home.social

#gcve — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #gcve, aggregated by home.social.

fetched live
  1. Sightings have long been a major topic of discussion in the CTI community, particularly in the field of vulnerability management. We have now published a GCVE BCP to standardise the format that has been implemented, tested and used operationally in Vulnerability-Lookup for some time.

    Thanks to everyone (Cédric Bonhomme, Éireann Leverett, Andras Iklody, Sami Mokaddem and many more) who participated in discussions and worked on the implementation details of sightings over the past several years. These efforts had a strong focus on practical implementation, while BCP-12 specifically addresses sightings in the context of vulnerability management.

    BCP-12 is still a draft open for review, but it already provides a strong foundation for existing implementations.

    gcve.eu/2026/08/01/gcve-bcp-12

    #cve #cra #gcve #vulnerabilitymanagement #cybersecurity #openstandard

  2. Sightings have long been a major topic of discussion in the CTI community, particularly in the field of vulnerability management. We have now published a GCVE BCP to standardise the format that has been implemented, tested and used operationally in Vulnerability-Lookup for some time.

    Thanks to everyone (Cédric Bonhomme, Éireann Leverett, Andras Iklody, Sami Mokaddem and many more) who participated in discussions and worked on the implementation details of sightings over the past several years. These efforts had a strong focus on practical implementation, while BCP-12 specifically addresses sightings in the context of vulnerability management.

    BCP-12 is still a draft open for review, but it already provides a strong foundation for existing implementations.

    gcve.eu/2026/08/01/gcve-bcp-12

    #cve #cra #gcve #vulnerabilitymanagement #cybersecurity #openstandard

  3. A new version of the BCP-11 "Community Contribution Fragments for Existing CVE Records" proposal has been published.

    discourse.ossbase.org/t/gcve-b

    This new version is a major refactoring of the originally proposed format.

    Feel free to comment, update or propose changes.

    An implementation will follow when the BCP-11 reach a more stable state.

    #gcve #cve #cybersecurity #vulnerabilitymanagement

    @gcve

  4. A new version of the BCP-11 "Community Contribution Fragments for Existing CVE Records" proposal has been published.

    discourse.ossbase.org/t/gcve-b

    This new version is a major refactoring of the originally proposed format.

    Feel free to comment, update or propose changes.

    An implementation will follow when the BCP-11 reach a more stable state.

    #gcve #cve #cybersecurity #vulnerabilitymanagement

    @gcve

  5. The GCVE Lab is an open space for experimenting with new ideas, tools, formats, and services related to the Global CVE Allocation System initiative.

    The lab allows the GCVE community to explore promising concepts without immediately imposing the stability, compatibility, and operational requirements expected from the core GCVE infrastructure.

    Open to comments/ideas.

    #gcve #cve #cybersecurity

    discourse.ossbase.org/t/gcve-l

    gcve.eu

    @[email protected] @[email protected]

  6. The GCVE Lab is an open space for experimenting with new ideas, tools, formats, and services related to the Global CVE Allocation System initiative.

    The lab allows the GCVE community to explore promising concepts without immediately imposing the stability, compatibility, and operational requirements expected from the core GCVE infrastructure.

    Open to comments/ideas.

    #gcve #cve #cybersecurity

    discourse.ossbase.org/t/gcve-l

    gcve.eu

    @[email protected] @[email protected]

  7. 282,000+ VEX records are now in Vulnerability-Lookup 🎉

    🔎 vulnerability.circl.lu/vex

    SUSE just joined Red Hat and Microsoft as a VEX source — so from any CVE you can see whether a vendor says a product is affected, fixed, or not affected.

    VEX statements are attached directly to each vulnerability and available via the open API.

    🧑‍💻 github.com/vulnerability-looku

    #VEX #CSAF #VulnerabilityManagement #OpenSource #InfoSec #GCVE #CVE #CYberSecurity #Vulnerability

  8. 282,000+ VEX records are now in Vulnerability-Lookup 🎉

    🔎 vulnerability.circl.lu/vex

    SUSE just joined Red Hat and Microsoft as a VEX source — so from any CVE you can see whether a vendor says a product is affected, fixed, or not affected.

    VEX statements are attached directly to each vulnerability and available via the open API.

    🧑‍💻 github.com/vulnerability-looku

    #VEX #CSAF #VulnerabilityManagement #OpenSource #InfoSec #GCVE #CVE #CYberSecurity #Vulnerability

  9. You can now browse VEX statements in Vulnerability-Lookup!

    The new VEX page lets you explore 220k+ vendor VEX records (Red Hat, Microsoft MSRC, more coming), filter by source, search by CVE ID or title, see product statuses at a glance (fixed, known affected, not affected, under investigation) and pivot straight to the related vulnerability.

    🔎 vulnerability.circl.lu/vex/
    🧩 API: vulnerability.circl.lu/api/vex/

    #VEX #VulnerabilityLookup #CVE #GCVE #OpenSource #CyberSecurity

  10. You can now browse VEX statements in Vulnerability-Lookup!

    The new VEX page lets you explore 220k+ vendor VEX records (Red Hat, Microsoft MSRC, more coming), filter by source, search by CVE ID or title, see product statuses at a glance (fixed, known affected, not affected, under investigation) and pivot straight to the related vulnerability.

    🔎 vulnerability.circl.lu/vex/
    🧩 API: vulnerability.circl.lu/api/vex/

    #VEX #VulnerabilityLookup #CVE #GCVE #OpenSource #CyberSecurity

  11. 📦 gcve 0.12.1 is out — a small maintenance release with updated dependencies.

    gcve is a Python client and CLI for the Global CVE Allocation System (GCVE), a decentralized approach to vulnerability identification where multiple GCVE Numbering Authorities can allocate IDs independently, with a cryptographically signed registry.

    🔗 gcve.eu
    🐍 pipx install gcve
    💻 github.com/gcve-eu/gcve

  12. 📦 gcve 0.12.1 is out — a small maintenance release with updated dependencies.

    gcve is a Python client and CLI for the Global CVE Allocation System (GCVE), a decentralized approach to vulnerability identification where multiple GCVE Numbering Authorities can allocate IDs independently, with a cryptographically signed registry.

    🔗 gcve.eu
    🐍 pipx install gcve
    💻 github.com/gcve-eu/gcve

    #GCVE #CVE #VulnerabilityManagement #CyberSecurity #Python #OpenSource

  13. 📦 gcve 0.12.1 is out — a small maintenance release with updated dependencies.

    gcve is a Python client and CLI for the Global CVE Allocation System (GCVE), a decentralized approach to vulnerability identification where multiple GCVE Numbering Authorities can allocate IDs independently, with a cryptographically signed registry.

    🔗 gcve.eu
    🐍 pipx install gcve
    💻 github.com/gcve-eu/gcve

    #GCVE #CVE #VulnerabilityManagement #CyberSecurity #Python #OpenSource

  14. We just released cve-search v6.0.1 - it is a security and maintenance release. All users are strongly encouraged to upgrade.

    Thanks to @oh2fih for the remediation fix and release support. Thanks to George Chen for the report about the security vulnerability.

    #cve #gcve #cybersecurity

    🔗 github.com/cve-search/cve-sear

  15. We just released cve-search v6.0.1 - it is a security and maintenance release. All users are strongly encouraged to upgrade.

    Thanks to @oh2fih for the remediation fix and release support. Thanks to George Chen for the report about the security vulnerability.

    #cve #gcve #cybersecurity

    🔗 github.com/cve-search/cve-sear

  16. A new KEV Catalog built from real-world exploitation data !

    vulnerability.circl.lu/known-e

    We are excited to share the result of a fruitful collaboration with @shadowserver: a new Known Exploited Vulnerabilities (KEV) Catalog (BCP-07 compliant) built directly from their global honeypot telemetry.

    #ShadowServer #KEV #GCVE #Vulnerability #VulnerabilityManagement #Decentralization #Fragmentation

  17. A new KEV Catalog built from real-world exploitation data !

    vulnerability.circl.lu/known-e

    We are excited to share the result of a fruitful collaboration with @shadowserver: a new Known Exploited Vulnerabilities (KEV) Catalog (BCP-07 compliant) built directly from their global honeypot telemetry.

    #ShadowServer #KEV #GCVE #Vulnerability #VulnerabilityManagement #Decentralization #Fragmentation

  18. Improving the CPE editor for the GCVE initiative: clearer API behavior, better performance, and many other enhancements. This will be released in version 1.1 and the improvements are already in the online version.

    🌍️ Online version cpe.gcve.eu/
    :github: github.com/gcve-eu/cpe-editor

    If you want to improve the CPE dataset, you can make proposal online.

    Thanks to all the users who provided feedback for improvements @righel @cedric @jgamblin

    @gcve

    #gcve #cpe #cve #vulnerability #vulnerabilitymanagement #opensource #opendata

  19. Improving the CPE editor for the GCVE initiative: clearer API behavior, better performance, and many other enhancements. This will be released in version 1.1 and the improvements are already in the online version.

    🌍️ Online version cpe.gcve.eu/
    :github: github.com/gcve-eu/cpe-editor

    If you want to improve the CPE dataset, you can make proposal online.

    Thanks to all the users who provided feedback for improvements @righel @cedric @jgamblin

    @gcve

    #gcve #cpe #cve #vulnerability #vulnerabilitymanagement #opensource #opendata

  20. 🎉 Vulnerability-Lookup 5.2.0 is out!

    This release comes with plenty of improvements and is the result of many expensive AI tokens consumed by Claude Code under the supervision of its human orchestrator.

    Curious? Have a look at the release notes:

    vulnerability-lookup.org/2026/

    #AI #Orchestration #Vulnerability #OpenSource #GCVE #CVE #CVD #GNA

  21. 🎉 Vulnerability-Lookup 5.2.0 is out!

    This release comes with plenty of improvements and is the result of many expensive AI tokens consumed by Claude Code under the supervision of its human orchestrator.

    Curious? Have a look at the release notes:

    vulnerability-lookup.org/2026/

    #AI #Orchestration #Vulnerability #OpenSource #GCVE #CVE #CVD #GNA

  22. The idea from @bagder is so interesting that it gave me the idea to extend the "GCVE-BCP-02 - Practical Guide to Vulnerability Handling and Disclosure" with "Temporary Closure of Vulnerability Intake Windows"

    #gcve #cve #vulnerabilitymanagement #vulnerability #opensource #cybersecurity

    🔗 Proposal discourse.ossbase.org/t/tempor
    🔗 Original BCP-02 gcve.eu/bcp/gcve-bcp-02/

  23. The idea from @bagder is so interesting that it gave me the idea to extend the "GCVE-BCP-02 - Practical Guide to Vulnerability Handling and Disclosure" with "Temporary Closure of Vulnerability Intake Windows"

    #gcve #cve #vulnerabilitymanagement #vulnerability #opensource #cybersecurity

    🔗 Proposal discourse.ossbase.org/t/tempor
    🔗 Original BCP-02 gcve.eu/bcp/gcve-bcp-02/

  24. 📢 Vulnerability-Lookup 5.1.0 released!

    New CNA Publication Service: publish vulnerabilities from your local instance (GCVE) directly to the official CVE Program via MITRE's CVE Services — one record, two identifiers, no duplication, with built-in moderation as part of CVD.

    Plus: exploited-CVE ratio statistics, CSAF advisories in full-text search, and UI improvements.

    vulnerability-lookup.org/2026/

    #CyberSecurity #OpenSource #CVD #GCVE #CNA #CVE

  25. 📢 Vulnerability-Lookup 5.1.0 released!

    New CNA Publication Service: publish vulnerabilities from your local instance (GCVE) directly to the official CVE Program via MITRE's CVE Services — one record, two identifiers, no duplication, with built-in moderation as part of CVD.

    Plus: exploited-CVE ratio statistics, CSAF advisories in full-text search, and UI improvements.

    vulnerability-lookup.org/2026/

    #CyberSecurity #OpenSource #CVD #GCVE #CNA #CVE

  26. Playing with CSAF 2.1 CSD02 and GCVE extensions.

    discourse.ossbase.org/t/csaf-a

    I think more and more that having GCVE extension on all vulnerability standard format makes much more sense nowadays.

    #gcve #cve #csaf

    @gcve

  27. Playing with CSAF 2.1 CSD02 and GCVE extensions.

    discourse.ossbase.org/t/csaf-a

    I think more and more that having GCVE extension on all vulnerability standard format makes much more sense nowadays.

    #gcve #cve #csaf

    @gcve

  28. I'm now GNA 119 under CIRCL's GCVE system — a decentralized vulnerability
    identification authority. I have authority to mint vulnerability
    identifiers for cloud findings, including ones where vendor CNAs decline
    to issue CVEs.

    I could start assigning IDs to my own research today. I won't.

    Cloud vulnerability validation shouldn't be one person's judgment. Mine
    or anyone else's.

    I'm forming a consensus panel of practitioners for each major cloud
    platform — AWS, GCP, Azure, and managed services. GCVE-119 allocations
    will go through panel review, not solo decisions.

    Charter, scope, and membership criteria coming. Community input on
    structure welcome before anything is finalized.

    Background on GCVE and the cloud finding gap:
    olearysec.com/gcve/

    #infosec #vulnerability #GCVE #cloudsecurity #security

  29. I'm now GNA 119 under CIRCL's GCVE system — a decentralized vulnerability
    identification authority. I have authority to mint vulnerability
    identifiers for cloud findings, including ones where vendor CNAs decline
    to issue CVEs.

    I could start assigning IDs to my own research today. I won't.

    Cloud vulnerability validation shouldn't be one person's judgment. Mine
    or anyone else's.

    I'm forming a consensus panel of practitioners for each major cloud
    platform — AWS, GCP, Azure, and managed services. GCVE-119 allocations
    will go through panel review, not solo decisions.

    Charter, scope, and membership criteria coming. Community input on
    structure welcome before anything is finalized.

    Background on GCVE and the cloud finding gap:
    olearysec.com/gcve/

    #infosec #vulnerability #GCVE #cloudsecurity #security

  30. RE: infosec.exchange/@sambowne/116

    If I understood #GCVE correctly, this is exactly the sort of case where you want to use this process to assign a #GCVE identifier, @adulau -> what do you think?

  31. RE: infosec.exchange/@sambowne/116

    If I understood #GCVE correctly, this is exactly the sort of case where you want to use this process to assign a #GCVE identifier, @adulau -> what do you think?

  32. GCVE has published a description of the scope of a GCVE record. It is based on feedback, misunderstandings from articles about the GCVE initiative, and ideas from GNAs actually assigning IDs.

    The document is still in draft before in a final publication. Feedback is welcome via the standard Discourse platform.

    BCP-09 -> gcve.eu/bcp/gcve-bcp-09/

    #gcve #cve #vulnerability #opensource #vulnerability #cybersecurity

    social.circl.lu/@gcve/11658895

  33. GCVE has published a description of the scope of a GCVE record. It is based on feedback, misunderstandings from articles about the GCVE initiative, and ideas from GNAs actually assigning IDs.

    The document is still in draft before in a final publication. Feedback is welcome via the standard Discourse platform.

    BCP-09 -> gcve.eu/bcp/gcve-bcp-09/

    #gcve #cve #vulnerability #opensource #vulnerability #cybersecurity

    social.circl.lu/@gcve/11658895

  34. @Le_suisse @ariadne @gregkh @wdormann @Viss @andrewnez @Di4na

    Yes! The #GCVE folks are really on the ball about all this

    I would be willing to bet a milkshake they will be one of the more authoritative sources in the future

  35. @Le_suisse @ariadne @gregkh @wdormann @Viss @andrewnez @Di4na

    Yes! The #GCVE folks are really on the ball about all this

    I would be willing to bet a milkshake they will be one of the more authoritative sources in the future

  36. RE: social.circl.lu/@gcve/11647277

    After the recent hackathon and the feedback from different contributors, we published a first draft version of GCVE-BCP-10 to refresh the Common Platform Enumeration model.

    #gcve #cpe #cybersecurity

    infosec.exchange/@gcve@social.

  37. RE: social.circl.lu/@gcve/11647277

    After the recent hackathon and the feedback from different contributors, we published a first draft version of GCVE-BCP-10 to refresh the Common Platform Enumeration model.

    #gcve #cpe #cybersecurity

    infosec.exchange/@gcve@social.