#csaf — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #csaf, aggregated by home.social.
-
282,000+ VEX records are now in Vulnerability-Lookup 🎉
🔎 https://vulnerability.circl.lu/vex
SUSE just joined Red Hat and Microsoft as a VEX source — so from any CVE you can see whether a vendor says a product is affected, fixed, or not affected.
VEX statements are attached directly to each vulnerability and available via the open API.
🧑💻 https://github.com/vulnerability-lookup/vulnerability-lookup
#VEX #CSAF #VulnerabilityManagement #OpenSource #InfoSec #GCVE #CVE #CYberSecurity #Vulnerability
-
282,000+ VEX records are now in Vulnerability-Lookup 🎉
🔎 https://vulnerability.circl.lu/vex
SUSE just joined Red Hat and Microsoft as a VEX source — so from any CVE you can see whether a vendor says a product is affected, fixed, or not affected.
VEX statements are attached directly to each vulnerability and available via the open API.
🧑💻 https://github.com/vulnerability-lookup/vulnerability-lookup
#VEX #CSAF #VulnerabilityManagement #OpenSource #InfoSec #GCVE #CVE #CYberSecurity #Vulnerability
-
🆕 Vulnerability-Lookup now imports Microsoft CSAF VEX documents from MSRC — joining the Red Hat VEX feed as a vendor VEX enrichment source.
Per-CVE VEX statements (product status, severity) are attached directly to CVE records, visible on the vulnerability page and via the API with the full CSAF documents.
Example with both Red Hat and Microsoft VEX:
https://vulnerability.circl.lu/vuln/CVE-2026-53359#vex -
🆕 Vulnerability-Lookup now imports Microsoft CSAF VEX documents from MSRC — joining the Red Hat VEX feed as a vendor VEX enrichment source.
Per-CVE VEX statements (product status, severity) are attached directly to CVE records, visible on the vulnerability page and via the API with the full CSAF documents.
Example with both Red Hat and Microsoft VEX:
https://vulnerability.circl.lu/vuln/CVE-2026-53359#vex -
Vulnerability-Lookup 5.4.0 released! 🚀
Highlights:
🔎 VEX enrichment from Red Hat CSAF VEX documents — new /api/vex endpoints, a VEX tab and a VEX badge on vulnerability pages
🔐 Per-user enable/disable of CNA publication
📬 Admin overview for KEV catalog e-mail subscriptions, richer digest e-mails
🛠️ Feeder robustness fixeshttps://www.vulnerability-lookup.org/2026/07/10/vulnerability-lookup-5-4-0/
-
Vulnerability-Lookup 5.4.0 released! 🚀
Highlights:
🔎 VEX enrichment from Red Hat CSAF VEX documents — new /api/vex endpoints, a VEX tab and a VEX badge on vulnerability pages
🔐 Per-user enable/disable of CNA publication
📬 Admin overview for KEV catalog e-mail subscriptions, richer digest e-mails
🛠️ Feeder robustness fixeshttps://www.vulnerability-lookup.org/2026/07/10/vulnerability-lookup-5-4-0/
-
👉 Ihr folgt uns als BSI hier im Fediverse und wollt keine IT-Sicherheitsmitteilung unseres CERT-Bund, dem Computer Emergency Response Team für Bundesbehörden, verpassen? Dann folgt auch @certbund, der zentralen Anlaufstelle für präventive und reaktive Maßnahmen bei sicherheitsrelevanten Vorfällen in Computer-Systemen.
CERT-Bund ist Mitglied des #CSIRTsNetwork der EU und ein starker Unterstützer des Common Security Advisory Framework #CSAF.
Gern weitersagen! 🔄
-
👉 Ihr folgt uns als BSI hier im Fediverse und wollt keine IT-Sicherheitsmitteilung unseres CERT-Bund, dem Computer Emergency Response Team für Bundesbehörden, verpassen? Dann folgt auch @certbund, der zentralen Anlaufstelle für präventive und reaktive Maßnahmen bei sicherheitsrelevanten Vorfällen in Computer-Systemen.
CERT-Bund ist Mitglied des #CSIRTsNetwork der EU und ein starker Unterstützer des Common Security Advisory Framework #CSAF.
Gern weitersagen! 🔄
-
Playing with CSAF 2.1 CSD02 and GCVE extensions.
https://discourse.ossbase.org/t/csaf-and-gcve-bcp-05-extensions/1093
I think more and more that having GCVE extension on all vulnerability standard format makes much more sense nowadays.
-
Playing with CSAF 2.1 CSD02 and GCVE extensions.
https://discourse.ossbase.org/t/csaf-and-gcve-bcp-05-extensions/1093
I think more and more that having GCVE extension on all vulnerability standard format makes much more sense nowadays.
-
"The Common Security Advisory Framework (#CSAF) is an effective and efficient means by which manufacturers can communicate their recommendations for action on vulnerabilities."
writes the Institute for Occupational Safety and Health (a main department of the German Social Accident Insurance) here:
https://www.dguv.de/ifa/fachinfos/industrial-security/csaf/index-2.jsp
further
"New EU regulations place greater responsibility on manufacturers of products with digital elements.For example, Article 14 (8) of the Cyber Resilience Act (CRA) sets out "reporting obligations of manufacturers", together with strict deadlines."
Note that https://www.csaf.io/specification/ version 2.1 is available as "Committee Specification Draft 02" since a few weeks. The technical committee welcomes comments!
-
"The Common Security Advisory Framework (#CSAF) is an effective and efficient means by which manufacturers can communicate their recommendations for action on vulnerabilities."
writes the Institute for Occupational Safety and Health (a main department of the German Social Accident Insurance) here:
https://www.dguv.de/ifa/fachinfos/industrial-security/csaf/index-2.jsp
further
"New EU regulations place greater responsibility on manufacturers of products with digital elements.For example, Article 14 (8) of the Cyber Resilience Act (CRA) sets out "reporting obligations of manufacturers", together with strict deadlines."
Note that https://www.csaf.io/specification/ version 2.1 is available as "Committee Specification Draft 02" since a few weeks. The technical committee welcomes comments!
-
#OT #Advisory VDE-2026-025
Helmholz: Multiple Vulnerabilities in myREX24V2 / myREX24V2.virtualMultiple vulnerabilities have been discovered in Helmholz myREX24V2 / myREX24V2.virtual that could allow unauthenticated RCE or SQLi.
#CVE CVE-2026-32968, CVE-2026-32969https://certvde.com/en/advisories/vde-2026-025/
#CSAF https://helmholz.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-025.json
-
#OT #Advisory VDE-2026-024
MB connect line: Multiple Vulnerabilities in mbCONNECT24/mymbCONNECT24Multiple vulnerabilities have been discovered in MB connect line mbCONNECT24/mymbCONNECT24 that could allow unauthenticated RCE or SQLi.
#CVE CVE-2026-32968, CVE-2026-32969https://certvde.com/en/advisories/vde-2026-024/
#CSAF https://mbconnectline.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-024.json
-
A new pull request for Vulnerability-Lookup adds a CSAF producer that publishes advisories for many manufacturers.
This is great for defenders and researchers, as it increases the amount of detailed vulnerability information available.
It will push the number of ingested feeds to more than 50 unique sources, highlighting the growing diversity of our data sources.
If someone tells you there is a single source of truth for vulnerability information, they’re ignoring the reality: vulnerability intelligence comes from many different sources.
Thanks to @rafi0t for the continuous work on adding CSAF and feeds to vulnerability-lookup
#gcve #cve #cybersecurity #csaf #vulnerability #opendata #opensource
🔗 The new PR with many new CSAF sources https://github.com/vulnerability-lookup/vulnerability-lookup/pull/348
🔗 The open source vulnerability-lookup software https://www.vulnerability-lookup.org/
🔗 GCVE instance https://db.gcve.eu/ -
A new pull request for Vulnerability-Lookup adds a CSAF producer that publishes advisories for many manufacturers.
This is great for defenders and researchers, as it increases the amount of detailed vulnerability information available.
It will push the number of ingested feeds to more than 50 unique sources, highlighting the growing diversity of our data sources.
If someone tells you there is a single source of truth for vulnerability information, they’re ignoring the reality: vulnerability intelligence comes from many different sources.
Thanks to @rafi0t for the continuous work on adding CSAF and feeds to vulnerability-lookup
#gcve #cve #cybersecurity #csaf #vulnerability #opendata #opensource
🔗 The new PR with many new CSAF sources https://github.com/vulnerability-lookup/vulnerability-lookup/pull/348
🔗 The open source vulnerability-lookup software https://www.vulnerability-lookup.org/
🔗 GCVE instance https://db.gcve.eu/ -
@bagder However, it's the classic chicken-egg problem: Why should I start? The answer is: #curl is a mature project and can lead the way.
We are happy to help you and others getting started. Feel free to reach out to our #CSAF team at [email protected].(2/2)
-
@bagder However, it's the classic chicken-egg problem: Why should I start? The answer is: #curl is a mature project and can lead the way.
We are happy to help you and others getting started. Feel free to reach out to our #CSAF team at [email protected].(2/2)
-
@bagder Great that you are considering #CSAF. We think that CSAF is a gamechanger: CSAF works for open source as well as closed source, hardware, specifications etc. - basically anything you can think of writing a security advisory or #VEX for.
Supply Chain Security: No one can secure single handed - everyone is needed. A single format: You can profit from the upstream CSAFs, your downstream users profit from your CSAFs.(1/2)
-
@bagder Great that you are considering #CSAF. We think that CSAF is a gamechanger: CSAF works for open source as well as closed source, hardware, specifications etc. - basically anything you can think of writing a security advisory or #VEX for.
Supply Chain Security: No one can secure single handed - everyone is needed. A single format: You can profit from the upstream CSAFs, your downstream users profit from your CSAFs.(1/2)
-
Für viele Unternehmen sind die Anforderungen an das #Schwachstellenmanagement in der #Cybersicherheit ein zunehmend dickes Brett.
Neben der reinen Menge an Meldungen ist ein weiteres Problem, dass #Cybersecurity-#Advisories bislang in den unterschiedlichen Formaten, also beispielsweise als PDF, als Website oder als Textfile veröffentlicht werden.
Deshalb empfiehlt das #BSI Unternehmen den #CSAF-Einsatz, um Risiken schneller erfassen und effizienter bewerten zu können:
-
Für viele Unternehmen sind die Anforderungen an das #Schwachstellenmanagement in der #Cybersicherheit ein zunehmend dickes Brett.
Neben der reinen Menge an Meldungen ist ein weiteres Problem, dass #Cybersecurity-#Advisories bislang in den unterschiedlichen Formaten, also beispielsweise als PDF, als Website oder als Textfile veröffentlicht werden.
Deshalb empfiehlt das #BSI Unternehmen den #CSAF-Einsatz, um Risiken schneller erfassen und effizienter bewerten zu können:
-
Want to know how to write and distribute #SecurityAdvisories that can be parsed and processed automatically?
Freshly announced are this years workshops for the Common Security Advisory Framework (#CSAF). They will be held in Nuremberg, Germany, November 10th to 12th.
See https://www.csaf.io/workshops/2025/
(right after this are the CSAF Community-Days). -
#OT #Advisory VDE-2025-020
WAGO: Switches affected by year 2k38 problem#CVE CVE-2025-1235
https://certvde.com/en/advisories/VDE-2025-020
#CSAF https://wago.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-020.json
-
#OT #Advisory VDE-2025-044
Weidmueller: Industrial ethernet switches are affected by multiple vulnerabilities#CVE CVE-2025-41651, CVE-2025-41652, CVE-2025-41649, CVE-2025-41650, CVE-2025-41653
https://certvde.com/en/advisories/VDE-2025-044
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-044.json
-
#OT #Advisory VDE-2025-041
Weidmueller: ResMa is affected by a Vulnerability for ASP.NET AJAXWeidmueller product ResMa is affected by ASP.NET AJAX vulnerability.
Weidmueller has released a new firmware for the affected product to fix the vulnerability.
#CVE CVE-2025-3600https://certvde.com/en/advisories/VDE-2025-041
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-041.json
-
#OT #Advisory #Update VDE-2023-046
WAGO: Multiple products vulnerable to local file inclusionAn attacker with administrative privileges which can access sensitive files can additionally access them in an unintended, undocumented way.
UPDATE 07.05.2025: The fixed versions have been updated, because the previously mentioned versions are still vulnerable to this issue. More details have been added to the hardware devices. More affected version numbers were added to the firmwares.
#CVE CVE-2023-4089https://certvde.com/en/advisories/VDE-2023-046
#CSAF https://wago.csaf-tp.certvde.com/.well-known/csaf/white/2023/vde-2023-046.json
-
Searching for an #OT #Advisory?
Want it machine readable?
Have a look at our #csaf aggregator https://aggregator.certvde.com for advisories of 35+ OT and #ICS vendors that partner with CERT@VDE.See https://certvde.com/en/more/csaf/ for a full list of the trusted providers used on the aggregator.
-
Searching for an #OT #Advisory?
Want it machine readable?
Have a look at our #csaf aggregator https://aggregator.certvde.com for advisories of 35+ OT and #ICS vendors that partner with CERT@VDE.See https://certvde.com/en/more/csaf/ for a full list of the trusted providers used on the aggregator.
-
Automating finding and parsing of security advisories? That is what the Common Security Advisory Framework (CSAF) attempts to. https://csaf.io. There are going to be workshops and community days in the 2nd week of December in Germany. See https://csaf.io/workshop/ .
The call for presentations is until the 3rd of November. The location is still to be announced within Germany. I guess Munich or Bonn. (My company is contracted by the BSI to help with CSAF software and spec)
-
Samen met het NCSC en collega's van DPC zit ik dinsdag 1 oktober in een track op de altijd mooie 'ONE Conference 2024'. We hebben het over waarom 'weten wat je hebt' belangrijk is in kwetsbaarhedenbeheer en hoe 'real time vulnerability feeds', CSAF en SBOMs je daarbij kunnen helpen. Als je op de ONE bent, kom langs! :-). https://one-conference.nl/side-event/ncsc-side-tracks/ #oneconference24 #sbom #csaf #ncscnl
-
Samen met het NCSC en collega's van DPC zit ik dinsdag 1 oktober in een track op de altijd mooie 'ONE Conference 2024'. We hebben het over waarom 'weten wat je hebt' belangrijk is in kwetsbaarhedenbeheer en hoe 'real time vulnerability feeds', CSAF en SBOMs je daarbij kunnen helpen. Als je op de ONE bent, kom langs! :-). https://one-conference.nl/side-event/ncsc-side-tracks/ #oneconference24 #sbom #csaf #ncscnl
-
CSAF Walker: Working with CSAF providers in Rust
A quick introduction blog post to a Rust crate & CLI for working with CSAF advisories and providers.
-
CSAF Walker: Working with CSAF providers in Rust
A quick introduction blog post to a Rust crate & CLI for working with CSAF advisories and providers.
-
vulnerability-lookup version v0.7.0 has been released.
- News feed added
- Support for CSAF sources (CERT Bund, RedHat, Siemens, CISA, CISCO, Nozomi Networks, OpenXchange, SICK)
- OSSF Malicious packages repository
- Pagination for recent vulnerabilities (API & Web)🔗 Source code https://github.com/cve-search/vulnerability-lookup/releases/tag/v0.7.0
🔗 Vulnerability lookup online https://vulnerability.circl.lu/
-
vulnerability-lookup version v0.7.0 has been released.
- News feed added
- Support for CSAF sources (CERT Bund, RedHat, Siemens, CISA, CISCO, Nozomi Networks, OpenXchange, SICK)
- OSSF Malicious packages repository
- Pagination for recent vulnerabilities (API & Web)🔗 Source code https://github.com/cve-search/vulnerability-lookup/releases/tag/v0.7.0
🔗 Vulnerability lookup online https://vulnerability.circl.lu/
-
Today's Live Cyber Security Awareness Forum panel session is on "The problem of employees using FREE stuff from the Internet."
Everyone is welcome.
#csaf #cybersecurityawarenessforumhttps://us02web.zoom.us/webinar/register/4117048890923/WN_aS5vJaPaRg-0CATjBcW07Q
-
Today's Live Cyber Security Awareness Forum panel session is on "The problem of employees using FREE stuff from the Internet."
Everyone is welcome.
#csaf #cybersecurityawarenessforumhttps://us02web.zoom.us/webinar/register/4117048890923/WN_aS5vJaPaRg-0CATjBcW07Q
-
Abschlussvortrag CSAF Tools – Projekt 510 am 29.11.23
https://www.bsi.bund.de/SharedDocs/Termine/DE/2023/Abschlussvortrag_Projekt510_CSAF.html
-
Working in cyber security can wear you down. Even if you love the work.
The results of your good work rarely show as a big red, flashing sign that says "You succeeded". Sometimes you wonder if anyone even notices.
But when you can speak to others who are facing the same issues in other organizations, you realize that the work you are doing is really important.
One day, you'll likely see a news story where another organization just like yours fell victim to an attack, and you realize that what you've done makes it less likely to happen in your organization.
That's when you understand the value of what you are contributing.
Come and join the Cyber Security Awareness Forum live panel discussion today, and hear from others in the security awareness industry who have dealt with similar challenges to the ones you're facing.
https://us02web.zoom.us/webinar/register/6017000567129/WN_638kBM5tTzaVM-_oCT3soA
#csaf #cybersecurityawarenessforum #securityawareness #securitymanagement #riskmanagement #humanriskmanagement
-
There are some well-known reasons why gamification is considered to be a good tool for cyber security training and awareness programs.
There are also some misconceptions about gamification that tend to lead people to dismiss the approach.
In today's live Cyber Security Awareness Forum panel discussion, we'll dig into "The pros and cons of gamification in a security awareness program"
Joing us at 1pm EDT today (Wednesday, November 1), and bring your questions or comments...
https://us02web.zoom.us/webinar/register/4316988555351/WN_FQ_uqVfESBazpD2HYNlcWA
#csaf #cybersecurityawarenessforum #gamification #securityawareness #securitymanagement #riskmanagement #securitytraining
-
Exklusive Workshops und mehr rund um das Thema Common Security Advisory Framework (CSAF)
Das BSI fördert und fordert CSAF und veranstaltet im Rahmen der ACS, vom 12.-15. Dezember 2023, insgesamt drei kostenfreie Workshops und Ask-the-Expert-Sessions rund um das Thema CSAF (Common Security Advisory Framework). Alle Workshops werden aufgezeichnet und im Nachgang für Lehrzwecke aufbereitet und öffentlich zur Verfügung gestellt.