home.social

#nvd — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #nvd, aggregated by home.social.

  1. Resulting from funding gaps and idiotic shifts in priorities the U.S.A. is now woefully under investing in our core CyberDefense Ecosystem....

    National Institute of Standards and Technology (NIST) is no longer enhancing all Common Vulnerabilities and Exposures (CVEs) with analysis and severity indicators, and instead NIST will prioritize enriching a much narrower set of security vulnerabilities.

    Related: In April 2025, a funding gap by in DHS appropriations threatened to cease CVE operations entirely —which would have creating systemic risk for global vulnerability management. An emergency funding extension was implemented to avoid a full on crisis. justsecurity.org/136914/nist-c #NIST #MITRE #CVEs #NVD #Security #Risk #CyberSecurity #CyberDefence #CyberInfrastructure #AI #AISecurity #CISA #DHS #Vulnerability #ThreatIntelligence

  2. Resulting from funding gaps and idiotic shifts in priorities the U.S.A. is now woefully under investing in our core CyberDefense Ecosystem....

    National Institute of Standards and Technology (NIST) is no longer enhancing all Common Vulnerabilities and Exposures (CVEs) with analysis and severity indicators, and instead NIST will prioritize enriching a much narrower set of security vulnerabilities.

    Related: In April 2025, a funding gap by in DHS appropriations threatened to cease CVE operations entirely —which would have creating systemic risk for global vulnerability management. An emergency funding extension was implemented to avoid a full on crisis. justsecurity.org/136914/nist-c #NIST #MITRE #CVEs #NVD #Security #Risk #CyberSecurity #CyberDefence #CyberInfrastructure #AI #AISecurity #CISA #DHS #Vulnerability #ThreatIntelligence

  3. Resulting from funding gaps and idiotic shifts in priorities the U.S.A. is now woefully under investing in our core CyberDefense Ecosystem....

    National Institute of Standards and Technology (NIST) is no longer enhancing all Common Vulnerabilities and Exposures (CVEs) with analysis and severity indicators, and instead NIST will prioritize enriching a much narrower set of security vulnerabilities.

    Related: In April 2025, a funding gap by in DHS appropriations threatened to cease CVE operations entirely —which would have creating systemic risk for global vulnerability management. An emergency funding extension was implemented to avoid a full on crisis. justsecurity.org/136914/nist-c #NIST #MITRE #CVEs #NVD #Security #Risk #CyberSecurity #CyberDefence #CyberInfrastructure #AI #AISecurity #CISA #DHS #Vulnerability #ThreatIntelligence

  4. Resulting from funding gaps and idiotic shifts in priorities the U.S.A. is now woefully under investing in our core CyberDefense Ecosystem....

    National Institute of Standards and Technology (NIST) is no longer enhancing all Common Vulnerabilities and Exposures (CVEs) with analysis and severity indicators, and instead NIST will prioritize enriching a much narrower set of security vulnerabilities.

    Related: In April 2025, a funding gap by in DHS appropriations threatened to cease CVE operations entirely —which would have creating systemic risk for global vulnerability management. An emergency funding extension was implemented to avoid a full on crisis. justsecurity.org/136914/nist-c #NIST #MITRE #CVEs #NVD #Security #Risk #CyberSecurity #CyberDefence #CyberInfrastructure #AI #AISecurity #CISA #DHS #Vulnerability #ThreatIntelligence

  5. Resulting from funding gaps and idiotic shifts in priorities the U.S.A. is now woefully under investing in our core CyberDefense Ecosystem....

    National Institute of Standards and Technology (NIST) is no longer enhancing all Common Vulnerabilities and Exposures (CVEs) with analysis and severity indicators, and instead NIST will prioritize enriching a much narrower set of security vulnerabilities.

    Related: In April 2025, a funding gap by in DHS appropriations threatened to cease CVE operations entirely —which would have creating systemic risk for global vulnerability management. An emergency funding extension was implemented to avoid a full on crisis. justsecurity.org/136914/nist-c

  6. NIST’s selective NVD enrichment is a big wake-up call for AppSec teams: more CVEs, less context, and more manual triage ahead. jpmellojr.blogspot.com/2026/05 #NVD #CVE #NIST #AppSec

  7. You have discovered a new vulnerability? Submit it here and we will assign a CVE in no time. vuldb.com/vuln/add #vuldb #cna #cve #mitre #nvd

  8. You have discovered a new vulnerability? Submit it here and we will assign a CVE in no time. vuldb.com/vuln/add #vuldb #cna #cve #mitre #nvd

  9. You have discovered a new vulnerability? Submit it here and we will assign a CVE in no time. vuldb.com/vuln/add #vuldb #cna #cve #mitre #nvd

  10. You have discovered a new vulnerability? Submit it here and we will assign a CVE in no time. vuldb.com/vuln/add #vuldb #cna #cve #mitre #nvd

  11. You have discovered a new vulnerability? Submit it here and we will assign a CVE in no time. vuldb.com/vuln/add #vuldb #cna #cve #mitre #nvd

  12. NIST has confirmed a major policy shift, drastically reducing its CVE enrichment efforts and focusing only on critical vulnerabilities like those in CISA's KEV catalog. This move, driven by an overwhelming backlog and budget cuts, means security teams can no longer depend on the NVD as a single source of truth, forcing a re-evaluation of vulnerability management strategies and skepticism towards…

    tpp.blog/1f95u2a

    #cybersecurity #nist #nvd

    🤖 This post was AI-generated.

  13. NIST Curtails CVE Enrichment Amid Vulnerability Surge

    The National Institute of Standards and Technology (NIST) is overhauling its approach to enriching entries in the National Vulnerability Database (NVD) due to a staggering 263% surge in vulnerability submissions. To keep pace, NIST will now prioritize enrichment for only the most critical entries that meet specific conditions.

    osintsights.com/nist-curtails-

    #VulnerabilityManagement #Nist #NationalVulnerabilityDatabase #Nvd #Cve

  14. NIST will now prioritize NVD enrichment for CVEs in CISA KEV & critical software. Other CVEs may see slower data updates. No direct exploit info, but vulnerability workflows could be impacted. Stay updated! radar.offseq.com/threat/nist-p #OffSeq #NVD #CISA #Infosec

  15. NIST will now prioritize NVD enrichment for CVEs in CISA KEV & critical software. Other CVEs may see slower data updates. No direct exploit info, but vulnerability workflows could be impacted. Stay updated! radar.offseq.com/threat/nist-p #OffSeq #NVD #CISA #Infosec

  16. NIST will now prioritize NVD enrichment for CVEs in CISA KEV & critical software. Other CVEs may see slower data updates. No direct exploit info, but vulnerability workflows could be impacted. Stay updated! radar.offseq.com/threat/nist-p #OffSeq #NVD #CISA #Infosec

  17. NIST will now prioritize NVD enrichment for CVEs in CISA KEV & critical software. Other CVEs may see slower data updates. No direct exploit info, but vulnerability workflows could be impacted. Stay updated! radar.offseq.com/threat/nist-p #OffSeq #NVD #CISA #Infosec

  18. 📰 NIST Overhauls NVD, Will No Longer Enrich All CVEs Amidst 'Unsustainable' Surge in Reports

    Major shift for vulnerability management: NIST will no longer enrich all CVEs in the NVD due to overwhelming volume. 📢 Focus will be on critical & exploited flaws. Time to re-evaluate your VT processes! #NIST #NVD #CVE #CyberSecurity

    🔗 cyber.netsecops.io/articles/ni

  19. NIST Shifts Focus to Enriching Exploited Vulnerabilities

    The National Vulnerability Database is shifting gears: going forward, it'll prioritize enriching newly reported and actively exploited vulnerabilities, temporarily deprioritizing older entries. This change comes as the database faces an unprecedented surge in reported software flaws, with a record number of Common Vulnerabilities and…

    osintsights.com/nist-shifts-fo

    #Nist #NationalVulnerabilityDatabase #Nvd #Cve #ExploitedVulnerabilities

  20. NIST Shifts Focus to Enriching Exploited Vulnerabilities

    The National Vulnerability Database is shifting gears: going forward, it'll prioritize enriching newly reported and actively exploited vulnerabilities, temporarily deprioritizing older entries. This change comes as the database faces an unprecedented surge in reported software flaws, with a record number of Common Vulnerabilities and…

    osintsights.com/nist-shifts-fo

    #Nist #NationalVulnerabilityDatabase #Nvd #Cve #ExploitedVulnerabilities

  21. NIST Refocuses CVE Analysis Amid Vulnerability Surge

    The National Institute of Standards and Technology (NIST) has adjusted its approach to vulnerability analysis, now prioritizing critical software, government systems, and actively exploited vulnerabilities amid a surge in reported threats. This strategic refocus aims to optimize its National Vulnerability Database's impact in a threat landscape…

    osintsights.com/nist-refocuses

    #VulnerabilityAnalysis #Nist #NationalVulnerabilityDatabase #Nvd #Cve

  22. Was searching for an explanation, why #NVD #CVE ratings are usually higher than others', landed on daniel.haxx.se/blog/2023/03/06 and saw a familiar face: Thanks for posting this, @bagder.

    #cybersecurity #CVSS

  23. Was searching for an explanation, why #NVD #CVE ratings are usually higher than others', landed on daniel.haxx.se/blog/2023/03/06 and saw a familiar face: Thanks for posting this, @bagder.

    #cybersecurity #CVSS

  24. Was searching for an explanation, why #NVD #CVE ratings are usually higher than others', landed on daniel.haxx.se/blog/2023/03/06 and saw a familiar face: Thanks for posting this, @bagder.

    #cybersecurity #CVSS

  25. Was searching for an explanation, why #NVD #CVE ratings are usually higher than others', landed on daniel.haxx.se/blog/2023/03/06 and saw a familiar face: Thanks for posting this, @bagder.

    #cybersecurity #CVSS

  26. ----------------

    🔹 🛠️ Tool: ThreatSentry AI

    ThreatSentry AI is presented as an enterprise-focused threat-hunting platform that automates external asset discovery, enriches findings from multiple sources, and applies ensemble machine learning to prioritize risk. The project lists PyQt5 for UI, scikit-learn for ML, and SQLAlchemy for persistence, and names EclipseManic as project lead.

    🔹 Core pipeline and integrations

    The platform performs continuous external visibility via Shodan queries (preset and custom), extracts service banners across common products (examples in the project include Apache, Nginx, MySQL, IIS), and correlates banner data with NVD CVE information. CVSS-based severity classification is applied where CVE matches are found; the README notes that CVE metrics are updated only when vulnerabilities are identified to avoid data loss.

    🔹 Machine learning and scoring

    The risk engine is described as an ensemble combining Random Forest, Gradient Boosting, and Neural Network components. Models evaluate 40+ attributes spanning temporal context (exposure duration, patch lag), network position (service criticality, segmentation), behavioral signals (authentication failures, traffic anomalies), and compliance impact (data sensitivity, regulatory exposure). Each risk prediction includes a confidence score in the 0–1 range. The system is described as having configurable automatic retraining with analyst feedback integration for continuous learning.

    🔹 Platform capabilities and outputs

    ThreatSentry AI emphasizes proactive alerting and executive-ready dashboards that surface high-risk assets ahead of incidents. Preset Shodan queries are provided for common service classes (SSL, RDP, ICS/Modbus), with support for organization-specific custom queries. The architecture is described as extensible for integrating internal systems (SIEM, CMDB, patch sources) although specifics are implementation-dependent.

    🔹 Project context

    The README highlights single-developer authorship with assistance from AI development tools for code generation and documentation. The repo frames the project as addressing alert fatigue, fragmented data, and reactive security postures by converting multi-source telemetry into prioritized, confidence-scored intelligence.

    🔹 Hashtags

    🔹 ThreatSentryAI #Shodan #NVD #CVE #CVSS

    🔗 Source: github.com/EclipseManic/Threat

  27. ----------------

    🔹 🛠️ Tool: ThreatSentry AI

    ThreatSentry AI is presented as an enterprise-focused threat-hunting platform that automates external asset discovery, enriches findings from multiple sources, and applies ensemble machine learning to prioritize risk. The project lists PyQt5 for UI, scikit-learn for ML, and SQLAlchemy for persistence, and names EclipseManic as project lead.

    🔹 Core pipeline and integrations

    The platform performs continuous external visibility via Shodan queries (preset and custom), extracts service banners across common products (examples in the project include Apache, Nginx, MySQL, IIS), and correlates banner data with NVD CVE information. CVSS-based severity classification is applied where CVE matches are found; the README notes that CVE metrics are updated only when vulnerabilities are identified to avoid data loss.

    🔹 Machine learning and scoring

    The risk engine is described as an ensemble combining Random Forest, Gradient Boosting, and Neural Network components. Models evaluate 40+ attributes spanning temporal context (exposure duration, patch lag), network position (service criticality, segmentation), behavioral signals (authentication failures, traffic anomalies), and compliance impact (data sensitivity, regulatory exposure). Each risk prediction includes a confidence score in the 0–1 range. The system is described as having configurable automatic retraining with analyst feedback integration for continuous learning.

    🔹 Platform capabilities and outputs

    ThreatSentry AI emphasizes proactive alerting and executive-ready dashboards that surface high-risk assets ahead of incidents. Preset Shodan queries are provided for common service classes (SSL, RDP, ICS/Modbus), with support for organization-specific custom queries. The architecture is described as extensible for integrating internal systems (SIEM, CMDB, patch sources) although specifics are implementation-dependent.

    🔹 Project context

    The README highlights single-developer authorship with assistance from AI development tools for code generation and documentation. The repo frames the project as addressing alert fatigue, fragmented data, and reactive security postures by converting multi-source telemetry into prioritized, confidence-scored intelligence.

    🔹 Hashtags

    🔹 ThreatSentryAI #Shodan #NVD #CVE #CVSS

    🔗 Source: github.com/EclipseManic/Threat

  28. You want to publish a new vulnerability? Just submit and we will handle your CVE assignment in no time. vuldb.com/?id.add #vuldb #cna #cve #mitre #nvd

  29. You want to publish a new vulnerability? Just submit and we will handle your CVE assignment in no time. vuldb.com/?id.add #vuldb #cna #cve #mitre #nvd

  30. You want to publish a new vulnerability? Just submit and we will handle your CVE assignment in no time. vuldb.com/?id.add #vuldb #cna #cve #mitre #nvd

  31. You want to publish a new vulnerability? Just submit and we will handle your CVE assignment in no time. vuldb.com/?id.add #vuldb #cna #cve #mitre #nvd

  32. You want to publish a new vulnerability? Just submit and we will handle your CVE assignment in no time. vuldb.com/?id.add #vuldb #cna #cve #mitre #nvd

  33. We have scheduled the community meetings for March 2026. This is where you meet fellows working with the same issues, discuss and help us set our priorities for the project.

    Register for free here: gvip-project.org/community/

    #CVE #gcve #NVD #EUVD #CWE #CVSS #EPSS

  34. A few weeks ago I had a conversation with Josh Bressers about the The Global Vulnerability Intelligence Platform and what we're doing there. It's now available on YouTube and your favourite podcast channels!

    opensourcesecurity.io/2026/202

    #GVIP #CVE #NVD #CYBERSECURITY #cra

  35. A few weeks ago I had a conversation with Josh Bressers about the The Global Vulnerability Intelligence Platform and what we're doing there. It's now available on YouTube and your favourite podcast channels!

    opensourcesecurity.io/2026/202

    #GVIP #CVE #NVD #CYBERSECURITY #cra

  36. A few weeks ago I had a conversation with Josh Bressers about the The Global Vulnerability Intelligence Platform and what we're doing there. It's now available on YouTube and your favourite podcast channels!

    opensourcesecurity.io/2026/202

    #GVIP #CVE #NVD #CYBERSECURITY #cra

  37. A few weeks ago I had a conversation with Josh Bressers about the The Global Vulnerability Intelligence Platform and what we're doing there. It's now available on YouTube and your favourite podcast channels!

    opensourcesecurity.io/2026/202

    #GVIP #CVE #NVD #CYBERSECURITY #cra

  38. A few weeks ago I had a conversation with Josh Bressers about the The Global Vulnerability Intelligence Platform and what we're doing there. It's now available on YouTube and your favourite podcast channels!

    opensourcesecurity.io/2026/202

    #GVIP #CVE #NVD #CYBERSECURITY #cra