home.social

#kev — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #kev, aggregated by home.social.

fetched live
  1. 📊 Vulnerability Report — July 2026 is out

    vulnerability-lookup.org/2026/

    A record of published CVEs (+23% over June) and 61,263 sightings.

    4 SharePoint flaws in CISA KEV in 4 weeks, a chained WordPress core pair topping the sightings, and a wave of Joomla extensions.

    We put 5 KEV catalogs side by side: 65 vulnerabilities entered at least one in July — watching only CISA would have missed nearly half.

    #CTI #KEV #VulnerabilityLookup #VulnerabilityReport #GCVE #CVE #OpenSource #CyberSecurity

  2. 🚀 Vulnerability-Lookup 6.0.0 is out!

    🔔 Webhook notifications — push your product reports to any HTTPS endpoint (chat, SIEM, ticketing), with a configurable payload and a strict outbound policy.

    📈 Local exploit hazard — new API endpoints, hazard-ordered reports, and daily standing exposure alerts.

    👥 A searchable vulnerability credits index
    🧭 SSVC v2.0 decisions on the CVE page

    👉 vulnerability-lookup.org/2026/

    #CVE #EPSS #KEV #GCVE #OpenSource #OpenData #Software #Community #AI #CyberSecurity

  3. An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS.

    KEV confirmed.

    #fortinet #kev #fortios #cybersecurity

    vulnerability.circl.lu/vuln/CV

  4. Here are two emails that landed in my inbox this morning.
    Sent by the @circl Vulnerability-Lookup instance, notifying me about new KEV entries in the excellent @shadowserver KEV Catalog and in the #CISA KEV Catalog.

    The catalogs are available here (including the link to the original sources):

    👉 vulnerability.circl.lu/kev-cat

    As well available via API and RSS/Atom!

    📬 And email subscriptions are free!

    #KEV #VulnerabilityManagement #Vulnerability #OpenSource

  5. A new KEV Catalog built from real-world exploitation data !

    vulnerability.circl.lu/known-e

    We are excited to share the result of a fruitful collaboration with @shadowserver: a new Known Exploited Vulnerabilities (KEV) Catalog (BCP-07 compliant) built directly from their global honeypot telemetry.

    #ShadowServer #KEV #GCVE #Vulnerability #VulnerabilityManagement #Decentralization #Fragmentation

  6. Vulnerability-Lookup now provides a coverage matrix on its KEV catalogs page, showing which Known Exploited Vulnerability catalogs (e.g. EUVD KEV, CISA KEV, CIRCL KEV) reference the most recently updated vulnerabilities. Each row corresponds to a vulnerability and each column to a catalog.

    The coverage matrix is available at:

    vulnerability.circl.lu/kev-cat

    #KEV #OpenSource #Vulnerability #VulnerabilityManagement

  7. Апрельский «В тренде VM»: уязвимость в Microsoft SharePoint

    Хабр, привет! На связи Александр Леонов, ведущий эксперт PT Expert Security Center и дежурный по самым опасным уязвимостям месяца. Мы с командой аналитиков Positive Technologies регулярно исследуем информацию об уязвимостях из баз и бюллетеней безопасности вендоров, социальных сетей, блогов, телеграм-каналов, баз эксплойтов, публичных репозиториев кода и выявляем во всем этом многообразии сведений трендовые уязвимости. Это те уязвимости, которые либо уже эксплуатируются вживую, либо будут эксплуатироваться в ближайшее время. С прошлого дайджеста мы добавили еще одну трендовую уязвимость. Подробности о ней читайте под катом. Читать

    habr.com/ru/companies/pt/artic

    #vm #cvss #kev #max_patrol_vm #sharepoint #уязвимости_и_их_эксплуатация #microsoft_office #debugs #cve

  8. Does anyone know if what CISA is putting out post-Jen is worth looking or is just like the rest of the anal flem this administration produces? I mean, for realz inside knowledge?

    thehackernews.com/2026/04/cisa

    #cisa #kev

  9. gcve-eu-kev updated — a CISA KEV and ENISA CNW/EUVD to GCVE BCP-07 converter.

    It now also includes a generic RSS/Atom exporter for any GCVE KEV BCP-07 feed.

    @gcve

    #cybersecurity #gcve #kev #cve #vulnerability #vulnerabilitymanagement

    🔗 github.com/gcve-eu/gcve-eu-kev
    🔗 gcve.eu/bcp/gcve-bcp-07/

  10. Following a great question from CERT.PL about GCVE KEV assertion format and especially about the confidence level for an evidence of a vulnerability assertion.

    We made a first table of confidence level for the evidence in the KEV record format.

    #kev #gcve #format #vulnerability #openstandard

    🔗 Discussions / Proposal discourse.ossbase.org/t/kev-kn

    🔗 GCVE BCP-07 gcve.eu/bcp/gcve-bcp-07/

    @gcve

  11. Exports matter to us. A lot. You’ve been warned 😉
    Vulnerability-Lookup now supports KEV catalog export to NDJSON.

    #OpenData #KEV #CVE #GCVE #Vulnerability #OpenSource #CyberSecurity

  12. We’re proud to be included in the VulnCheck State of Exploitation 2026 report and recognized for CrowdSec’s growth as a leading source in first reporting KEVs throughout 2025.

    Big thanks to @vulncheck and Patrick Garrity for the recognition, and congrats on the launch of VulnCheck Canary Intelligence.

    👉 Read the full article: vulncheck.com/blog/state-of-ex

    #threatintelligence #VulnCheck #vulnerability #KEV #cybersecurity @vulncheckai

  13. In 2025, the top 5 known exploited vulnerability (#KEV) vendors as of cyble.com/blog/cisa-kev-2025-e were:

    Microsoft (39)
    #Apple (9)
    #Cisco (8)
    #Fortinet (8)
    #Google #Chromium (7)

    If you like to minimize your #security risk here, avoiding those vendors could improve your overall exposure.

    As you can see, this is particularly true for #Microsoft.

    Mitigation using #AntiMalware or #EndPointProtection is not the answer as we've learned in the previous year where the "Most Frequently Exploited #Vulnerabilities" have been security products!
    Source: services.google.com/fh/files/m

    If you have high requirements for #ITsecurity, you need to migrate your systems to #Linux which is also part of KEV but on a *much* better level!

    #Windows #macOS #iOS #exploits

  14. KEV Assertion Format – Draft Specification (potential BCP?)

    This format describes a generic KEV (Known Exploited Vulnerability) assertion format.

    The goal is to express who claims exploitation, when, based on what, where it was observed, and with which level of confidence, without turning KEV into full threat intelligence. A KEV assertion is usually very binary and lacking some meta-information. The format adds some information which could better capture details about the exploitation. A majority of the fields are optional except vulnerability, status and evidence.[].source which are recommended.

    Feedback, ideas, comments more than welcome!

    🔗 discourse.ossbase.org/t/kev-kn

    @gcve

    #kev #gcve #cve #vulnerability #vulnerabilitymanagement

  15. Maybe some of you are not aware about the @enisa_eu Known Exploited Vulnerabilities Catalog. In any case, it is now available via Vulnerability-Lookup:

    vulnerability.circl.lu

    and with the API:
    vulnerability.circl.lu/api

    #KEV #Vulnerability #VulnerabilityLookup #OpenSource #ENISA