#nvd — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #nvd, aggregated by home.social.
-
NIST is asking how to modernize the NVD in the age of AI, months after saying most new CVEs are now lowest priority for enrichment. Comments close October 13 (docket NIST-2026-0100). Our analysis covers what NIST is asking, the AI enrichment failure modes worth putting on the record, and what a useful comment looks like: https://blog.disclose.io/nvd-modernization-rfi-2026/
-
NVD Modernization: NIST Seeks Public Input on an AI-Ready National Vulnerability Database - https://www.redpacketsecurity.com/nist-seeks-public-input-on-ai-ready-nvd-modernization/
-
🚨 Ah yes, the perilous saga of imaginary #SQLite #vulnerabilities - where #JFrog #Security bravely fights against the fearsome specter of non-existent code. 🙄 #NVD and #CISA, always on the pulse of non-issues, declared a crisis, but JFrog heroically deduced the obvious: the boogeyman doesn’t exist. 👏
https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/ #Cybersecurity #Humor #HackerNews #ngated -
The US National Vulnerabilities Database https://nvd.nist.gov/ the centralized repository of digital security holes, recorded 45,207 flaws between January and Monday, so we are looking at more than double the number of flaws reported in all of 2025.
The good news - a very large percentage of the reported flaws are coming from internal security teams presumably using AI powered cyber-security tools.
Example: of the 433 vulnerabilities reported in Chrome in July, 401 were “reported by Google” internally, according to the company.
There has been no rise in the number of exploits this year despite the uptick in discovered flaws. https://www.bloomberg.com/news/articles/2026-07-27/ai-hunts-for-cyber-flaws-finding-record-numbers-in-tech-sector?accessToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzb3VyY2UiOiJTdWJzY3JpYmVyR2lmdGVkQXJ0aWNsZSIsImlhdCI6MTc4NTE3ODM1OSwiZXhwIjoxNzg1NzgzMTU5LCJhcnRpY2xlSWQiOiJUSVVETlBUOU5KTFQwMCIsImJjb25uZWN0SWQiOiI0OEFDOEE5MkEwNTM0MkQ4OEIyRjkwQjhDMTgzMTdDMyJ9.z3BDvCQbIyLyRcRQgIsKejrHduNgHbyS9TXTJZhVFi0&leadSource=article-gifting #AI #AISecurity #NVD #Security #Software #CyberSecurity #SecurityFlaws #Vulnerabilities #SoftwareExploits #Hackers #VulnerabilityDataBase #NIST
-
I'm not mentoring any youth this week, so I'm working on throwing together #EUVD (EU Vulnerability Database) support for #NuGetDefense (as an alternative to #NVD which is already supported) as well as Snyk and Vulners if I have time in the evenings.
It's not as useful as it once was since even the dotnet CLI includes basic known vulnerability info now, but it's still an alternative and perhaps a place to experiment with `npm audit fix` style functionality eventually.
-
This Week in Security: Messing with AI, 7Zip and Notepad++ Vulnerabilities, HTTP2 Bomb, and More
-
Das US-amerikanische #NIST gibt einen zentralen Teil seiner Arbeit auf: Die unabhängige Bewertung von IT-#Sicherheitslücken nach dem #CVSS-Standard soll künftig weitgehend entfallen und den Herstellern überlassen werden - die dies erfahrungsgemäß herunterspielen.
Hintergrund ist ein massiver Bearbeitungsrückstau in der #Schwachstellendatenbank #NVD, weil das Budget seit Jahren nicht mehr mit der wachsenden Zahl gemeldeter Schwachstellen Schritt hält:
https://www.oig.doc.gov/wp-content/OIGPublications/OIG-26-020-I-SECURED.pdf #cybersecurity
-
Resulting from funding gaps and idiotic shifts in priorities the U.S.A. is now woefully under investing in our core CyberDefense Ecosystem....
National Institute of Standards and Technology (NIST) is no longer enhancing all Common Vulnerabilities and Exposures (CVEs) with analysis and severity indicators, and instead NIST will prioritize enriching a much narrower set of security vulnerabilities.
Related: In April 2025, a funding gap by in DHS appropriations threatened to cease CVE operations entirely —which would have creating systemic risk for global vulnerability management. An emergency funding extension was implemented to avoid a full on crisis. https://www.justsecurity.org/136914/nist-cant-keep-up/ #NIST #MITRE #CVEs #NVD #Security #Risk #CyberSecurity #CyberDefence #CyberInfrastructure #AI #AISecurity #CISA #DHS #Vulnerability #ThreatIntelligence
-
New NFD40 blog about Nokia’s presentation: Nokia Networking for AI. Tags: #PeterWelcher #CCIE1773 #NFD40 #NetworkingFieldDay #TechFieldDay #NetworkingForAI #AINetworking #Nokia #NVD URL: https://www.linkedin.com/pulse/nfd40-nokia-networking-ai-peter-welcher-uvtqe/
-
Was searching for an explanation, why #NVD #CVE ratings are usually higher than others', landed on https://daniel.haxx.se/blog/2023/03/06/nvd-makes-up-vulnerability-severity-levels/ and saw a familiar face: Thanks for posting this, @bagder.
-
A few weeks ago I had a conversation with Josh Bressers about the The Global Vulnerability Intelligence Platform and what we're doing there. It's now available on YouTube and your favourite podcast channels!
https://opensourcesecurity.io/2026/2026-02-GVIP-olle-johansson/
-
Join our community and contribute to the work! Register today at https://www.gvip-project.org/community/
-
Everyone that manages security reports for Open Source projects have been getting a higher workload because of AI. Both real reports and just slop - reports including vulnerabilities in code that doesn't exist. For some, this is becoming a denial of service attack, with developers having to spend valuable, and in some cases unpaid, time to sort out what's real and may be a vulnerability.
Jarek Potiuk, member of The Apache Software Foundation will talk about this on the GVIP Summit Wednesday Jan 28th in Brussels. We still have a few seats available - but hurry up to register!