Make a deal with Jerry Gamblin
🔒 Paid proposals held safely in escrow — released only when the work's approved.
Known for
4 views
The bugs that get exploited are not the bugs you see most.
I mapped every CVE on CISA's Known Exploited Vulnerabilities list back to its weakness class. Two things stood out.
First, a data-quality one. The organization that reports a bug fills in the weakness class only about a third of the time. On the exploited list, roughly two-thirds of the CNA-authored records leave the CWE blank, and it only
2 views
Mid-year CVE check-in: the first half of 2026 produced 35,364 CVEs. More than any full year before 2024, and more than the program's entire first decade (1999-2008) combined. One every 7.4 minutes.
The counterweight: only 85 of them (0.24%) are on CISA's KEV list. Volume keeps climbing; confirmed exploitation stays rare. The signal-to-noise problem is the story.
Full writeup + reproducible code: h
1 views
Stop triaging by bug class.
Here are the 10 most common weakness types, lined up by the CVSS scores they actually get. The ranking looks sensible: injection and memory corruption up in the 7s and 8s (stack buffer overflow tops out at a median 8.5), the high-volume web classes down in the 5s and 6s. Folk wisdom, confirmed.
Then look at the grey band in the middle. Every one of these ten classes, to
📊 Post engagement
🔥 Top post: The bugs that get exploited are not the bugs you see most. I map · 4 likes + reposts
📊 Activity & format
Recent posts
View on Mastodon ↗
🔥 Top post
The bugs that get exploited are not the bugs you see most.
I mapped every CVE on CISA's Known Exploited Vulnerabilities list back to its weakness class. Two things stood out.
First, a data-quality one. The organization that reports a bug fills in the weakness class only about a …
A third of 2026 CVEs so far carry a CVSS v4 score, up from under 9% in 2024. Fast climb for a version that only shipped in late 2023.
Then you see who did it: VulnCheck, VulDB, and GitHub are 71% of all v4 scores. The other 200+ CNAs went …
By July 16, the 2026 CVE count hit 39,952, the entire 2024 total, with the year barely half over.
Each year now clears the two-years-earlier total sooner: mid-November in 2020, mid-August in 2025, mid-July in 2026. The earliest in this ser…
When Cisco ended the life of Cisco Vulnerability Management (formerly Kenna Security), I knew it marked the end of my time there.
So today, I'm thrilled to share that I've joined Empirical Security as Head of Research.
Back to the data, ba…
CISA added 154 CVEs to its Known Exploited Vulnerabilities list so far in 2026. Over half landed within a month of publication, but a stubborn 16% were more than three years old at listing.
I measured the gap from a CVE.org record being pu…
PURL was supposed to be the upgrade. A package-native identifier built to describe the open-source packages CPE never handled well. Here is where it actually landed in the CVE feed: about 2% of 2026 CVEs, and most of that from a single thi…
Stop triaging by bug class.
Here are the 10 most common weakness types, lined up by the CVSS scores they actually get. The ranking looks sensible: injection and memory corruption up in the 7s and 8s (stack buffer overflow tops out at a med…
A CVSS score is not a fact about a bug. It is an opinion with a decimal point.
Cross-site scripting is the most common bug on the internet. Here it is scored by 13 different organizations: the same weakness averages about a 3.4 at VulDB an…
For years, MITRE, the nonprofit that runs the CVE program, was its #1 issuer almost every month. Not anymore.
GitHub has been #1 every month of 2026. MITRE has slid to about #7.
GitHub Security Advisories are now the #1 CVE issuer (6,801). VulnCheck climbed to #3 (VulDB 🛡sits #2). The people assigning CVEs changed in 2026: platforms, ecosystems, and research CNAs now set the pace. High counts reflect scope, not pa…
Mid-year CVE check-in: the first half of 2026 produced 35,364 CVEs. More than any full year before 2024, and more than the program's entire first decade (1999-2008) combined. One every 7.4 minutes.
The counterweight: only 85 of them (0.24%…
Launching LycosAI today.
The wilderness is encroaching. We are holding the line.
Deploying autonomous wolf packs at prefecture scale to secure the rural perimeter where legacy systems have failed.
lycosai.com
🐘 Community & instance
💡 Facts
🕵️ Fake follower check
Estimated- Est. 99% real, active audience · Low fake-follower risk.
- Strong engagement (~2.6% of followers engage each post) — an active, real audience.
- Verified account.
- Established account (3+ years old).
Heuristic estimate from engagement, follower ratios, account age & growth — a screening signal, not a guarantee.
About
📸 Gallery
🔀 Audience overlap
EstimatedEstimated shared audience with similar creators — useful for avoiding overlap (or doubling down) when planning a campaign.
More like this
Find more →✉ Message Jerry Gamblin
Reaching out to influencers is a Pro feature. Upgrade to message any influencer directly — perfect for brands and agencies booking sponsorships.
- ✓ Message any influencer from their listing
- ✓ The influencer gets notified by email
- ✓ Manage every conversation in one inbox
Already Pro? Log in.
🎤 Event / appearance with Jerry Gamblin
Booking an event / appearance is a Pro feature. Upgrade to book Jerry Gamblin for an in-person or virtual appearance — payment held safely in escrow until the event is done.
- ✓ Book them for events, livestreams, panels & more
- ✓ Jerry Gamblin gets notified by email
- ✓ Fee held in escrow, released after the appearance
Already Pro? Log in.
You're out of free requests this month
Free accounts get 5 per month. Go Pro for unlimited sponsor pitches, collab requests & sponsorship deals — plus featured placement, the Verified badge, free withdrawals and more.
Upgrade to Pro — $9.95/mo →Your free limit resets on the 1st of next month.