Jeremiah Grossman: The 1% of CVEs That Actually Matter
Download MP3Only about 1% of all CVEs have ever been exploited, and closer to 0.2% have caused real financial loss. Jeremiah Grossman, founder of WhiteHat Security and Bit Discovery and now CEO of Root Evidence, explains why finding vulnerabilities was never the hard part, and what security teams should focus on instead.
We talk about what Anthropic's Mythos findings in OpenBSD and Firefox actually mean, why companies don't just "patch everything," and how breaches really happen today. Then we get into founding companies, how Grossman Ventures picks investments, and jiu-jitsu.
In this episode:
- Why most AI-found vulnerabilities will never be weaponized
- The real reason companies don't patch everything
- How breaches actually happen: edge devices, credential stuffing, and BEC
- Why he calls compliance-driven security "actually evil"
- A 90-day security plan for a Series A startup: scanning, MFA everywhere, and canaries
- "Kamikaze" vs. "optionality": two ways to build a startup
- The daily habit he uses to find problems worth solving
- Why he never doubted he could be a founder, only an employee
0:00 Intro
1:33 AI vuln discovery: finding vs. exploiting
3:50 Mythos, the remediation gap, and the 1% of CVEs that matter
6:21 Why companies don't patch everything
8:35 How breaches actually happen today
9:16 Is the annual pen test dead? Compliance vs. security
10:58 Software liability
12:07 CVSS: keep, kill, or ignore?
13:34 How much of security sells more findings
14:49 MSPs, SMBs, and how insurers scan
16:59 SOC 2 and pen tests for a Series A founder
17:52 The most common mistake: inconsistent MFA
20:03 Security vendor warranties
21:14 A 90-day security plan for a new fintech
22:57 Lightning round
25:27 Hacking Yahoo at 19
26:26 What he wishes he knew before WhiteHat
28:25 Kamikaze vs. optionality startups
29:07 Bootstrap or raise? Talk to a customer every day
31:18 Technical founders who hate selling
32:40 The 3 people founders should talk to daily
35:32 How Grossman Ventures picks investments
39:29 Security problems he'd start a company around
41:10 What Grossman Ventures wants to fund
42:34 Why some security firms stall and others scale
44:19 AI startups and the moat problem
45:34 ToyBox Car Club and moving to Boise
47:39 Jiu-jitsu and the Black Hat BJJ event
57:00 Book recommendations
1:01:06 What's next: Root Evidence and competing at Worlds
1:08:32 Where to find Jeremiah and who should be on next
1:09:36 How he met his co-founders
1:10:52 Did he ever doubt he could be a founder?
1:11:57 Wrap-up
1:12:55 Outro
Watch the full video on YouTube: https://youtu.be/fp3F6nc2pcQ
Links:
Jeremiah Grossman on LinkedIn: https://www.linkedin.com/in/grossmanjeremiah/
Root Evidence: https://rootevidence.com/
Grossman Ventures: https://www.grossman.vc/
Chris Magistrado on LinkedIn: https://www.linkedin.com/in/cmagistrado/
Hackers to Founders features the hackers and security practitioners who went on to build companies. Subscribe wherever you listen.
We talk about what Anthropic's Mythos findings in OpenBSD and Firefox actually mean, why companies don't just "patch everything," and how breaches really happen today. Then we get into founding companies, how Grossman Ventures picks investments, and jiu-jitsu.
In this episode:
- Why most AI-found vulnerabilities will never be weaponized
- The real reason companies don't patch everything
- How breaches actually happen: edge devices, credential stuffing, and BEC
- Why he calls compliance-driven security "actually evil"
- A 90-day security plan for a Series A startup: scanning, MFA everywhere, and canaries
- "Kamikaze" vs. "optionality": two ways to build a startup
- The daily habit he uses to find problems worth solving
- Why he never doubted he could be a founder, only an employee
0:00 Intro
1:33 AI vuln discovery: finding vs. exploiting
3:50 Mythos, the remediation gap, and the 1% of CVEs that matter
6:21 Why companies don't patch everything
8:35 How breaches actually happen today
9:16 Is the annual pen test dead? Compliance vs. security
10:58 Software liability
12:07 CVSS: keep, kill, or ignore?
13:34 How much of security sells more findings
14:49 MSPs, SMBs, and how insurers scan
16:59 SOC 2 and pen tests for a Series A founder
17:52 The most common mistake: inconsistent MFA
20:03 Security vendor warranties
21:14 A 90-day security plan for a new fintech
22:57 Lightning round
25:27 Hacking Yahoo at 19
26:26 What he wishes he knew before WhiteHat
28:25 Kamikaze vs. optionality startups
29:07 Bootstrap or raise? Talk to a customer every day
31:18 Technical founders who hate selling
32:40 The 3 people founders should talk to daily
35:32 How Grossman Ventures picks investments
39:29 Security problems he'd start a company around
41:10 What Grossman Ventures wants to fund
42:34 Why some security firms stall and others scale
44:19 AI startups and the moat problem
45:34 ToyBox Car Club and moving to Boise
47:39 Jiu-jitsu and the Black Hat BJJ event
57:00 Book recommendations
1:01:06 What's next: Root Evidence and competing at Worlds
1:08:32 Where to find Jeremiah and who should be on next
1:09:36 How he met his co-founders
1:10:52 Did he ever doubt he could be a founder?
1:11:57 Wrap-up
1:12:55 Outro
Watch the full video on YouTube: https://youtu.be/fp3F6nc2pcQ
Links:
Jeremiah Grossman on LinkedIn: https://www.linkedin.com/in/grossmanjeremiah/
Root Evidence: https://rootevidence.com/
Grossman Ventures: https://www.grossman.vc/
Chris Magistrado on LinkedIn: https://www.linkedin.com/in/cmagistrado/
Hackers to Founders features the hackers and security practitioners who went on to build companies. Subscribe wherever you listen.
Creators and Guests
Host
Chris Magistrado
Host of @HackerToFounderOwner of @TopClearedRecSecurity Researcher. Defcon is fun. CCCamp is a trip.
