Written By:
Brian Martin

Brian Martin has been studying, collecting, and cataloging vulnerabilities since 1993, both personally and professionally. Starting with a personal collection organized in the venerable FILES.BBS format and ultimately becoming the Content Manager of the Open Source Vulnerability Database (OSVDB), he has pushed for the evolution of vulnerability databases (VDBs) for years. Via blogs, presentations, and public dialogue on social media, Martin has challenged every major vulnerability database to improve their processes and coverage, but non more so than the one he manages.

Brian has been involved in all aspects of the vulnerability disclosure process, including finding new vulnerabilities, writing advisories, coordinating disclosure, creating disclosure programs, and working with a variety of organizations to improve vulnerability handling and response. This includes feedback and contributions to major vendor security programs and more recently, companies that manage bounty programs on behalf of vendors.

Additionally, Brian was on the CVE Editorial Board for ten years and remains a sought after speaker on vulnerability topics.

Vulnerability Management

Marconi’s Wireless Telegraph and the First Vulnerability

What is the first vulnerability? On first thought, it doesn’t seem like pinpointing the first correctly defined vulnerability would be difficult. After all, isn’t the computer security industry relatively young? If only software comes to mind when thinking of vulnerabilities, then yes, the computer security industry is considerably brief compared to the discovery of fire. However, if you remember that vulnerabilities also encompass hardware issues, then the security industry is actually over a century old!

Vulnerability Management

The Types of Zero-Day Vulnerabilities and How to Defend Against Them

For many years, the term “zero-day” has been overused by news outlets and some security providers—mythologizing it to become the ‘big bad wolf’ of the security world that renders any organization’s systems useless with one click of a mouse. While that may be technically true, there is a lot more to it. Are zero-day vulnerabilities truly impossible to defend against? Well, depending on how you define it, organizations might have a lot more defensive options.