# Jerry Gamblin

Curiosity in Practice

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## RBP Tracker: Counting the CVE IDs the CVE List Cannot See

DevFeed: [RBP Tracker: Counting the CVE IDs the CVE List Cannot See](<https://devfeed.tech/articles/rbp-tracker-counting-the-cve-ids-the-cve-list-cannot-see-27481.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2026/09/14/rbp-tracker-counting-the-cve-ids-the-cve-list-cannot-see/>)

Author: jgamblin

Published: 2026-09-14T14:16:42Z

Content type: article

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [NVD](<https://devfeed.tech/topics/nvd.md>), [API](<https://devfeed.tech/topics/api.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-list](<https://devfeed.tech/tags/cve-list.md>), [data](<https://devfeed.tech/tags/data.md>), [ids](<https://devfeed.tech/tags/ids.md>), [list](<https://devfeed.tech/tags/list.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [report](<https://devfeed.tech/tags/report.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [source](<https://devfeed.tech/tags/source.md>), [state](<https://devfeed.tech/tags/state.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>)

### AI overview

The article examines a corrected RogoLabs tracker for Reserved but Public CVE IDs. It explains that the CVE Services API returns 404 for reserved IDs, while a separate unauthenticated endpoint reveals their RESERVED state. The tracker lists IDs from public advisory feeds and describes how reserved records are absent from the bulk CVE List until publication.

### Source excerpt

A new RogoLabs site lists Reserved but Public CVE IDs: 2,315 of them on September 14, drawn from 17 public advisory feeds, refreshed every six hours, and held a week before they appear. The first version of this tracker reported that none of the CVE IDs it found existed in the CVE List, in any ... Read more

## 10,501 Radios in Seven Days: What a $69 Badge Heard at Summer Camp

DevFeed: [10,501 Radios in Seven Days: What a $69 Badge Heard at Summer Camp](<https://devfeed.tech/articles/10-501-radios-in-seven-days-what-a-69-badge-heard-at-summer-camp-27480.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2026/08/10/10501-radios-in-seven-days-what-a-69-badge-heard-at-summer-camp/>)

Author: jgamblin

Published: 2026-08-10T13:07:44Z

Content type: article

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [Bluetooth](<https://devfeed.tech/topics/bluetooth.md>), [MicroPython](<https://devfeed.tech/topics/micropython.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [Networks](<https://devfeed.tech/topics/networks.md>)

Tags: [black-hat](<https://devfeed.tech/tags/black-hat.md>), [bluetooth](<https://devfeed.tech/tags/bluetooth.md>), [bsides](<https://devfeed.tech/tags/bsides.md>), [capture](<https://devfeed.tech/tags/capture.md>), [claude](<https://devfeed.tech/tags/claude.md>), [devices](<https://devfeed.tech/tags/devices.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [micropython](<https://devfeed.tech/tags/micropython.md>), [networks](<https://devfeed.tech/tags/networks.md>), [open](<https://devfeed.tech/tags/open.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>)

### AI overview

A seven-day passive listening project using a Pimoroni Tufty 2350 examined WiFi and Bluetooth activity at BSides, Black Hat, and DEF CON. The article reports 4,653 access points and 5,848 Bluetooth devices, including 673 open networks and a beacon flooder that advertised 77 fake networks. It also explains why rotating addresses can inflate device counts and documents important limitations, including 2.4 GHz-only WiFi coverage.

### Source excerpt

Seven days of passive listening at BSides, Black Hat and DEF CON: 673 open networks, one beacon flooder, and what it takes to count devices honestly. I have wanted to build one of these for a long time. A little screen on my bag that tells me what the air around me is actually made ... Read more

## Hydrate, Hack, Repeat: Security Summer Camp 2026

DevFeed: [Hydrate, Hack, Repeat: Security Summer Camp 2026](<https://devfeed.tech/articles/hydrate-hack-repeat-security-summer-camp-2026-27479.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2026/07/22/hydrate-hack-repeat-security-summer-camp-2026/>)

Author: jgamblin

Published: 2026-07-22T21:34:54Z

Content type: opinion

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [data](<https://devfeed.tech/topics/data.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ai](<https://devfeed.tech/tags/ai.md>), [black-hat](<https://devfeed.tech/tags/black-hat.md>), [bsides](<https://devfeed.tech/tags/bsides.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [con](<https://devfeed.tech/tags/con.md>), [cves](<https://devfeed.tech/tags/cves.md>), [data](<https://devfeed.tech/tags/data.md>), [kev-catalog](<https://devfeed.tech/tags/kev-catalog.md>), [management](<https://devfeed.tech/tags/management.md>), [models](<https://devfeed.tech/tags/models.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [talks](<https://devfeed.tech/tags/talks.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

A personal guide to the author's 2026 security conference schedule, new role as Head of Research at Empirical Security, and recommended CVE and vulnerability talks. It argues that effective vulnerability management requires granular, transparent, accurate data, citing the growth in CVEs and the limited share listed in CISA KEV.

### Source excerpt

My schedule, a new role at Empirical Security, and the CVE and vulnerability talks worth your time. It is almost the first week of August, which means it is time to point myself at the desert one more time. BSides Las Vegas, Black Hat, and DEF CON all land back to back, and for me ... Read more

## CVE Mid-Year 2026 Check-In: Volume Vertical, Exploitation Rare

DevFeed: [CVE Mid-Year 2026 Check-In: Volume Vertical, Exploitation Rare](<https://devfeed.tech/articles/cve-mid-year-2026-check-in-volume-vertical-exploitation-rare-27478.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2026/07/01/3528/>)

Author: jgamblin

Published: 2026-07-01T15:47:10Z

Content type: article

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Statistics](<https://devfeed.tech/topics/statistics.md>), [cisa](<https://devfeed.tech/topics/cisa.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [comparison](<https://devfeed.tech/tags/comparison.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [statistics](<https://devfeed.tech/tags/statistics.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This mid-year review finds that 35,364 CVEs were published in the first half of 2026, up 49.5% from the same period in 2025, while only 85 had entered CISA's KEV list. The article argues that the main challenge is distinguishing exploitable vulnerabilities from the rapidly growing volume of disclosures.

### Source excerpt

We are halfway through 2026, so it is time for the mid-year CVE check-in. The short version: the volume curve has gone vertical while exploitation has not. This review covers everything published in the first half of 2026 (Jan 1 - Jun 30, 2026), the volume, the severity, what is actually being exploited, and who ... Read more

## Good Data For Bad Golf

DevFeed: [Good Data For Bad Golf](<https://devfeed.tech/articles/good-data-for-bad-golf-27477.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2026/05/13/good-data-for-bad-golf/>)

Author: jgamblin

Published: 2026-05-13T14:05:06Z

Content type: article

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [Python](<https://devfeed.tech/topics/python.md>), [CSV](<https://devfeed.tech/topics/csv.md>), [GitHub Pages](<https://devfeed.tech/topics/github-pages.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>)

Tags: [analytics-pipeline](<https://devfeed.tech/tags/analytics-pipeline.md>), [csv](<https://devfeed.tech/tags/csv.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [github-pages](<https://devfeed.tech/tags/github-pages.md>), [pipeline](<https://devfeed.tech/tags/pipeline.md>), [python](<https://devfeed.tech/tags/python.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>)

### AI overview

The article presents jgamblin/golf, a self-hosted Python analytics pipeline that converts Garmin Golf app CSV exports into a multi-page GitHub Pages dashboard. It describes features including session analysis, club-level consistency, session replay, gapping, coaching recommendations, and data-quality tracking, with deployment automated through GitHub Actions.

### Source excerpt

I play golf. I am not good at golf. But I have a Garmin Approach R10 launch monitor, a Python interpreter, and too much free time, so naturally I spent way more time building a dashboard to analyze my swing data than I did actually swinging a club. The result is jgamblin/golf, a self-hosted analytics ... Read more

## Prioritizing What Matters: Bringing CVE Intelligence to Splunk

DevFeed: [Prioritizing What Matters: Bringing CVE Intelligence to Splunk](<https://devfeed.tech/articles/prioritizing-what-matters-bringing-cve-intelligence-to-splunk-27476.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2026/04/18/prioritizing-what-matters-bringing-cve-intelligence-to-splunk/>)

Author: jgamblin

Published: 2026-04-18T23:50:46Z

Content type: release

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [FIRST](<https://devfeed.tech/topics/first.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [net](<https://devfeed.tech/tags/net.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

An update to the free, open-source CVE Intelligence TA for Splunk adds EPSS, CISA KEV, and CISA SSVC enrichment to a vulnerability database. Version 2.0 includes a pre-joined Risk Priority lookup, four Dashboard Studio views, and automatic hourly updates without API keys or setup pages.

### Source excerpt

I spend a significant amount of my time thinking about EPSS, CVSS, and the inherent gaps in how we prioritize vulnerabilities. We all know the drill: a 9.8 CRITICAL that remains unexploited shouldn't jump the line ahead of a 7.5 HIGH that is being actively used in the wild. Closing that gap between theoretical severity ... Read more

## 2025 CVE Data Review

DevFeed: [2025 CVE Data Review](<https://devfeed.tech/articles/2025-cve-data-review-27475.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2026/01/01/2025-cve-data-review/>)

Author: jgamblin

Published: 2026-01-01T18:38:43Z

Content type: article

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [data](<https://devfeed.tech/topics/data.md>), [Statistics](<https://devfeed.tech/topics/statistics.md>), [Security](<https://devfeed.tech/topics/security.md>), [Content Management System](<https://devfeed.tech/topics/cms.md>), [Linux Kernel](<https://devfeed.tech/topics/linux-kernel.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [cms](<https://devfeed.tech/tags/cms.md>), [cve](<https://devfeed.tech/tags/cve.md>), [data](<https://devfeed.tech/tags/data.md>), [linux-kernel](<https://devfeed.tech/tags/linux-kernel.md>), [patch-tuesday](<https://devfeed.tech/tags/patch-tuesday.md>), [report](<https://devfeed.tech/tags/report.md>), [statistics](<https://devfeed.tech/tags/statistics.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [trends](<https://devfeed.tech/tags/trends.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>), [volume](<https://devfeed.tech/tags/volume.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This review analyzes 2025 CVE publication data, reporting 48,185 published CVEs, a 20.6% increase from 2024. It highlights stable median CVSS scores, growth in web application and CMS-related flaws, publication clustering around vendor release cycles, and the Linux Kernel as the product with the most listed vulnerabilities. The article recommends prioritizing vulnerabilities by exploitability and automating remediation where possible.

### Source excerpt

2025 set a new baseline with 48,185 published CVEs. While the sheer volume is climbing, the median CVSS score remained surprisingly stable. We are seeing a distinct shift toward web application flaws (specifically in the CMS ecosystem) and a wider distribution of vendors, proving that vulnerabilities are spreading deeper into the supply chain. This massive growth ... Read more

## CNAScorecard.org Measures CVE Data Quality and Completeness

DevFeed: [CNAScorecard.org Measures CVE Data Quality and Completeness](<https://devfeed.tech/articles/a-new-era-of-transparency-for-cve-data-quality-27474.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2025/08/14/a-new-era-of-transparency-for-cve-data-quality/>)

Author: jgamblin

Published: 2025-08-14T00:43:12Z

Content type: opinion

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [Data Quality](<https://devfeed.tech/topics/data-quality.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [NVD](<https://devfeed.tech/topics/nvd.md>)

Tags: [alert-fatigue](<https://devfeed.tech/tags/alert-fatigue.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-data](<https://devfeed.tech/tags/cve-data.md>), [data-quality](<https://devfeed.tech/tags/data-quality.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article introduces CNAScorecard.org, a public scorecard intended to measure the quality and completeness of CVE data supplied by CVE Numbering Authorities. It describes missing or incomplete weakness, product, severity, and fix information as a practical vulnerability-management problem, and connects the effort to the NVD backlog.

### Source excerpt

I'm incredibly excited to finally share something I've been pouring my heart into at RogoLabs. For those of you who caught my talk at BSidesLV, you got a sneak peek, but today it's official: CNAScorecard.org is live! For years, the CVE program has been our shared language for identifying vulnerabilities. But lately, we've all felt ... Read more

## Jerry Gamblin Announces Two CVE Ecosystem Talks at BSides Las Vegas and DEF CON

DevFeed: [Jerry Gamblin Announces Two CVE Ecosystem Talks at BSides Las Vegas and DEF CON](<https://devfeed.tech/articles/vegas-bound-for-security-summer-camp-27473.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2025/07/30/vegas-bound-for-security-summer-camp/>)

Author: jgamblin

Published: 2025-07-30T18:05:00Z

Content type: opinion

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [black-hat](<https://devfeed.tech/tags/black-hat.md>), [bsides](<https://devfeed.tech/tags/bsides.md>), [cves](<https://devfeed.tech/tags/cves.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [management](<https://devfeed.tech/tags/management.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>)

### AI overview

Jerry Gamblin announces that he will give two talks on the CVE ecosystem during Security Summer Camp, including appearances at BSides Las Vegas and the AppSec Village at DEF CON.

### Source excerpt

It's that time of year again! The first week of August means my annual trip to the desert for "Security Summer Camp"--the whirlwind of BSides Las Vegas, Black Hat, and DEF CON. It's always an exhausting but amazing week, and I can't wait to dive in, catch up with everyone, and talk about what I've ... Read more

## 2024 CVE Data Review

DevFeed: [2024 CVE Data Review](<https://devfeed.tech/articles/2024-cve-data-review-27472.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2025/01/05/2024-cve-data-review/>)

Author: jgamblin

Published: 2025-01-05T00:04:57Z

Content type: article

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [Statistics](<https://devfeed.tech/topics/statistics.md>), [data](<https://devfeed.tech/topics/data.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [Cisco](<https://devfeed.tech/topics/cisco.md>), [iOS](<https://devfeed.tech/topics/ios.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [WordPress](<https://devfeed.tech/topics/wordpress.md>), [WordPress Plugins](<https://devfeed.tech/topics/wordpress-plugins.md>)

Tags: [cisco](<https://devfeed.tech/tags/cisco.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-data](<https://devfeed.tech/tags/cve-data.md>), [github](<https://devfeed.tech/tags/github.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [numbers](<https://devfeed.tech/tags/numbers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [packages](<https://devfeed.tech/tags/packages.md>), [statistics](<https://devfeed.tech/tags/statistics.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [wordpress](<https://devfeed.tech/tags/wordpress.md>), [wordpress-plugins](<https://devfeed.tech/tags/wordpress-plugins.md>)

### AI overview

This review examines 2024 CVE statistics, reporting 40,009 published CVEs, a 38.83% increase from 2023. It covers publication patterns, CVSS severity scores, CPE records, and CVE Numbering Authorities.

### Source excerpt

2024 brought unprecedented growth in CVE data, so I figured it would be appropriate to start the new year by exploring these statistics and highlighting some of the more intriguing data points. CVEs By The Numbers We ended 2024 with 40,009 published CVEs, up over 38% from the 28,818 CVEs published in 2023. CVEs By Month Month ... Read more