE

infosec.exchange

Infosec Exchange

0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 9mo ago

It’s official: 48,185 CVEs were published in 2025 (+21% YoY). 🚨

The landscape has shifted. WordPress security firms are now out-publishing Big Tech, and "Patch Tuesday" is now "Patch Every Day."

See the full data review:
https://jerrygamblin.com/2026/01/01/2025-cve-data-review/

jerrygamblin.com
0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 7mo ago

The CVE Board January minutes read like a gossip mag for vuln geeks.

Good: The March "funding cliff" is a myth—the lights are staying on.

Bad: Mystery draft legislation wants to force "International Participation" & limit "Organizational Concentration."

Drama: The Board is already at 22 members with no term limits, but they just voted to interview #23.

Full gossip here: https://www.mail-archive.com/cve-editorial-board-list@mitre.org/msg00314.html

mail-archive.com
0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 6mo ago

I heard you like CVEs, so I reported CVEs in your CVE filing software.

I reported and fixed CVE-2026-35466 & CVE-2026-35467 in CVEClient.

https://github.com/CERTCC/cveClient

github.com
0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 10mo ago

2025 CVE Growth Report (Data through Nov 30):

⚠️ Total: 42,697 CVEs (+16.9% YoY)
📅 Daily Avg: 128
📉 November Dip: Monthly volume dropped 25% YoY (3,028 CVEs), the lowest since Jan.

We are still on track for a record year, sitting at +6,187 CVEs over 2024.

0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 2mo ago
A third of 2026 CVEs so far carry a CVSS v4 score, up from under 9% in 2024. Fast climb for a version that only shipped in late 2023. Then you see who did it: VulnCheck, VulDB, and GitHub are 71% of all v4 scores. The other 200+ CNAs went from ~4% to ~10%, real growth but nowhere near those three. Most of the rise of v4 is in three organizations.
0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 3mo ago
GitHub Security Advisories are now the #1 CVE issuer (6,801). VulnCheck climbed to #3 (VulDB 🛡sits #2). The people assigning CVEs changed in 2026: platforms, ecosystems, and research CNAs now set the pace. High counts reflect scope, not padding. https://jerrygamblin.com/2026/07/01/3528/
CVE Mid-Year 2026 Check-In: Volume Vertical, Exploitation Rare
JerryGamblin.com

CVE Mid-Year 2026 Check-In: Volume Vertical, Exploitation Rare

We are halfway through 2026, so it is time for the mid-year CVE check-in. The short version: the volume curve has gone vertical while exploitation has not. This review covers everything published i…

0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 2mo ago

PURL was supposed to be the upgrade. A package-native identifier built to describe the open-source packages CPE never handled well. Here is where it actually landed in the CVE feed: about 2% of 2026 CVEs, and most of that from a single third-party CNA.

As CNAs write them, 75% of CVEs carry neither CPE nor PURL. Then NVD and CISA go to work: they backfill CPEs and cut that no-ID pile to 41%. Every point of that improvement is CPE. They add zero PURLs, and not by choice. NVD has no PURL field to fill.

Here is the strange part. PURL is alive and well outside this pipeline, in OSV, GitHub Security Advisories, and every SBOM and SCA tool. It just never made it into the CVE and NVD pipeline that most of the industry still triages from. The problem is not PURL. It is that the feed everyone relies on structurally cannot see it. How long do we keep matching CVEs to assets through a format that cannot name a package?

#vulnerabilitymanagement #cybersecurity #CVE

infosec.exchange

Infosec Exchange

0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 6mo ago

@0x00string@infosec.exchange Yeah, it's a ton.

0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 2mo ago
By July 16, the 2026 CVE count hit 39,952, the entire 2024 total, with the year barely half over. Each year now clears the two-years-earlier total sooner: mid-November in 2020, mid-August in 2025, mid-July in 2026. The earliest in this series. The two-years-ago total is now a summer checkpoint, not a year-end line.
0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 10mo ago

London bound next week (Dec 7–15)! 🇬🇧

I’ll be at #BlackHatEU giving my talk on the "Post-NVD Era" (Thurs Dec 11 @ 2:30 PM) and then hitting up #BSidesLDN for the weekend.

#Infosec #VulnMgmt #CVE

infosec.exchange
0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 2mo ago

CISA added 154 CVEs to its Known Exploited Vulnerabilities list so far in 2026. Over half landed within a month of publication, but a stubborn 16% were more than three years old at listing.

I measured the gap from a CVE.org record being published to that CVE landing on KEV. Most move fast: about three-quarters are listed within a year of publication. That tracks with how we picture exploitation: a new bug, a quick confirmation, onto the list.

But 16% break the pattern, more than three years old when CISA lists them, including a 2008 Windows bug (nearly 18 years) and a 2009 Office bug (about 17). Listing dates cannot tell us whether that exploitation is new or long-running, only that CISA confirmed it years after disclosure.

#vulnerabilitymanagement #cybersecurity #CVE

infosec.exchange

Infosec Exchange

0
0
0
0
Open post
Jerry Gamblin @jgamblin@infosec.exchange
· 8mo ago

Jan 2026 CVEs: 4,319.

While +1.0% YoY looks flat, it's 139 CVEs/day—nearly 7% HIGHER than 2025's average.

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 18:16:50 UTC