/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

RiskSense report analyzing the top 54 open source projects finds security vulnerabilities doubled from 421 bugs in 2018 to 968 in 2019

Jenkins and MySQL vulnerabilities have had the most weaponized vulnerabilities in the past five years.  —  A study that analyzed the top 54 open source projects found …

ZDNet Catalin Cimpanu

Context & Ripple Effects

This report lands two months after researchers at the Linux Foundation and Harvard mapped how deeply enterprises depend on widely used FOSS components — the exact population whose defect rate RiskSense is now quantifying. It also extends the picture painted by the stream of security advisories for Jenkins plugins that ran through 2019: Jenkins now appears again, this time as one of the two projects with the most weaponized vulnerabilities of the past five years.

The doubling matters because it is measured against a known baseline: earlier ZDNet reporting established that only about 4,183 of 76,000 disclosed flaws from 2009–2018 were exploited in the wild. RiskSense's weaponization lens — which projects get attacked, not just which have bugs — is what turns a raw count into an enterprise risk signal.

First-order effects

  • Enterprises running the top 54 open source projects face a doubled annual disclosure load (421 to 968 bugs), with patching priority increasingly dictated by weaponization history rather than severity scores alone.
  • Jenkins and MySQL carry the heaviest weaponization records of the past five years, putting their maintainers and the organizations deploying them at the center of remediation triage.

Second-order effects

  • Aggregation efforts like Google's Open Source Vulnerabilities database — later extended across Python, Rust, Go, and project-specific feeds — gain urgency as enterprises need per-project vulnerability visibility at this volume.
  • Plugin-heavy ecosystems follow the same curve: WordPress third-party plugin disclosures hit a record 2,240 in 2021 with 77% carrying public exploits, confirming the pattern RiskSense flagged in core projects.

Third-order effects

  • If disclosure counts keep compounding while actual exploitation stays comparatively rare, the industry's scarce security resources shift toward exploit-intelligence-driven prioritization rather than universal patching — the NVD's own tally on pace to double year-over-year makes triage-by-volume untenable.
  • Widely deployed volunteer-maintained projects like Jenkins become structural supply-chain risk, pushing enterprises toward funded stewardship and formal dependency accounting for the components they embed.

The trend: Open source security is moving from counting disclosed bugs to tracking which ones get weaponized, turning vulnerability databases into core enterprise infrastructure.