Tag: Vulnerability Ecosystem

  • VulnCon Day 2 Errata & Taking Ben Edwards to Task

    VulnCon Day 2 Errata & Taking Ben Edwards to Task

    [4/13/2025 Update: See very end, below last image, for an amusing update.][2/19/2026 Update: See very very end for an amusing update, yet positive!] Today was the second day of VulnCon 2025, a conference whose stated purpose is “to collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken…

  • Reason #283 Why InfoSec Has Failed

    Reason #283 Why InfoSec Has Failed

    For those familiar with my social media, you know that I have frequently said that our industry is failing the commons. InfoSec represents a huge market, companies get paid exorbitant amounts of money, salaries can border on the ridiculous, and the concept of researchers being famous for their work is still alive. Meanwhile, vulnerabilities are…

  • 400 CNAs, Yay?

    400 CNAs, Yay?

    Introduction This week, or in the next two, we’re likely to see MITRE heralding the milestone of minting their 400th CVE Numbering Authority (CNA). These are, primarily, organizations that can assign a CVE ID without having to go to MITRE each time to obtain the ID. This is part of what MITRE calls a “federated”…