jayjacobs (@jayjacobs) 's Twitter Profile
jayjacobs

@jayjacobs

Founder, Partner and Data Scientist at Cyentia Institute. EPSS Author, first.org/epss and Co-author of Data-Driven Security amzn.to/ddsec;

ID: 14851470

linkhttp://www.cyentia.com calendar_today21-05-2008 02:53:10

4,4K Tweet

3,3K Takipçi

571 Takip Edilen

jayjacobs (@jayjacobs) 's Twitter Profile Photo

Updated model released for the Exploit Prediction Scoring System #EPSS improved performance and 168,325 CVEs scored today. first.org/epss/model

Updated model released for the Exploit Prediction Scoring System #EPSS improved performance and 168,325 CVEs scored today. first.org/epss/model
Michael Roytman (@mroytman) 's Twitter Profile Photo

EPSS v2 is the most important work done in the vulnerability world in the past 10 years. Free and open science to replace dogma:

jayjacobs (@jayjacobs) 's Twitter Profile Photo

"EPSS v2 is out!" I wrote up a brief history of how the objectives of EPSS have shifted with this release: cyentia.com/epss-version-2…

Wade Baker (@wadebaker) 's Twitter Profile Photo

Anytime I hear superlatives like "worst vuln in recent history" my skepticalometer goes off. Heard that a lot in ref to Log4j and this chart from Fortinet 2H 2021 report seems to back it up. Log4j is like "Aw -Keep pushing Struts; you'll make it to the Big Leagues one day..."

Anytime I hear superlatives like "worst vuln in recent history" my skepticalometer goes off. Heard that a lot in ref to Log4j and this chart from Fortinet 2H 2021 report seems to back it up. Log4j is like "Aw -Keep pushing Struts; you'll make it to the Big Leagues one day..."
jayjacobs (@jayjacobs) 's Twitter Profile Photo

This isn't another post about Log4Shell. Instead it's about what Log4Shell can teach us about the Exploit Prediction Scoring System (EPSS) first.org/epss/log4shell

This isn't another post about Log4Shell. Instead it's about what Log4Shell can teach us about the Exploit Prediction Scoring System (EPSS) first.org/epss/log4shell
SocietyInfoRisk (@societyinforisk) 's Twitter Profile Photo

Join us at #SiRAcon22 where jayjacobs will discuss a different approach, the Exploit Prediction Scoring System (EPSS), that improves measurement by collecting real-world data, using modern analysis, and mixing with domain expertise. More Info here: societyinforisk.org/SIRAcon22

Join us at #SiRAcon22  where <a href="/jayjacobs/">jayjacobs</a> will discuss a different approach, the Exploit Prediction Scoring System (EPSS), that improves measurement by collecting real-world data, using modern analysis, and mixing with domain expertise.

More Info here: societyinforisk.org/SIRAcon22
jayjacobs (@jayjacobs) 's Twitter Profile Photo

Sasha put a lot of work into making the EPSS API a reality. Current and historical EPSS scores are now available on demand!

Wade Baker (@wadebaker) 's Twitter Profile Photo

Doing anything at 11ET today? How about joining me and Wendy Nather for an encore presentation of our 2022 RSA Conference talk for tips on measurably improving infosec programs. rsaconference.com/library/top-ra…

jayjacobs (@jayjacobs) 's Twitter Profile Photo

We've been working hard on EPSS and the next version is going live in one week on March 7th, expect the scores to shift around a bit. Details on our process: arxiv.org/abs/2302.14172 and performance is vastly improved as we continue to expand data partners!

We've been working hard on EPSS and the next version is going live in one week on March 7th, expect the scores to shift around a bit. Details on our process: arxiv.org/abs/2302.14172 and performance is vastly improved as we continue to expand data partners!
jayjacobs (@jayjacobs) 's Twitter Profile Photo

I deny any responsibility. The only wave I’ve brought is a wave of confusion when people mistake me for some politician.

I deny any responsibility. 

The only wave I’ve brought is a wave of confusion when people mistake me for some politician.