fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

10K
active users

#CVE

271 posts202 participants7 posts today

#CVE Foundation just dropped a FAQ.

thecvefoundation.org/frequentl

Also, just FYI, I’ve been helping with the Foundation setup and goals articulation and logistics for the last few weeks. I didn’t expect we’d pull the trigger on being public this week, precisely, but here we are!

I’m not employed there or anything (I work at @runZeroInc) but since I care about CVE, I want to do what I can to make sure it thrives and we don’t wind up back again with 15 competing standards for #vulnerability tracking if USG funding goes 💨 poof! 💨 one day (or other single-source-funding style disasters).

Anyway, back to my ill-timed family vacation. I’ll be more online next week. :)

www.thecvefoundation.orgCVE Foundation - Frequently Asked QuestionsWhat do you believe? We believe that CVEs are the cornerstone of cybersecurity defense. Without a common language to communicate about vulnerabilities, chaos follows. This is why the CVE Program was created 25 years ago and it is even more true today. We believe in a free, publicly available

in letzter Sekunde gerettet: US-Cybersicherheitsbehörde CISA hat den Betrieb der CVE-Datenbank (Liste aller gemeldeten IT-Sicherheitslücken) für die nächsten 11 Monate sichergestellt; Alternativen von EU und Luxemburg ...

#cve #itsecurity #dpsvd33uus25

heise.de/news/Nach-drohendem-C

heise online · CVE-Aus abgewendet, Schwachstellendatenbank der EU geht an den Start
More from Dr. Christopher Kunz
Continued thread

I frequently grump about what the #CVE system has become in practice. Folks may think that I’m not a proponent of the program. That’s not true at all. I’m an advocate for it, and for all those who pour their time and talent into it (often voluntarily).

But, IMO it is an overstatement to say that a CVE is a critical element in coordinating response to emerging vulnerabilities like heartbleed or log4shell. Embargoed critical vulns are rarely identified with CVEs among defenders.

The US Cybersecurity and Infrastructure Security Agency (CISA) has moved to secure continued operations of the Common Vulnerabilities and Exposures (CVE) programme by extending its contract with MITRE, preventing a potentially disruptive lapse in critical cybersecurity services.

computing.co.uk/news/2025/secu

www.computing.co.ukCISA extends MITRE's CVE bug tracking funding – for nowRelents at the last moment to avert disruption to critical cybersecurity infrastructure
#mitre#cisa#infosec

We're taking a first step to mitigate future damage from the irreparably broken, and IRL harmful legacy #CVE system by adding EUVD (euvd.enisa.europa.eu/) references to all formerly CVE-based tags.

I hope ENISA becomes a GCVE (gcve.eu/) CNA, soon, and starts to transition to a more stable vulnerability reference system/standard, free from U.S. government ineptness and vendor biases.

Gonna try to get all the EUVD URL refs added while y'all are boozing it up at RSA next week.

euvd.enisa.europa.euVulnerability DatabaseWeb site created using create-react-app