Damien Hull

65 Followers
109 Following
77 Posts
Security Engineer, part of a GRC team and recently PCI QSA certified. Always interested in learning more about security and IT.
Websitehttps://section9.us

I boosted several posts about this already, but since people keep asking if I've seen it....

MITRE has announced that its funding for the Common Vulnerabilities and Exposures (CVE) program and related programs, including the Common Weakness Enumeration Program, will expire on April 16. The CVE database is critical for anyone doing vulnerability management or security research, and for a whole lot of other uses. There isn't really anyone else left who does this, and it's typically been work that is paid for and supported by the US government, which is a major consumer of this information, btw.

I reached out to MITRE, and they confirmed it is for real. Here is the contract, which is through the Department of Homeland Security, and has been renewed annually on the 16th or 17th of April.

https://www.usaspending.gov/award/CONT_AWD_70RCSJ23FR0000015_7001_70RSAT20D00000001_7001

MITRE's CVE database is likely going offline tomorrow. They have told me that for now, historical CVE records will be available at GitHub, https://github.com/CVEProject

Yosry Barsoum, vice president and director at MITRE's Center for Securing the Homeland, said:

“On Wednesday, April 16, 2025, funding for MITRE to develop, operate, and modernize the Common Vulnerabilities and Exposures (CVE®) Program and related programs, such as the Common Weakness Enumeration (CWE™) Program, will expire. The government continues to make considerable efforts to support MITRE’s role in the program and MITRE remains committed to CVE as a global resource.”

USAspending.gov

Sweet! Got /etc up in #github using #etckeeper. Version control for /etc. https://github.com/wertarbyte/etckeeper
GitHub - wertarbyte/etckeeper

Contribute to wertarbyte/etckeeper development by creating an account on GitHub.

GitHub
Trying to learn the ways of #github. Need to manage a Linux server configuration. Plus a few other config files. git seems to be a bit of a learning curve for me.
2. You are still in a way better position, having used a password manager, then you would have been if you just reused passwords or used some predictable scheme for them. This is NOT some kind of proof that password managers (even cloud password managers) are inherently a bad idea. The alternatives are worse.

Is it time to walk away from #LastPass ? If I do walk away, what password manager do I switch to?

I do have an account on #bitwarden. I was going to close that account, but now I'm not so sure.

Added an API from dehashed.com to spiderfish. Got me some email addresses with passwords. Not sure how sites like this do it, but what a game changer.

Note: Don't do this unless authorized to do so. You could get your self into a lot of trouble.

#hacking #haveibeenpwned #OSINT
https://www.dehashed.com/
https://www.spiderfoot.net/

Checking my spiderfoot scans. First one included API keys for #shodan and #HaveIBeenPwned. Second one included a lot more API keys for modules I've never used before.

First scan has 5479 elements. Second scan has 22824 elements. That's a huge difference. Should have added the API keys sooner.

#hacking #osint https://www.spiderfoot.net/

Home - SpiderFoot

SpiderFoot
Running #spiderfoot scans. I think I've got API keys for a good number of modules. Lets see if the current scan finds more info than the previous one. #OSINT https://www.spiderfoot.net/
Home - SpiderFoot

SpiderFoot

Gotta do some Azure and Google testing sometime today. Need to get my CPE credits out of the way first. Don't wait until the last minute to get your CPE credits. This is more work than it should be.

#CPE #Google #Azure

Watching a video for CPE credits. The product is suppose to help manage 3rd party risk. I guess if I had a lot of 3rd parties it might be worth it. More of a 3rd party portfolio management software solution. Who knows, maybe this is awesome and I'm just pooping on it cause I don't work in this space.

So hard to evaluate this kind of stuff.