from/prod
← All companies

THE COMPANY INDEX TRACKED BLOG

Jerry Gamblin

Ideas, decisions, and lessons from the team.

jerrygamblin.com (opens on the source site)
12Posts tracked
6 days agoLatest publication
0.7Posts / month over the last 12 months

Latest writing

12 of 12 posts

Decision Models vs. CVE Data (opens on the source site)

Ollama’s new decision endpoint, Cloudflare’s Clef models on a MacBook, and two questions asked of all 27,489 CVEs published in the last 60 days: does the description say why the bug matters, and is it clear? I read the announcement and had a weekend project before I finished it, because the question I care about ... Read more

Read at the source

Hydrate, Hack, Repeat: Security Summer Camp 2026 (opens on the source site)

My schedule, a new role at Empirical Security, and the CVE and vulnerability talks worth your time. It is almost the first week of August, which means it is time to point myself at the desert one more time. BSides Las Vegas, Black Hat, and DEF CON all land back to back, and for me ... Read more

Read at the source

Good Data For Bad Golf (opens on the source site)

I play golf. I am not good at golf. But I have a Garmin Approach R10 launch monitor, a Python interpreter, and too much free time, so naturally I spent way more time building a dashboard to analyze my swing data than I did actually swinging a club. The result is jgamblin/golf, a self-hosted analytics ... Read more

Read at the source

2025 CVE Data Review (opens on the source site)

2025 set a new baseline with 48,185 published CVEs. While the sheer volume is climbing, the median CVSS score remained surprisingly stable. We are seeing a distinct shift toward web application flaws (specifically in the CMS ecosystem) and a wider distribution of vendors, proving that vulnerabilities are spreading deeper into the supply chain. This massive growth ... Read more

Read at the source

A New Era of Transparency for CVE Data Quality (opens on the source site)

I’m incredibly excited to finally share something I’ve been pouring my heart into at RogoLabs. For those of you who caught my talk at BSidesLV, you got a sneak peek, but today it’s official: CNAScorecard.org is live! For years, the CVE program has been our shared language for identifying vulnerabilities. But lately, we’ve all felt ... Read more

Read at the source

Vegas Bound for Security Summer Camp! (opens on the source site)

It’s that time of year again! The first week of August means my annual trip to the desert for “Security Summer Camp”—the whirlwind of BSides Las Vegas, Black Hat, and DEF CON. It’s always an exhausting but amazing week, and I can’t wait to dive in, catch up with everyone, and talk about what I’ve ... Read more

Read at the source

2024 CVE Data Review (opens on the source site)

2024 brought unprecedented growth in CVE data, so I figured it would be appropriate to start the new year by exploring these statistics and highlighting some of the more intriguing data points. CVEs By The Numbers We ended 2024 with 40,009 published CVEs, up over 38% from the 28,818 CVEs published in 2023. CVEs By Month Month ... Read more

Read at the source

Celebrating 25 Years of CVE’s (opens on the source site)

The Common Vulnerabilities and Exposures (CVE) program, launched in late October 1999, has not only marked its presence but has become a pivotal force in shaping how we perceive and manage cybersecurity threats. A Journey Through Time The CVE program emerged as a beacon, standardizing how vulnerabilities are identified, shared, and mitigated. From its inception ... Read more

Read at the source

Privacy choices

Reading never requires analytics. These choices last 90 days on this browser.

Essential sign-in and security storage always stays on. Read the privacy notice.