Remote
Rob Pomeroy
@robpomeroy@infosec.exchange
TLDR: #infosec #cloud #devops #OpenSource #JC #MostlyHarmless
👋🏻🔒 Friendly British Security/Technology wonk.
😇🙏 Good guy wannabe.
✍🏻👽 Sci-fi author.
👦🏻👦🏻 Father to twins (one passed away 24 Feb 2024) with severe learning difficulties and other disabilities.
🦸🏻♀️ Husband to superhero wife.
⚖️ Solicitor (no longer practising law though).
✝️ To everything there is a season.
🔐👍🏻 Visit my website for secure/private methods of contacting me
800 Followers
898 Following
7 Posts
Joined June 14, 2019
Website 🌍:
GitHub 👨🏻💻:
Keybase 🔑:
BrightOS 💡:
A patch-lag leaderboard is less useful than it looks. The vendor that publishes a discovery date is double-reporting; the one that doesn't shows a misleading zero. The metric that matters is disclosure-to-patch for known-exploited bugs.
https://vulntrends.org/blog/which-vendors-patch-the-fastest/
#patching #vulnerabilities #msrc #mttp #infosec
Open post
I've released VulnTrends v1.2.0.
Rather than adding lots of new features, this update focuses on improving the foundations:
• Higher quality data
• Better analysis
• New explanatory pages describing each metric and its limitations
• Greater transparency into how the charts are produced
The aim is to make VulnTrends a useful reference for understanding vulnerability disclosure and remediation trends—not just another CVE counter.
Feedback is always welcome.
https://vulntrends.org
Release notes:
https://github.com/robpomeroy/vulntrends/releases/tag/v1.2.0
#cybersecurity #opensource #infosec #analytics #bugpocalpyse #vulnpocalypse
1
0
0
0
Open post
Some people spend their holiday time on the beach. I play with websites, apparently. Don't tell Mrs P.
I've enhanced the data gathered for my open source project VulnTrends (v1.1.0), and the picture is even more pronounced than the project originally showed. It's impossible (and irresponsible) to ignore the impact of frontier (or well-harnessed) LLMs on vulnerability discovery.
Will there be a growing disparity between discovery and remedation? That remains to be seen. What IS certain is that the severity and quantity of bugs now discovered place immense pressure on patching. The loop (download, test, pilot, release) needs to be tighter than ever.
https://vulntrends.org
#bugpocalpyse #ai #llm #vulnerabilities
1
0
1
0
Open post
We've all been talking about AI accelerating vulnerability discovery, but I hadn't seen a good way to visualise it.
So I built https://vulntrends.org/
The "Vulnerabilities Discovered" graph, tracking major vendors over time, makes the recent acceleration very hard to ignore.
Feedback welcome.
0
0
0
0
Open post
Is software security actually improving?
It's tempting to judge by the ever-increasing number of CVEs, but vulnerability counts tell only part of the story.
In this article I explore the difference between vulnerability discovery and software quality, why modern engineering practices have improved security, and how AI could fundamentally change the balance between finding and fixing bugs.
I'd love to hear your thoughts.
https://vulntrends.org/blog/software-security-actually-improving/
0
1
0
0
Open post
The arrival of 622 CVEs in a single Patch Tuesday is the visible signal of something that has been happening for years: discovery is now machine-speed, and a once-a-month batched disclosure is straining to keep up.
Read more: https://vulntrends.org/blog/the-evolution-of-patch-tuesday/
#vulnerabilities #PatchTuesday #AISecurity #Microsoft
0
0
0
0
