home.social

#vex — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vex, aggregated by home.social.

  1. Is your security team drowning in "critical" alerts that aren't actually exploitable?

    🌊🧘‍♂️ Most teams treat dependency risk as a periodic task, but our webinar on April 8 shows you how to make it continuous.

    We'll explore how #DependencyTrack uses #EPSS and #VEX to filter out the noise and prioritize the 10% of vulnerabilities that actually pose a threat to your production environment.

    🔗 amazee.io/blog/post/live-uncov

  2. 45 years ago today
    Bad Religion at the VEX, March 5, 1981, Los Angeles, CA, supported by The Chiefs and China White.

    Photos by Gary Leonard.

    #punk #punks #punkrock #badrelegion #vex #history #punkrockhistory #otd

  3. @bagder Great that you are considering #CSAF. We think that CSAF is a gamechanger: CSAF works for open source as well as closed source, hardware, specifications etc. - basically anything you can think of writing a security advisory or #VEX for.
    Supply Chain Security: No one can secure single handed - everyone is needed. A single format: You can profit from the upstream CSAFs, your downstream users profit from your CSAFs.

    (1/2)

  4. What an amazing week! hashtag#devoxx Belgium 2025 did not disappoint!
    So much great content and friendly faces I've finally met IRL!
    And wow, they already posted to Youtube all recordings!

    You can check out my talk about #paketo #buildpacks youtu.be/RX9zwgHuNmA

    As well as my new one about #security #sca #vex youtu.be/EDNmUpE32aM

  5. Mein Borderlands 4 Vex Leveling Zusammengeschreibsel. docs.cbrueggenolte.de/s/qrrcNb

    Wenn ihr Vorschläge habt, nur her damit.

    #Borderlands4 #Gaming #Games #Guide #Vex

  6. @jacques @bagder @gregkh

    ICYMI, here's a paper that was trying to answer this research question in the context of #OpenSource #Java projects on GitHub: "What do open-source maintainers think about integrating #VEX into their existing SBOMs?"

    TL;DR: "In most cases, our augmented SBOMs were not directly accepted because developers required a continuous SBOM update."

    dl.acm.org/doi/pdf/10.1145/369

    #SBOM #CVE #InfoSec

  7. GitHub - jurassicLizard/vex2pdf: Convert CycloneDX JSON docs to PDF reports. Was designed to work for VEX reports but can also generate PDFs for standard BoMs.
    github.com/jurassicLizard/vex2
    #Security #sbom #vex

  8. Want an action-packed docket of dynamic speakers and cross-industry topics? Look no further💪 Register for VulnCon25 today! 🔗 first.org/conference/vulncon20 #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX #Raleigh

  9. Feeling vulnerable? Don't worry, we've got you 🤝 Register for the CVE/FIRST VulnCon 2025 & Annual CNA Summit today!🔗go.first.org/SBf3W #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX #Raleigh

  10. 44 years ago today
    Bad Religion at the VEX, March 5, 1981, Los Angeles, CA, supported by The Chiefs and China White.

    Photos by Gary Leonard.

    #punk #punks #punkrock #badrelegion #vex #history #punkrockhistory #otd

  11. Not able to attend VulnCon25 in person? 😥 Attend from home and register for our virtual option today 😁🔗 go.first.org/jDHDu #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX

  12. Not able to attend VulnCon25 in person? 😥 Attend from home and register for our virtual option today 😁🔗 go.first.org/jDHDu #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX

  13. Want an action-packed docket of dynamic speakers and cross-industry topics? Look no further,💪 Register for VulnCon25 today! 🔗go.first.org/jDHDu #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX #Raleigh

  14. Do you want to be a part of the 40+ action-packed sessions at VulnCon25? If you said yes, now is your chance to submit your paper today! CFP has been extended until Jan 31st. 😎 #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX #Raleigh 🔗 go.first.org/MPudV

  15. Want an action-packed docket of dynamic speakers and cross-industry topics? Look no further,💪 Register for VulnCon25 today! 🔗first.org/conference/vulncon20 #vulnerabilitymanagement #CVE #CVSS #EPSS #CISA #MITRE #VEX #Raleigh

  16. Same text, new layout. v2.1 is getting there with the design. Going to be amazing to see how far we could take this design, it’s also easier to keep updated.

    #WebDevelopment #Homepage #Website #WebsiteUpdate #WebDev #VEX #VideoEditing #Services #OnlineBusiness #Southampton #CSS #HTML

  17. Same text, new layout. v2.1 is getting there with the design. Going to be amazing to see how far we could take this design, it’s also easier to keep updated.

    #WebDevelopment #Homepage #Website #WebsiteUpdate #WebDev #VEX #VideoEditing #Services #OnlineBusiness #Southampton #CSS #HTML

  18. Same text, new layout. v2.1 is getting there with the design. Going to be amazing to see how far we could take this design, it’s also easier to keep updated.

    #WebDevelopment #Homepage #Website #WebsiteUpdate #WebDev #VEX #VideoEditing #Services #OnlineBusiness #Southampton #CSS #HTML

  19. Same text, new layout. v2.1 is getting there with the design. Going to be amazing to see how far we could take this design, it’s also easier to keep updated.

    #WebDevelopment #Homepage #Website #WebsiteUpdate #WebDev #VEX #VideoEditing #Services #OnlineBusiness #Southampton #CSS #HTML

  20. SBOM alone may not encode enough detail to separate non-exploitable vulnerabilities from exploitable ones writes Surendra Pathak in our latest guest blog on #VDR, #VEX, #OpenVEX and #CSAF openssf.org/blog/2023/09/07/vd

  21. At the heart of the CVE process and the matching done with the NVD database is the name of the manufacturer and the artefact - the software, system, library or mobile application. It's vital for this to work that the name in the #SBOM is correct to make the match work. The community has developed #PURL - package URL - to improve but so far the CVE/NVD eco system has not adopted PURL.

    This needs to be fixed to make sure that the name in the SBOM matches the right set of vulnerabilities.

    #SBOM #securesupplychain #CycloneDX #OpenVEX #VEX #OpenSource

  22. Die US-Behörde CISA hat am 10. November 2022 einen 3 Punkteplan für effizientes Schwachstellenmanagement veröffentlicht: cisa.gov/blog/2022/11/10/trans

    Zentrale Punkte sind der #CSAF-Standard und das #VEX-Profil: Maschinenlesbare #Advisory reduzieren den manuellen Aufwand und mitigieren effektiver Schwachstellen.

    Die #CISA zeigt hiermit offiziell ihre Unterstützung dieses Standards. Das #BSI erwartet eine Signalwirkung für alle PSIRTs – speziell auch #IndustrialSecurity.

    #DeutschlandDigitalSicherBSI