Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Jerry Gamblin

@jgamblin@infosec.exchange
  • Open on infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

77 Followers
10 Following
39 Posts
Joined November 06, 2022
Website:
https://jerrygamblin.com
RogoLabs:
https://rogolabs.net

Posts

Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Jul 28, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange
CVSS is a severity label the industry treats like a priority list. A 9.8 tells you how bad a bug could be. It cannot tell you which 9.8 to do first. This year 4,719 CVEs carry a CVSS v3 score of 9.0 or higher. Half of them, 2,493, land on the identical 9.8, the arithmetic result of a remote, unauthenticated, full-impact vector. Nine distinct scores exist in the entire critical band. There is no 9.5 and no 9.7. That is the resolution you are triaging with. Rank the same 4,719 by EPSS percentile and the median lands at the 37th, so half the drop-everything tier ranks below 63% of all CVEs. Cut at the 90th percentile and 211 CVEs hold 49 of the 54 now on CISA's KEV list. One caveat: EPSS reads exploitation signal, and all 54 were listed before these scores were computed, so that is two sources agreeing, not a prediction. It still gives you an order. 9.8 does not. 2,493 CVEs this year share one score. If your tooling had to put them in a fix order tomorrow morning, what field would it sort on, and who would argue with you about it? #vulnerabilitymanagement #cybersecurity #CVE
4
2
4
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Jul 22, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange
Off to Vegas for Summer Camp. New role at Empirical Security (Head of Research, working on EPSS), a CVE panel at BSidesLV, a Black Hat luncheon on autonomous exploitation, and a curated list of the 18 CVE and vulnerability talks I would clear my calendar for across BSidesLV, Black Hat, and DEF CON. The data behind it: H1 2026 gave us 34,601 CVEs, but only 0.24% are in CISA KEV. That gap is the whole game. Full rundown: https://jerrygamblin.com/2026/07/22/hydrate-hack-repeat-security-summer-camp-2026/
3
0
2
1
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Jul 21, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange
A third of 2026 CVEs so far carry a CVSS v4 score, up from under 9% in 2024. Fast climb for a version that only shipped in late 2023. Then you see who did it: VulnCheck, VulDB, and GitHub are 71% of all v4 scores. The other 200+ CNAs went from ~4% to ~10%, real growth but nowhere near those three. Most of the rise of v4 is in three organizations.
0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Jul 17, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange
By July 16, the 2026 CVE count hit 39,952, the entire 2024 total, with the year barely half over. Each year now clears the two-years-earlier total sooner: mid-November in 2020, mid-August in 2025, mid-July in 2026. The earliest in this series. The two-years-ago total is now a summer checkpoint, not a year-end line.
0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Jul 16, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

When Cisco ended the life of Cisco Vulnerability Management (formerly Kenna Security), I knew it marked the end of my time there.

So today, I'm thrilled to share that I've joined Empirical Security as Head of Research.

Back to the data, back to building, back home.

https://research.empiricalsecurity.com/research/country-roads-take-me-home

1
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Jul 14, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

CISA added 154 CVEs to its Known Exploited Vulnerabilities list so far in 2026. Over half landed within a month of publication, but a stubborn 16% were more than three years old at listing.

I measured the gap from a CVE.org record being published to that CVE landing on KEV. Most move fast: about three-quarters are listed within a year of publication. That tracks with how we picture exploitation: a new bug, a quick confirmation, onto the list.

But 16% break the pattern, more than three years old when CISA lists them, including a 2008 Windows bug (nearly 18 years) and a 2009 Office bug (about 17). Listing dates cannot tell us whether that exploitation is new or long-running, only that CISA confirmed it years after disclosure.

#vulnerabilitymanagement #cybersecurity #CVE

0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Jul 13, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

PURL was supposed to be the upgrade. A package-native identifier built to describe the open-source packages CPE never handled well. Here is where it actually landed in the CVE feed: about 2% of 2026 CVEs, and most of that from a single third-party CNA.

As CNAs write them, 75% of CVEs carry neither CPE nor PURL. Then NVD and CISA go to work: they backfill CPEs and cut that no-ID pile to 41%. Every point of that improvement is CPE. They add zero PURLs, and not by choice. NVD has no PURL field to fill.

Here is the strange part. PURL is alive and well outside this pipeline, in OSV, GitHub Security Advisories, and every SBOM and SCA tool. It just never made it into the CVE and NVD pipeline that most of the industry still triages from. The problem is not PURL. It is that the feed everyone relies on structurally cannot see it. How long do we keep matching CVEs to assets through a format that cannot name a package?

#vulnerabilitymanagement #cybersecurity #CVE

0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Jul 11, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange
The bugs that get exploited are not the bugs you see most. I mapped every CVE on CISA's Known Exploited Vulnerabilities list back to its weakness class. Two things stood out. First, a data-quality one. The organization that reports a bug fills in the weakness class only about a third of the time. On the exploited list, roughly two-thirds of the CNA-authored records leave the CWE blank, and it only reaches about 90% coverage because NVD and CISA's enrichment program (ADP) go back and add it. Pull the class from the CNA feed alone and it is nearly empty. Pull it from NVD or CISA and it is nearly complete. Same bugs, very different picture depending on who you ask. Now the finding. Using the enriched data, exploitation concentrates in two families. Memory corruption: out-of-bounds writes, use-after-free, buffer errors, type confusion. And code execution: OS command injection, code injection, deserialization. Add improper input validation and broken authentication, and you have most of the list. Notice what is missing. Cross-site scripting is the single most common weakness on the internet, tens of thousands of CVEs, and it barely registers here. CSRF does not make the top 12 at all. The classes that flood your feed by volume are not the ones attackers reach for. So "most common" and "most exploited" are nearly different lists, and the CWE data is only as complete as the source you pull it from. Ranking a backlog by volume, or by raw CVSS, points you at the wrong shelf. Which of these classes is your program actually resourced to find? #vulnerabilitymanagement #cybersecurity #CVE
3
0
1
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Jul 10, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange
Stop triaging by bug class. Here are the 10 most common weakness types, lined up by the CVSS scores they actually get. The ranking looks sensible: injection and memory corruption up in the 7s and 8s (stack buffer overflow tops out at a median 8.5), the high-volume web classes down in the 5s and 6s. Folk wisdom, confirmed. Then look at the grey band in the middle. Every one of these ten classes, top to bottom, has a stack of vulnerabilities in the same 6.3 to 7.1 window. Pull a CVE scored 6.5 and it could be any of them. The class does not pin the score, and the score does not pin the class. And the ranking itself is soft. Within a single weakness type the middle 80% of scores spans three to four and a half points, so knowing a bug is "an XSS" or "a path traversal" tells you little about its severity. The category is not destiny either: out-of-bounds read is a memory bug like the top-ranked stack overflow, yet it sits near the bottom. So a "critical CWE" is not really a thing. The class shifts the odds, but severity lives in the specific bug. Which weakness class do you think your program over-weights, and which does it wave through? #vulnerabilitymanagement #cybersecurity #CVE
1
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Jul 09, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

A CVSS score is not a fact about a bug. It is an opinion with a decimal point.

Cross-site scripting is the most common bug on the internet. Here it is scored by 13 different organizations: the same weakness averages about a 3.4 at VulDB and about a 6.7 at Microsoft. Same bug class, same scoring system, more than a full severity band apart.

Most of that spread is really one organization. VulDB sits alone at the bottom while the other twelve cluster between 5.5 and 6.7. So the real question is why VulDB reads the same bugs so much lower.

The biggest reason is not the metric people argue about. It is whether an XSS leaks data at all. VulDB scores confidentiality impact as None on essentially every XSS, treating it as a bug that can alter a page but not read anything. Almost everyone else scores it Low: an XSS can read the page, lift a session token, scrape what the victim can see. That single call is worth about 1.4 points, the largest lever in the whole vector.

VulDB then stacks two more conservative calls on top: it marks XSS as not crossing a trust boundary (Scope:Unchanged) where most others mark it Changed, and it usually requires the attacker to already have some privilege. Each is worth about half as much as the confidentiality call. That is the twist: Scope is the metric the community argues about most for XSS, yet the quieter confidentiality call moves the score twice as far.

None of these orgs is being sloppy. They are applying the same defined metrics to a genuinely ambiguous bug and landing in different places, and no single dial orders them. The number just depends on who holds the pen.

When a CVE carries two different CVSS scores, which one does your program actually use?

#vulnerabilitymanagement #cybersecurity #CVE

0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Jul 07, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

For years, MITRE, the nonprofit that runs the CVE program, was its #1 issuer almost every month. Not anymore.

GitHub has been #1 every month of 2026. MITRE has slid to about #7.

0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Jul 02, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange
GitHub Security Advisories are now the #1 CVE issuer (6,801). VulnCheck climbed to #3 (VulDB 🛡sits #2). The people assigning CVEs changed in 2026: platforms, ecosystems, and research CNAs now set the pace. High counts reflect scope, not padding. https://jerrygamblin.com/2026/07/01/3528/
0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Jul 01, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

Mid-year CVE check-in: the first half of 2026 produced 35,364 CVEs. More than any full year before 2024, and more than the program's entire first decade (1999-2008) combined. One every 7.4 minutes.

The counterweight: only 85 of them (0.24%) are on CISA's KEV list. Volume keeps climbing; confirmed exploitation stays rare. The signal-to-noise problem is the story.

Full writeup + reproducible code: https://jerrygamblin.com/2026/07/01/3528/

1
0
1
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · May 17, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

Launching LycosAI today.

The wilderness is encroaching. We are holding the line.

Deploying autonomous wolf packs at prefecture scale to secure the rural perimeter where legacy systems have failed.

lycosai.com

1
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · May 01, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

April 2026 CVE Stats:
🚨 5,820 New CVEs (+44% YoY)
📊 175/day avg
📈 YTD: 20,991 (+31% YoY)
🔥 Median CVSS: 7.0

Top CWEs:
1️⃣ XSS (588)
2️⃣ Path Traversal (238)
3️⃣ Missing Auth (235)
4️⃣ SQLi (218)

#InfoSec #CyberSecurity #CVE

infosec.exchange

Infosec Exchange

1
0
1
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Apr 19, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

Version 2 of my CVE Intelligence TA for
Splunk is live on Splunkbase.

I’ve added EPSS probability, CISA KEV status, and SSVC data to the baseline for 327k+ vulnerabilities.

No API keys, zero-config, and pre-joined lookups for faster triage.

Full details and download: https://jerrygamblin.com/2026/04/18/prioritizing-what-matters-bringing-cve-intelligence-to-splunk/

6
0
4
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Apr 15, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

When the NVD and GitHub disagree on a CVSS score, who do you trust?

I’m at #VulnCon and built Vuln Anarchy to visualize the scoring gap. This chart shows nearly 1,500 instances where the math doesn't align.

Live Data: https://rogolabs.github.io/vuln-anarchy/
Repo: https://github.com/RogoLabs/vuln-anarchy

4
1
4
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Apr 09, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

Paid $25 on eBay for a 1943 cryptography book. It arrived signed by LTC George R. Eckman, the Executive Officer of the Alsos Mission, the WWII task force that hunted Nazi nuclear scientists across Europe.

It's going to the U.S. Army Intelligence Hall of Fame. Some books belong in archives. 🔐

0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Apr 07, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

I heard you like CVEs, so I reported CVEs in your CVE filing software.

I reported and fixed CVE-2026-35466 & CVE-2026-35467 in CVEClient.

https://github.com/CERTCC/cveClient

0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Apr 01, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

@0x00string@infosec.exchange So many WordPress vulnerabilities!

infosec.exchange

Nullstring 🏴‍☠️ (@0x00string@infosec.exchange) - Infosec Exchange

0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Apr 01, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

@0x00string@infosec.exchange Yeah, it's a ton.

infosec.exchange

Nullstring 🏴‍☠️ (@0x00string@infosec.exchange) - Infosec Exchange

0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Apr 01, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

March 2026 was a brutal month for vulnerabilities. 🛡️

Here is the damage:
• 6,246 new CVEs (+55.7% Over Last March)
• 169 new vulns per day 🤯
• 7.1 median CVSS severity (High)

The Top 3 Culprits:
🥇 XSS (730)
🥈 SQLi (325)
🥉 Missing Auth (292)

2026 is already up 27% YoY.

2
0
2
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Mar 24, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

The "Zero Day Clock" is a Masterclass in Bad Data Science.

I've heard this clock mentioned multiple times at #RSAC this week. It predicts an "exponential collapse" of the time-to-exploit (TTE) toward zero. It makes for a scary keynote slide, but the math is fundamentally broken.

The model suffers from:

Right-Censoring: It ignores that slow exploits for 2025 haven't happened yet, artificially forcing the "average" to zero.

Selection Bias: It only tracks the fastest 1.5% of vulnerabilities and ignores the "long tail."

Administrative Lag: It mistakes the growing NVD backlog for "attacker velocity."

We don’t need hyperbolic "scare-ware" statistics to justify our urgency. Defense is hard enough without distorting the data.

I’ve written a full technical audit on why this methodology fails a basic statistical peer review:

Technical Breakdown: https://gist.github.com/jgamblin/91f7843b62069616c951f32957c921cd

#RSAC #RSAC2026 #Infosec #CyberSecurity #DataScience #VulnerabilityManagement

3
1
2
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Mar 19, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

I just read this essay by Kenneth Reitz, and it’s a powerful, necessary look at the "hidden human cost" of the tech industry.

Kenneth pulls back the curtain on how Open Source can build a career while simultaneously draining a person's spirit. He captures the "identity fusion" that happens when we tie our entire self-worth to our code.

It’s a sentiment that has hit home for me in the past. At times, I've had to wrestle with that nagging internal voice that says, "I am only as valuable as my last project." It’s an exhausting mindset to break—the feeling that your worth has an expiration date unless you’re constantly shipping something new. Reading this was a vital reminder that we are more than our output.

A final note: Kenneth’s story reminds us that these pressures can sometimes reach an extreme. If you ever find yourself struggling with these feelings to the point of feeling unmanageable, seeking professional help is a sign of strength. We are humans first, developers second.

https://kennethreitz.org/essays/2026-03-18-open_source_gave_me_everything_until_i_had_nothing_left_to_give

Open Source Gave Me Everything Until I Had Nothing Left to Give
Kenneth Reitz

Open Source Gave Me Everything Until I Had Nothing Left to Give

I thought I was having a spiritual awakening. I was having a psychiatric emergency. I was at a tech conference in Sweden when it started. I hadn't slept in...

0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Mar 11, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

RE: @gcve@social.circl.lu

GCVE now allows publishing.

1
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Mar 01, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

February 2026 CVE Growth Report:

YTD (February):
▸ 8,932 total CVEs (+12.4% vs 2025 YTD)
▸ 151 new vulnerabilities per day
▸ +982 more CVEs than 2025 through February

February alone:
▸ 4,619 CVEs (+25.7% vs February 2025)

1
0
1
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Feb 25, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

The CVE Board January minutes read like a gossip mag for vuln geeks.

Good: The March "funding cliff" is a myth—the lights are staying on.

Bad: Mystery draft legislation wants to force "International Participation" & limit "Organizational Concentration."

Drama: The Board is already at 22 members with no term limits, but they just voted to interview #23.

Full gossip here: https://www.mail-archive.com/cve-editorial-board-list@mitre.org/msg00314.html

0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Feb 21, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

Just wrapped up my talk at #BSidesGalway and officially launched VulnRadar!

I built this to show how any team can create a high-fidelity vulnerability intelligence capability for $0 in cloud spend. It’s about shifting from passive consumption to engineering autonomy.

The Highlights:

Serverless: Runs entirely on GitHub Actions with zero infrastructure overhead.

No APIs: Harvests directly from NVD, CVE List V5, and CISA KEV—no rate limits or auth headaches.

Contextual: Uses a simple watchlist.yaml to filter for the specific tech you actually run.

Actionable: Automatically creates GitHub Issues and triggers Slack/Discord alerts.

If you're here in Galway, let’s grab a coffee and talk shop! ☕

Code: https://github.com/RogoLabs/vulnradar

Slides: https://rogolabs.net/Talks/BSides-Galway-Open-Source-Intelligence.pdf

#CyberSecurity #InfoSec #OSINT #OpenSource #VulnerabilityManagement #RogoLabs #BSidesGalway

12
1
10
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Feb 18, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

The @openclaw project has exploded this month. 🛡️

Since I've given it deep local access, I’m tracking its security in real-time.

📈 92 Advisories
🚨 55 High/Critical
🔄 Hourly V5 sync

Link: https://github.com/jgamblin/OpenClawCVEs/
Plot twist: I had OpenClaw build the tracker for me. 🤖

GitHub

GitHub - jgamblin/OpenClawCVEs: Tracking OpenClaw CVEs

Tracking OpenClaw CVEs. Contribute to jgamblin/OpenClawCVEs development by creating an account on GitHub.

1
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Feb 15, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

Vulnerability intel shouldn’t be a luxury.

Next week at @BSidesGalway, I’m launching VulnRadar:
✅ 100% Open Source
✅ Runs on free @github@infosec.exchange services
✅ NO API keys to manage

Good intel is a community necessity. Let’s make it the standard.

#BSidesGalway #CyberSecurity #OSS

infosec.exchange

Github (@github@infosec.exchange) - Infosec Exchange

3
0
1
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Feb 01, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

Jan 2026 CVEs: 4,319.

While +1.0% YoY looks flat, it's 139 CVEs/day—nearly 7% HIGHER than 2025's average.

0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Jan 12, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

Finding CVEs that technically "don't exist" yet. 🕵️‍♂️

Ghost CVEs are live. A "Ghost CVE" is a vulnerability identifier that’s already popped up in the wild—think GitHub commits or security advisories—but is still listed as RESERVED or NOT_FOUND in official registries like NVD or MITRE.

It catches the threats that are already out there, even if the paperwork says they aren't. 📝💨

Admittedly, there are a lot more sources to add—this was just a quick weekend POV—but I plan on extending it soon.

Check out the latest ghost report here: https://github.com/RogoLabs/GhostCVEs/blob/main/reports/ghost_report.md

#InfoSec #ThreatIntel #OpenSource #GhostCVEs

8
0
4
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Jan 01, 2026
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

It’s official: 48,185 CVEs were published in 2025 (+21% YoY). 🚨

The landscape has shifted. WordPress security firms are now out-publishing Big Tech, and "Patch Tuesday" is now "Patch Every Day."

See the full data review:
https://jerrygamblin.com/2026/01/01/2025-cve-data-review/

0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Dec 05, 2025
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

London bound next week (Dec 7–15)! 🇬🇧

I’ll be at #BlackHatEU giving my talk on the "Post-NVD Era" (Thurs Dec 11 @ 2:30 PM) and then hitting up #BSidesLDN for the weekend.

#Infosec #VulnMgmt #CVE

0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Dec 04, 2025
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

A professor reached out about my 3-year-old CVElk project—it was broken. Spent some time last night fixing it: 4 live data sources, 300K+ CVEs, modern Python CLI, auto-updates.

Always happy to fix old code if it helps! 🙏

github.com/jgamblin/CVElk

0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Dec 01, 2025
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

2025 CVE Growth Report (Data through Nov 30):

⚠️ Total: 42,697 CVEs (+16.9% YoY)
📅 Daily Avg: 128
📉 November Dip: Monthly volume dropped 25% YoY (3,028 CVEs), the lowest since Jan.

We are still on track for a record year, sitting at +6,187 CVEs over 2024.

0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Nov 27, 2025
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

🚨 BLACK FRIDAY DOORBUSTER 🚨

CVE.ICU just got a MASSIVE upgrade: EPSS, CISA KEV, & Risk Matrix.

Our unbeatable price remains: $0.00.

No credit card. No sales calls. Just vibes and vulnerabilities.

#BlackFriday #CyberSecurity #OpenSource

0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Nov 01, 2025
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

2025 CVE Stats Update (October 31st, 2025)
Total Number of CVEs: 39,681
Average CVEs Per Day: 130.53
Average CVSS Score: 6.61
YOY Growth: 22.42% or +7,267 (32,414 CVEs in 2024)

0
0
0
0
Open post
jgamblin
Jerry Gamblin @jgamblin@infosec.exchange · Oct 23, 2025
Jerry Gamblin
@jgamblin@infosec.exchange

Bringing clarity to vulnerability intelligence through open-source tools. Founder of RogoLabs | Creator of http://cve.icu & http://patchthis.app.

infosec.exchange

Forget cryptocurrency—let's talk real cryptography! If you're into ciphers and code-breaking, this special on the hidden messages of Mary, Queen of Scots, is a must-watch. https://www.pbs.org/video/cracking-the-queens-code-sp1wq9/

0
0
0
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 01:08:07 UTC