Research
Our team (formerly of Kenna Security as well as co-creators of the EPSS) invented risk-based vulnerability management. But we believe there's areas of exposure management that haven't even been tapped, and they need to be explored urgently given the monumental challenges facing security teams. We're excited to publish our research (including ongoing benchmarks of our global and local models) and present them here.
Jay Jacobs, Chief Data Scientist
Michael Roytman, CTO
Dr. Benjamin Edwards, Head of Modeling
Jerry Gamblin, Head of Research
July 2026 CVE of the Month: The Apache Solr Backdoor You Installed on Purpose (CVE-2026-44825)
July 2026 CVE of the Month: The Apache Solr Backdoor You Installed on Purpose (CVE-2026-44825)
Teaming Up Against Exposure
Having focused the last decade on Exposure Management, I can’t help but feel we are in unprecedented times. The moment we’re trying to meet is an impending future marked by an explosion in the scale, velocity, and complexity of exploitation. Meeting this moment requires focusing on the core values of exposure reduction—which is why I am truly honored to join Empirical Security as Head of Platform.
Unfinished Mission: Empirical’s New Funding
Today, Empirical Security announced our $25 million Series A led by Brightmind Partners. We started Empirical because prediction has become a requirement for modern defense, and because the technology finally exists to build this the right way.
Country Roads, Take Me Home
If you have been watching the World Cup this summer, you have probably heard stadiums full of fans belting out John Denver's "Take Me Home, Country Roads." There is something undeniable about that song. It taps into a universal pull toward the places, the people, and the work where we truly belong. For me, the last few weeks have felt exactly like that. A homecoming.
That is why I am incredibly excited to finally announce that I have joined Empirical as their Head of Research.
Looking for the AI vulnerability flood
Looking for the AI vulnerability flood — Why a firehose worth AI vulns hasn’t fully manifested itself in the CVE ecosystem.
The Vulnerability Identity Crisis
Art Manion and I have been spending roughly an hour a week for the past couple of years working through what sounds like a simple question: What are the minimum viable elements needed to define and identify a vulnerability?
EPSS V5 Is Here
It’s an exciting day at Empirical: we’ve released V5 of EPSS, the scoring system that our team helped create and which was recently recommended by Anthropic to help teams prepare for an AI-accelerated tsunami of vulnerabilities.
Accurate Representation
For most of the last decade, the question we have spent our research time on at Empirical Security is some version of the same one. Given a vulnerability, what is the probability it will be exploited? Given an organization, how much risk does it carry? Given a remediation strategy, how much better does it perform than the alternatives? These are measurement questions. They have answers, even if the answers are imperfect.
Predict, Don’t Enumerate
Michael Roytman wrote an article for O’Reilly that makes it clear: the new frontier in exposure management is knowing what’s dangerous, not remediating vulns by volume.
The DBIR Confirms the New Bottleneck in Security: Not Pointing, but Prioritizing
The 2026 DBIR is out, and vulnerabilities are the name of the game. Empirical is proud to have contributed critical research to this year’s report.
Anthropic Is Right About EPSS. That Still Leaves the Hard Part.
Anthropic’s security team recently gave defenders sensible advice for an AI-accelerated world, which is to patch KEV then use EPSS to prioritize the rest. The team wrote: “EPSS provides a daily-updated probability that a given Common Vulnerability and Exposure (CVE) will be exploited in the next 30 days. Patching the KEV list first and then everything above a chosen EPSS threshold will help you turn thousands of open CVEs into a manageable queue.”
The Knowing Machine
Dan Geer posed the right question at Black Hat in 2014: are vulnerabilities sparse or dense? If sparse, you can patch your way to safety. If dense, patching without prioritization is the myth of Sisyphus, but the boulder is growing in size. Eleven years later, writing with Dave Aitel in Lawfare, he conceded the terms and moved to the next problem. What the industry needs, he argued, is a "knowing machine" that converts hazards into risks, not a "pointing machine" that merely enumerates flaws and screams equally at all of them.
The 500 Organization Reality Check
This is part five of our series on empirical exposure management. Data from 500+ organizations in P2P Vol. 8 showed that 95% of enterprise assets already carried a top-tier exploitable vulnerability when the CVE firehose was 18,000 a year; at 48,000+ in 2025 and climbing, that exposure has only compounded while remediation capacity has not.
Using ServiceNow? We’ve got you covered.
Empirical Security’s new ServiceNow Vulnerability Response app brings predictive exploit intelligence directly into ServiceNow workflows so security teams can move from reactive vulnerability management to forward-looking remediation.
When Headcount Doesn’t Help
The practical implication is a reframe of how programs are governed. Most teams measure remediation volume—tickets closed, patch compliance rates, mean time to remediate. These metrics describe throughput. They do not measure the marginal risk reduction of each remediation slot. Under constrained optimization, what matters is not how many findings you close but whether each slot is allocated to the vulnerability that reduces exploitability probability the most at the margin.