About

I am Jerry Gamblin. I have been writing here since 2011 about whatever I am taking apart at the time: proximity badges, hotel TVs, conference wifi, container pipelines, and my own golf swing.

The thread running through most of it now is vulnerability data, and what the CVE record actually says once you stop reading it one entry at a time.

My day job is Head of Research at Empirical Security.

RogoLabs is my personal open source research lab, the shingle I hang my side projects under when I am off the clock. Three of those projects are worth your time: CVE.ICU for the shape of the whole CVE record, CNA Scorecard for how completely each numbering authority fills in what it publishes, and CVE Forecast for where publication volume is heading. There is more about each on the tools page.

Closing the gap between theoretical severity and actual exploitability is why I started RogoLabs, and it is why I keep writing the annual CVE analysis. Every one of those ships with its dataset and the code that produced it. I would rather be corrected than believed.

Elsewhere

Find me on GitHub, LinkedIn, X, Bluesky, or infosec.exchange. I am @jgamblin on all of them.

If the numbers here look wrong to you, mail me at [email protected] and say so.