Wednesday, 2025-04-16

JayFhttps://infosec.exchange/@briankrebs/114343835430587973 this is likely going to be a non-trivial impact to us. Tldr mitre and cves are going away13:03
JayFIt looks like there might be some efforts to privatize this work into a foundation. It's very difficult to see exactly how it's going to shake out though.13:07
rosmaitaand they're not going to have it all moved over today! this is crazy13:12
JayFAt first I was wondering if there's anything maybe the foundation could do in this direction, but then I realized that while we're big, there really are going to be some 500 lb gorillas that are going to be attacking this problem13:16
JayFI'm sure our new overlords at the Lenox foundation are on it 😂13:16
JayF**Linux13:16
fungihttps://www.thecvefoundation.org/13:19
fungienough large corporations with deep pockets depend on mitre's work that private funding seems likely13:20
rosmaitayeah, so was the CVE Foundation launched today?13:21
rosmaitathey do seem to be responding quickly13:21
rosmaitagotta say, i agree with Brian Krebs's comment on that post Jay linked: "Probably the last CVE indexed before it goes dark should be CVE-2025-DOGE (critical, local privilege escalation vulnerability that leads to malicious code execution and data exfiltration)."13:25
fungiyes, that foundation was created and announced today, seems like13:28
JayFhttps://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-program-funding-cut-what-it-means-and-what-to-do-next/ Forbes has updated this post to indicate that the contract has been re-upped. I'd be surprised if it stays a public service instead of being privatized for long though.14:21
JayFIf this was a scream test, good on the internet for screaming I guess14:21
fungiwell, it was already privately operated, it merely received funding from the usg14:22
fungibut i can certainly see there being a rising interest in making mitre less dependent on government grants regardless14:23
opendevreviewMerged openstack/security-doc master: Updated from openstack-manuals  https://review.opendev.org/c/openstack/security-doc/+/94716615:12

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!