#EPSS gives us a lens into global exploit pressure.
But to further understand our vulnerability risk posture, we need to adjust that pressure through the lens of our own controls — and their measured effectiveness.
In my latest blog, I show you how to take EPSS asset-level exploit likelihoods (EPSSg) and update them with #Bayesian inference to reflect control effectiveness.
It’s a simple but powerful way to turn the Swiss cheese model from a metaphor into something measurable — a living model that evolves as new evidence arrives.
https://stephenshaffer.io/quantifying-swiss-cheese-the-bayesian-way-b2b512472d85
Nature presents us with 80 "octaves" of light, of which humans can see exactly 1.
Bringing the other 79 octaves into view has taken two centuries of effort, but it has transformed our ability to sense our place in the cosmic order.
My new essay in Aeon magazine:
https://aeon.co/essays/william-herschels-sensors-let-us-see-the-invisible-universe #space #science #nature #tech
My kid just WhatsApped from his German exchange trip. They had to call an ambulance for him.
He has food poisoning, was very pale and nauseous. He was dehydrated and his blood pressure was dropping.
He's fine now but I wanted to share this because it has the most Western Europe Is a Civilized Place ending ever.
The paramedics came to the mall, took him into the ambulance, gave him an IV, checked him out, stayed with him until he felt better, then told him "No charge. Enjoy your trip to Germany." And if that wasn't enough, when they realized the group had had to move onto the train station without him, they gave him a ride over there to catch up with them.
I'm so ground down by the predatory realities of America in general in 2025 that this just about blew my fucking mind.
Rubbish? Fine? Brilliant? British superlatives graded and ranked.
https://yougov.co.uk/society/articles/21568-how-good-good
US version here ('quite' interesting comparison)
https://today.yougov.com/society/articles/21717-how-good-good-1
After last month's CVE funding crisis, I started talking to experts on what went wrong and what's ahead.
By the end of my interviews, I learned that a chief rival to the CISA-funded MITRE-run program, the CVE Foundation, thinks it can have a CVE database not dependent on the US government up and running by December, with the support of dozens of private sector companies and four non-US governments.
Check out my latest CyberScoop piece. Thanks to Sasha Romanosky, Peter Allor, Jerry Gamblin, Ben Edwards, Jay Jacobs and Michael Roytman for their insight.
CVE Foundation eyes year-end launch following 11th-hour rescue of MITRE program
https://cyberscoop.com/cve-program-funding-crisis-cve-foundation-mitre/
The unintended consequences of this regime's actions are delightfully ironic.
Reduced consumption and a crashed economy may very well result in the US finally meeting Paris Climate Agreement carbon emission goals.
I do not want your Gemini,
I do not want any AI.
I do not want it in my Chrome,
I do not want it in my home.
Not in my mail,
Even on sale,
Not in my app,
None of this crap.
I do not want it here or there,
I do not want it anywhere!
(with apologies to the estate of Dr. Seuss 🍳🍖)