From a research paper to running open-source code in just a few days.
We (with @cedric@fosstodon.org) have been experimenting in Vulnerability-Lookup with the concept of Local Exploit Hazard, based on the recent research paper “Modeling Local Exploit Hazard — A Bayesian Framework for Quantifying Exploit Risk and Operational Efficiency” by Stephen Shaffer and Laura Cristiana Voicu.
The idea addresses an important question in vulnerability management:
Not simply “How dangerous is this vulnerability globally?” but “How much exploitation risk does this vulnerability represent in my environment?”
Instead of introducing yet another static vulnerability score, the model starts from exploit likelihood such as EPSS and combines it with local security controls, CVSS attack vectors, vulnerability age and KEV policy to estimate an exploitation hazard.
We implemented an experimental version in Vulnerability-Lookup and connected it directly to operational workflows.
For the full details: https://www.vulnerability-lookup.org/2026/08/11/local-exploit-hazard/
#cve #gcve #vulnerabilitymanagement #vulnerability #opensource #opendata
@circl@social.circl.lu
About This Hashtag
#gcve
10 posts
Last used Aug 11
#gcve
10 posts· Last used Aug 11
Pretty cool idea from @nyanbinary@infosec.exchange - a bot to analyse fucked up references from the CVE records.
@fuckeduprefs_bot@infosec.exchange
Maybe we could imagine an archive bot at the same time to ensure that the references don't get lost. Just like archive.org or similar. Maybe something for @gcve@social.circl.lu to look into.
#cve #vulnerability #gcve
A new version of the BCP-11 "Community Contribution Fragments for Existing CVE Records" proposal has been published.
https://discourse.ossbase.org/t/gcve-bcp-11-community-proposed-updates-to-existing-cve-records/1110/8#p-1495-gcve-bcp-11-community-contribution-fragments-for-existing-cve-records-1
This new version is a major refactoring of the originally proposed format.
Feel free to comment, update or propose changes.
An implementation will follow when the BCP-11 reach a more stable state.
#gcve #cve #cybersecurity #vulnerabilitymanagement
@gcve@social.circl.lu
The GCVE Lab is an open space for experimenting with new ideas, tools, formats, and services related to the Global CVE Allocation System initiative.
The lab allows the GCVE community to explore promising concepts without immediately imposing the stability, compatibility, and operational requirements expected from the core GCVE infrastructure.
Open to comments/ideas.
#gcve #cve #cybersecurity
https://discourse.ossbase.org/t/gcve-lab-proposal/1117
https://gcve.eu
@gcve@social.circl.lu @gcve@discourse.ossbase.org
You can now browse VEX statements in Vulnerability-Lookup!
The new VEX page lets you explore 220k+ vendor VEX records (Red Hat, Microsoft MSRC, more coming), filter by source, search by CVE ID or title, see product statuses at a glance (fixed, known affected, not affected, under investigation) and pivot straight to the related vulnerability.
🔎 https://vulnerability.circl.lu/vex/
🧩 API: https://vulnerability.circl.lu/api/vex/
#VEX #VulnerabilityLookup #CVE #GCVE #OpenSource #CyberSecurity
282,000+ VEX records are now in Vulnerability-Lookup 🎉
🔎 https://vulnerability.circl.lu/vex
SUSE just joined Red Hat and Microsoft as a VEX source — so from any CVE you can see whether a vendor says a product is affected, fixed, or not affected.
VEX statements are attached directly to each vulnerability and available via the open API.
🧑💻 https://github.com/vulnerability-lookup/vulnerability-lookup
#VEX #CSAF #VulnerabilityManagement #OpenSource #InfoSec #GCVE #CVE #CYberSecurity #Vulnerability
📦 gcve 0.12.1 is out — a small maintenance release with updated dependencies.
gcve is a Python client and CLI for the Global CVE Allocation System (GCVE), a decentralized approach to vulnerability identification where multiple GCVE Numbering Authorities can allocate IDs independently, with a cryptographically signed registry.
🔗 https://gcve.eu
🐍 pipx install gcve
💻 https://github.com/gcve-eu/gcve
#GCVE #CVE #VulnerabilityManagement #CyberSecurity #Python #OpenSource
We just released cve-search v6.0.1 - it is a security and maintenance release. All users are strongly encouraged to upgrade.
Thanks to @oh2fih@infosec.exchange for the remediation fix and release support. Thanks to George Chen for the report about the security vulnerability.
#cve #gcve #cybersecurity
🔗 https://github.com/cve-search/cve-search/releases/tag/v6.0.1
GCVE-BCP-07 - Known Exploited Vulnerability - KEV Assertion Format - updated to version 2.1
🔗 BCP-07 https://gcve.eu/bcp/gcve-bcp-07/
🔗 Contribution https://discourse.ossbase.org/t/kev-known-exploited-vulnerabilities-potential-format-bcp-07/744/46
#gcve #cve #vulnerabilitymanagement #cybersecurity
A new KEV Catalog built from real-world exploitation data !
https://vulnerability.circl.lu/known-exploited-vulnerabilities-catalog/?sort=first_seen&catalog_uuid=c8fb6bf1-f81f-4cb8-95b1-eadbb3b54ee8
We are excited to share the result of a fruitful collaboration with @shadowserver@infosec.exchange: a new Known Exploited Vulnerabilities (KEV) Catalog (BCP-07 compliant) built directly from their global honeypot telemetry.
#ShadowServer #KEV #GCVE #Vulnerability #VulnerabilityManagement #Decentralization #Fragmentation
You've seen all posts