Jerry Gamblin @jgamblin.bsky.social · 10/09/2026KEV used to be a patch list. Now, for most of what CISA adds, it is an IR list: was this box already owned? 48 of the 73 KEV entries added since July 1 carry CISA's forensic-triage flag. The 1,630 before them predate it. BOD 26-04's top tier: 3 days & forensic triage. 000
Jerry Gamblin @jgamblin.bsky.social · 08/09/2026NVD's April policy did not remove the enrichment work. It moved it. 39% of settled 2026 CVEs are Deferred: no CPE, no NVD analysis. The rule is written about products, the result sorts by publisher. WordPress CNAs 99%, VulDB 70%, Microsoft 0%. How much of that moved to you? 000
Jerry Gamblin @jgamblin.bsky.social · 24/08/2026"Are we covered for this one?" is the first question after a CVE is assigned to the CISA KEV list. 60% of cases, there is no public rule to detect it. 329 of 554 KEV CVEs published since Aug 2023 have no open rule carrying the CVE ID. Apple has none. 000
Jerry Gamblin @jgamblin.bsky.social · 10/08/2026A $69 badge, seven days of BSides/Black Hat/DEF CON, 10,501 radios heard. 673 open networks, and someone beaconing 77 fake APs across all 13 channels. Also: counting addresses is not counting devices. Took me four rewrites to learn that. jerrygamblin.com/2026/08/10/1...jerrygamblin.com 000
Jerry Gamblin @jgamblin.bsky.social · 04/08/2026Everyone says the security world stops for Vegas. Your CVE queue never got the memo. 010
Jerry Gamblin @jgamblin.bsky.social · 01/08/2026July 2026 closed with 9,775 published CVEs, up from 3,776 in July 2025 (+158.9%). That puts 2026 at 45,626 CVEs year to date, +66.4% year over year, and 215 CVEs published a day so far this year. July 21 alone accounted for 1,474 of them, 1,097 of which were from Oracle. 000
Jerry Gamblin @jgamblin.bsky.social · 28/07/2026CVSS is a severity label the industry treats like a priority list. This year 4,719 CVEs scored CVSS v3 9.0+, and half carry the identical 9.8. Only nine distinct scores exist in that band: no 9.5, no 9.7. What would your tooling sort them on? 000
Jerry Gamblin @jgamblin.bsky.social · 22/07/2026Heading to Vegas for Summer Camp with a new title (Head of Research @ Empirical Security), a CVE panel at BSidesLV, a Black Hat luncheon, and a list of the 18 CVE/vuln/exploitation talks I would clear my calendar for across all three cons. jerrygamblin.com/2026/07/22/h...jerrygamblin.comHydrate, Hack, Repeat: Security Summer Camp 2026 010
Jerry Gamblin @jgamblin.bsky.social · 17/07/2026By July 16, the 2026 CVE count hit 39,952, the entire 2024 total, with the year barely half over. Each year now clears the two-years-earlier total sooner: mid-November in 2020, mid-August in 2025, mid-July in 2026. The earliest in this series. 000
Jerry Gamblin @jgamblin.bsky.social · 14/07/2026CISA added 154 CVEs to its Known Exploited Vulnerabilities list so far in 2026. Over half landed within a month of publication. But 16% were more than three years old when they hit the list. 000
Jerry Gamblin @jgamblin.bsky.social · 11/07/2026The bugs you see most are not the bugs that get exploited. I mapped every CVE on CISA's list of exploited vulnerabilities to its corresponding CWE. What attackers actually use: memory corruption and injection. XSS is the most common bug on the internet, and it barely shows up. 000
Jerry Gamblin @jgamblin.bsky.social · 10/07/2026Stop triaging by bug class. The 10 most common CWEs and their CVSS scores. But every one of the 10 has vulnerabilities in the same 6.3-7.1 band. The class does not tell you the severity. 000
Jerry Gamblin @jgamblin.bsky.social · 09/07/2026A CVSS score is not a fact about a bug. It is an opinion with a decimal point. 13 orgs scored XSS: averages range from 3.4 to 6.7, mostly because VulDB sits at the bottom. The biggest reason is not the metric people argue about (Scope). That one call is worth ~1.4 points, double Scope. 000
Jerry Gamblin @jgamblin.bsky.social · 07/07/2026For years, MITRE, the nonprofit that runs the CVE program, was its #1 issuer almost every month. Not anymore. GitHub has been #1 every month of 2026. MITRE has slid to about #7. 000
Jerry Gamblin @jgamblin.bsky.social · 01/07/2026H1 2026: 35,364 CVEs. More than any full year before 2024. One every 7.4 minutes, +49.5% YoY. But only 85 (0.24%) are on CISA's KEV list so far. We're drowning in CVEs while confirmed exploitation stays rare. That gap is the whole game. Review + Code: jerrygamblin.com/2026/07/01/3... 000
Jerry Gamblin @jgamblin.bsky.social · 17/05/2026Launching LycosAI today. The wilderness is encroaching. We are holding the line. Deploying autonomous wolf packs at prefecture scale to secure the rural perimeter where legacy systems have failed. lycosai.comlycosai.comLycosAIRestoring the Ghost of the Predator via Edge-Computing. Deployed at prefecture scale. Access by qualification only. 000
Jerry Gamblin @jgamblin.bsky.social · 10/05/2026I'm bad at golf. But I'm good at data visualization. So I built this: a self-hosted @Garmin R10 analytics dashboard with club analysis, gapping tables, carry tracking, and AI coaching recommendations. All from your own data. 🔗 github.com/jgamblin/golf 010
Jerry Gamblin @jgamblin.bsky.social · 01/05/2026April 2026 CVE Stats: 🚨 5,820 New CVEs (+44% YoY) 📊 175/day avg 📈 YTD: 20,991 (+31% YoY) 🔥 Median CVSS: 7.0 Top CWEs: 1️⃣ XSS (588) 2️⃣ Path Traversal (238) 3️⃣ Missing Auth (235) 4️⃣ SQLi (218) #InfoSec #CyberSecurity #CVE 000
Jerry Gamblin @jgamblin.bsky.social · 19/04/2026Version 2 of my CVE Intelligence TA for Splunk is live on Splunkbase. I’ve added EPSS probability, CISA KEV status, and SSVC data to the baseline for 327k+ vulnerabilities. Zero-config and pre-joined lookups for faster triage. Full details and download: jerrygamblin.com/2026/04/18/p...jerrygamblin.comPrioritizing What Matters: Bringing CVE Intelligence to Splunk 010
Jerry Gamblin @jgamblin.bsky.social · 15/04/2026When the NVD and GitHub disagree on a CVSS score, who do you trust? I’m at #VulnCon and built Vuln Anarchy to visualize the scoring gap. This chart shows nearly 1,500 instances where the math doesn't align. Live Data: rogolabs.github.io/vuln-anarchy/ Repo: github.com/RogoLabs/vul... 010
Jerry Gamblin @jgamblin.bsky.social · 10/04/2026Paid $25 on eBay for a 1943 cryptography book. It arrived signed by LTC George R. Eckman, the Executive Officer of the Alsos Mission, the WWII task force that hunted Nazi nuclear scientists across Europe. It's going to the U.S. Army Intelligence Hall of Fame. Some books belong in archives. 🔐 030
Jerry Gamblin @jgamblin.bsky.social · 07/04/2026I heard you like CVEs, so I reported CVEs in your CVE filing software. I reported and fixed CVE-2026-35466 & CVE-2026-35467 in CVEClient. github.com/CERTCC/cveCl...github.comGitHub - CERTCC/cveClient: A client and library to cve-services 2.x to provide CVE management for CNA and CERTsA client and library to cve-services 2.x to provide CVE management for CNA and CERTs - CERTCC/cveClient 000
Jerry Gamblin @jgamblin.bsky.social · 01/04/2026March 2026 was a brutal month for vulnerabilities. 🛡️ Here is the damage: • 6,246 new CVEs (+55.7% Over Last March) • 169 new vulns per day 🤯 • 7.1 median CVSS severity (High) The Top 3 Culprits: 🥇 XSS (730) 🥈 SQLi (325) 🥉 Missing Auth (292) 2026 is already up 27% YoY. 001
Jerry Gamblin @jgamblin.bsky.social · 24/03/2026The "Zero Day Clock" is a masterclass in bad data science. 📉 Ignoring right-censoring and selection bias forces a "collapse" that doesn't exist. It mistakes NVD backlog for attacker velocity. Data audit & technical receipts here: gist.github.com/jgamblin/91f... #RSAC2026 #Infosec #CyberSecuritygist.github.comA Critical Audit of the "Zero Day Clock" MethodologyA Critical Audit of the "Zero Day Clock" Methodology - zeroday.md 000
Jerry Gamblin @jgamblin.bsky.social · 01/03/2026February 2026 CVE Growth Report: YTD (February): ▸ 8,932 total CVEs (+12.4% vs 2025 YTD) ▸ 151 new vulnerabilities per day ▸ +982 more CVEs than 2025 through February February alone: ▸ 4,619 CVEs (+25.7% vs February 2025) 100
Jerry Gamblin @jgamblin.bsky.social · 25/02/2026The CVE Board January minutes read like a gossip mag for vuln geeks. Good: The March "funding cliff" is a myth. Bad: Mystery draft legislation. Drama: A Board With No Term Limits Votes For Member 23. Full gossip here: www.mail-archive.com/cve-editoria...mail-archive.comCVE Board Meeting Minutes: January 21, 2026 000
Jerry Gamblin @jgamblin.bsky.social · 18/02/2026The @openclaw project has exploded this month. 🛡️ Since I've given it deep local access, I’m tracking its security in real-time. 📈 92 Advisories 🚨 55 High/Critical 🔄 Hourly V5 sync Link: github.com/jgamblin/Ope... Plot twist: I had OpenClaw build the tracker for me. 🤖github.comGitHub - jgamblin/OpenClawCVEs: Tracking OpenClaw CVEsTracking OpenClaw CVEs. Contribute to jgamblin/OpenClawCVEs development by creating an account on GitHub. 200
Jerry Gamblin @jgamblin.bsky.social · 15/02/2026Vulnerability intel shouldn’t be a luxury. Next week at BSidesGalway, I’m launching VulnRadar: ✅ 100% Open Source ✅ Runs on free GitHub services ✅ NO API keys to manage Good intel is a community necessity. Let’s make it the standard. #BSidesGalway #CyberSecurity #OSS 010
Jerry Gamblin @jgamblin.bsky.social · 01/02/2026Jan 2026 CVEs: 4,319. While +1.0% YoY looks flat, it's 139 CVEs/day—nearly 7% HIGHER than 2025's average. #cybersecurity #CVE #infosec #RogoLabs 010
Jerry Gamblin @jgamblin.bsky.social · 12/01/2026I built Ghost CVEs this weekend to catch bugs that are public in code commits but invisible in the official registries. See what I found so far 👇 github.com/RogoLabs/Gho... #ThreatIntel #OpenSource #GhostCVEsgithub.com 010
Jerry Gamblin @jgamblin.bsky.social · 01/01/2026It’s official: 48,185 CVEs were published in 2025 (+21% YoY). 🚨 The landscape has shifted. WordPress security firms are now out-publishing Big Tech, and "Patch Tuesday" is now "Patch Every Day." See the full data review: jerrygamblin.com/2026/01/01/2...jerrygamblin.com2025 CVE Data Review 020
Jerry Gamblin @jgamblin.bsky.social · 05/12/2025London bound next week (Dec 7–15)! 🇬🇧 I’ll be at #BlackHatEU giving my talk on the "Post-NVD Era" (Thurs Dec 11 @ 2:30 PM) and then hitting up #BSidesLDN for the weekend. #Infosec #VulnMgmt #CVE 000
Jerry Gamblin @jgamblin.bsky.social · 04/12/2025A professor reached out about my 3-year-old CVElk project—it was broken. Spent some time last night fixing it: 4 live data sources, 300K+ CVEs, modern Python CLI, auto-updates. Always happy to fix old code if it helps! 🙏 github.com/jgamblin/CVElk 000
Jerry Gamblin @jgamblin.bsky.social · 01/12/20252025 CVE Growth Report (Data through Nov 30): ⚠️ Total: 42,697 CVEs (+16.9% YoY) 📅 Daily Avg: 128 📉 November Dip: Monthly volume dropped 25% YoY (3,028 CVEs), the lowest since Jan. We are still on track for a record year, sitting at +6,187 CVEs over 2024. 000
Jerry Gamblin @jgamblin.bsky.social · 27/11/2025🚨 BLACK FRIDAY DOORBUSTER 🚨 CVE.ICU just got a MASSIVE upgrade: EPSS, CISA KEV, & Risk Matrix. Our unbeatable price remains: $0.00. No credit card. No sales calls. Just vibes and vulnerabilities. #BlackFriday #CyberSecurity #OpenSource 020
Jerry Gamblin @jgamblin.bsky.social · 01/11/20252025 CVE Stats Update (October 31st, 2025) Total Number of CVEs: 39,681 Average CVEs Per Day: 130.53 Average CVSS Score: 6.61 YOY Growth: 22.42% or +7,267 (32,414 CVEs in 2024) 000
Jerry Gamblin @jgamblin.bsky.social · 23/10/2025Forget cryptocurrency—let's talk real cryptography! If you're into ciphers and code-breaking, this special on the hidden messages of Mary, Queen of Scots, is a must-watch. www.pbs.org/video/cracki...pbs.orgSecrets of the Dead | Cracking the Queen's Code | Season 22 | Episode 9See how secret letters written by Mary, Queen of Scots, were finally decoded. 000
Jerry Gamblin @jgamblin.bsky.social · 20/10/2025Spent Sunday watching football & analyzing 314,705 CVEs to track update velocity. Key takeaway: Some issues require constant attention—the top CVE, CVE-2023-4255, has been updated 220 times! See the full analysis and charts: rogolabs.github.io/CVE-Updates/ 010
Jerry Gamblin @jgamblin.bsky.social · 16/10/2025📢 New Open-Source Tool: CNAPulse.org Getting a quick, transparent overview of CNA activity was nearly impossible. It required manual processing of raw CVE data. I built CNAPulse.org to automate and bring transparency to publishing in the CVE ecosystem.cnapulse.orgCNAPulse 010
Jerry Gamblin @jgamblin.bsky.social · 01/10/20252025 CVE Stats Update (September 30th, 2025) Total Number of CVEs: 35,404 Average CVEs Per Day: 129.68 Average CVSS Score: 6.62 YOY Growth: 22.72% or +6,555 (28,849 CVEs in 2024) 000
Jerry Gamblin @jgamblin.bsky.social · 17/09/2025I've added a new page to CVEForecast.org: a CNA Forecast. It's a fun project to track the growth and decline trends. Hopefully, it provides some interesting insights for anyone in the vuln space. Check it out here: cveforecast.org/cna_forecast... #infosec #cybersecurity #vulnerability #cvecveforecast.orgCVEForecast 020
Jerry Gamblin @jgamblin.bsky.social · 12/09/2025The CVE Program is stepping into its Quality Era, and I couldn't be happier. CISA's vision prioritizes trust, quality, and responsiveness in vulnerability management. This is a fantastic step to ensure CVE data remains a public good for everyone www.cisa.gov/sites/defaul...cisa.gov 110
Jerry Gamblin @jgamblin.bsky.social · 01/09/20252025 CVE Stats Update (August 31st, 2025) Total Number of CVEs: 31,077 Average CVEs Per Day: 127.89 Average CVSS Score: 6.63 YOY Growth: 17.81% or +4,699 (26,378 CVEs in 2024) 000
Jerry Gamblin @jgamblin.bsky.social · 12/08/2025Here are my slides from #BSidesLV on "The Art of Concealment." TLDR: Many CVEs are published without the four pillars (CWE, CPE, CVSS, Fix) needed for security teams to remediate the vulnerabilities successfully. rogolabs.net/Talks/The%20...rogolabs.net 000
Jerry Gamblin @jgamblin.bsky.social · 08/08/2025At DEF CON? I'm speaking today at 1PM in the AppSec Village. Stop by to hear me talk about the post NVD era of vulnerability data. 000
Jerry Gamblin @jgamblin.bsky.social · 05/08/2025Just announced after my talk: CNAScorecard.org is LIVE! 🚀 Did you know only 2% of CVEs have CPE data and just 4.8% have patch info? This cripples automation & leaves us blind.cnascorecard.orgCNA Scorecard 011
Jerry Gamblin @jgamblin.bsky.social · 01/08/20252025 CVE Stats Update (July 31st, 2025) Total Number of CVEs: 27,447 Average CVEs Per Day: 129.47 Average CVSS Score: 6.62 YOY Growth: 17.32% or +4,053 (23,394 CVEs in 2024) 000
Jerry Gamblin @jgamblin.bsky.social · 30/07/2025Relaunched my open-source project, cve.icu! It's been completely rewritten in pure HTML—making it blazing fast & fully interactive. Designed to cut through the noise of 40k+ new vulns a year. Explore vulnerability data faster. 🚀 cve.icucve.icuCVE.ICU - CVE Analysis DashboardComprehensive CVE analysis and visualization from 1999 to present 000
Jerry Gamblin @jgamblin.bsky.social · 29/07/2025Vegas-bound! ✈️ I'm giving two talks next week on CVEs and vulnerability disclosure. First up is @bsideslv.org on Tues, 2:30pm: "The Art of Concealment: CVE's Challenge with Transparency"(thread 👇) 110
Jerry Gamblin @jgamblin.bsky.social · 19/07/2025CVEScoreCard v.06 is live. 🤖 My open-source CVE forecast now auto-tunes itself daily, learning from past runs to get more accurate. Today, it's predicting 46,796 CVEs for the year. See the live forecast: cveforecast.org #cybersecurity #cve #opensource #infoseccveforecast.orgCVEForecast 021