The History Of Vulnerabilities w/ Brian Martin. All about vulnerabilities from 1993 to Current Era.
Listen / watch on
About this episode
In this episode, we sit down with Brian Martin, a 33-year vulnerability historian and longtime OSVDB maintainer, to trace the chasm between what CVE actually tracks and what's really out there. Brian explains why VulnCheck's KEV is 3.5x bigger than CISA's, why the real public vulnerability count is missing somewhere between 500K and several million entries, and how he personally mined 105,000 vulns out of changelogs and bug trackers. The conversation digs into the manufactured 2024 funding crisis, NVD's quiet abandonment of a 30,000-vuln backlog, why CVSS V4 is a "train wreck," and the LLM-driven vulnerability spike about to dwarf the fuzzer era. They close on the 1903 Marconi wireless telegraph hack, the first documented exploit in the wild.