home.social

#nvd — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #nvd, aggregated by home.social.

fetched live
  1. NIST is asking how to modernize the NVD in the age of AI, months after saying most new CVEs are now lowest priority for enrichment. Comments close October 13 (docket NIST-2026-0100). Our analysis covers what NIST is asking, the AI enrichment failure modes worth putting on the record, and what a useful comment looks like: blog.disclose.io/nvd-moderniza

    #NVD #CVE #infosec #cybersecurity

  2. You have discovered a new vulnerability? Submit it here and we will assign a CVE in no time. vuldb.com/vuln/add #vuldb #cna #cve #mitre #nvd

  3. 🚨 Ah yes, the perilous saga of imaginary #SQLite #vulnerabilities - where #JFrog #Security bravely fights against the fearsome specter of non-existent code. 🙄 #NVD and #CISA, always on the pulse of non-issues, declared a crisis, but JFrog heroically deduced the obvious: the boogeyman doesn’t exist. 👏
    research.jfrog.com/post/sqlite #Cybersecurity #Humor #HackerNews #ngated

  4. The US National Vulnerabilities Database nvd.nist.gov/ the centralized repository of digital security holes, recorded 45,207 flaws between January and Monday, so we are looking at more than double the number of flaws reported in all of 2025.

    The good news - a very large percentage of the reported flaws are coming from internal security teams presumably using AI powered cyber-security tools.

    Example: of the 433 vulnerabilities reported in Chrome in July, 401 were “reported by Google” internally, according to the company.

    There has been no rise in the number of exploits this year despite the uptick in discovered flaws. bloomberg.com/news/articles/20 #AI #AISecurity #NVD #Security #Software #CyberSecurity #SecurityFlaws #Vulnerabilities #SoftwareExploits #Hackers #VulnerabilityDataBase #NIST

  5. Submit your new vulnerability discovery here and we will assign a CVE in no time. vuldb.com/vuln/add #vuldb #cna #cve #mitre #nvd

  6. I'm not mentoring any youth this week, so I'm working on throwing together #EUVD (EU Vulnerability Database) support for #NuGetDefense (as an alternative to #NVD which is already supported) as well as Snyk and Vulners if I have time in the evenings.

    It's not as useful as it once was since even the dotnet CLI includes basic known vulnerability info now, but it's still an alternative and perhaps a place to experiment with `npm audit fix` style functionality eventually.

  7. You want to publish a new vulnerability? Just submit and we will handle your CVE assignment in no time. vuldb.com/vuln/add #vuldb #cna #cve #mitre #nvd

  8. Das US-amerikanische #NIST gibt einen zentralen Teil seiner Arbeit auf: Die unabhängige Bewertung von IT-#Sicherheitslücken nach dem #CVSS-Standard soll künftig weitgehend entfallen und den Herstellern überlassen werden - die dies erfahrungsgemäß herunterspielen.

    Hintergrund ist ein massiver Bearbeitungsrückstau in der #Schwachstellendatenbank #NVD, weil das Budget seit Jahren nicht mehr mit der wachsenden Zahl gemeldeter Schwachstellen Schritt hält:

    oig.doc.gov/wp-content/OIGPubl #cybersecurity

  9. Resulting from funding gaps and idiotic shifts in priorities the U.S.A. is now woefully under investing in our core CyberDefense Ecosystem....

    National Institute of Standards and Technology (NIST) is no longer enhancing all Common Vulnerabilities and Exposures (CVEs) with analysis and severity indicators, and instead NIST will prioritize enriching a much narrower set of security vulnerabilities.

    Related: In April 2025, a funding gap by in DHS appropriations threatened to cease CVE operations entirely —which would have creating systemic risk for global vulnerability management. An emergency funding extension was implemented to avoid a full on crisis. justsecurity.org/136914/nist-c #NIST #MITRE #CVEs #NVD #Security #Risk #CyberSecurity #CyberDefence #CyberInfrastructure #AI #AISecurity #CISA #DHS #Vulnerability #ThreatIntelligence

  10. You have discovered a new vulnerability? Submit it here and we will assign a CVE in no time. vuldb.com/vuln/add #vuldb #cna #cve #mitre #nvd

  11. Was searching for an explanation, why #NVD #CVE ratings are usually higher than others', landed on daniel.haxx.se/blog/2023/03/06 and saw a familiar face: Thanks for posting this, @bagder.

    #cybersecurity #CVSS

  12. You want to publish a new vulnerability? Just submit and we will handle your CVE assignment in no time. vuldb.com/?id.add #vuldb #cna #cve #mitre #nvd

  13. A few weeks ago I had a conversation with Josh Bressers about the The Global Vulnerability Intelligence Platform and what we're doing there. It's now available on YouTube and your favourite podcast channels!

    opensourcesecurity.io/2026/202

    #GVIP #CVE #NVD #CYBERSECURITY #cra

  14. You want to publish a new vulnerability? Just submit and we will handle your CVE assignment in no time. vuldb.com/?id.add #vuldb #cna #cve #mitre #nvd

  15. Want to help working on a future global vulnerability intelligence platform with us? Join our community meetings!

    gvip-project.org/blog/2026/com

    #CVE #NVD #GCVE #CRA

  16. Everyone that manages security reports for Open Source projects have been getting a higher workload because of AI. Both real reports and just slop - reports including vulnerabilities in code that doesn't exist. For some, this is becoming a denial of service attack, with developers having to spend valuable, and in some cases unpaid, time to sort out what's real and may be a vulnerability.

    Jarek Potiuk, member of The Apache Software Foundation will talk about this on the GVIP Summit Wednesday Jan 28th in Brussels. We still have a few seats available - but hurry up to register!

    gvip-project.org

    #NVD #CVE #EUVD #EUCRA #CRA

  17. Join us for the GVIP Summit - the pre-FOSDEM conference on vulnerability management. Supported by the @sovtechfund

    gvip-project.org

    #NVD #CVE #SBOM #CVSS #CWE #CRA

  18. You have discovered a new vulnerability? Submit it here and we will assign a CVE in no time. vuldb.com/?id.add #vuldb #cna #cve #mitre #nvd