← All transcripts
EP. 05

Past, Present & Future of CISA KEV w/ Patrick Garrity

May 6th, 2026 · 57 min ·Patrick Garrity
Watch episode on YouTube
~51 min read · 189 exchanges
Mehul 00:01.442

Patrick, it is so nice to have you on this interview series. Nice to signal. You are the most influential influencer in vulnerability management. You have led marketing teams in the past. You have led research teams, vulnerability research teams in the past. You are a vulnerability researcher. You have put Seesa Kev on the map, both literally and figuratively, with your periodic table for Seesa Kev. You write about Seesa Kev all the time. And the thing I find interesting is.

You are a vulnerability researcher, but not a classical vulnerability researcher in the sense that you're not finding zero days, exploits, but you have more of an analytical bent in your analysis of vulnerabilities. So I'm curious to understand like what got you into vulnerability research? Like what happened there?

PatrickGarrity 00:49.886

Yeah. Yeah, kinda crazy. So I started my career in tech. I was working for MSP and then I I got involved in in cybersecurity startups in twenty twelve at Duo Security and I w I ended up leading the sales engineering team there. So I have a a somewhat technical background in in implementing and working with customers and deploying technologies. Back then it was the first cloud product most people had deployed.

and a lot of fun. But you know, as I gravitated over the years, I did a lot of different roles and ended up doing a lot of product marketing and marketing types of things. And as I went from kind of like a technical implementation role into more product marketing and marketing, naturally I I understood how to connect the dots of like technical concepts with marketing concepts, if that makes sense.

And so I ended up in a position being a VP of marketing kind of multiple times, VP operations roles, things that manage sales and marketing. And what I discovered when I joined the company I was at last, nuclear security, was that what really resonated with people was actually research.

Like they wanted to understand real anacl analytical research. They wanted to understand what the data looked like. And you know, I would I would go grab the data and it was Excel file, pivot tables, you know, JSON, CSVs, APIs, and and those things just don't translate to most people. and so for me, I'm a very visual learner and person.

Mehul 02:40.737

I see.

PatrickGarrity 02:40.914

And so naturally what I saw was other industries tend to convert data into visualizations in order to translate so everyone has a better understanding of the the data and the research. And so I j I just started learning how to draw charts by looking at the data.

Mehul 03:01.782

And you know, you and you got your start before Sisa Kev. And I I I remember you were you were pushing for Sisa Kev changes early on because you were finding things, maybe it was it was at your previous role or something, where you were finding vulnerabilities that were getting exploited in the wild, but they were not getting reported as exploited in the wild in Sisa Kev. So I believe that you had like a big struggle there that got you into CSA Kev.

PatrickGarrity 03:30.122

Yeah. Yeah, so me and and Yotam Perkle, good friend of mine, I can't remember the company he was at at the time, I I naturally was like, Sisakev is cool, like this is a centralized source for exploitation evidence, right? And that was a federal mandate in the the US, Sisabad twenty I don't know, three two, maybe something like that. I forget the year and the the date.

Mehul 03:32.792

So

Mehul 03:47.597

No.

Mehul 03:56.174

I don't know what

PatrickGarrity 03:59.668

But yeah, what was interesting is this was like the first centralized source of vulnerability exploitation data. And, you know, before there was scraps of information, or you had commercial products and vendors that had proprietary information. but largely there wasn't a whole lot of aggregate information available publicly. And so, you know, first I wanted to visualize, so I created the Mondrian Sisakev to visualize like the product and vendors that.

Mehul 04:15.245

Mm-hmm.

PatrickGarrity 04:28.496

the Sisakev had. And then as I was doing my own research, I kept on coming across the other exploited vulnerabilities that were being reported publicly. And I started reporting those to Sisakev and they didn't get added to Sisakev. So to me it was kind of interesting. Some of them did. Some of them got added, some of them didn't and there's a multitude of of reasons why. but I was more advocating that like Sisakev is a is a great initiative. This is provides good visibility defenders. Like

Mehul 04:29.997

Yeah.

Mehul 04:41.889

I see.

PatrickGarrity 04:58.346

Let's make it complete. and you know, I think sometimes when you you have your interests of of trying to make contributions as a researcher, you know, there's there's reasons why and why not they want to curate a list a certain way. I think in in SISA's mandate particularly had to have a fix and it and it was more federally scoped. And I think a lot of us didn't understand that when it first came out.

Mehul 05:00.225

Mm.

Mehul 05:22.549

Yeah.

Mehul 05:26.295

Same.

PatrickGarrity 05:27.666

In in generally, I think a lot of us wanted it to be the single source for exploitation data, but the the reality is is it's got a defined scope, it's limited, it's a great resource, but it didn't quite have all the exploitation evidence. There wasn't much evidence referring where it came from. and that was more of like what we started poking at and challenging was, you know, what exactly is the criteria to get a

Mehul 05:48.501

Mm.

Mehul 05:56.865

Yes.

PatrickGarrity 05:57.288

a vulnerability being exploited onto CIS's known exploited vulnerability catalog.

Mehul 06:03.103

And you know, that is very interesting because before before if I remember correctly, before Cisa Cap there was no catalog of known exploitable vulnerabilities. I mean, a and as a vendor, as a vendor, you always gravitated towards is an exploit available, you know, from the metasploits of the world and the core immunity and core impacts of the world. That was the that was the extent of which

People knew about a vulnerability. They had no insight into what is the state of active exploitation of this vulnerability in the wild. You might have, you might have vulnerabilities that are getting discussed in the news, but there was no real good sense of which vulnerabilities are actively used by ransomware, threat actors. I mean, obviously there were some feeds and whatnot, but the

PatrickGarrity 06:51.168

There there yeah, there was a few yeah, a few smaller disparate sources. Shadow S Shadow Server is a great public source for exploitation data where they have honeypots. There was Google Project Zero, which was disclosing their own discoveries, which was really impactful. Like most of those ended up on Sysacap. So but but like still defined scope. And then vendor advisories, there's a lot of exploitation that was being disclosed via like

Mehul 06:55.82

Yeah.

Mehul 07:06.689

Yeah. Yeah, but you're discussing you're not

Mehul 07:15.415

Yeah.

PatrickGarrity 07:20.252

Microsoft MSRC, some of the advisories from different product companies. but no one was really like collecting this outside of commercial vendors, including the one I work for, Volncheck, was doing this and selling it commercially before I even joined. and so you had you had you know, more of where people were purchasing or or buying this would be like a a mandient or recorded future.

Mehul 07:37.675

Hmm.

PatrickGarrity 07:48.14

but generally the data was like limited to just an indicator saying like, hey, this is known exploited. There was no actual evidence. and so that you know that was that that was and has been historically a a challenge of like having a place to get that information. And then there is one other interesting one, which is a Catalan from Risky Business who previously w has been a journalist for Bleeping Computer and a bunch of other ones.

Mehul 08:15.146

Okay.

PatrickGarrity 08:17.502

His Twitter feed, a lot a lot of people I've interviewed actually were using that as their tip. so literally that Twitter feed people would insert it into their, you know, SimSor automation tooling. And that would be an indicator of like if Caitlin talked about it, there's a good probability that it's ex you know being exploited. Not not all of them, but like I have manually audited almost all of his re articles he's ever wrote. But that that was the extent of like

Mehul 08:23.445

Whoa.

Mehul 08:44.823

Mm-hmm.

PatrickGarrity 08:46.688

how you would get exploitation evidence prior to more more recently.

Mehul 08:49.463

Yeah.

Mehul 08:53.111

So weird, so weird. Even like I agree with you with respect to the MSRC, the Google project, the Google Zero project as well, it was just mostly finding vulnerabilities, not giving you evidence of exploitation. Maybe sometimes they had evidence of exploitation, but I don't remember having it like you know widely accepted as the signal for exploitation. So Sisa Cab was a game changer in that context, where you know, most organizations were struggling with vulnerabilities, regardless.

So Sisa Kev was like a breath of fresh air where you just had to focus on at least you had to start with these 1500 or thousand vulnerabilities that were out there. Get these out of the, you know, get these out of your network because these are really bad. They're getting actively exploited and so on. And I always thought for a long period of time, this this is a very comprehensive list in terms of the vulnerabilities that are getting exploited in the wine.

PatrickGarrity 09:30.186

Yeah.

Mehul 09:47.176

And the limited scope is not something that people know. It's very focused on the federal side and so on and so forth. And my sense is the active, the true active list of exploited vulnerabilities is way bigger than what SISACF says it is, right?

PatrickGarrity 10:00.884

Yeah, yeah. Yeah, I mean for for context, right? It's I mean infinite number of possibilities, but ultimately you have to have detections in some way to figure out, you know, is it is there s something being exploited? You have to have a way to associate that with a product vendor and vulnerability. we do a lot of that that work, like we coordinate with Shadow Server on some of that event. In some cases, like you don't know.

and so I think that that's a reality, but also you know, SISA's really focused on US centric federal government, US products, very pervasive. If it's on Sys a Kev, certainly it's impactful. You should focus on it, you should make sure it gets fixed fast. but there's just so much other activity going on beyond that. I think today we track like somewhere around forty five hundred, forty seven hundred different Kevs.

Mehul 10:29.515

Yeah.

PatrickGarrity 10:57.862

And you know, I think y i if you have time to go spin up different services, detection rules, and you look at more places as well publicly disclosing exploitation, yeah, you you'll quickly find that, you know, there's a lot more evidence out out there that you can you can find. Whether it's impactful or not, I think is always a great question, but impact can really like

It can be different based on which region of the world that you're in and what target you know technologies are being targeted. you know, a lot of things that are being exploited might be EOL and don't have a patch or just don't have a patch. and so this the scope, you know, if you think of software is is almost infinite. but yeah, really focusing on, hey, yeah, w which of these things are being exploited helps people to focus on.

you know, what they can make the most impact and reduce risk on now. which is really, really important from a signal perspective when we're talking about lots and lots of vulnerabilities.

Mehul 12:05.099

So last time the last time I looked at it, the the list, the official list from Cisa Kev was about fifteen hundred or seventeen hundred. And you're saying that list is close to forty, forty five hundred. So the delta is around three thousand.

PatrickGarrity 12:15.39

No, yeah, sorry, I'll clarify. Their list is fifteen hundred. Yeah, currently what we're we're looking at a Volncheck Kev, which we also provide as a free service. now. When I joined, Anthony was like, Hey, should we make our commercial Kev free? And I was like, Cool, see I was never asked that question. I think that's awesome. Like, to give out, you know, free indicators with with references and all that fun stuff.

Mehul 12:24.749

Hmm.

PatrickGarrity 12:41.306

and so naturally it was kind of a perfect fit when I came to VolnCheck of of something I had already spent a ton of time researching. but yeah, r right now I think we're right around forty seven hundred CVEs that we've identified and cataloged exploitation evidence for across hundreds of different sources.

Mehul 12:50.156

Mm.

Mehul 13:01.057

This does this and does this include the European, the Asian, or or is it still a federal focused, US focused?

PatrickGarrity 13:10.308

no, yeah, anything and everything. So we have disclosures of exploitation from Chinese companies, Japan vulnerability notes, European entities, Anisakev. Anissa Kev's only like fifteen CVEs right now. and and so I think you have to be very mindful of understanding when someone, you know, says, Hey, we have a list of Kevs, spend the time to understand what's on the list, 'cause like if you only fix fifteen vulnerabilities.

you're you're gonna be in trouble. but ultimately all all these sources independently have different vulnerabilities that they're cataloging as being exploited. and then sometimes there's crossover where many different places are reporting exploitation. React to shell would be a good example recently where like there's just mass exploitation so everyone sees it. log4j being another example too.

Mehul 13:51.925

I see.

Mehul 14:04.417

I see.

Mehul 14:08.001

And are you seeing, you know, are you seeing changes in terms of attack vectors for vulnerabilities that are getting exploited from an attacker's point of view? Is there a you know you have you you probably

closely monitoring this space for over five or six years, if I remember it correctly. You you can I mean you want to see in around twenty tw 2019, 2020, I remember like your most viral post was this periodic table for Sysakev. And it just went it just went crazy from there. But if you if you look back you if you look back at your time doing vulnerability research, are seeing a change in patterns for rotation?

PatrickGarrity 14:28.469

Yeah.

PatrickGarrity 14:47.668

Yeah. Yeah, so pri even prior to me getting into the vulnerability management space, really if you look at the the prior decade, most of it was like Internet Explorer, Flash, like desktop application, Word, PDF, that sort of stuff. I was actually really surprised there's a new Adobe reader Kev just recently. There hasn't been one since like twenty twenty three.

and so that that probably speaks to like Adobe likely did a ton of work on that product to harden it. maybe, maybe operating system improvements as well. but you know, the the days I think of like macro, you know, based word exploitation, flash plug-in, flu flash being deprecated, great, great thing for everyone. Internet Explorer getting deprecated. and and then

Mehul 15:23.007

Mm.

PatrickGarrity 15:45.194

You know, now we have Chrome predominantly on the Windows desktop and Mac, you know, and you have some other browsers too. But yeah, a big shift from, you know, th those types of excellents being used to initial access. So network edge devices, internet facing devices, file transfer protocols, yeah, VPN. you know, places that are like

Mehul 16:02.548

Hm VPN

PatrickGarrity 16:11.424

giving full remote access and a lot of times keys to the kingdom or entry into the the enterprise. and that's probably the biggest theme is is that's where people are getting hit the hardest. And then change in tactics, like recently, I think in 2023, when we saw Progress Move it, that was a shift to Smash and Grab where they're targeting file transfer servers.

grabbing the information and then essentially saying, you know, extor it doing extortion, saying, we're gonna release all this data if you don't pay us money. and so that that you know that was a new technique. I think Scattered Spider did that one. and so certainly there's been some changes and adjustments over the last decade as far as what people are targeting. And you know one of the things from working at Duo Security for eight years is

I think credential compromise we just seen it, you know, become so much harder with the the advent of multi factor authentication.

Mehul 17:16.67

You know, I know the funny thing is the funny thing is, you know, when I used to write I used to write plugins for tenable, the one Nessus plugins. And obviously we would write plugins for vulnerabilities and so on. The most important plugins were default passwords.

PatrickGarrity 17:34.965

Yeah, yeah.

Mehul 17:35.251

Yeah, admin, admin. So you know, you could write you could write the best exploit and so on and so forth, but the most important and the most critical plugins we wrote were like the default passwords because that's the easiest way to get in. Once you get in, you have admin access and you can do anything you want. So I know the thing that you're mentioning about duo, I mean, g getting the credentials is probably the best vulnerability that is out there and it stays there forever if you don't fix it.

PatrickGarrity 18:02.366

Yeah. Yeah, and you th you see a lot of the manufacturers and and products hardened so they don't have default passwords or you have to at least reset them the first time you log in. you know, and so I think there's been a lot of maturity in in the respective understanding that like credential compromise is a big problem. We still have the problem of like people putting their their network management interface on the internet and and SISA has done take gone great lengths to issue guidance regarding that, that you shouldn't be

Mehul 18:06.497

Yeah.

PatrickGarrity 18:31.591

putting network configuration access on the internet.

Mehul 18:33.9

Or or they put like all the secrets on GitHub and make it public.

PatrickGarrity 18:37.738

Yeah, yeah. Or V Center on the internet. I mean a combination of different things where it's like these things should just not be exposed and you're opening your attack surface by doing that.

Mehul 18:51.254

So so yeah, you start you started, you mentioned the duo and when your when you're initially started a duo, that's where the initial focus was, was the credential compromise. And I have also one thing that I've noticed is, I mean, if you look at like the DBIR reports, if you look at the Mandian reports, vulnerability exploitation was not like at the top of the charts in the initial reports that came out. But if you look at the recent trends.

PatrickGarrity 19:16.139

No.

Mehul 19:18.412

vulnerability exploitation has now become like the top three attack vector to break in.

PatrickGarrity 19:25.546

Yeah. Yeah, so I a combination of things, right? kind of funny, but yeah, I spent the twenty twenty twelve to twenty twenty at Duo. And I w I was running sales engineering. So everything was an IR team pulling us in to deploy duo because there was a breach. you know, many, many large scale breaches. Yahoo, DNC, RNC with the twenty sixteen election. you had Target early on, I think that was in twenty thirteen.

Mehul 19:43.052

I

PatrickGarrity 19:55.158

then you had Equifax, Starwood S S PG, all your hotel you know stuff compromised. it it kind of went on and on nonstop. And I ended up being the one to like hop in and deploy duo to get the the people out as quickly as possible because most of it was they had credits. multi factor got them out, you know, then you rotate your passwords and hopefully you're on your way. but

Yeah, the the w when I I I then did a a short term a sym vendor Blue Mira, small business, medium sized business. It was kinda interesting going there because in 2021, the biggest theme I saw was exchange servers getting popped. I think it was gosh, what shell was it? Not React to Shell, not not what? proxy login. Sorry, not shell.

Mehul 20:47.788

Proxy shell, proxylogon, proxylogon. Yeah.

PatrickGarrity 20:54.03

but yeah, with proxy login, like the the I think the FBI actually was like, hey, we're gonna go pop some of these machines and remove shells from exchange servers. Like that's how bad it got. and and it's like, wow, this dynamic, something's changing fast. and and then I took some time off and logged for shell happened. So I actually wasn't working in security during that time. and when I came back to decide to work at a security company, I I

you know, I I was looking at trends and I'm like, something's going on here regarding vulnerabilities and exploitation. And I ended up landing at nuclear security. And at the time, this was in twenty twenty two, all my friends made fun of me. They're like, who cares about vulnerability management? Like that's a two decade long old problem that was solved a long time ago. So that was only, you know, that was only like four years ago.

where no one no one cared about this space other than the people that had been in it for a long time. and I think at the time I remember like looking on LinkedIn, there were only like five hundred people with the word vulnerability management in their title in the US on LinkedIn. and so yeah, you know, kinda interesting, but not not really a well-maintained established practice other than like really compliance driven at that point.

Mehul 22:15.584

Yeah, true. Even though a lot of compliance driven vulnerability management, PCI, you know, I think it is the requirement number twelve you have to do in vulnerability scan. And that's what drives alpha.

PatrickGarrity 22:25.706

Yeah. Yeah, that wa so that's always a sign when you're seeing like change of market and then you see compliance. It's like, okay, something's going on here. and yeah, the the Mtrends report came out in twenty twenty three and they're like, Well, the number one attack vector or something of that nature is an i is exploitation of vulnerabilities. And everyone kinda doubted it and I was like, No, like I I worked with with iSight partners, I worked with Mandy and when I duo, they're like on

the largest incidents in the world. So you know, probably worth paying some attention here. and it wasn't until a year later that the DBR came out that they're like, hey, we see like a 180 or 200% increase in initial access exploitation as well. and and so, you know, 2023, 2024, I spent or t or 2022, 2023 while I was spending time at Nucleus, like

Mehul 23:11.551

Interesting.

PatrickGarrity 23:24.19

this kind of rapidly evolved, they accelerated quickly and and right before then is when SissaCev came out with her catalog. So I mean kudos to Sissa for kind of, you know, foreseeing some aspect of this coming and and being like, hey, we need to make a central list so people understand what things they need to fix and prioritize. 'cause as we kind of mentioned before, that just wasn't the case. that people had an easy accessible list of known exploited vulnerabilities before that.

Mehul 23:54.029

If you notice the the speed of exploitation, the rate of exploitation is increasing, right? And you would imagine the SISA Cavs of the world would get more funding to do their work to support this effort. And all I read about is funding war.

NVD is losing funding. MITR there was a s miter scare around losing funding. I just in la just last week, NVD lost its funding all over again. I'm curious what do you think about that? I mean this these things then they have been on and off where in in wars have been on

PatrickGarrity 24:22.752

Yeah.

PatrickGarrity 24:38.782

Yeah, yeah. I mean it's kind of a it's kind of an unfortunate time too. So yeah, if I break it down, like the the funding issues really started in 2024. And so, you know, one of the things I think you have to consider is there's geopolitics through multiple administrations going on. and and so you gotta consider that factor. I'll talk about that in a second. but also my observation is there's like politics between agencies historically.

Mehul 24:56.736

Mm.

PatrickGarrity 25:09.112

relating to sys kev, sys funding the C V E program, MITRE runs the C V E program, and then NIST NBD. And I think generally speaking, like there's some s aspect of doing similar work in competing interests. That's just a reality. and and so in twenty twenty four we had VoneCon and right around

that time it was in March, right before February in February, NIST MBD just stopped enriching all C V E records. Like just stopped. Like everyone's like, hey, anyone know why for two weeks NIST hasn't enriched a single C V E record? Like there's a federal government agency that's been doing this for like twenty years, right? And suddenly like that data just goes away. and and so there's a lot of questions. And so we had Volmcon and

Mehul 25:56.641

Yeah.

PatrickGarrity 26:04.926

NIS came to the table and said, like, hey, yeah, we had funding issues. We did we lost funding, right? you can do your own research if you want to like see who that points back to, but that that kind of speaks to sometimes interagency geo like politics maybe or funding issues. and and you know, naturally they came out and were like, don't worry about it, we got it covered, we'll have the whole backlog covered by September at the latest, or maybe July, I don't know.

That never happened. they just, you know, s kept on having issues from an enrichment perspective. they they finally got back to like some baseline, but at the same time, then Sys is like, we're gonna start this other experimental project, I guess, called Vol enrichment. so Sys is like, Hey, we're gonna try and pipe data into the C V E program so that you get C VSS scores, you get some CWE, you get these new things called

stakeholder specific vulnerability categorization d decision nodes. And and you're gonna get some CPE. And we're all like, that's great. So like you guys are coordinating to help fill this gap. and and you know that that project has been successful. I think I'm the the second largest non-government contributor to that project, mostly like providing feedback of like Jake

Mehul 27:06.896

yeah, yeah, yeah, yeah, yeah.

Mehul 27:27.164

The first magic. Who's the first?

PatrickGarrity 27:31.53

Baines, our CTO, right? So we're we're always like, dude, we love these public projects and we always want to contribute back. We always want them to get better because ultimately, like the more public goods that have good quality stuff, it's better downstream for everyone, including someone like ourselves which commercializes data. and so you know, i that that's just the reality is like how much can we contribute, help provide feedback. I think later in the year.

Sissa then was like this CPE stuff is hard and some a lot of people might not know what CPE is. It's gosh, I forget what it's enumeration. Yeah, sorry. common platform enumeration. But essentially that's how most security products historically have associated a vendor software version with a vulnerability. Right? So that's a very important

Mehul 28:10.504

It's the common platform enumeration.

PatrickGarrity 28:31.818

thing. And so when this stopped doing it, then it's like, okay, Sis is gonna start doing it and then December they're like, the CPE stuff is too hard, we're just gonna stop doing it. yeah, go ahead.

Mehul 28:41.568

Can I can I say something? this the CPE thing was only relevant to non-VM vendors because the VM vendors have their own way of fingerprinting applications and so on. So they never cared about CPE. So like like you know, places I've been at, like the the tenables and the car, we never cared about CPE because

PatrickGarrity 28:52.842

Some Yeah.

Mehul 29:00.116

CPE was good if you are a new vendor in VM and you didn't know how to catalog an application or a server or a hardware. CPE was like a very quick way. We get a CPE and you get the one DB, you can put them together. I have a VM solution. But you know what I mean?

PatrickGarrity 29:00.149

Yes.

PatrickGarrity 29:18.142

You knew no, you're co you're completely right. Like on the detection side, right? Like a tenable or a qualist have have proprietary processes and how they process their information. But the hundred other products out there in the VM space are relying on CPE. Yeah. and and so I think that like that that was kind of a reality of one of the things we saw early on.

Mehul 29:25.738

Exactly.

Mehul 29:31.862

They they they have no way to do it. Exactly. They had to rely on CPE.

PatrickGarrity 29:42.578

And actually when NIST made their announcement, that was the number one thing we identified as a company that we could provide value back to the community on was CPE. It wasn't C VSS scores, it wasn't CWE. It's like, man, so many tools that people are using rely on CPE for detection that like it's bad for the industry if if there's no CPE. and so naturally we we internally very quickly

led by Jake Baines, our CTO, as I mentioned, one of the the contributors back to Vulner Richment, we're like, how quickly can we provide high fidelity, high quality quality, automated CPE? Because most of the CPE you see today that is through NIST NVD is manually generated through analyst. And and we know with the explosion of vulnerabilities that just doesn't scale. in in, you know, we there are some pieces of CPE that we do commercialize, but largely we

Mehul 30:31.508

Mm.

PatrickGarrity 30:38.58

decided to take the CPE that we generate and provide it as a free service. in Volnshek, I think it's called N V D Plus Plus, which is like NIST NVD delivered reliably with those enrichments. and and so, you know, kinda kinda interesting like us being opportunistic of like, hey, here's an opportunity to help, but ultimately it's like it's still not good that like the these government

entities aren't doing it because you know there's there's a lot to cover is is the real reality and then kind of fast forward to twenty twenty five so then we had VoneCon and VoneCon is like the C V E's programs conference and that happened last year. NIS NIS kind of did

Mehul 31:27.541

Yeah.

PatrickGarrity 31:31.358

A little bit of lip service, I would say, and said the same exact thing they said the same before. Don't worry about it. We're automating everything. I think the year before they talked about a consortium with the industry and then they never did it. and I'm not trying to point figures, it's just like the communication is all over the place, right? and and this has real world implications to defenders, vulnerability management teams, everyone. Like everyone is impacted.

Mehul 31:48.308

Mm-hmm.

PatrickGarrity 31:58.314

Right, from a security perspective. So it has real real world implications. and and so the consortium never happened, 2025, kind of same thing. But like a week after Voluncan, suddenly like the board members from CVE dropped some news that tomorrow CVE is no longer gonna be funded. you know, Sis Sissa didn't sign the contract, and boom, next crisis. So

You know, naturally I'm I'm not trying to be critical of these things, but like systemic crisis across multiple administrations of of, you know, challenges within government of like what do consumers expect? And so I think there's been a pretty, pretty quick narrative shift as well of like, well, we never designed this for like global use. This was just designed for federal scope as we're going down down this path.

Mehul 32:41.075

Right.

Mehul 32:49.749

Yeah, I mean it's

PatrickGarrity 32:52.686

and so I think like that that's something just a lot of people reality have had to process and figure out like what am I gonna do? how am I gonna address gaps potentially from a tooling perspective if I'm building a product security tooling? What do I do if there isn't the information that's needed, you know? and and so it it creates a bunch of these problems. But ultimately, you know, the the funding, they were like, we got an 11 month extension, don't worry about it.

And so I I think generally like this continued like domino of of you know government services, I'm not trying to criticize them all. I know they're in they're doing great work, they're in challenging positions, right? But it it does it does make it hard for a lot of organizations to put trust in something that has essentially degradated over time. And the message around it hasn't been exactly like

Mehul 33:35.379

Mm.

PatrickGarrity 33:53.128

You know, maybe people had well intentions and they thought they were being transparent, but if you're gonna say stuff publicly like deliver on it, is a big lesson there.

Mehul 34:00.34

And and I've read and I

And then one of the things that I read was there were thirty-six thousand or thirty-seven thousand vulnerabilities that were not enriched or something on those lines. And then they came back with a report that thirty-two thousand of them are not scheduled to be enriched anymore. So the outstanding count is like just four thousand. So magically so magically that entire backlog disappeared. we just have four thousand issues to take care of, and these thirty-two thousand or whatever that number is.

PatrickGarrity 34:18.517

Yeah.

Well soon

PatrickGarrity 34:25.791

Yeah.

Mehul 34:31.113

Whatever the number is, is not scheduled or something on those lines.

PatrickGarrity 34:35.028

Yeah, so so so the and I I d I don't think this is bad. Like I think they're being more transparent at least of like, hey, look, you know, we told you we're gonna get to the backlog, we're really not, and here's how we're gonna communicate, we're not. And we have and so at this year at Voluncon twenty twenty six, you know, the conversation is is a bit more transparent, but also like you already eroded trust, right? for a while. And so the yeah, generally it's like, hey, look, like

Mehul 34:47.338

Yeah.

Mehul 34:58.452

Yeah.

PatrickGarrity 35:03.348

We don't have the analysts and people capacity to do the work we used to do and the backlog continues to grow. So we're just gonna make a conscious decision rather than marking old things as deferred or marking not marking anything on new things and letting it sit in a queue where we're gonna use this term not scheduled, which I think at least is like a good thing for people like myself that have to understand like government ain't touching this.

Mehul 35:30.603

Yeah.

PatrickGarrity 35:32.174

you know, but all ultimately it's like continuing, you know, to analyze what is the impact of the the things that they say and the announcements they're making. And really the criteria I I think the criteria is great to start with, which is we're gonna make sure that Kevs are enriched first, makes complete logic sense. I actually reached out to them and said, Hey, you should use our Volncheck Kev to like prioritize things in addition to SISA.

but then they said, hey, and then things in the federal scope, which is incredibly vague. and and I think to me what this is is like, okay, they can make an excuse however they want. there really isn't any accountability in the model because essentially they can make a determination whether they want to analyze it or not. I think in good faith they're gonna they are gonna focus on things that are gonna be much more pervasive.

Mehul 36:12.447

Yeah.

PatrickGarrity 36:25.366

much US centric. But when I talk about people throughout the world that were leveraging and using this service globally, they're like, I don't know if I'm gonna be able to leverage and use it how we historically have, because they're just so focused on a single scope and and they're limiting it. And there's n you know no guarantee that things are going to get covered. and and so, you know, naturally I think, you know, reaction wise, I think that's fair.

I think it's good there's more transparency, but also like even a week later, it's like things are in flux. Like the website is updating, but the API data isn't yet. This is pretty normal. So we're kind of going through a phase of trying to learn, you know, w what there is and isn't gonna be out of the data moving forward. but I do think ultimately it's gonna prov provide everyone with a lot more transparency around like what is gonna get coverage, what's gonna get enrichment quick and fast.

Mehul 37:23.455

Yeah, because

PatrickGarrity 37:23.735

and then what thing what things aren't, and it's gonna be you know, the responsibility of the private sector to fill the gaps.

Mehul 37:32.938

It remind reminds me of my product management days where you know as a product leader you get a lot of feature requests coming in, right? And you have a lot of feature requests, customers are waiting on feature requests. and if you don't classify the feature request, then the customers get angry. Hey, what what happened to my feature request? So one of the things I I did in my previous job was not on roadmap. So it was very clear, not on roadmap. You're never going to do this feature. So there was some closure.

PatrickGarrity 37:55.146

Yeah, yeah, yeah, yeah.

Mehul 38:01.599

There was some closure of the feature. So I think not scheduled is at least some level of closure for advice that we are not going to do this. If you find other ways to do it, go for it. We're not going to, you know, we're not going to touch it in the but these 4,000 we maybe will do something. The other thing, the other thing I want to talk about is you or your team got involved in this, especially with this hype around mythos and exploitation and so on and so forth.

PatrickGarrity 38:07.411

Yeah.

Mehul 38:29.463

There is a your team or your product got involved with the zero day clock project. Right? The zero day clock project. And one of the core one of the core arguments of that project is the time to exploitation is essentially gone down from years to hours, and it is projected to go down to minutes with AI. I'm curious what your take is on that in terms of the rate of exploitation going down. That is one. Second is

do you have a differing point of view on how the data was represented?

PatrickGarrity 39:01.78

Yeah, yeah. So I think two things there. You mentioned mythosanthropic clawed stuff and then we can talk about that and then also the zero day clock. So I I think sorry, excuse me. Give me one second. Pause.

Sorry.

PatrickGarrity 39:27.382

All right, zero day clock. I got this. Sorry, I needed a break for a second there.

Yeah, from a z so so yeah, go ahead.

Mehul 39:35.371

Hold on, hold on, hold on. You have to look at the camera. You're looking down. Yeah, yeah. This is this is much better. This is much better. Whatever you're doing now. No, you're looking down. You're looking down. So but look up, look up, look up, look up. Yep, that's good. That's good. That's the how that's how you need to do it.

PatrickGarrity 39:39.72

I I'll look. Was I doing good so far, just right now I was looking down? Okay. Yeah.

PatrickGarrity 39:53.463

Alright, I'm working towards it. So so really two things. okay. So really two things. first off the zero day clock, right? great project. I think it drives awareness of of things are moving faster quicker. There are a lot of different ways you can calculate data in charts and graphs like that. So I I don't think the discrepancies of like is it hours, is it days, is it a month?

Mehul 39:56.393

Yeah. Yeah.

PatrickGarrity 40:20.984

I think no one would agree it has shrinked substantially from where it was at a couple of years ago as far as how quick people are moving. And and I really, you know, if you look at the timeline and how fast people are moving, like when I I look at it, we're probably somewhere around on average, and average is like or median or however you want to calculate it. There's so many discrepancies with that. But the reality is is a lot of vulnerabilities are getting exploited before they're even disclosed. Right? I think somewhere around

Mehul 40:47.441

And

PatrickGarrity 40:50.07

26% that I calculated of vulnerabilities with exploitation evidence for the first time publicly were the disclosure of the exploitation evidence was on the same day or prior to the vulnerability being disclosed. So those are things that you don't have visibility into and you don't even have a have a patch to fix it. So mitigating controls are particularly important in those cases.

And and so what that says is is yeah, there there's a lot of vulnerabilities, zero days, threat actors are finding ways in and and being opportunistic. There's also a long tail of vulnerabilities that are what I would equate to be legacy vulnerability debt, where there might be a vulnerability that sits around for four years and then starts getting exploited suddenly. and so the the time windows can really, you know, vary, but

What we're seeing now is the ability for just about anyone to develop an exploit with AI tools. So I'd say in the last six to twelve months, now discovery of vulnerabilities and the ability to exploit them, like a much broader set of people can leverage those capabilities, but people that already know how to do it can accelerate the ability to develop new new zero days with these tools. and exploit faster, quicker. And so

Mehul 41:48.692

Hmm.

PatrickGarrity 42:11.37

You know, if anything we're seeing from like the anthropic claude open AI tooling side of things, and we manage a report of vulnerability service. So we're seeing this firsthand. At first it was a bunch of slop where people were just submitting reports and the vulnerabilities weren't real. Very quickly that has transitioned to a high volume of real vulnerabilities being reported that have to go through vulnerability disclosure process, have to get fixed, have to get a patch.

Mehul 42:27.071

Mm.

Mehul 42:33.405

Interesting.

PatrickGarrity 42:39.234

then people have to go apply that patch once it actually gets disclosed. and and you know, so just nature of the beast, like this is coming faster, quicker, both on the exploitation side, but then on the vulnerability discover side discovery side. And what that means is like it is going to be way more information moving forward. probably at levels that people aren't used to processing.

especially if you're on a product security team where you're maintaining a a tool, software, open source software, any of these different things.

Mehul 43:17.619

And what do you think if what do you think is happening? Why do you think the time to exploitation is going down? Do you are because are you seeing evidence that these AI models are contributing to the speed of exploitation getting sped up or is this there is something else happening for the for time for exploitation coming down?

PatrickGarrity 43:36.115

Yeah, I I I wouldn't correlate it necessarily with the AI models. Like this has been happening for three two or three years, right? Where where it really is accelerated. I really think the attack has just shifted from credential compromise to exploitation and a lot of are getting really good at it or or were really good at it. and so naturally more people are using that from a tactic perspective, which is gonna accelerate the timeline because they're that's where they're spending their time.

Mehul 43:43.219

That's okay.

Mehul 43:53.141

Yeah.

Mehul 44:06.229

Mm.

PatrickGarrity 44:07.37

from a resource perspective, not saying that credential compromise still isn't a problem, but but the the it's harder. And if you start implementing things like FIDO U2F, it's substantially harder. and so naturally now I shift my resources towards exploitation of vulnerabilities. Those timelines are all going to accelerate. And what I've seen on the reverse engineering side is a lot of times these researchers on the research side

Or on the bad bad guy side, threat actors, they focus on a certain product. Maybe they focus on file transfer products, maybe they focus on an ed network edge devices, and they just kind of fixate on that and they're able to go find bugs that they can exploit and then they go after it. I mean, they're not reporting those, of course, to the vendors. and so a lot of times the vendor

Mehul 44:45.396

Mm.

PatrickGarrity 45:03.602

might learn about a vulnerability for the first time when it's getting exploited. and then they have to go fix and release a patch and then everyone else finds out about it if there isn't like a mass exploitation event. Now what's interesting there is is a little bit tangent. I know we're talking about a lot of things here, but in Europe, the new Cyber Resilience Act actually requires vulnerabilities to disclose exploitation of vulnerabilities within

Mehul 45:09.5

I see.

PatrickGarrity 45:33.002

I think it's twenty four hours of it happening. so naturally circling full back, this should contribute to more disclosures of exploitation events in the wild, which I think is gonna be good for everybody.

PatrickGarrity 45:50.494

Yeah, the the an anybody doing business in Europe under the CRA has to disclose exploitation evidence to the European entities like the C CERTS. And if they don't comply with that, there's there's like two to six percent fines. I might be wrong with that range of total revenue. so the the once we we kind of circle back to compliance, but like now in Europe this is being driven as a compliance vehicle.

And the large majority of like tech companies do business in Europe. So they're gonna ha yeah, they're gonna have to comply with that. that starts September twenty twenty six. They have to start reporting. So

Mehul 46:23.143

Interesting.

Mehul 46:31.433

What you what do you think happens to the future of Sissa Cav? You've identified all these loopholes in the Sissa Cav. It on it's only focused on the federal side, it's not focused on the you know, the European or Asian markets and so on and so forth. They don't have the full scope, and then vendors like one check come in, fill the gap. And my my sense is my sense is

We are used to using these crutches like C VSS, EPSS, CSACev as a proxy for exploitation. And that will at least this is my sense, will not be relevant in the future. The thing that would matter is is this exploitable by AI or is it not exploitable by AI? Or in the sense of, you know,

PatrickGarrity 47:18.698

Yeah. It's it's early. It's early. So I'm not I'm I don't disagree with you. I think that's gonna be a factor is in and we already have companies that do like reachability analysis. you know, is it is a good example kind of like, you know, looking at the AI aspect. I think AI is it exploitable is different. But ultimately, yeah, you definitely wanna focus on the things that you know the threat actors are using if you have that information. and so

Mehul 47:31.304

Mm-hmm.

PatrickGarrity 47:48.532

This is probably more like a Metasploit module where like, yeah, if you know an AI model can exploit it, it's you know, the the the new bar is essentially like can AI exploit it? I think is a fair bar. Similar to like, is there a metasploit module that's been weaponized and we know that it works? it doesn't mean it's gonna get used, but it probably is. and so yeah, I think.

Mehul 48:06.41

Exactly.

Mehul 48:11.942

Especially by the medium, yeah. There are some companies that are very cutting edge in terms of their vulnerability management processes. They're at the top of their game. Maybe they will use it, but there is a long tail of organizations they're still fixing lock for shell. You know, even even now they are you find you run a scan and you find lock for shell in these organizations. the the the follow-up question I had is is what happens to the future of exploitation? Is it

PatrickGarrity 48:26.536

Yes, yeah.

Mehul 48:41.322

and you all you you briefly mentioned you're seeing a lot of AI slop, or at least you were seeing a lot of AI slop early on. Do you still see that kind of a slop in your in your in your day to day work right now?

PatrickGarrity 48:54.848

We see yeah, we still see some, but what we're seeing is a shift where the stuff that that the AI tools are using, whether they're using Cloud or or OpenAI or or whatever AI tool they're using, like they're getting better. And the reports tend to be more accurate. And when we report these things that are reported to us to the software supplier, most of them are ending up being real or legitimate. in some cases not. And so I think

Mehul 49:10.162

Mm.

PatrickGarrity 49:24.458

Validation and verification becomes a very important step at scale. But I do think that a lot of these product teams and and software teams need to realize that that, you know, AI is going to find a lot more vulnerabilities that were in your software that just weren't discovered. And so na naturally that that's gonna create a similar experience to when fuzzing tooling came about, right? Where people all of a sudden were like, wow.

Mehul 49:41.567

Yeah.

PatrickGarrity 49:51.904

Look at all these things. I need to go fix them now. I just think the reality is is it's at a a very accelerated rate. It's ficker quest faster, quicker. And you know, I think Firefox is probably the best example we have with with anthropic glass wing. one of the areas I've been spending a lot of time and research on. It's like, yeah, this this this anthropic thing is real. It found 300 vulnerabilities in our software and we fixed them all. Most teams

probably don't have the capacity or skill set to be able to do all those fixes. Now AI could help with that. Like here's the fixes, here's what you want to change. But like this is a complete shift in how you develop software. and it's gonna change the game for everyone out there as far as how they might approach security from a software standpoint. so I think, you know, I'm super careful of like you know, I I I think a

Mehul 50:32.372

Yeah.

PatrickGarrity 50:47.196

A lot a lot of this is marketing talk, like well mar marketed campaign from Anthropic and Glasswing, but at the same time it's it's like, hey, yeah, it's gonna find a lot more new findings that you didn't know. and naturally you can expect any of this tooling to end up in the threat actor's hands. Like any any tool that you have access to, creatively a threat actor is gonna find a way to get access to similar technology.

Mehul 50:58.962

Mm.

PatrickGarrity 51:15.028

Whether that's accessing the same model or just building their own model. and and that's a reality.

Mehul 51:19.262

The thing the thing that that I don't have a clear line of sight. I mean I can understand this happening I can understand this happening to the open source software, which you know the open basically you connect Claude or some of these frontier models to these open source projects, find these flaws, these f flaws get fixed and so on. I don't have a clear line of sight on what happens to the commercial software. I don't know if this results into more of trying to take over

the source code of commercial projects, then find the vulnerabilities and then go after them. I don't know if that is a new attack pattern that will emerge from this. Because the open source it's very clear because any open source project that is out there, you should just assume these models will run an assessment on them, especially like OpenSSL, OpenSSH, you know, Apache Web Server. These should be like by default part of their assessment program. As soon as the new model comes out, you know, there is some level of assessment done.

And the bugs are fixed. But I don't have a clear line of sight on what happens to the commercial software. Do we see do we see more evidence of stealing commercial software source code to find vulnerabilities and then exploit them?

PatrickGarrity 52:29.802

Yeah. I i great questions. And then it's like, are you putting these source codes in these models now? And what are the models doing with that source code? like I I I know like people are like, it's contained, don't worry about it. But generally what I'm seeing in the space around AI tooling is it's evolving so quickly and a lot of times it's being released without security in mind. and so I think there's there's inherent risk with that too, of like leakage of source code, leakage of information.

I don't think we need to be like fear, uncertainty, and doubt, and and this is an apocalyptic thing. yeah, I I I think it's just the reality of like there's gonna be more stuff, more findings. And frankly, the threat actors don't have a problem finding things to target and exploit today. So maybe they can do it faster, quicker, but I don't even think that like from my perspective, that like that is gonna move the needle substantially from what what's already happened.

Mehul 53:03.73

I think the the industry has done enough of that. We will add to the fear.

PatrickGarrity 53:29.41

and and so, you know, maybe maybe this gives the opportunity of defender advantage in that respect more than anything. And that's what I would be hopeful for is is, you know, these tools have real world impact in relation to the defender and being able to identify and fix these things.

Mehul 53:46.419

Last question for you, Patrick. you you've been looking at vulnerabilities for so many years. Any crazy vulnerabilities come to your mind that which has you've had like the craziest experience navigating the the inception to closure of the vulnerabilities? Any any cool stories come to your mind in terms of vulnerabilities?

PatrickGarrity 54:06.8

man. I w I wish I had this question earlier because I know there's a ton. on the spot. I mean like some of are funny as far as like C if you go through C V U records you can find all sorts of wild vulnerabilities for different software, hardware, or different products.

Mehul 54:22.814

Were you around when proxy you were around when proxy log on happened, right?

PatrickGarrity 54:27.774

Yeah, yeah. Proxy proxy login on the exch exchange side. That was the one where the FBI came in and was removing reverse shells off of organizations' exchange servers. you know, so they weren't compromised and they get they could patch. and so yeah, that was like that was my first real widespread exposure to vulnerability exploitation. And I remember we had a client at that time that got got owned.

And you know, we we helped from an IR perspective when I was at Blue Mira. And, you know, of of course I think they were trying to deploy ransomware and other things, but mitigating and containing that and then deploying a new exchange server in order to g you know make sure that they weren't compromised and things were operational. But that in and here's the deal, it's like yeah, as much as you can hardening I think if you're a small business outsourcing to trusted cloud providers.

is generally a good idea not dangling too much of your software out there on the internet if you can't maintain and update it. you know, I think that that's a real reality. I'm trying to think of any other real interesting ones. yeah, I I I mean I kind of mentioned the the file sharing aspect. and and sometimes too, like crush FTP was a good example of file transferring where they just they disclosed a vulnerability. We assigned an ID and they got mad at us.

for just assigning an ID. and so some sometimes like people have perceptions of like C V E IDs are a bad thing. Whereas in fact a C V E ID is how people get visibility and a vulnerability so they can actually patch and fix. Cause most people aren't aren't watching your advisories if you're a vendor. Like some do, large enterprises do. But I think that's probably yeah that

Mehul 56:06.004

Nice.

Mehul 56:11.945

Okay.

Mehul 56:16.57

Exactly. you do it for patch two days. Yeah, you do it for patch two and but nothing else.

PatrickGarrity 56:24.756

Yeah, and so that that's probably one of the mi biggest misconceptions is like because someone issues a C V E, they're not the one responsible for what a threat actor does to your product. that's probably the biggest thing I've had to navigate, which is rather interesting. you know, when you're going through it for a first time of like, okay, what's the reality here? You know? but yeah, public

Public disclosure, I think organizations generally have gotten better about it, but there are a lot of companies still that kinda hide their vulnerabilities and they see it as more like public shame and it's like, no man, th this stuff is really important to get out there so that people actually know to patch, mitigate, and do other things.

Mehul 57:02.826

Thank you.

Mehul 57:11.306

Cool Patrick, this was this was a fun interview. We covered a lot of ground. you're way too generous with your time. Thank you for your time. what's the what's the next big thing that is dropping from Patrick Garrity?

PatrickGarrity 57:25.55

man. I mean for me a lot like the the on the research side, I think the anthropic stuff I'm tracking closely, trying to understand what vulnerabilities are being disclosed in the products. and so I have a tracker where I'm tracking that. Spending a lot of time in analyzing and understanding the implications of NIST MVD and their new new statuses and what they're gonna tackle. so that's natural. And then I think generally just paying attention to you know, reported vulnerabilities.

you know, if you look at us and you look at GitHub, the the substantial spike in C V E issuance and disclosures, some of it's historical work that we've been doing, but by and far the the trends are off the chart from a disclosure perspective in the volume, and the reported vulnerabilities that we're seeing. And I I think like keeping track of that and ensuring people have the enrichments that are needed to take action and you know do

get to what they need. But yeah, generally speaking it's it's man, get ready to stay up on the latest updated software. especially for network edge devices, user facing devices, that sort of stuff. And yeah, I mean I have a lot of fun research ideas, but it is a matter of time.

Mehul 58:43.698

Good. Thank you, Patrick. Thank you for your time.

PatrickGarrity 58:47.114

Thanks, May Hel. Take care.

Mehul 58:50.097

stop recording now.