Tag: CVSS

  • How Much Lipstick Can That CVE Pig Wear?

    How Much Lipstick Can That CVE Pig Wear?

    Preface When I started writing this, I was still on the CVE editorial board, which I was removed from in 2018. That means I have been taking notes and working on this blog for over eight years. It’s a case of more and more evidence piling up and me not having time to pick a…

  • Q&A: Modernizing the National Vulnerability Database in the Age of Artificial Intelligence

    Q&A: Modernizing the National Vulnerability Database in the Age of Artificial Intelligence

    The last two years of the National Vulnerability Database (NVD) has been tenuous, perfidious, and an outright disaster for organizations world-wide. That isn’t hyperbole unfortunately, as the program has continued to go downhill for more than two years. NVD is no longer a place to get usable vulnerability intelligence. It started back in 2024 at…

  • A Word on Microsoft and Vulnerability Exploitation

    A Word on Microsoft and Vulnerability Exploitation

    Intro Microsoft Security Response Center (MSRC) is the group responsible for triage when researchers report new vulnerabilities. They handle a wide variety of other tasks, but my focus is on their analysis of vulnerabilities in one context or another. That could be the researcher’s disclosure or investigating an actively exploited vulnerability in a customer environment.…

  • Captain Obvious Audits the NVD

    Captain Obvious Audits the NVD

    During my recent trip to the East Coast several people linked an article from Recorded Future to me since it was on a topic I have written extensively about. The article covered a May 26 report from the Office of the Inspector General (OIG) at the Department of Commerce that was summarized as “mistakes have…

  • Squirrel Goes Down the Rabbit Hole … Podcast

    Squirrel Goes Down the Rabbit Hole … Podcast

    On November 17, I joined the three hosts of the Down the Security Rabbithole (DtSR) podcast to talk about CVSS, CVE, and how they play into risk and defending networks. My time followed Robert “RSnake” Hansen’s podcast where he had a pretty controversial take on risk management. One of the hosts, Rafal Los, asked my…

  • VulnCon Day 2 Errata & Taking Ben Edwards to Task

    VulnCon Day 2 Errata & Taking Ben Edwards to Task

    [4/13/2025 Update: See very end, below last image, for an amusing update.][2/19/2026 Update: See very very end for an amusing update, yet positive!] Today was the second day of VulnCon 2025, a conference whose stated purpose is “to collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken…

  • Log4Shell: Redefining Painful Disclosure

    Log4Shell: Redefining Painful Disclosure

    Log4Shell is yet another example of why we simply don’t get security right, and it strongly suggests there is little hope for change. There are plenty of blogs and articles that do a great analysis of the vulnerability from the exploitation and impact angle of this vulnerability. There are a lot fewer that examine why…

  • A critique of the summary of “Latent Feature Vulnerability Rankings of CVSS Vectors”

    A critique of the summary of “Latent Feature Vulnerability Rankings of CVSS Vectors”

    Update: Corren McCoy has written a wonderful response to this blog where she goes into more detail about her conclusions as well as citing more portions of the original research that led to her conclusions. As she notes, there are several layers of condensing the original research at play here, which can dilute and distort…

  • More authorities, more CVEs; Oh, and more commentary.

    More authorities, more CVEs; Oh, and more commentary.

    On November 10, TechBeacon published a great article by Rob Lemos titled “More authorities, more CVEs: What it means for app sec teams” in which I was quoted, along with several other people. Like many articles of this nature, those who provide input often will talk for as long as half an hour and ultimately…

  • Why Anaconda INC Doesn’t Fully Understand CVEs

    Why Anaconda INC Doesn’t Fully Understand CVEs

    It’s worrisome that in 2020 we still have people in influential technical roles that don’t understand CVE. A friend told me earlier this year he was in a meeting where someone said that CVE IDs are assigned in order, so CVE-2020-9500 meant there were 9500 vulns in 2020 so far. Of course that is not…