Sign in

Jerry Gamblin

@jgamblin.bsky.social
218 followers 5 following 71 posts

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of cve.icu & patchthis.app.

PostsRepliesMedia
Jerry Gamblin @jgamblin.bsky.social · 10/09/2026
KEV used to be a patch list. Now, for most of what CISA adds, it is an IR list: was this box already owned? 48 of the 73 KEV entries added since July 1 carry CISA's forensic-triage flag. The 1,630 before them predate it. BOD 26-04's top tier: 3 days & forensic triage.
000
Jerry Gamblin @jgamblin.bsky.social · 08/09/2026
NVD's April policy did not remove the enrichment work. It moved it. 39% of settled 2026 CVEs are Deferred: no CPE, no NVD analysis. The rule is written about products, the result sorts by publisher. WordPress CNAs 99%, VulDB 70%, Microsoft 0%. How much of that moved to you?
000
Jerry Gamblin @jgamblin.bsky.social · 24/08/2026
"Are we covered for this one?" is the first question after a CVE is assigned to the CISA KEV list. 60% of cases, there is no public rule to detect it. 329 of 554 KEV CVEs published since Aug 2023 have no open rule carrying the CVE ID. Apple has none.
000
Jerry Gamblin @jgamblin.bsky.social · 10/08/2026
A $69 badge, seven days of BSides/Black Hat/DEF CON, 10,501 radios heard. 673 open networks, and someone beaconing 77 fake APs across all 13 channels. Also: counting addresses is not counting devices. Took me four rewrites to learn that. jerrygamblin.com/2026/08/10/1...
jerrygamblin.com
000
Jerry Gamblin @jgamblin.bsky.social · 04/08/2026
Everyone says the security world stops for Vegas. Your CVE queue never got the memo.
010
Jerry Gamblin @jgamblin.bsky.social · 01/08/2026
July 2026 closed with 9,775 published CVEs, up from 3,776 in July 2025 (+158.9%). That puts 2026 at 45,626 CVEs year to date, +66.4% year over year, and 215 CVEs published a day so far this year. July 21 alone accounted for 1,474 of them, 1,097 of which were from Oracle.
Line chart titled "Cumulative CVEs Published, 2026 vs 2025", through July 31, 2026. Two rising lines from January to July: 2026 in red, 2025 in dashed grey. The lines track together through February, then 2026 pulls steadily ahead and the gap widens all year. 2026 ends July at 45,626 cumulative CVEs against 27,426 in 2025, a gap of 18,200 or 66.4 percent. Daily average 215 CVEs. Busiest completed month July with 9,775, quietest January with 4,305. Source: NVD, excluding rejected CVEs.
000
Jerry Gamblin @jgamblin.bsky.social · 28/07/2026
CVSS is a severity label the industry treats like a priority list. This year 4,719 CVEs scored CVSS v3 9.0+, and half carry the identical 9.8. Only nine distinct scores exist in that band: no 9.5, no 9.7. What would your tooling sort them on?
000
Jerry Gamblin @jgamblin.bsky.social · 22/07/2026
Heading to Vegas for Summer Camp with a new title (Head of Research @ Empirical Security), a CVE panel at BSidesLV, a Black Hat luncheon, and a list of the 18 CVE/vuln/exploitation talks I would clear my calendar for across all three cons. jerrygamblin.com/2026/07/22/h...
jerrygamblin.com
Hydrate, Hack, Repeat: Security Summer Camp 2026
010
Jerry Gamblin @jgamblin.bsky.social · 17/07/2026
By July 16, the 2026 CVE count hit 39,952, the entire 2024 total, with the year barely half over. Each year now clears the two-years-earlier total sooner: mid-November in 2020, mid-August in 2025, mid-July in 2026. The earliest in this series.
000
Jerry Gamblin @jgamblin.bsky.social · 14/07/2026
CISA added 154 CVEs to its Known Exploited Vulnerabilities list so far in 2026. Over half landed within a month of publication. But 16% were more than three years old when they hit the list.
000
Jerry Gamblin @jgamblin.bsky.social · 11/07/2026
The bugs you see most are not the bugs that get exploited. I mapped every CVE on CISA's list of exploited vulnerabilities to its corresponding CWE. What attackers actually use: memory corruption and injection. XSS is the most common bug on the internet, and it barely shows up.
000
Jerry Gamblin @jgamblin.bsky.social · 10/07/2026
Stop triaging by bug class. The 10 most common CWEs and their CVSS scores. But every one of the 10 has vulnerabilities in the same 6.3-7.1 band. The class does not tell you the severity.
000
Jerry Gamblin @jgamblin.bsky.social · 09/07/2026
A CVSS score is not a fact about a bug. It is an opinion with a decimal point. 13 orgs scored XSS: averages range from 3.4 to 6.7, mostly because VulDB sits at the bottom. The biggest reason is not the metric people argue about (Scope). That one call is worth ~1.4 points, double Scope.
000
Jerry Gamblin @jgamblin.bsky.social · 07/07/2026
For years, MITRE, the nonprofit that runs the CVE program, was its #1 issuer almost every month. Not anymore. GitHub has been #1 every month of 2026. MITRE has slid to about #7.
000
Jerry Gamblin @jgamblin.bsky.social · 01/07/2026
H1 2026: 35,364 CVEs. More than any full year before 2024. One every 7.4 minutes, +49.5% YoY. But only 85 (0.24%) are on CISA's KEV list so far. We're drowning in CVEs while confirmed exploitation stays rare. That gap is the whole game. Review + Code: jerrygamblin.com/2026/07/01/3...
000
Jerry Gamblin @jgamblin.bsky.social · 17/05/2026
Launching LycosAI today. The wilderness is encroaching. We are holding the line. Deploying autonomous wolf packs at prefecture scale to secure the rural perimeter where legacy systems have failed. lycosai.com
lycosai.com
LycosAI
Restoring the Ghost of the Predator via Edge-Computing. Deployed at prefecture scale. Access by qualification only.
000
Jerry Gamblin @jgamblin.bsky.social · 10/05/2026
I'm bad at golf. But I'm good at data visualization. So I built this: a self-hosted @Garmin R10 analytics dashboard with club analysis, gapping tables, carry tracking, and AI coaching recommendations. All from your own data. 🔗 github.com/jgamblin/golf
010
Jerry Gamblin @jgamblin.bsky.social · 01/05/2026
April 2026 CVE Stats: 🚨 5,820 New CVEs (+44% YoY) 📊 175/day avg 📈 YTD: 20,991 (+31% YoY) 🔥 Median CVSS: 7.0 Top CWEs: 1️⃣ XSS (588) 2️⃣ Path Traversal (238) 3️⃣ Missing Auth (235) 4️⃣ SQLi (218) #InfoSec #CyberSecurity #CVE
000
Jerry Gamblin @jgamblin.bsky.social · 19/04/2026
Version 2 of my CVE Intelligence TA for Splunk is live on Splunkbase. I’ve added EPSS probability, CISA KEV status, and SSVC data to the baseline for 327k+ vulnerabilities. Zero-config and pre-joined lookups for faster triage. Full details and download: jerrygamblin.com/2026/04/18/p...
jerrygamblin.com
Prioritizing What Matters: Bringing CVE Intelligence to Splunk
010
Jerry Gamblin @jgamblin.bsky.social · 15/04/2026
When the NVD and GitHub disagree on a CVSS score, who do you trust? I’m at #VulnCon and built Vuln Anarchy to visualize the scoring gap. This chart shows nearly 1,500 instances where the math doesn't align. Live Data: rogolabs.github.io/vuln-anarchy/ Repo: github.com/RogoLabs/vul...
010
Jerry Gamblin @jgamblin.bsky.social · 10/04/2026
Paid $25 on eBay for a 1943 cryptography book. It arrived signed by LTC George R. Eckman, the Executive Officer of the Alsos Mission, the WWII task force that hunted Nazi nuclear scientists across Europe. It's going to the U.S. Army Intelligence Hall of Fame. Some books belong in archives. 🔐
030
Jerry Gamblin @jgamblin.bsky.social · 07/04/2026
I heard you like CVEs, so I reported CVEs in your CVE filing software. I reported and fixed CVE-2026-35466 & CVE-2026-35467 in CVEClient. github.com/CERTCC/cveCl...
github.com
GitHub - CERTCC/cveClient: A client and library to cve-services 2.x to provide CVE management for CNA and CERTs
A client and library to cve-services 2.x to provide CVE management for CNA and CERTs - CERTCC/cveClient
000
Jerry Gamblin @jgamblin.bsky.social · 01/04/2026
March 2026 was a brutal month for vulnerabilities. 🛡️ Here is the damage: • 6,246 new CVEs (+55.7% Over Last March) • 169 new vulns per day 🤯 • 7.1 median CVSS severity (High) The Top 3 Culprits: 🥇 XSS (730) 🥈 SQLi (325) 🥉 Missing Auth (292) 2026 is already up 27% YoY.
001
Jerry Gamblin @jgamblin.bsky.social · 24/03/2026
The "Zero Day Clock" is a masterclass in bad data science. 📉 Ignoring right-censoring and selection bias forces a "collapse" that doesn't exist. It mistakes NVD backlog for attacker velocity. Data audit & technical receipts here: gist.github.com/jgamblin/91f... #RSAC2026 #Infosec #CyberSecurity
gist.github.com
A Critical Audit of the "Zero Day Clock" Methodology
A Critical Audit of the "Zero Day Clock" Methodology - zeroday.md
000
Jerry Gamblin @jgamblin.bsky.social · 01/03/2026
February 2026 CVE Growth Report: YTD (February): ▸ 8,932 total CVEs (+12.4% vs 2025 YTD) ▸ 151 new vulnerabilities per day ▸ +982 more CVEs than 2025 through February February alone: ▸ 4,619 CVEs (+25.7% vs February 2025)
100
Jerry Gamblin @jgamblin.bsky.social · 25/02/2026
The CVE Board January minutes read like a gossip mag for vuln geeks. Good: The March "funding cliff" is a myth. Bad: Mystery draft legislation. Drama: A Board With No Term Limits Votes For Member 23. Full gossip here: www.mail-archive.com/cve-editoria...
mail-archive.com
CVE Board Meeting Minutes: January 21, 2026
000
Jerry Gamblin @jgamblin.bsky.social · 18/02/2026
The @openclaw project has exploded this month. 🛡️ Since I've given it deep local access, I’m tracking its security in real-time. 📈 92 Advisories 🚨 55 High/Critical 🔄 Hourly V5 sync Link: github.com/jgamblin/Ope... Plot twist: I had OpenClaw build the tracker for me. 🤖
github.com
GitHub - jgamblin/OpenClawCVEs: Tracking OpenClaw CVEs
Tracking OpenClaw CVEs. Contribute to jgamblin/OpenClawCVEs development by creating an account on GitHub.
200
Jerry Gamblin @jgamblin.bsky.social · 15/02/2026
Vulnerability intel shouldn’t be a luxury. Next week at BSidesGalway, I’m launching VulnRadar: ✅ 100% Open Source ✅ Runs on free GitHub services ✅ NO API keys to manage Good intel is a community necessity. Let’s make it the standard. #BSidesGalway #CyberSecurity #OSS
010
Jerry Gamblin @jgamblin.bsky.social · 01/02/2026
Jan 2026 CVEs: 4,319. While +1.0% YoY looks flat, it's 139 CVEs/day—nearly 7% HIGHER than 2025's average. #cybersecurity #CVE #infosec #RogoLabs
010
Jerry Gamblin @jgamblin.bsky.social · 12/01/2026
I built Ghost CVEs this weekend to catch bugs that are public in code commits but invisible in the official registries. See what I found so far 👇 github.com/RogoLabs/Gho... #ThreatIntel #OpenSource #GhostCVEs
github.com
010
Jerry Gamblin @jgamblin.bsky.social · 01/01/2026
It’s official: 48,185 CVEs were published in 2025 (+21% YoY). 🚨 The landscape has shifted. WordPress security firms are now out-publishing Big Tech, and "Patch Tuesday" is now "Patch Every Day." See the full data review: jerrygamblin.com/2026/01/01/2...
jerrygamblin.com
2025 CVE Data Review
020
Jerry Gamblin @jgamblin.bsky.social · 05/12/2025
London bound next week (Dec 7–15)! 🇬🇧 I’ll be at #BlackHatEU giving my talk on the "Post-NVD Era" (Thurs Dec 11 @ 2:30 PM) and then hitting up #BSidesLDN for the weekend. #Infosec #VulnMgmt #CVE
000
Jerry Gamblin @jgamblin.bsky.social · 04/12/2025
A professor reached out about my 3-year-old CVElk project—it was broken. Spent some time last night fixing it: 4 live data sources, 300K+ CVEs, modern Python CLI, auto-updates. Always happy to fix old code if it helps! 🙏 github.com/jgamblin/CVElk
000
Jerry Gamblin @jgamblin.bsky.social · 01/12/2025
2025 CVE Growth Report (Data through Nov 30): ⚠️ Total: 42,697 CVEs (+16.9% YoY) 📅 Daily Avg: 128 📉 November Dip: Monthly volume dropped 25% YoY (3,028 CVEs), the lowest since Jan. We are still on track for a record year, sitting at +6,187 CVEs over 2024.
000
Jerry Gamblin @jgamblin.bsky.social · 27/11/2025
🚨 BLACK FRIDAY DOORBUSTER 🚨 CVE.ICU just got a MASSIVE upgrade: EPSS, CISA KEV, & Risk Matrix. Our unbeatable price remains: $0.00. No credit card. No sales calls. Just vibes and vulnerabilities. #BlackFriday #CyberSecurity #OpenSource
020
Jerry Gamblin @jgamblin.bsky.social · 01/11/2025
2025 CVE Stats Update (October 31st, 2025) Total Number of CVEs: 39,681 Average CVEs Per Day: 130.53 Average CVSS Score: 6.61 YOY Growth: 22.42% or +7,267 (32,414 CVEs in 2024)
000
Jerry Gamblin @jgamblin.bsky.social · 23/10/2025
Forget cryptocurrency—let's talk real cryptography! If you're into ciphers and code-breaking, this special on the hidden messages of Mary, Queen of Scots, is a must-watch. www.pbs.org/video/cracki...
pbs.org
Secrets of the Dead | Cracking the Queen's Code | Season 22 | Episode 9
See how secret letters written by Mary, Queen of Scots, were finally decoded.
000
Jerry Gamblin @jgamblin.bsky.social · 20/10/2025
Spent Sunday watching football & analyzing 314,705 CVEs to track update velocity. Key takeaway: Some issues require constant attention—the top CVE, CVE-2023-4255, has been updated 220 times! See the full analysis and charts: rogolabs.github.io/CVE-Updates/
010
Jerry Gamblin @jgamblin.bsky.social · 16/10/2025
📢 New Open-Source Tool: CNAPulse.org Getting a quick, transparent overview of CNA activity was nearly impossible. It required manual processing of raw CVE data. I built CNAPulse.org to automate and bring transparency to publishing in the CVE ecosystem.
cnapulse.org
CNAPulse
010
Jerry Gamblin @jgamblin.bsky.social · 01/10/2025
2025 CVE Stats Update (September 30th, 2025) Total Number of CVEs: 35,404 Average CVEs Per Day: 129.68 Average CVSS Score: 6.62 YOY Growth: 22.72% or +6,555 (28,849 CVEs in 2024)
000
Jerry Gamblin @jgamblin.bsky.social · 17/09/2025
I've added a new page to CVEForecast.org: a CNA Forecast. It's a fun project to track the growth and decline trends. Hopefully, it provides some interesting insights for anyone in the vuln space. Check it out here: cveforecast.org/cna_forecast... #infosec #cybersecurity #vulnerability #cve
cveforecast.org
CVEForecast
020
Jerry Gamblin @jgamblin.bsky.social · 12/09/2025
The CVE Program is stepping into its Quality Era, and I couldn't be happier. CISA's vision prioritizes trust, quality, and responsiveness in vulnerability management. This is a fantastic step to ensure CVE data remains a public good for everyone www.cisa.gov/sites/defaul...
cisa.gov
110
Jerry Gamblin @jgamblin.bsky.social · 01/09/2025
2025 CVE Stats Update (August 31st, 2025) Total Number of CVEs: 31,077 Average CVEs Per Day: 127.89 Average CVSS Score: 6.63 YOY Growth: 17.81% or +4,699 (26,378 CVEs in 2024)
000
Jerry Gamblin @jgamblin.bsky.social · 12/08/2025
Here are my slides from #BSidesLV on "The Art of Concealment." TLDR: Many CVEs are published without the four pillars (CWE, CPE, CVSS, Fix) needed for security teams to remediate the vulnerabilities successfully. rogolabs.net/Talks/The%20...
rogolabs.net
000
Jerry Gamblin @jgamblin.bsky.social · 08/08/2025
At DEF CON? I'm speaking today at 1PM in the AppSec Village. Stop by to hear me talk about the post NVD era of vulnerability data.
000
Jerry Gamblin @jgamblin.bsky.social · 05/08/2025
Just announced after my talk: CNAScorecard.org is LIVE! 🚀 Did you know only 2% of CVEs have CPE data and just 4.8% have patch info? This cripples automation & leaves us blind.
cnascorecard.org
CNA Scorecard
011
Jerry Gamblin @jgamblin.bsky.social · 01/08/2025
2025 CVE Stats Update (July 31st, 2025) Total Number of CVEs: 27,447 Average CVEs Per Day: 129.47 Average CVSS Score: 6.62 YOY Growth: 17.32% or +4,053 (23,394 CVEs in 2024)
000
Jerry Gamblin @jgamblin.bsky.social · 30/07/2025
Relaunched my open-source project, cve.icu! It's been completely rewritten in pure HTML—making it blazing fast & fully interactive. Designed to cut through the noise of 40k+ new vulns a year. Explore vulnerability data faster. 🚀 cve.icu
cve.icu
CVE.ICU - CVE Analysis Dashboard
Comprehensive CVE analysis and visualization from 1999 to present
000
Jerry Gamblin @jgamblin.bsky.social · 29/07/2025
Vegas-bound! ✈️ I'm giving two talks next week on CVEs and vulnerability disclosure. First up is @bsideslv.org on Tues, 2:30pm: "The Art of Concealment: CVE's Challenge with Transparency"(thread 👇)
110
Jerry Gamblin @jgamblin.bsky.social · 19/07/2025
CVEScoreCard v.06 is live. 🤖 My open-source CVE forecast now auto-tunes itself daily, learning from past runs to get more accurate. Today, it's predicting 46,796 CVEs for the year. See the live forecast: cveforecast.org #cybersecurity #cve #opensource #infosec
cveforecast.org
CVEForecast
021