Tag: NVD

  • NVD Gives Up

    NVD Gives Up

    Since 2024, representatives from NIST’s National Vulnerability Database (NVD) have given a presentation at VulnCon with updates to the program. This has been where news broke about significant changes, admissions, and omissions. The talks, typically 30 minutes, are certainly not enough time to tell us what the industry needs to know and leaves no time…

  • What Do 2025 CVE Numbers Mean? An Intro.

    What Do 2025 CVE Numbers Mean? An Intro.

    [This was originally my proposed introduction for Flashpoint’s 2026 Global Threat Intelligence Report. Due to the style of the report and covering a lot more intelligence sectors than vulnerabilities, only pieces of this were used. So I am publishing the entire original draft here for posterity.] The fact that there were over 48,000 CVEs published…

  • Shadow, Ghost, and Phantasmawhatever Vulnerabilities – The Reality

    Shadow, Ghost, and Phantasmawhatever Vulnerabilities – The Reality

    Back in September of 2024, I took some notes on a blog I wanted to write about “Shadow” vulnerabilities, based on a corporate blog with a poor concept and misunderstanding of CVE. The title was to be “Shadow Vulnerabilities – Rebuttal” and pretty straight-forward. Vulnerability life is crazy when you help manage a true vulnerability…

  • CVE: The Big Vote of No Confidence

    CVE: The Big Vote of No Confidence

    Yesterday, Matt Hartman, CISA Acting Executive Assistant Director for Cybersecurity, issued a statement on the CVE program. Trying to summarize the last several days and what happened is tricky, but you can read my LinkedIn posts as well as countless news articles and folks talking about.ย  The super tl;dr is that on April 15, a…

  • The Curious Case of CVE-2015-2551 & CVE-2019-9081 – Doom and Gloom! Or not.

    The Curious Case of CVE-2015-2551 & CVE-2019-9081 – Doom and Gloom! Or not.

    What’s Your Story CVE-2015-2551? This CVE-2015-2551 entry seems straight-forward, based on the description provided by CVE or NVD. Looking at the change history on NVD it is a bit more informative: So the ID was created for the 2015 calendar year, apparently not used, rejected seven years later, and confirmed by the assigning CNA (Microsoft).…

  • ChatGPT Exploited by Threat Actors, Doom and Gloom! Or not.

    ChatGPT Exploited by Threat Actors, Doom and Gloom! Or not.

    After years of chasing down typos in CVE IDs, now we all have to contend with poorly researched headlines and apparent to me ambulance chasing over mistaken product names. If you missed the news, threat actors are exploiting a vulnerability in ChatGPT! This is obviously a huge warning and we should all be afraid because…

  • 2024 NIST / ANALYGENCE FOIA Results

    2024 NIST / ANALYGENCE FOIA Results

    On June 5, 2024, I sent a FOIA request to National Institute of Standards and Technology requesting a copy of the contract between the National Vulnerability Database (NVD) and ANALYGENCE, a contractor that had been retained to help with the NVD backlog. This was one of two trying to determine how much the U.S. Government…

  • Thoughts on CISA’s “Vulnrichment” Initiative

    Thoughts on CISA’s “Vulnrichment” Initiative

    As many in the vulnerability disclosure ecosystem are now aware, the Cybersecurity & Infrastructure Security Agency (CISA), announced a new program called “Vulnrichment” on LinkedIn yesterday. News about the program spread rapidly via news sites and private companies. In this statement and elsewhere, there are definitely some general questions to be asked out loud since…

  • VulnCon: NVD Symposium, Answers, and More Concerns

    VulnCon: NVD Symposium, Answers, and More Concerns

    Yesterday, at the first inaugural VulnCon, Tanya Brewer from the NVD gave a presentation that was listed on the agenda as “NVD Symposium”. At the talk, her slides began with a header “The National Vulnerability Database: Exploring Opportunities”. However, neither the symposium nor the opportunities were the primary topics that most people were interested in.…

  • That Vulnerability is “Trending” … So What?

    That Vulnerability is “Trending” … So What?

    Yesterday, more than one organization reached out to my company asking why a particular vulnerability wasn’t in VulnDB yet. First, it had been less than 24 hours since publication in CVE/NVD, NVD hasn’t analyzed it as of the time of this blog, and it is in software no significant business would use. It’s part of…