Tag: CVSS
-
How Much Lipstick Can That CVE Pig Wear?

Preface When I started writing this, I was still on the CVE editorial board, which I was removed from in 2018. That means I have been taking notes and working on this blog for over eight years. It’s a case of more and more evidence piling up and me not having time to pick a…
-
Q&A: Modernizing the National Vulnerability Database in the Age of Artificial Intelligence

The last two years of the National Vulnerability Database (NVD) has been tenuous, perfidious, and an outright disaster for organizations world-wide. That isn’t hyperbole unfortunately, as the program has continued to go downhill for more than two years. NVD is no longer a place to get usable vulnerability intelligence. It started back in 2024 at…
-
A Word on Microsoft and Vulnerability Exploitation

Intro Microsoft Security Response Center (MSRC) is the group responsible for triage when researchers report new vulnerabilities. They handle a wide variety of other tasks, but my focus is on their analysis of vulnerabilities in one context or another. That could be the researcher’s disclosure or investigating an actively exploited vulnerability in a customer environment.…
-
Captain Obvious Audits the NVD

During my recent trip to the East Coast several people linked an article from Recorded Future to me since it was on a topic I have written extensively about. The article covered a May 26 report from the Office of the Inspector General (OIG) at the Department of Commerce that was summarized as “mistakes have…
-
Squirrel Goes Down the Rabbit Hole … Podcast

On November 17, I joined the three hosts of the Down the Security Rabbithole (DtSR) podcast to talk about CVSS, CVE, and how they play into risk and defending networks. My time followed Robert “RSnake” Hansen’s podcast where he had a pretty controversial take on risk management. One of the hosts, Rafal Los, asked my…
-
VulnCon Day 2 Errata & Taking Ben Edwards to Task

[4/13/2025 Update: See very end, below last image, for an amusing update.][2/19/2026 Update: See very very end for an amusing update, yet positive!] Today was the second day of VulnCon 2025, a conference whose stated purpose is “to collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken…
-
Log4Shell: Redefining Painful Disclosure

Log4Shell is yet another example of why we simply don’t get security right, and it strongly suggests there is little hope for change. There are plenty of blogs and articles that do a great analysis of the vulnerability from the exploitation and impact angle of this vulnerability. There are a lot fewer that examine why…
-
A critique of the summary of “Latent Feature Vulnerability Rankings of CVSS Vectors”

Update: Corren McCoy has written a wonderful response to this blog where she goes into more detail about her conclusions as well as citing more portions of the original research that led to her conclusions. As she notes, there are several layers of condensing the original research at play here, which can dilute and distort…
-
More authorities, more CVEs; Oh, and more commentary.

On November 10, TechBeacon published a great article by Rob Lemos titled “More authorities, more CVEs: What it means for app sec teams” in which I was quoted, along with several other people. Like many articles of this nature, those who provide input often will talk for as long as half an hour and ultimately…
-
Why Anaconda INC Doesn’t Fully Understand CVEs

It’s worrisome that in 2020 we still have people in influential technical roles that don’t understand CVE. A friend told me earlier this year he was in a meeting where someone said that CVE IDs are assigned in order, so CVE-2020-9500 meant there were 9500 vulns in 2020 so far. Of course that is not…