GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 16-Apr-2025 03:58:50 JST Kevin Beaumont Kevin Beaumont

    My take on the CVE contract issue for businesses: don’t overreact, wait and see what impacts are.

    The NVD backlog was already pretty crazy.. the US gov has gotta put real funding into this area if it wants to retain control of cyber standards.

    In conversation about 2 months ago from cyberplace.social permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 16-Apr-2025 06:38:48 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • BrianKrebs

      Just as an update to this - @briankrebs has confirmed with MITRE the letter is real, and as it stands the CVE database is likely to offline tomorrow.

      In conversation about 2 months ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Mark Esler (eslerm@cyberplace.social)'s status on Wednesday, 16-Apr-2025 06:42:18 JST Mark Esler Mark Esler
      in reply to
      • BrianKrebs

      @GossiTheDog @briankrebs multiple CVE Board members have confirmed.

      In conversation about 2 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 16-Apr-2025 06:45:48 JST Kevin Beaumont Kevin Beaumont
      in reply to

      To widen it out - CVE is the globally recognised system orgs use for vulnerability management.

      Every vulnerability management product uses CVEs. Vulnerability management is a core part of cybersecurity - often, the most important part.

      Additionally, CVE is written into several US government standards that orgs have to follow.

      So the US Government not funding it is a major and historic own goal.

      In conversation about 2 months ago permalink
    • Embed this notice
      BrianKrebs (briankrebs@infosec.exchange)'s status on Wednesday, 16-Apr-2025 07:01:30 JST BrianKrebs BrianKrebs
      in reply to

      @GossiTheDog See my updates. CVEs will still be issued to CNAs (via API, as long as that's running), but the more manual stuff they do (i.e. issuing cves to non-CNAs) may suffer in the time being.

      In conversation about 2 months ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      daniel:// stenberg:// (bagder@mastodon.social)'s status on Wednesday, 16-Apr-2025 07:01:30 JST daniel:// stenberg:// daniel:// stenberg://
      in reply to
      • BrianKrebs

      @briankrebs @GossiTheDog yeah, as CNAs we have direct API access so we can still register and publish them as long as they don't shut down the servers

      In conversation about 2 months ago permalink
    • Embed this notice
      Stefan Eissing (icing@chaos.social)'s status on Wednesday, 16-Apr-2025 07:07:20 JST Stefan Eissing Stefan Eissing
      in reply to
      • daniel:// stenberg://
      • BrianKrebs

      @bagder @briankrebs @GossiTheDog it seems a small step to just have CNAs own a permanent, published number range or prefix and an RSS feed. (which history teaches us will end up in DNS)

      Anyone interested can then build their own database.

      In conversation about 2 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 16-Apr-2025 07:13:59 JST Kevin Beaumont Kevin Beaumont
      in reply to

      There's an argument that MITRE should try to keep everything alive and run things without funding and contracts etc.. but, honestly? My take - stop doing everything that isn't in the contract. Force the issue.

      In conversation about 2 months ago permalink
      Mr. Bill repeated this.
    • Embed this notice
      Lauren Weinstein (lauren@mastodon.laurenweinstein.org)'s status on Wednesday, 16-Apr-2025 07:24:50 JST Lauren Weinstein Lauren Weinstein
      in reply to

      @GossiTheDog That's tantamount to recommending suicide.

      In conversation about 2 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 16-Apr-2025 07:27:48 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CISA comment on CVE situation: https://infosec.exchange/@metacurity/114344326544856491

      In conversation about 2 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: media.infosec.exchange
        Metacurity (@metacurity@infosec.exchange)
        from Metacurity
        Attached: 1 image Regarding the end of MITRE's CVE program, here's a statement that a CISA spokesperson gave me for a piece I'm writing.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 16-Apr-2025 07:52:53 JST Kevin Beaumont Kevin Beaumont
      in reply to

      NextGov piece on the CVE mess. https://www.nextgov.com/cybersecurity/2025/04/mitre-backed-cyber-vulnerability-program-lose-funding-wednesday/404585/

      In conversation about 2 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: cdn.nextgov.com
        MITRE-backed cyber vulnerability program to lose funding Wednesday
        from David DiMolfetta
        Organizations across industry, government, national security and critical infrastructure rely on the CVE Program, which serves as the de-facto global standard for vulnerability identification and management.
      Puniko ? and GreenSkyOverMe (Monika) repeated this.
    • Embed this notice
      dave (hologram@cyberplace.social)'s status on Wednesday, 16-Apr-2025 12:09:45 JST dave dave
      in reply to

      @GossiTheDog 👍

      In conversation about 2 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 16-Apr-2025 16:54:58 JST Kevin Beaumont Kevin Beaumont
      in reply to

      DOGE have terminated MITREs contracts, they say they will be laying off nearly 500 people. This will have impacts beyond CVE - think MITRE ATT&CK etc. https://virginiabusiness.com/nova-govcon-firm-mitre-to-lay-off-442-employees-after-doge-cuts-contracts/

      In conversation about 2 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: virginiabusine.wpenginepowered.com
        NoVa govcon firm Mitre to lay off 442 employees after DOGE cuts contracts - Virginia Business
        from Beth JoJack
        Federal contracting firm Mitre, which has dual headquarters in McLean and Massachusetts, expects to lay off 442 people in Virginia in two months. The cuts come after the Trump administration has announced more than $28 million in canceled contracts for the company. Mitre notified the state Wednesday of 442 job cuts in McLean, in compliance […]
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 16-Apr-2025 17:08:22 JST Kevin Beaumont Kevin Beaumont
      in reply to

      If you want to know how stupid the CVE situation is - CISA are trying to source last minute funding or look at taking CVE management in house, but they themselves have had a massive budget cut where the staff trying to fix it are also at risk of being cut.

      In conversation about 2 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/346/615/524/679/501/original/421385df81c38d4e.png
      Puniko ? and Haelwenn /элвэн/ :triskell: repeated this.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 16-Apr-2025 17:22:55 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Looks like the US Government are going to lose control of CVE. https://www.thecvefoundation.org/

      In conversation about 2 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: lh3.googleusercontent.com
        CVE Foundation
        FOR IMMEDIATE RELEASE April 16, 2025 CVE Foundation Launched to Secure the Future of the CVE Program [Bremerton, Washington] – The CVE Foundation has been formally established to ensure the long-term viability, stability, and independence of the Common Vulnerabilities and Exposures (CVE) Program, a
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 16-Apr-2025 18:14:57 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Another effort - https://gcve.eu/ Global CVE Allocation System

      In conversation about 2 months ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        GCVE.eu
        GCVE: Global CVE Allocation SystemThe Global CVE (GCVE) allocation system is a new, decentralized approach to vulnerability identification and numbering, designed to improve flexibility, scalability, and autonomy for participating entities. While remaining compatible with the traditional CVE system, GCVE introduces GCVE Numbering Authorities (GNAs). GNAs are independent entities that can allocate identifiers without relying on a centralised block distribution system or rigid policy enforcement. Explore About FAQ News Contact
    • Embed this notice
      Viraptor (viraptor@cyberplace.social)'s status on Wednesday, 16-Apr-2025 18:24:46 JST Viraptor Viraptor
      in reply to

      @GossiTheDog Love the "let me put some anonymous website up and Yolo it" attempts. I'm sure it's a well funded long term commitment. GCVE vs lettuce webcam time...

      In conversation about 2 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 16-Apr-2025 21:14:36 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • Metacurity

      CISA have, at the last minute, extended the MITRE CVE contract. “The CVE Program is invaluable to cyber community and a priority of CISA. Last night, CISA executed the option period on the contract to ensure there will be no lapse in critical CVE services. We appreciate our partners’ and stakeholders’ patience.” HT @metacurity

      In conversation about 2 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 16-Apr-2025 21:44:49 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Now all we need is for Breachforums to get back online and the threat intelligence industry is alive again!

      In conversation about 2 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 16-Apr-2025 23:14:35 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CVE extension by CISA = 11 months. https://infosec.exchange/@metacurity/114348047105534455

      In conversation about 2 months ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Metacurity (@metacurity@infosec.exchange)
        from Metacurity
        I hear that the extension granted to MITRE for its CVE contract lasts eleven months.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 16-Apr-2025 23:31:37 JST Kevin Beaumont Kevin Beaumont
      in reply to

      CVE extension to March 16th 2026

      See y’all March 15th 2026 for the last minute renewal 🫡😅

      https://www.usaspending.gov/award/CONT_AWD_70RCSJ24FR0000018_7001_70RSAT20D00000001_7001

      In conversation about 2 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/348/122/205/370/434/original/574ab8fc6e0c1081.jpeg
    • Embed this notice
      Misuse Case (misusecase@twit.social)'s status on Wednesday, 16-Apr-2025 23:43:27 JST Misuse Case Misuse Case
      in reply to

      @GossiTheDog I have to say, as someone who lives in the D.C. area and is plugged into gossip networks of both civil servants and contractors…there is a lot of this kind of thing* going on lately.

      *”This kind of thing” being “the contract is off, no, wait, now it’s back on.”

      In conversation about 2 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 17-Apr-2025 05:31:26 JST Kevin Beaumont Kevin Beaumont
      in reply to

      MITRE’s statement is interesting as they included trademark and copyright symbols on terms like CVE.. one to watch as people try to start their own systems.

      https://mastodon.social/@bagder/114349504703321362

      In conversation about a month ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        daniel:// stenberg:// (@bagder@mastodon.social)
        from daniel:// stenberg://
        "Greetings CVE Partners, We wanted to let you know that thanks to actions taken by the government, a break in service for the Common Vulnerabilities and Exposures (CVE®) Program and the Common Weakness Enumeration (CWE™) Program has been avoided. ... The CVE Services infrastructure will continue to operate as normal, as will updates to the CVE List and the cve.org website."
    • Embed this notice
      Trexdrumkit (trexdrumkit@infosec.exchange)'s status on Thursday, 17-Apr-2025 20:32:19 JST Trexdrumkit Trexdrumkit
      in reply to

      @GossiTheDog Not seeing any other source than this shady website in every report on this. No board member is actually claiming this foundation, or responding to comments, and there are SEVERAL red flags. Do you have on good authority that this is legit in the slightest?

      In conversation about a month ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 21-Apr-2025 07:32:21 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • The CVE Foundation

      The CVE Foundation now lists the people involved https://www.thecvefoundation.org/frequently-asked-questions @thecvefoundation

      In conversation about a month ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/372/662/006/128/130/original/ca72df8057af8ec2.jpeg
      2. Domain not in remote thumbnail source whitelist: lh5.googleusercontent.com
        CVE Foundation - Frequently Asked Questions
        What do you believe? We believe that CVEs are the cornerstone of cybersecurity defense. Without a common language to communicate about vulnerabilities, chaos follows. This is why the CVE Program was created 25 years ago and it is even more true today. We believe in a free, publicly available

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.