Scoring non-CVEs.
1
Major points for transparency, but room for improvement.
All the wheat and none of the chaff.
And how to measure the risk correctly.
Why you generally shouldn't care too much about individual vulnerability counts.
A generally good tool for evaluating CVE exploitability.
Studies examining the risk posed by CVEs.
1
A deep dive into the multitude of federal systems for prioritizing known software security flaws.
2
Deploying Securely with ChatGPT
2
A response to CISA's recent Foreign Affairs piece.
10
A roundup and some potential future developments.
A speculative attribution.