Category: InfoSec

  • How Much Lipstick Can That CVE Pig Wear?

    How Much Lipstick Can That CVE Pig Wear?

    Preface When I started writing this, I was still on the CVE editorial board, which I was removed from in 2018. That means I have been taking notes and working on this blog for over eight years. It’s a case of more and more evidence piling up and me not having time to pick a…

  • Q&A: Modernizing the National Vulnerability Database in the Age of Artificial Intelligence

    Q&A: Modernizing the National Vulnerability Database in the Age of Artificial Intelligence

    The last two years of the National Vulnerability Database (NVD) has been tenuous, perfidious, and an outright disaster for organizations world-wide. That isn’t hyperbole unfortunately, as the program has continued to go downhill for more than two years. NVD is no longer a place to get usable vulnerability intelligence. It started back in 2024 at…

  • Meta – The No Child Left Behind of LLMs?

    Meta – The No Child Left Behind of LLMs?

    Intro Last month, headlines told us about a novel incident where OpenAI’s agents “went rogue, escaped, and hacked” a company during testing. Some are calling it a “watershed moment” for computer security. Details quickly emerged that led some to conclude it was “remarkably easy“. From there it just got more interesting, weirder, and more serious…

  • A Word on Microsoft and Vulnerability Exploitation

    A Word on Microsoft and Vulnerability Exploitation

    Intro Microsoft Security Response Center (MSRC) is the group responsible for triage when researchers report new vulnerabilities. They handle a wide variety of other tasks, but my focus is on their analysis of vulnerabilities in one context or another. That could be the researcher’s disclosure or investigating an actively exploited vulnerability in a customer environment.…

  • CISA KEV’s Revolving Door

    CISA KEV’s Revolving Door

    Some time ago, perhaps last year or two years ago during VulnCon, I made an offhand comment about Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerability (KEV) catalog and how there were more than one vulnerability that had appeared in it and were subsequently removed. I received doubt from someone (Tod Beardsley?) that didn’t…

  • VDBs: Pedantic Nuances on Version Tracking

    VDBs: Pedantic Nuances on Version Tracking

    I am all about the pedantic nature of running a vulnerability database (VDB). It’s the backbone of running one well as “simply aggregating vulnerability information” is anything but simple. I’ve been outspoken on the issue of perceived simplicity for at least two decades and brought it up in various presentations and blogs. This blog is…

  • F5 Contributes to KEV Confusion

    F5 Contributes to KEV Confusion

    F5 is a technology vendor that sells a variety of networking technology including security products. With a considerable security portfolio and long tenure in the industry they are well positioned to observe known exploited vulnerabilities (KEV). Their staff frequently write blogs about threat actor activity, exploit campaigns, and associated topics. Unfortunately, while they have great…

  • We’re Losing the “Cyber” War to Ourselves

    We’re Losing the “Cyber” War to Ourselves

    It’s hard to pinpoint where the concept of cyberwar originated. In roundabout ways it likely goes back many decades in fiction. As far as citations go, some believe a seminal work is titled Unrestricted Warfare by Qiao Liang and Wang Xiangsui, two colonels in the People’s Liberation Army (PLA). Regardless of when the premise started,…

  • Captain Obvious Audits the NVD

    Captain Obvious Audits the NVD

    During my recent trip to the East Coast several people linked an article from Recorded Future to me since it was on a topic I have written extensively about. The article covered a May 26 report from the Office of the Inspector General (OIG) at the Department of Commerce that was summarized as “mistakes have…

  • 2026 East Coast Drive (Part 1: NaClCON)

    2026 East Coast Drive (Part 1: NaClCON)

    Pre-game For the first half of June I attended NaClCON and then drove through five states and the District of Columbia. The trip began with a rare flight that required a layover as Wilmington, North Carolina is a small regional airport. That put me through O’Hare which I despise due to past trips that left…