sbs_at_work

34 Followers
285 Following
341 Posts

Likes #cybersec, #electro and #monkeyisland
Dislikes #voicemessages


Berlin, Hamburg, Zurich

Header image by @tvick (Unsplash)

PGO Level42
I just finished editing the commercial for our latest Defensive Security Podcast sponsor: https://youtu.be/OgvzdgfAUd0?si=8TBmuSDBU1i8cUlt
GICASTR

YouTube
I hope yall have a good Wednesday!
Hearing a bit more on this. Apparently it's up to the CVE board to decide what to do, but for now no new CVEs will be added after tomorrow. the CVE website will still be up.

I boosted several posts about this already, but since people keep asking if I've seen it....

MITRE has announced that its funding for the Common Vulnerabilities and Exposures (CVE) program and related programs, including the Common Weakness Enumeration Program, will expire on April 16. The CVE database is critical for anyone doing vulnerability management or security research, and for a whole lot of other uses. There isn't really anyone else left who does this, and it's typically been work that is paid for and supported by the US government, which is a major consumer of this information, btw.

I reached out to MITRE, and they confirmed it is for real. Here is the contract, which is through the Department of Homeland Security, and has been renewed annually on the 16th or 17th of April.

https://www.usaspending.gov/award/CONT_AWD_70RCSJ23FR0000015_7001_70RSAT20D00000001_7001

MITRE's CVE database is likely going offline tomorrow. They have told me that for now, historical CVE records will be available at GitHub, https://github.com/CVEProject

Yosry Barsoum, vice president and director at MITRE's Center for Securing the Homeland, said:

“On Wednesday, April 16, 2025, funding for MITRE to develop, operate, and modernize the Common Vulnerabilities and Exposures (CVE®) Program and related programs, such as the Common Weakness Enumeration (CWE™) Program, will expire. The government continues to make considerable efforts to support MITRE’s role in the program and MITRE remains committed to CVE as a global resource.”

USAspending.gov

Watch Oracle PR their way out of their responsibilities.. they’ve managed to publish a security incident notification and have the press run it as a denial. https://insight.scmagazineuk.com/oracle-further-dismisses-breach-rumours-in-customer-communication
Oracle Further Dismisses Breach Rumours in Customer Communication

SC Media UK

Why did the Linux server get a therapist?

It had too many daemons.

Classified is a good name for a pet. Name of my cat? Oh, that's Classified.
i cant believe ChatGPT lost its job to AI
I love that I've been on Mastodon more than 2 years now as my one and only social media platform (apart from LinkedIn, sorta), and I can say with some confidence that most of the accounts I'm interacting with are not bots, but instead are real live human beings with fascinating lives and interests. Thanks again everyone, and may we continue to enjoy this remarkable achievement for a long time to come.
In Singapur ist für Sicherheit gesorgt.