For hackathon.lu, I was initially unsure what my main project would be, but I ultimately decided to focus on implementing the future GCVE BCP-10.
GCVE-BCP-10: Improved Common Platform Enumeration for GCVE
The idea is combine it with the cpe-guesser and have a registry to facilitate the interaction with the CPE values to handle vendor and product references.
#gcve #cve #cpe #opensource #cybersecurity
đ Draft https://discourse.ossbase.org/t/gcve-bcp-10-improved-common-platform-enumeration-for-gcve/1042
đ Hackathon https://hackathon.lu/

GCVE-BCP-10: Improved Common Platform Enumeration for GCVE Document ID: GCVE-BCP-10 Title: Improved Common Platform Enumeration for GCVE Status: Draft Category: Best Current Practice Updates: CPE-compatible naming and match semantics Author: GCVE.eu Intended use: Platform and product identification, applicability matching, vendor management, and synonym handling in the GCVE ecosystem Abstract This document specifies an improved platform enumeration format for GCVE. The format is intentionally ...
cpe-guesser 2.0 released - Multi-Source CPE Imports, Better Ranking, and Greater Autonomy Beyond NVD
Version 2.0 brings major improvements to CPE import, ranking, and CVE v5 data handling. This release focuses on better import performance, broader format support, improved search relevance, and more robust indexing for vendor and product matching.
A notable change in this release is that cpe-guesser is no longer limited to NVD as its only practical CPE source. In addition to the NVD feeds, it can also leverage the Vulnerability-Lookup dump available at https://vulnerability.circl.lu/dumps/ , providing additional CPE sources and more autonomy from the previously NVD-only source model.
This release lays an important foundation for improving the GCVE ecosystem, especially by strengthening vendor and product references through better CPE source diversity, indexing, and matching capabilities. If you have ideas for further improvements, additional data sources, or better ways to refine vendor and product identification, we would be very happy to hear your feedback.
https://www.vulnerability-lookup.org/2026/03/22/cpe-guesser-2.0-released/
https://github.com/vulnerability-lookup/cpe-guesser
#gcve #cve #opensource #cpe #vulnerability #vulnerabilitymanagement
Lundi 9 mars, jour de rentrĂ©e pour les Ă©lĂšves de la rĂ©gion parisienne, les collĂ©giens de Jean-Jacques Rousseau Ă Argenteuil (95) ont retrouvĂ© un certain nombre de leurs professeurs⊠devant la grille, accrochant une banderole fraĂźchement rĂ©alisĂ©e « JJR en galĂšre + de moyens pour la vie scolaire ! ». Ces derniers, avecâŠ
Québec
politicians consider using notwithstanding clause to exclude asylum seeker children from subsidized daycares
https://ici.radio-canada.ca/rci/en/news/2235646/supreme-court-rules-quebec-asylum-seekers-eligible-for-subsidized-daycare
- - -
Les politiciensâąiennes du QuĂ©bec
considĂšrent utiliser la clause nonobstant pour exclure les enfants des demandeursâąeuses dâasile des CPE
https://ici.radio-canada.ca/nouvelle/2235373/demandeurs-asile-cpe-cour-supreme
Supreme Court found that QuĂ©becâs
exclusion of assylum seekers from subsidized daycare is discriminatory
https://www.cbc.ca/news/canada/montreal/supreme-court-asylum-seekers-subsidized-daycare-ruling-9.7117175
- - -
La Cour suprĂȘme a trouvĂ©e que lâexclusion des demandeurs dâasile aux centres de la petite enfance au QuĂ©bec
est discriminatoire
https://ici.radio-canada.ca/nouvelle/2235373/demandeurs-asile-cpe-cour-supreme
Ok.. so sadly I cannot make DEFCON this year. I am looking for an equally fun, though driven conference that is ideally not in Vegas and not that week.
I don't want to go to a vendor con.. because I can get that info from a vendor. Who has a kick-ass bsides? Anyone know about Blueteamcon?
I can't make cackalackycon as I will be in the middle of the ocean that week.
@deviantollam I feel like you would have some pointers!
Or maybe I should use my "training and conference" budget to go to RTA and do some PACS stuff! I know most of the course material but it would be nice to fill in the gaps.
#hackersummerCamp #Security #cybersecurity #confrence #training #CPE
@iron_bug @torproject @ooni @limping Oh, I forgot that some Russian ISPs do that, and L2TP...
I didn't mean fuckibg aroubd with the Router / #CPE but rather one's own system behind an own router (basically double-NATting)
I guess #Roskomnadnozr filters for any connection that goes outside #Russia?