GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    J. R. DePriest :verified_trans: :donor: :Moopsy: :EA DATA. SF: (jrdepriest@infosec.exchange)'s status on Friday, 18-Apr-2025 00:21:24 JSTJ. R. DePriest :verified_trans: :donor: :Moopsy: :EA DATA. SF:J. R. DePriest :verified_trans: :donor: :Moopsy: :EA DATA. SF:
    • Kevin Beaumont

    @GossiTheDog

    Thinking about CVEs.
    We don't need CVEs to detect or manage vulnerabilities. We have plugin IDs. We have TTPs. We have flashy vulnerabilities that get their own marketing websites. We have MITRE ATT&CK.
    Our threat intel feeds give us TTPs which may include CVEs, but do not rely on them by any means.
    Our threat hunting is more concerned with TTPs and MITRE ATT&CK.
    When we set up officially supported orchestration between systems, they typically have the logic needed to understand each other.
    The main way we use CVEs is as shorthand or a shortcut. It's super simple to determine which tools can detect a certain CVE. It's convenient to have a single database to look up details about almost any vulnerability. It also gives us a simple way to discuss the vulnerability.
    It's important but not critical.
    The last minute rescue is less about CVEs and more about this administration's haphazard and thoughtless treatment of... well, of everything. If CVSS and CVE, two things that are considered bedrocks of worldwide cyber security, are treated this poorly, what does that mean for the less visible projects? Just how truly fucked is our national cyber security?

    In conversationabout 2 months ago from infosec.exchangepermalink
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.