Tag: CPE

  • Captain Obvious Audits the NVD

    Captain Obvious Audits the NVD

    During my recent trip to the East Coast several people linked an article from Recorded Future to me since it was on a topic I have written extensively about. The article covered a May 26 report from the Office of the Inspector General (OIG) at the Department of Commerce that was summarized as “mistakes have…

  • 2025 BSidesLV CVE Panel – My Comments

    2025 BSidesLV CVE Panel – My Comments

    This year at BSides Las Vegas, a panel discussing the CVE program and crisis occurred. I watched the panel discussion after the fact, since I did not attend. For full transparency, something MITRE isn’t fond of, I almost attended as a keynote speaker on the subject of CVE. I was invited to, but personally did…

  • Thoughts on CISA’s “Vulnrichment” Initiative

    Thoughts on CISA’s “Vulnrichment” Initiative

    As many in the vulnerability disclosure ecosystem are now aware, the Cybersecurity & Infrastructure Security Agency (CISA), announced a new program called “Vulnrichment” on LinkedIn yesterday. News about the program spread rapidly via news sites and private companies. In this statement and elsewhere, there are definitely some general questions to be asked out loud since…