#epss — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #epss, aggregated by home.social.
-
🚀 Vulnerability-Lookup 6.0.0 is out!
🔔 Webhook notifications — push your product reports to any HTTPS endpoint (chat, SIEM, ticketing), with a configurable payload and a strict outbound policy.
📈 Local exploit hazard — new API endpoints, hazard-ordered reports, and daily standing exposure alerts.
👥 A searchable vulnerability credits index
🧭 SSVC v2.0 decisions on the CVE page👉 https://www.vulnerability-lookup.org/2026/08/13/vulnerability-lookup-6-0-0/
#CVE #EPSS #KEV #GCVE #OpenSource #OpenData #Software #Community #AI #CyberSecurity
-
You scanned dependencies last month. 👍 But 47 new #CVEs dropped since then. 😵💫
The gap between periodic scans is where risk lives. When a critical vulnerability hits, can you instantly tell which apps are affected?
This on-demand webinar covers continuous #SBOM monitoring, #EPSS scoring for active exploits, and #VEX for cutting false positives, without adding ops work.
https://www.amazee.io/resources/webinar/uncover-hidden-vulnerabilities-with-dependency-track
-
📰 CSO covered CISA's new Binding Operational Directive 26-04, which tells federal agencies to patch smarter, not harder. The directive moves beyond #CVSS severity scores toward a four-factor risk model that weighs internet exposure, KEV listing, whether exploitation can be automated, and how much control an attacker gains after exploitation.
FIRST EPSS SIG member and RogoLabs founder Jerry Gamblin commented, "BOD 26-04 is a massive step in the right direction and validates what data-driven teams already know: Patching every CVSS High or Critical is mathematically impossible. By formalizing the use of the KEV catalog alongside advanced predictive data like #EPSS, CISA is helping drive the industry toward practical, risk-based operational maturity."
Hear more from CISA next week at #FIRSTCON26.
-
Modern supply chain security can't rely on periodic scans. When the next CVE drops, you need fleet-wide visibility immediately.
Our Managed #DependencyTrack provides continuous #SBOM monitoring with multi-source vulnerability intelligence, smart triage (#VEX + #EPSS), and complete data sovereignty, all without the operational overhead of DIY deployment.
#OpenSource at the core. Managed where it matters.
Read our 2026 guide to continuous supply chain security:
https://www.amazee.io/blog/post/dependency-track-software-supply-chain-security -
Is your security team drowning in "critical" alerts that aren't actually exploitable?
🌊🧘♂️ Most teams treat dependency risk as a periodic task, but our webinar on April 8 shows you how to make it continuous.
We'll explore how #DependencyTrack uses #EPSS and #VEX to filter out the noise and prioritize the 10% of vulnerabilities that actually pose a threat to your production environment.
🔗 https://www.amazee.io/blog/post/live-uncover-hidden-vulnerabilities-with-dependency-track
-
Гадание на взломах. Предсказательная сила EPSS
В конце года принято подводить итоги и делать предсказания. Давайте совместим оба ритуала и посмотрим, насколько лучше эксперты СайберОК могли бы контролировать поверхность атак, если бы слепо верили в магию EPSS. Спойлер: контролировали бы не очень.
https://habr.com/ru/articles/981876/
#cve #vulnerability #эксплуатация_уязвимостей #epss #патчменеджмент #easm #киберугрозы
-
🚀 NEW on We ❤️ Open Source 🚀
Nigel Douglas explains why CVSS scores alone don’t cut it anymore. Learn how EPSS, VEX, SSVC & reachability analysis provide real-world prioritization.
Read more: https://allthingsopen.org/articles/vulnerability-prioritization-beyond-cvss
#WeLoveOpenSource #Cybersecurity #EPSS #OpenSourceSecurity #VulnerabilityManagement #DevSecOps
-
🌍 In this week's "Improving Security Across Nations with FIRST" video series, we spotlight Jay Jacobs, FIRST EPSS SIG Co-Chair and Chief Data Scientist at Empirical Security.
He shares how predictive models are transforming vulnerability management:
🎯 EPSS evolution - Co-developed the Exploit Prediction Scoring System, now scoring over 271,000 CVEs and integrated by 100+ companies
📊 Predictive intelligence - Created models that estimate exploitation probability over the next 30 days, helping security teams focus remediation efforts where they matter most
🤖 Data-driven approach - Leveraging complex analysis of exploit code, vulnerability attributes, and threat patterns to transform how organizations assess risk
Watch to learn how Jay's pioneering work with FIRST advances global vulnerability prioritization: https://go.first.org/Zqj6Z
-
We're getting riled up for Raleigh 😜 Are you? 🔗https://go.first.org/jDHDu #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX #Raleigh
-
Want an action-packed docket of dynamic speakers and cross-industry topics? Look no further💪 Register for VulnCon25 today! 🔗 https://www.first.org/conference/vulncon2025/ #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX #Raleigh
-
Feeling vulnerable? Don't worry, we've got you 🤝 Register for the CVE/FIRST VulnCon 2025 & Annual CNA Summit today!🔗https://go.first.org/SBf3W #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX #Raleigh
-
🥁The moment we've all been waiting for is here! #VulnCon25 agenda is out now 🔗https://go.first.org/r91zE #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX
-
Feeling vulnerable? Don't worry, we've got you 🤝 Register for the CVE/FIRST #VulnCon25 & Annual CNA Summit today!🔗https://go.first.org/SBf3W #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX #Raleigh
-
Let's be vulnerable together💕 Register for VulnCon25 today🔗 https://www.first.org/conference/vulncon2025/ #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX #Raleigh
-
Not able to attend VulnCon25 in person? 😥 Attend from home and register for our virtual option today 😁🔗 https://go.first.org/jDHDu #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX
-
Not able to attend VulnCon25 in person? 😥 Attend from home and register for our virtual option today 😁🔗 https://go.first.org/jDHDu #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX
-
Let's be vulnerable together💕 Register for #VulnCon25 today🔗 https://www.first.org/conference/vulncon2025/ #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX #Raleigh
-
#SecureCoding: Risiken einschätzen mit dem #ExploitPredictionScoringSystem | Developer https://www.heise.de/hintergrund/Secure-Coding-Risiken-einschaetzen-mit-dem-Exploit-Prediction-Scoring-System-10252792.html #ITSecurity #Cybersecurity #VulnerabilityManagement #ExploitPrediction #EPSS #CVSS #SSVC #CWE #RiskManagement #ThreatIntelligence #MachineLearning #DataDrivenSecurity #PatchManagement #SecurityBestPractices #ZeroDay #VulnerabilityAssessment #SecurityTools #InfoSec
-
Let's be vulnerable together💕 Register for #VulnCon25 today🔗 https://www.first.org/conference/vulncon2025/ #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX #Raleigh
-
Let's be vulnerable together💕 Register for #VulnCon25 today🔗 https://www.first.org/conference/vulncon2025/ #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX #Raleigh
-
Want an action-packed docket of dynamic speakers and cross-industry topics? Look no further,💪 Register for VulnCon25 today! 🔗https://go.first.org/jDHDu #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX #Raleigh
-
Do you want to be a part of the 40+ action-packed sessions at VulnCon25? If you said yes, now is your chance to submit your paper today! CFP has been extended until Jan 31st. 😎 #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX #Raleigh 🔗 https://go.first.org/MPudV
-
Want an action-packed docket of dynamic speakers and cross-industry topics? Look no further,💪 Register for VulnCon25 today! 🔗https://www.first.org/conference/vulncon2025/ #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX #Raleigh
-
It's your lucky day! 🎉 The CFP for #VulnCon25 has been extended to January 31st! #submittoday #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX #Raleigh 🔗 https://go.first.org/MPudV
-
Submit your #CFP for #VulnCon2025 today to be a part of the 40+ action-packed sessions😎🔗 https://go.first.org/MPudV #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX #Raleigh