Month: August 2026

  • How Much Lipstick Can That CVE Pig Wear?

    How Much Lipstick Can That CVE Pig Wear?

    Preface When I started writing this, I was still on the CVE editorial board, which I was removed from in 2018. That means I have been taking notes and working on this blog for over eight years. It’s a case of more and more evidence piling up and me not having time to pick a…

  • Q&A: Modernizing the National Vulnerability Database in the Age of Artificial Intelligence

    Q&A: Modernizing the National Vulnerability Database in the Age of Artificial Intelligence

    The last two years of the National Vulnerability Database (NVD) has been tenuous, perfidious, and an outright disaster for organizations world-wide. That isn’t hyperbole unfortunately, as the program has continued to go downhill for more than two years. NVD is no longer a place to get usable vulnerability intelligence. It started back in 2024 at…

  • Apparently Turkeys Obtained Personhood According to AI

    Apparently Turkeys Obtained Personhood According to AI

    Introduction Each morning I do a quick skim of recorded events from my security system. Living in the mountains I get to enjoy clips of a wide variety of wildlife that visit for the last three years. That’s typically bears, deer, foxes, turkeys, rabbits, and a skunk. On rare occasions that includes mountain lions, coyotes,…

  • Meta – The No Child Left Behind of LLMs?

    Meta – The No Child Left Behind of LLMs?

    Intro Last month, headlines told us about a novel incident where OpenAI’s agents “went rogue, escaped, and hacked” a company during testing. Some are calling it a “watershed moment” for computer security. Details quickly emerged that led some to conclude it was “remarkably easy“. From there it just got more interesting, weirder, and more serious…

  • A Word on Microsoft and Vulnerability Exploitation

    A Word on Microsoft and Vulnerability Exploitation

    Intro Microsoft Security Response Center (MSRC) is the group responsible for triage when researchers report new vulnerabilities. They handle a wide variety of other tasks, but my focus is on their analysis of vulnerabilities in one context or another. That could be the researcher’s disclosure or investigating an actively exploited vulnerability in a customer environment.…