Hackers to Founders

Chris Magistrado

Jeremiah Grossman: The 1% of CVEs That Actually Matter

SEP 23, 202673 MIN

Description

Only about 1% of all CVEs have ever been exploited, and closer to 0.2% have caused real financial loss. Jeremiah Grossman, founder of WhiteHat Security and Bit Discovery and now CEO of Root Evidence, explains why finding vulnerabilities was never the hard part, and what security teams should focus on instead. We talk about what Anthropic's Mythos findings in OpenBSD and Firefox actually mean, why companies don't just "patch everything," and how breaches really happen today. Then we get into founding companies, how Grossman Ventures picks investments, and jiu-jitsu. In this episode: - Why most AI-found vulnerabilities will never be weaponized - The real reason companies don't patch everything - How breaches actually happen: edge devices, credential stuffing, and BEC - Why he calls compliance-driven security "actually evil" - A 90-day security plan for a Series A startup: scanning, MFA everywhere, and canaries - "Kamikaze" vs. "optionality": two ways to build a startup - The daily habit he uses to find problems worth solving - Why he never doubted he could be a founder, only an employee 0:00 Intro 1:33 AI vuln discovery: finding vs. exploiting 3:50 Mythos, the remediation gap, and the 1% of CVEs that matter 6:21 Why companies don't patch everything 8:35 How breaches actually happen today 9:16 Is the annual pen test dead? Compliance vs. security 10:58 Software liability 12:07 CVSS: keep, kill, or ignore? 13:34 How much of security sells more findings 14:49 MSPs, SMBs, and how insurers scan 16:59 SOC 2 and pen tests for a Series A founder 17:52 The most common mistake: inconsistent MFA 20:03 Security vendor warranties 21:14 A 90-day security plan for a new fintech 22:57 Lightning round 25:27 Hacking Yahoo at 19 26:26 What he wishes he knew before WhiteHat 28:25 Kamikaze vs. optionality startups 29:07 Bootstrap or raise? Talk to a customer every day 31:18 Technical founders who hate selling 32:40 The 3 people founders should talk to daily 35:32 How Grossman Ventures picks investments 39:29 Security problems he'd start a company around 41:10 What Grossman Ventures wants to fund 42:34 Why some security firms stall and others scale 44:19 AI startups and the moat problem 45:34 ToyBox Car Club and moving to Boise 47:39 Jiu-jitsu and the Black Hat BJJ event 57:00 Book recommendations 1:01:06 What's next: Root Evidence and competing at Worlds 1:08:32 Where to find Jeremiah and who should be on next 1:09:36 How he met his co-founders 1:10:52 Did he ever doubt he could be a founder? 1:11:57 Wrap-up 1:12:55 Outro Watch the full video on YouTube: https://youtu.be/fp3F6nc2pcQ Links: Jeremiah Grossman on LinkedIn: https://www.linkedin.com/in/grossmanjeremiah/ Root Evidence: https://rootevidence.com/ Grossman Ventures: https://www.grossman.vc/ Chris Magistrado on LinkedIn: https://www.linkedin.com/in/cmagistrado/ Hackers to Founders features the hackers and security practitioners who went on to build companies. Subscribe wherever you listen.