Jean-Baptiste Maillet

26 Followers
49 Following
339 Posts
Hardcore embedded C/C++ caveman.
Supply chain cybersecurity, SBOM , vulnerability management.
#embedded #linux #oss #psirt
he/him
embedded
linux
oss
psirt
@joshbressers @deftpunk @wdormann @Viss Honestly, there was nothing "obvious" about this one being a "big one" compared to all of the bugs we get, and fix, on a daily/weekly basis in the kernel.

The ONLY thing different here from those bugfixes, was that someone made a web site, a simple reproducer, and announced it to the world. For 99.9% of the bugs we fix, that are reproducible like this, no one ever does that. That we know of...

In other words, this was just another Tuesday for us.
AI is not taking anyone's job, it's some guy making that decision

I struggle to hold all the CWEs in my head in a useful way, so I made a little visualization tool.

And then I thought, what if they used a more Dewey-style numbering system rather than just random numbers, so I added a toggle.

https://nesbitt.io/cwe/

"Federate, don't concentrate: balkanisation is freedom.
- Vulnerability triage in the LLM era."

"The political instinct that calls federation "balkanisation" inverts the engineering reality. In a system whose sole central producer has just publicly conceded it cannot keep up, balkanisation (multiple producers, multiple identifier spaces, interoperability-by-design rather than interoperability-by-monopoly) is freedom: freedom from single-point-of-failure, freedom for specialised producers to enrich the slices they understand best, and freedom for consumers to compose the synthesis that fits their environment."

https://codeberg.org/tzafaar/Buffers_overflow_into_policy/src/branch/main/briefing%20notes/federate-dont-concentrate-briefing.md

Buffers_overflow_into_policy/briefing notes/federate-dont-concentrate-briefing.md at main

Buffers_overflow_into_policy

Codeberg.org

Don’t Do Team Meetings

Regular team meetings are often treated as a default part of work. They are seen as a sign of coordination, alignment, and healthy communication. In practice, they often reveal the opposite.

A recurring team meeting where everyone goes around the room to explain what they did last week is usually not a good use of time. It turns communication into a performance instead of a real exchange of useful information. If the team needs a formal meeting just to learn what people have been doing, that is often a sign that day-to-day communication is already failing.

🔗 Read the blog post https://www.foo.be/2026/04/dont-do-team-meetings

#meeting #collaboration #team #workingtogether

Don’t Do Team Meetings

Personal webpage of Alexandre Dulaunoy - from information security to open source and art

Alexandre Dulaunoy - adulau - Home Page

GCVE-BCP-10: Improved Common Platform Enumeration for GCVE

This document specifies an improved platform enumeration model for GCVE aligned with the current implementation of cpe-editor.

#cpe #cve #gcve #infosec #vulnerabilitymanagement

🔗 https://gcve.eu/bcp/gcve-bcp-10/

GCVE-BCP-10 - Improved Common Platform Enumeration for GCVE

GCVE-BCP-10: Improved Common Platform Enumeration for GCVE Version: 1.0 Status: Draft (for Public Review) Date: 2026-04-26 Authors: GCVE Working Group BCP ID: BCP-10 This guide is distributed and available under CC-BY-4.0. Copyright (C) 2025-2026 GCVE Initiative. Abstract This document specifies an improved platform enumeration model for GCVE aligned with the current implementation of cpe-editor. The model remains compatible with existing Common Platform Enumeration (CPE) practices and string formats, while adding registry records for vendors, products, CPE entries, metadata, relationships, and optional moderation proposals.

My all-time favourite method of debugging is going to bed and looking at it again the next morning.

The CVE funding disruption exposed a single point of failure in the infrastructure that underpins global vulnerability management. In this Help Net Security interview, ENISA's Nuno Rodrigues Carvalho, #VulnCon26 speaker, breaks down what needs to change.

📖 Read more: https://go.first.org/bSrxK

#CyberDefense #cybersecurity #CVE

Coordinated vulnerability disclosure is now an EU obligation, but cultural change takes time - Help Net Security

ENISA's Nuno Carvalho on CVE program risks, EU regulatory enforcement, and building a distributed vulnerability disclosure ecosystem.

Help Net Security
Maybe we should start a gofundme/kickstarter to buy a load of stars on a repo that simply says “don’t use GitHub stars as a source of trust”?

runZero’s @todb is just back from VulnCon 2026, and he is sharing his insights on conference announcements, recent news, and more, including:

✔️ AI’s dual role in vulnerability discovery and defense
✔️ CVE ecosystem updates
✔️ A cautiously optimistic outlook for the future of vulnerability disclosure and remediation

Read his full post today to learn more! 👇
https://www.runzero.com/blog/vulncon-ai-cves/