Rob Pomeroy
robpomeroy@infosec.exchange
<p>TLDR: <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="tag">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/cloud" class="mention hashtag" rel="tag">#<span>cloud</span></a> <a href="https://infosec.exchange/tags/devops" class="mention hashtag" rel="tag">#<span>devops</span></a> <a href="https://infosec.exchange/tags/OpenSource" class="mention hashtag" rel="tag">#<span>OpenSource</span></a> <a href="https://infosec.exchange/tags/JC" class="mention hashtag" rel="tag">#<span>JC</span></a> <a href="https://infosec.exchange/tags/MostlyHarmless" class="mention hashtag" rel="tag">#<span>MostlyHarmless</span></a></p><p>ππ»π Friendly British Security/Technology wonk.</p><p>ππ Good guy wannabe.<br />βπ»π½ Sci-fi author.<br />π¦π»π¦π» Father to twins (one passed a
Posts
-
View post
A patch-lag leaderboard is less useful than it looks. The vendor that publishes a discovery date is double-reporting; the one that doesn't shows a misleading zero. The metric that matters is disclosure-to-patch for known-exploited bugs. https://vulntrends.org/blog/which-vendors-patch-the-fastest/ #patching #vulnerabilities #msrc #mttp #infosec
-
View post
The arrival of 622 CVEs in a single Patch Tuesday is the visible signal of something that has been happening for years: discovery is now machine-speed, and a once-a-month batched disclosure is straining to keep up. Read more: https://vulntrends.org/blog/the-evolution-of-patch-tuesday/ #vulnerabilities #PatchTuesday #AISecurity #Microsoft
-
View post
I've released VulnTrends v1.2.0. Rather than adding lots of new features, this update focuses on improving the foundations: β’ Higher quality data β’ Better analysis β’ New explanatory pages describing each metric and its limitations β’ Greater transparency into how the charts are produced The aim is to make VulnTrends a useful reference for understanding vulnerability disclosure and remediation trendsβnot just another CVE counter. Feedback is always welcome. https://vulntrends.org Release...
-
View post
Some people spend their holiday time on the beach. I play with websites, apparently. Don't tell Mrs P. I've enhanced the data gathered for my open source project VulnTrends (v1.1.0), and the picture is even more pronounced than the project originally showed. It's impossible (and irresponsible) to ignore the impact of frontier (or well-harnessed) LLMs on vulnerability discovery. Will there be a growing disparity between discovery and remedation? That remains to be seen. What IS cert...
-
View post
Is software security actually improving? It's tempting to judge by the ever-increasing number of CVEs, but vulnerability counts tell only part of the story. In this article I explore the difference between vulnerability discovery and software quality, why modern engineering practices have improved security, and how AI could fundamentally change the balance between finding and fixing bugs. I'd love to hear your thoughts. https://vulntrends.org/blog/software-security-actually-improving...
-
View post
We've all been talking about AI accelerating vulnerability discovery, but I hadn't seen a good way to visualise it. So I built https://vulntrends.org/ The "Vulnerabilities Discovered" graph, tracking major vendors over time, makes the recent acceleration very hard to ignore. Feedback welcome.