home.social

#csaf — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #csaf, aggregated by home.social.

fetched live
  1. 282,000+ VEX records are now in Vulnerability-Lookup 🎉

    🔎 vulnerability.circl.lu/vex

    SUSE just joined Red Hat and Microsoft as a VEX source — so from any CVE you can see whether a vendor says a product is affected, fixed, or not affected.

    VEX statements are attached directly to each vulnerability and available via the open API.

    🧑‍💻 github.com/vulnerability-looku

    #VEX #CSAF #VulnerabilityManagement #OpenSource #InfoSec #GCVE #CVE #CYberSecurity #Vulnerability

  2. 282,000+ VEX records are now in Vulnerability-Lookup 🎉

    🔎 vulnerability.circl.lu/vex

    SUSE just joined Red Hat and Microsoft as a VEX source — so from any CVE you can see whether a vendor says a product is affected, fixed, or not affected.

    VEX statements are attached directly to each vulnerability and available via the open API.

    🧑‍💻 github.com/vulnerability-looku

    #VEX #CSAF #VulnerabilityManagement #OpenSource #InfoSec #GCVE #CVE #CYberSecurity #Vulnerability

  3. 🆕 Vulnerability-Lookup now imports Microsoft CSAF VEX documents from MSRC — joining the Red Hat VEX feed as a vendor VEX enrichment source.

    Per-CVE VEX statements (product status, severity) are attached directly to CVE records, visible on the vulnerability page and via the API with the full CSAF documents.

    Example with both Red Hat and Microsoft VEX:
    vulnerability.circl.lu/vuln/CV

  4. 🆕 Vulnerability-Lookup now imports Microsoft CSAF VEX documents from MSRC — joining the Red Hat VEX feed as a vendor VEX enrichment source.

    Per-CVE VEX statements (product status, severity) are attached directly to CVE records, visible on the vulnerability page and via the API with the full CSAF documents.

    Example with both Red Hat and Microsoft VEX:
    vulnerability.circl.lu/vuln/CV

    #VEX #CSAF #VulnerabilityManagement #CVE #OpenSource

  5. Vulnerability-Lookup 5.4.0 released! 🚀

    Highlights:
    🔎 VEX enrichment from Red Hat CSAF VEX documents — new /api/vex endpoints, a VEX tab and a VEX badge on vulnerability pages
    🔐 Per-user enable/disable of CNA publication
    📬 Admin overview for KEV catalog e-mail subscriptions, richer digest e-mails
    🛠️ Feeder robustness fixes

    vulnerability-lookup.org/2026/

  6. Vulnerability-Lookup 5.4.0 released! 🚀

    Highlights:
    🔎 VEX enrichment from Red Hat CSAF VEX documents — new /api/vex endpoints, a VEX tab and a VEX badge on vulnerability pages
    🔐 Per-user enable/disable of CNA publication
    📬 Admin overview for KEV catalog e-mail subscriptions, richer digest e-mails
    🛠️ Feeder robustness fixes

    vulnerability-lookup.org/2026/

    #VulnerabilityLookup #VEX #CSAF #CVE

  7. 👉 Ihr folgt uns als BSI hier im Fediverse und wollt keine IT-Sicherheitsmitteilung unseres CERT-Bund, dem Computer Emergency Response Team für Bundesbehörden, verpassen? Dann folgt auch @certbund, der zentralen Anlaufstelle für präventive und reaktive Maßnahmen bei sicherheitsrelevanten Vorfällen in Computer-Systemen.

    CERT-Bund ist Mitglied des #CSIRTsNetwork der EU und ein starker Unterstützer des Common Security Advisory Framework #CSAF.

    Gern weitersagen! 🔄

  8. 👉 Ihr folgt uns als BSI hier im Fediverse und wollt keine IT-Sicherheitsmitteilung unseres CERT-Bund, dem Computer Emergency Response Team für Bundesbehörden, verpassen? Dann folgt auch @certbund, der zentralen Anlaufstelle für präventive und reaktive Maßnahmen bei sicherheitsrelevanten Vorfällen in Computer-Systemen.

    CERT-Bund ist Mitglied des #CSIRTsNetwork der EU und ein starker Unterstützer des Common Security Advisory Framework #CSAF.

    Gern weitersagen! 🔄

  9. Playing with CSAF 2.1 CSD02 and GCVE extensions.

    discourse.ossbase.org/t/csaf-a

    I think more and more that having GCVE extension on all vulnerability standard format makes much more sense nowadays.

    #gcve #cve #csaf

    @gcve

  10. Playing with CSAF 2.1 CSD02 and GCVE extensions.

    discourse.ossbase.org/t/csaf-a

    I think more and more that having GCVE extension on all vulnerability standard format makes much more sense nowadays.

    #gcve #cve #csaf

    @gcve

  11. "The Common Security Advisory Framework (#CSAF) is an effective and efficient means by which manufacturers can communicate their recommendations for action on vulnerabilities."

    writes the Institute for Occupational Safety and Health (a main department of the German Social Accident Insurance) here:

    dguv.de/ifa/fachinfos/industri

    further
    "New EU regulations place greater responsibility on manufacturers of products with digital elements.

    For example, Article 14 (8) of the Cyber Resilience Act (CRA) sets out "reporting obligations of manufacturers", together with strict deadlines."

    Note that csaf.io/specification/ version 2.1 is available as "Committee Specification Draft 02" since a few weeks. The technical committee welcomes comments!

  12. "The Common Security Advisory Framework (#CSAF) is an effective and efficient means by which manufacturers can communicate their recommendations for action on vulnerabilities."

    writes the Institute for Occupational Safety and Health (a main department of the German Social Accident Insurance) here:

    dguv.de/ifa/fachinfos/industri

    further
    "New EU regulations place greater responsibility on manufacturers of products with digital elements.

    For example, Article 14 (8) of the Cyber Resilience Act (CRA) sets out "reporting obligations of manufacturers", together with strict deadlines."

    Note that csaf.io/specification/ version 2.1 is available as "Committee Specification Draft 02" since a few weeks. The technical committee welcomes comments!

  13. #OT #Advisory VDE-2026-025
    Helmholz: Multiple Vulnerabilities in myREX24V2 / myREX24V2.virtual

    Multiple vulnerabilities have been discovered in Helmholz myREX24V2 / myREX24V2.virtual that could allow unauthenticated RCE or SQLi.
    #CVE CVE-2026-32968, CVE-2026-32969

    certvde.com/en/advisories/vde-

    #CSAF helmholz.csaf-tp.certvde.com/.

  14. #OT #Advisory VDE-2026-024
    MB connect line: Multiple Vulnerabilities in mbCONNECT24/mymbCONNECT24

    Multiple vulnerabilities have been discovered in MB connect line mbCONNECT24/mymbCONNECT24 that could allow unauthenticated RCE or SQLi.
    #CVE CVE-2026-32968, CVE-2026-32969

    certvde.com/en/advisories/vde-

    #CSAF mbconnectline.csaf-tp.certvde.

  15. A new pull request for Vulnerability-Lookup adds a CSAF producer that publishes advisories for many manufacturers.

    This is great for defenders and researchers, as it increases the amount of detailed vulnerability information available.

    It will push the number of ingested feeds to more than 50 unique sources, highlighting the growing diversity of our data sources.

    If someone tells you there is a single source of truth for vulnerability information, they’re ignoring the reality: vulnerability intelligence comes from many different sources.

    Thanks to @rafi0t for the continuous work on adding CSAF and feeds to vulnerability-lookup

    #gcve #cve #cybersecurity #csaf #vulnerability #opendata #opensource

    🔗 The new PR with many new CSAF sources github.com/vulnerability-looku
    🔗 The open source vulnerability-lookup software vulnerability-lookup.org/
    🔗 GCVE instance db.gcve.eu/

    @gcve
    @cedric

  16. A new pull request for Vulnerability-Lookup adds a CSAF producer that publishes advisories for many manufacturers.

    This is great for defenders and researchers, as it increases the amount of detailed vulnerability information available.

    It will push the number of ingested feeds to more than 50 unique sources, highlighting the growing diversity of our data sources.

    If someone tells you there is a single source of truth for vulnerability information, they’re ignoring the reality: vulnerability intelligence comes from many different sources.

    Thanks to @rafi0t for the continuous work on adding CSAF and feeds to vulnerability-lookup

    #gcve #cve #cybersecurity #csaf #vulnerability #opendata #opensource

    🔗 The new PR with many new CSAF sources github.com/vulnerability-looku
    🔗 The open source vulnerability-lookup software vulnerability-lookup.org/
    🔗 GCVE instance db.gcve.eu/

    @gcve
    @cedric

  17. @bagder However, it's the classic chicken-egg problem: Why should I start? The answer is: #curl is a mature project and can lead the way.
    We are happy to help you and others getting started. Feel free to reach out to our #CSAF team at [email protected].

    (2/2)

  18. @bagder However, it's the classic chicken-egg problem: Why should I start? The answer is: #curl is a mature project and can lead the way.
    We are happy to help you and others getting started. Feel free to reach out to our #CSAF team at [email protected].

    (2/2)

  19. @bagder Great that you are considering #CSAF. We think that CSAF is a gamechanger: CSAF works for open source as well as closed source, hardware, specifications etc. - basically anything you can think of writing a security advisory or #VEX for.
    Supply Chain Security: No one can secure single handed - everyone is needed. A single format: You can profit from the upstream CSAFs, your downstream users profit from your CSAFs.

    (1/2)

  20. @bagder Great that you are considering #CSAF. We think that CSAF is a gamechanger: CSAF works for open source as well as closed source, hardware, specifications etc. - basically anything you can think of writing a security advisory or #VEX for.
    Supply Chain Security: No one can secure single handed - everyone is needed. A single format: You can profit from the upstream CSAFs, your downstream users profit from your CSAFs.

    (1/2)

  21. Für viele Unternehmen sind die Anforderungen an das #Schwachstellenmanagement in der #Cybersicherheit ein zunehmend dickes Brett.

    Neben der reinen Menge an Meldungen ist ein weiteres Problem, dass #Cybersecurity-#Advisories bislang in den unterschiedlichen Formaten, also beispielsweise als PDF, als Website oder als Textfile veröffentlicht werden.

    Deshalb empfiehlt das #BSI Unternehmen den #CSAF-Einsatz, um Risiken schneller erfassen und effizienter bewerten zu können:

    bsi.bund.de/SharedDocs/Downloa

  22. Für viele Unternehmen sind die Anforderungen an das #Schwachstellenmanagement in der #Cybersicherheit ein zunehmend dickes Brett.

    Neben der reinen Menge an Meldungen ist ein weiteres Problem, dass #Cybersecurity-#Advisories bislang in den unterschiedlichen Formaten, also beispielsweise als PDF, als Website oder als Textfile veröffentlicht werden.

    Deshalb empfiehlt das #BSI Unternehmen den #CSAF-Einsatz, um Risiken schneller erfassen und effizienter bewerten zu können:

    bsi.bund.de/SharedDocs/Downloa

  23. Want to know how to write and distribute #SecurityAdvisories that can be parsed and processed automatically?

    Freshly announced are this years workshops for the Common Security Advisory Framework (#CSAF). They will be held in Nuremberg, Germany, November 10th to 12th.

    See csaf.io/workshops/2025/
    (right after this are the CSAF Community-Days).

  24. #OT #Advisory VDE-2025-044
    Weidmueller: Industrial ethernet switches are affected by multiple vulnerabilities

    #CVE CVE-2025-41651, CVE-2025-41652, CVE-2025-41649, CVE-2025-41650, CVE-2025-41653

    certvde.com/en/advisories/VDE-

    #CSAF weidmueller.csaf-tp.certvde.co

  25. #OT #Advisory VDE-2025-041
    Weidmueller: ResMa is affected by a Vulnerability for ASP.NET AJAX

    Weidmueller product ResMa is affected by ASP.NET AJAX vulnerability.
    Weidmueller has released a new firmware for the affected product to fix the vulnerability.
    #CVE CVE-2025-3600

    certvde.com/en/advisories/VDE-

    #CSAF weidmueller.csaf-tp.certvde.co

  26. #OT #Advisory #Update VDE-2023-046
    WAGO: Multiple products vulnerable to local file inclusion

    An attacker with administrative privileges which can access sensitive files can additionally access them in an unintended, undocumented way.
    UPDATE 07.05.2025: The fixed versions have been updated, because the previously mentioned versions are still vulnerable to this issue. More details have been added to the hardware devices. More affected version numbers were added to the firmwares.
    #CVE CVE-2023-4089

    certvde.com/en/advisories/VDE-

    #CSAF wago.csaf-tp.certvde.com/.well

  27. Searching for an #OT #Advisory?
    Want it machine readable?
    Have a look at our #csaf aggregator aggregator.certvde.com for advisories of 35+ OT and #ICS vendors that partner with CERT@VDE.

    See certvde.com/en/more/csaf/ for a full list of the trusted providers used on the aggregator.

  28. Searching for an #OT #Advisory?
    Want it machine readable?
    Have a look at our #csaf aggregator aggregator.certvde.com for advisories of 35+ OT and #ICS vendors that partner with CERT@VDE.

    See certvde.com/en/more/csaf/ for a full list of the trusted providers used on the aggregator.

  29. Automating finding and parsing of security advisories? That is what the Common Security Advisory Framework (CSAF) attempts to. csaf.io. There are going to be workshops and community days in the 2nd week of December in Germany. See csaf.io/workshop/ .

    #Security #CSAF

    The call for presentations is until the 3rd of November. The location is still to be announced within Germany. I guess Munich or Bonn. (My company is contracted by the BSI to help with CSAF software and spec)

  30. Samen met het NCSC en collega's van DPC zit ik dinsdag 1 oktober in een track op de altijd mooie 'ONE Conference 2024'. We hebben het over waarom 'weten wat je hebt' belangrijk is in kwetsbaarhedenbeheer en hoe 'real time vulnerability feeds', CSAF en SBOMs je daarbij kunnen helpen. Als je op de ONE bent, kom langs! :-). one-conference.nl/side-event/n #oneconference24 #sbom #csaf #ncscnl

  31. Samen met het NCSC en collega's van DPC zit ik dinsdag 1 oktober in een track op de altijd mooie 'ONE Conference 2024'. We hebben het over waarom 'weten wat je hebt' belangrijk is in kwetsbaarhedenbeheer en hoe 'real time vulnerability feeds', CSAF en SBOMs je daarbij kunnen helpen. Als je op de ONE bent, kom langs! :-). one-conference.nl/side-event/n #oneconference24 #sbom #csaf #ncscnl

  32. CSAF Walker: Working with CSAF providers in Rust

    A quick introduction blog post to a Rust crate & CLI for working with CSAF advisories and providers.

    dentrassi.de/2024/05/19/csaf-w

    #csaf #opensource #rustlang #SoftwareSupplyChain

  33. CSAF Walker: Working with CSAF providers in Rust

    A quick introduction blog post to a Rust crate & CLI for working with CSAF advisories and providers.

    dentrassi.de/2024/05/19/csaf-w

    #csaf #opensource #rustlang #SoftwareSupplyChain

  34. vulnerability-lookup version v0.7.0 has been released.

    - News feed added
    - Support for CSAF sources (CERT Bund, RedHat, Siemens, CISA, CISCO, Nozomi Networks, OpenXchange, SICK)
    - OSSF Malicious packages repository
    - Pagination for recent vulnerabilities (API & Web)

    🔗 Source code github.com/cve-search/vulnerab

    🔗 Vulnerability lookup online vulnerability.circl.lu/

    #cve #vulnerability #vulnerabilities #csaf #infosec

  35. vulnerability-lookup version v0.7.0 has been released.

    - News feed added
    - Support for CSAF sources (CERT Bund, RedHat, Siemens, CISA, CISCO, Nozomi Networks, OpenXchange, SICK)
    - OSSF Malicious packages repository
    - Pagination for recent vulnerabilities (API & Web)

    🔗 Source code github.com/cve-search/vulnerab

    🔗 Vulnerability lookup online vulnerability.circl.lu/

    #cve #vulnerability #vulnerabilities #csaf #infosec

  36. Today's Live Cyber Security Awareness Forum panel session is on "The problem of employees using FREE stuff from the Internet."

    Everyone is welcome.
    #csaf #cybersecurityawarenessforum

    us02web.zoom.us/webinar/regist

  37. Today's Live Cyber Security Awareness Forum panel session is on "The problem of employees using FREE stuff from the Internet."

    Everyone is welcome.
    #csaf #cybersecurityawarenessforum

    us02web.zoom.us/webinar/regist

  38. Working in cyber security can wear you down. Even if you love the work.

    The results of your good work rarely show as a big red, flashing sign that says "You succeeded". Sometimes you wonder if anyone even notices.

    But when you can speak to others who are facing the same issues in other organizations, you realize that the work you are doing is really important.

    One day, you'll likely see a news story where another organization just like yours fell victim to an attack, and you realize that what you've done makes it less likely to happen in your organization.

    That's when you understand the value of what you are contributing.

    Come and join the Cyber Security Awareness Forum live panel discussion today, and hear from others in the security awareness industry who have dealt with similar challenges to the ones you're facing.

    us02web.zoom.us/webinar/regist

    #csaf #cybersecurityawarenessforum #securityawareness #securitymanagement #riskmanagement #humanriskmanagement

  39. There are some well-known reasons why gamification is considered to be a good tool for cyber security training and awareness programs.

    There are also some misconceptions about gamification that tend to lead people to dismiss the approach.

    In today's live Cyber Security Awareness Forum panel discussion, we'll dig into "The pros and cons of gamification in a security awareness program"

    Joing us at 1pm EDT today (Wednesday, November 1), and bring your questions or comments...

    us02web.zoom.us/webinar/regist

    #csaf #cybersecurityawarenessforum #gamification #securityawareness #securitymanagement #riskmanagement #securitytraining

  40. Exklusive Workshops und mehr rund um das Thema Common Security Advisory Framework (CSAF)

    allianz-fuer-cybersicherheit.d

    Das BSI fördert und fordert CSAF und veranstaltet im Rahmen der ACS, vom 12.-15. Dezember 2023, insgesamt drei kostenfreie Workshops und Ask-the-Expert-Sessions rund um das Thema CSAF (Common Security Advisory Framework). Alle Workshops werden aufgezeichnet und im Nachgang für Lehrzwecke aufbereitet und öffentlich zur Verfügung gestellt.

    #ISMSBlog #BSI #CSAF