My schedule, a new role at Empirical Security, and the CVE and vulnerability talks worth your time.
It is almost the first week of August, which means it is time to point myself at the desert one more time. BSides Las Vegas, Black Hat, and DEF CON all land back to back, and for me it is the same ritual it has always been: an exhausting, sunburned, over-caffeinated, absolutely amazing week of reconnecting with the people who make this industry worth being in. If you have never done all three in a row, a word of warning: hydrate, wear real shoes, and clear your calendar for the following Monday.
This year the trip feels a little different, because I am showing up with some news.
Big News: I Joined Empirical Security
A few weeks back I announced that I have taken on the role of Head of Research at Empirical Security. I wrote about why in Country Roads, Take Me Home, but the short version is that this is a homecoming. Empirical is where the math actually gets done: predictive models, EPSS, and the kind of data-driven vulnerability management I have been talking about for years, built alongside people I have wanted to work with again for a long time.
The thesis I keep coming back to is simple: you cannot run a data-driven VM program on top of abstracted, artificially grouped vulnerability data. The numbers make the case. The first half of 2026 produced 34,601 CVEs, up nearly 49% over last year, and only 0.24% of them have landed in the CISA KEV catalog. KEV is a conservative floor, not a full exploitation census, so the real number runs higher, but even generously, exploitation stays a small fraction of the total. You cannot triage that flood, let alone predict it, unless the underlying data stays granular, transparent, and accurate. That is the work, and it is the thread that ties together everything on my schedule this week.
Where to Find Me in Vegas
I am on stage (and at a lunch table) a couple of times this week. Come say hi.
| Event | Session | When / Where |
|---|---|---|
| BSides Las Vegas | Panel: I am CVE, AMA!, with Tod Beardsley, Lindsey Cerkovnik, Madison Ficorilli, and Katie Noble (Common Ground track) | Wed, Aug 5, 12:00-12:45pm PT, Tuscany Suites |
| Black Hat | Panel Luncheon: Universal Zero Trust in the Age of Autonomous Exploitation, with Dr. Chase Cunningham and Vikram Bedi (JP Morgan Chase) | Thu, Aug 6, 12:00-1:30pm PT, Cipriani at the Wynn |
The BSidesLV panel is the one I never miss. Last year we ran out of time before we ran out of questions, so bring the hard ones. The Black Hat luncheon is the one I am most curious about, because “what defenders do when AI collapses the gap between discovery and exploitation” is exactly the problem I moved to Empirical to work on. Seats are limited, so grab one if the topic is your thing (the free lunch from Cipriani does not hurt).
Fair warning: both of my sessions are in the noon slot, so a few of the talks I recommend below run at the same time. Choose wisely. I will be at DEF CON too, so if you want to meet up there, just reach out.
The Talks I’d Clear My Calendar For
Enough about me. I went through all three schedules and pulled the CVE, vulnerability, and exploitation talks that made my own must-see list, grouped by con and in rough time order. One theme jumps out of every program this year: AI is now doing vulnerability research at scale, and the gap between discovery and exploitation is collapsing. That is the exact thread running through my Black Hat panel, so I am biased, but the lineups back it up.
BSides Las Vegas
- The Timing of Exploitation Evidence and Prediction (Jay Jacobs). Ground Truth, Mon Aug 3, 2:00pm. One of the actual creators of EPSS on how predictive scores and “known exploited” signals differ in coverage and latency. Full disclosure: Jay is my Empirical colleague, but I would be in that room either way. This is the source talk on the exact signal-to-noise problem I keep hammering.
- Low Severity, High Impact: The Bugs Companies Ignore (Ali Kabeel). Breaking Ground, Mon Aug 3, 5:00pm. A good reminder that prioritization is about impact, not just the CVSS number.
- Five AIs Walk Into a Severity Meeting: Auto-Triage and the Evolution of GM’s Bug Bounty (Jacob Martinez, Aakash Krishana, Christopher Walter, Jason Brown). Common Ground, Tue Aug 4, 6:00pm. Real-world AI-assisted triage and severity at scale.
- Agents of Chaos: A Systemic Approach to Finding GCP 0-Days (Moshe Bernstein). Common Ground, Wed Aug 5, 10:30am. Finding cloud 0-days is usually a one-off art; turning it into a repeatable, agent-driven method is the part worth stealing. If it scales, it changes how every cloud security team hunts.
Black Hat
- Can AI Do Novel Security Research? Meet the HTTP Terminator (James Kettle). Wed Aug 5, 12:00pm. Kettle is always a must-see, and the title asks the year’s central question. [Note: runs opposite my BSidesLV panel.]
- Apple macOS Kernel Exploitation with MIE: Building on the Ashes of 100 Vulnerabilities (Dion Blazakis, Josh Maine, Bruce Dang). Wed Aug 5, 2:35pm. A rare look at how a modern mitigation, Apple’s Memory Integrity Enforcement, holds up under real exploitation pressure.
- Zero-Day Provisioning: Chaining TP-Link ZTP Vulnerabilities for Infiltrating Networks (Stanislav Dashevskyi, Francesco La Spina). Wed Aug 5, 2:35pm. Turning zero-touch provisioning into network-wide compromise, the kind of flaw that scales the moment it ships.
- Lights Out: BMCs Are Still Broken and Now We Have the Receipts (HD Moore). Wed Aug 5, 3:35pm. HD Moore back on baseboard management controllers, the foundational attack surface most orgs forget they even run.
- Closed Loop: From Autonomous Exploit to Deployed Defense in Under 5 Minutes (Conor Sherman, Sherwyn Moodley). Thu Aug 6, 11:05am. The discovery-to-exploitation gap, timed with a stopwatch. This is my panel’s topic in a single talk.
- Beyond Detection: What We Learned Testing Every AI Approach to Vulnerability Classification (Arshan Dabirsiaghi). Thu Aug 6, 12:00pm. An empirical look at what AI does for vulnerability classification, which is the predictive VM question I care about most. [Note: runs opposite my Black Hat luncheon.]
- A 0-Click Exploit Chain for the Pixel 10 (Natalie Silvanovich, Seth Jenkins). Thu Aug 6, 12:00pm. Silvanovich on a fresh 0-click chain is an automatic yes. [Note: runs opposite my Black Hat luncheon.]
- The 0-Day Engine: Finding 100+ Vulns with LLMs in Chrome and Android (Povcfe, Huiming Liu). Thu Aug 6, 2:35pm. The scale story: over 100 vulns found by LLMs in two of the hardest targets there are.
DEF CON 34
- Patch Gap to Mobile Renderer RCE: Pwning Samsung Internet’s V8 on the Galaxy S25 (Hrvoje Mišetić, Jamie Hill-Daniel, William Liu). Main Track, Fri Aug 7, 12:30pm. A flagship phone shipping a six-month-old, already-patched V8 bug (CVE-2025-10891) turned into RCE. The patch gap is not theoretical, and this is what it costs.
- Witchcraft Solver: Automated 0day Discovery in Stripped Binaries (Jonathan “endrazine” Brossard). Main Track, Fri Aug 7, 3:00pm. A fully automated, binary-only 0day pipeline, MIT-licensed and released at the con. Stripped binary to working PoC in about 30 minutes changes the economics of finding bugs.
- Policy Without Maintainers Is a Supply Chain Vulnerability (Christopher “CRob” Robinson, Kris Borchers). Policy @ DEF CON, Sat Aug 8, 11:00am. CRob from OpenSSF on what happens when policy gets written without the maintainers who secure open source. Disclosure and supply-chain rules only work if they match how the software is really built.
- Slop Spotting: Using Rules to Detect AI Slop for Bug Bounty (Katie Paxton-Fear, Max vonBlankenburg). Bug Bounty Village, Sat Aug 8, 2:30pm. curl killed its bug bounty over AI-generated slop; this is a lightweight way to tell real reports from convincing fakes. My signal-to-noise thesis, live on the ground.
- One Firmware Flaw, 70+ Device Models: Lessons in Industrial IoT Disclosure and Mitigation (Weihan Goh). IoT Village, Sun Aug 9, 11:30am. One CVE (CVE-2026-29988) across 70+ industrial sensor models, where the real story is remediation landing long after disclosure. Fleet-scale VM in the hardest environment there is.
- Your WAF Blocked Us, That Was The Exploit: Remote Agent Takeover via Cloudflare, Sentry and a Claude Zero-Day (Barak Sternberg, Nevo Poran, Ron Bo). Main Track, Sun Aug 9, 12:00pm. Agent-to-agent lateral movement plus a Claude zero-day for exfil, with an estimated 15,000+ orgs exposed via Cloudflare MCP alone. The autonomous-exploitation future my Black Hat panel is arguing about, demoed live.
Let’s Connect
Summer Camp is, and always has been, about the people. If you want to talk CVE data, EPSS, and predictive VM, or just trade stories from the hallway track, find me. I will have a fresh run of stickers to hand out, so track me down before they are gone.
You can find me on LinkedIn, X, Bluesky, and infosec.exchange, or just yell my name in a hallway at any of the three cons. It usually works.
And tell me: what is the one talk you are not missing this year? I am always looking to fill the gaps in my own schedule.
See you in the desert. Stay hydrated.
One More Thing: Breakfast?
Still reading? Then you have earned an invite.
RogoLabs presents: Breakfast Forecast
Decoding Risks: From Omelets to Zero-Days
Quick context, since the top of this post is all Empirical: RogoLabs is my personal open-source research lab, the shingle I hang my side projects under when I am off the clock. Once a year, it also does breakfast.
- When: Friday, Aug 7 (DEF CON), 8:00 AM
- Where: The Peppermill, Las Vegas
- Seats: Capped at 20, so this one is for the folks who made it to the bottom of the post
- RSVP: [email protected] or Signal
jgamblin.01
First come, first served. Bring your appetite and your hardest questions.
