#vulnerabilitymanagement — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vulnerabilitymanagement, aggregated by home.social.
-
CISA orders federal agencies to patch critical TrueConf flaw being actively exploited by threat actors.
https://www.theregister.com/patches/2026/08/21/homeland-security-cybercops-say-patch-trueconf-russias-zoom-if-youre-using-it/5291156
#cybersecurity #vulnerabilitymanagement #TrueConf -
Calling all cybersecurity professionals, academics, and CSIRTs to join us in Luxembourg for #VulnOptiCON 2026, FIRST's evolution of Vuln4Cast!
📆 September 23-25, 2026
Hosted in partnership with the Computer Incident Response Centre Luxembourg (CIRCL), this year's event theme is "The A-Eyes See All." Keynote speakers Jaya Baloo, COO & CISO at AISLE and a world-renowned top 100 CISO, and Regina Joseph, a leading behavioral scientist and applied forecasting expert, will share actionable strategies for defenders and forecasting teams facing unprecedented levels of change driven by AI.
The three-day program covers:
✅ Global & Open Ecosystems: rethinking vulnerability tracking for an open security landscape
✅ Forecasting & Metrics: measuring and forecasting exploitation conditions
✅ Policy & Program Futures: what's next for the CVE Program
✅ Data & Observable Evidence: what happens when the industry sets its own standards
✅ Next-Gen Threat Detection: detecting threats that cannot yet be named🎟️ Limited tickets available
🔗 Learn more about the speaker lineup: https://go.first.org/kxOHk -
AI has turned vulnerability discovery into a machine-speed arms race, says IT manager Michael Dear. Our human-speed patching model simply can’t keep up.
Read his latest piece here: https://www.techfinitive.com/opinions/when-it-comes-to-keeping-up-with-ai-powered-updates-we-need-to-move-from-human-speed-to-machine-speed/
-
If you are curious about (nearly) everything we did the past months at the GCVE.eu initiative:
https://gcve.eu/2026/08/13/gcve-recent-activities-standards-software-and-a-growing-gna-community/
We published a recap blog post.
#gcve #cve #vulnerability #vulnerabilitymanagement #cra #cybersecurity #openstandard #opensource
-
vulnerability-lookup 6.0 will be released this week with many (really, many!) new features.
One of the smaller, but important, additions is support for multiple SSVC views alongside CVSS. When SSVC information is available from an ADP (such as CISA) , or from additional sources such as GCVE, it is now displayed by default.
This allows users to more easily compare the different severity and prioritization assessments associated with a vulnerability.
The CIRCL vulnerability-lookup instance is running the pre-release of 6.0 -
https://vulnerability.circl.lu/vuln/cve-2026-59124#cve #gcve #opensource #vulnerabilitylookup #opendata #vulnerabilitymanagement #cyberecurity #ssvc
-
From a research paper to running open-source code in just a few days.
We (with @cedric) have been experimenting in Vulnerability-Lookup with the concept of Local Exploit Hazard, based on the recent research paper “Modeling Local Exploit Hazard — A Bayesian Framework for Quantifying Exploit Risk and Operational Efficiency” by Stephen Shaffer and Laura Cristiana Voicu.
The idea addresses an important question in vulnerability management:
Not simply “How dangerous is this vulnerability globally?” but “How much exploitation risk does this vulnerability represent in my environment?”
Instead of introducing yet another static vulnerability score, the model starts from exploit likelihood such as EPSS and combines it with local security controls, CVSS attack vectors, vulnerability age and KEV policy to estimate an exploitation hazard.
We implemented an experimental version in Vulnerability-Lookup and connected it directly to operational workflows.
For the full details: https://www.vulnerability-lookup.org/2026/08/11/local-exploit-hazard/
#cve #gcve #vulnerabilitymanagement #vulnerability #opensource #opendata
-
Patches Now Arrive Late. By a Week https://youtu.be/TagTgrk-dZY #CyberSecurity #ThreatIntelligence #CISO #VulnerabilityManagement #Ransomware #SecurityLeadership #Mandiant #MTrends
-
Sharing because the name resemble that one legendary song (nagareteku.... ehm).
In summary, there is a race condition vuln inside Linux's epoll system, that can be used to root any Android device, the only advice the author give is just to apply the patch in your system.
Details can be found here:
https://github.com/J-jaeyoung/bad-epoll#cybersecurity #infosec #vulnerabilitymanagement #android #linux #badepoll
-
New by me: CybersecKyle Security How-To Series: Blue Team Fundamentals, Part 3 - Vulnerability Scanning with Real Triage
#Cybersecurity #InfoSec #VulnerabilityManagement #BlueTeam #CybersecKyleHowTo
-
Big Tech Bolsters Open-Source AI as Attackers Target Vulnerabilities
Big tech giants like Nvidia, Amazon, and Google are joining forces to supercharge open-source AI, embracing a new era of transparency and collaboration. By adopting open-weight models, they're acknowledging that the future of AI safety lies in community-driven innovation and collective vigilance.
#OpensourceAi #BigTech #ArtificialIntelligence #EmergingThreats #VulnerabilityManagement