#vulnerabilitymanagement

43 posts · Last used 3d

Back to Timeline
Alexandre Dulaunoy @adulau@infosec.exchange · 3d ago
From a research paper to running open-source code in just a few days. We (with @cedric@fosstodon.org) have been experimenting in Vulnerability-Lookup with the concept of Local Exploit Hazard, based on the recent research paper “Modeling Local Exploit Hazard — A Bayesian Framework for Quantifying Exploit Risk and Operational Efficiency” by Stephen Shaffer and Laura Cristiana Voicu. The idea addresses an important question in vulnerability management: Not simply “How dangerous is this vulnerability globally?” but “How much exploitation risk does this vulnerability represent in my environment?” Instead of introducing yet another static vulnerability score, the model starts from exploit likelihood such as EPSS and combines it with local security controls, CVSS attack vectors, vulnerability age and KEV policy to estimate an exploitation hazard. We implemented an experimental version in Vulnerability-Lookup and connected it directly to operational workflows. For the full details: https://www.vulnerability-lookup.org/2026/08/11/local-exploit-hazard/ #cve #gcve #vulnerabilitymanagement #vulnerability #opensource #opendata @circl@social.circl.lu
0
1
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 4d ago
This weekly CVE report covers 1,877 new CVEs and 6 actively exploited flaws added to CISA KEV, including N-able, TeamCity, and Langflow bugs. #CVE #CISAKEV #VulnerabilityManagement #InfoSec #PatchNow #CyberSecurity https://securityonline.info/weekly-cve-report-august-2026/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
ICS Advisory Project @AdvisoryICS@infosec.exchange · 5d ago

ICS[AP] Dashboards are updated with the 1 CISA Advisory released on 8/7/2026:

FAA: 1 New

www.icsadvisoryproject.com #icssecurity #otsecurity #vulnerabilitymanagement

0
0
0
ICS Advisory Project @AdvisoryICS@infosec.exchange · Aug 05, 2026

ICS[AP] Dashboards are updated with the 2 CISA Advisories released on 8/4/2026:

Acrisure: 1 New Thermo Fisher: 1 New

www.icsadvisoryproject.com #icssecurity #otsecurity #vulnerabilitymanagement

0
0
0
ICS Advisory Project @AdvisoryICS@infosec.exchange · Aug 05, 2026
ICS[AP] updated CISA ICS Advisories Master File for 8/4/2026 & the following year's CSVs: CISA_ICS_ADV_2026_8_4_26.csv Available @ ICS[AP] GitHub: https://github.com/icsadvprj/ICS-Advisory-Project/tree/main #opensource #vulnerabilitymanagement #icssecurity
0
0
0
Kyle Reddoch (CybersecKyle) @cyberseckyle@infosec.exchange · Aug 04, 2026
0
0
0
ICS Advisory Project @AdvisoryICS@infosec.exchange · Jul 31, 2026

ICS[AP] Dashboards are updated with the 11 new and 1 updated CISA Advisories released on 7/30/2026:

MZ Automation GmbH: 2 New Johnson Controls Inc.: 1 New MikroTik: 1 New Mitsubishi Electric: 1 New NASA: 1 New Rockwell Automation: 1 New Schneider Electric: 1 New Toptech Systems: 1 New Watchfire: 1 New o6 Automation GmbH: 1 New Hardy Barth: 1 Update

www.icsadvisoryproject.com #icssecurity #otsecurity #vulnerabilitymanagement

0
0
0
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 30, 2026
A new version of the BCP-11 "Community Contribution Fragments for Existing CVE Records" proposal has been published. https://discourse.ossbase.org/t/gcve-bcp-11-community-proposed-updates-to-existing-cve-records/1110/8#p-1495-gcve-bcp-11-community-contribution-fragments-for-existing-cve-records-1 This new version is a major refactoring of the originally proposed format. Feel free to comment, update or propose changes. An implementation will follow when the BCP-11 reach a more stable state. #gcve #cve #cybersecurity #vulnerabilitymanagement @gcve@social.circl.lu
0
0
1
CVE Program @CVE_Program@mastodon.social · Jul 28, 2026
Anthropic is now a CVE Numbering Authority assigning CVE IDs for vulnerabilities in software, services, & open-source projects developed, maintained, or distributed by Anthropic https://cve.org/Media/News/item/news/2026/07/28/Anthropic-Added-as-CNA #cve #cna #vulnerabilitymanagement #vulnerability #cybersecurity #ai #artificialintellegence
0
1
1
ICS Advisory Project @AdvisoryICS@infosec.exchange · Jul 29, 2026
ICS[AP] Dashboards are updated with the 7 CISA Advisories released on 7/28/2026: Siemens: 4 New ABB: 1 New MikroTik: 1 New igloohome: 1 New www.icsadvisoryproject.com #icssecurity #otsecurity #vulnerabilitymanagement
0
0
0
ICS Advisory Project @AdvisoryICS@infosec.exchange · Jul 29, 2026
ICS[AP] updated CISA ICS Advisories Master File for 7/28/2026 & the following year's CSVs: CISA_ICS_ADV_2026_7_28_26.csv Available @ ICS[AP] GitHub: https://github.com/icsadvprj/ICS-Advisory-Project/tree/main #opensource #vulnerabilitymanagement #icssecurity
0
0
0
Jerry Gamblin @jgamblin@infosec.exchange · Jul 28, 2026
CVSS is a severity label the industry treats like a priority list. A 9.8 tells you how bad a bug could be. It cannot tell you which 9.8 to do first. This year 4,719 CVEs carry a CVSS v3 score of 9.0 or higher. Half of them, 2,493, land on the identical 9.8, the arithmetic result of a remote, unauthenticated, full-impact vector. Nine distinct scores exist in the entire critical band. There is no 9.5 and no 9.7. That is the resolution you are triaging with. Rank the same 4,719 by EPSS percentile and the median lands at the 37th, so half the drop-everything tier ranks below 63% of all CVEs. Cut at the 90th percentile and 211 CVEs hold 49 of the 54 now on CISA's KEV list. One caveat: EPSS reads exploitation signal, and all 54 were listed before these scores were computed, so that is two sources agreeing, not a prediction. It still gives you an order. 9.8 does not. 2,493 CVEs this year share one score. If your tooling had to put them in a fix order tomorrow morning, what field would it sort on, and who would argue with you about it? #vulnerabilitymanagement #cybersecurity #CVE
4
2
4
ICS Advisory Project @AdvisoryICS@infosec.exchange · Jul 24, 2026
ICS[AP] updated CISA ICS Advisories Master File for 7/23/2026 & the following year's CSVs: CISA_ICS_ADV_2026_7_23_26.csv Available @ ICS[AP] GitHub: https://github.com/icsadvprj/ICS-Advisory-Project/tree/main #opensource #vulnerabilitymanagement #icssecurity
0
0
0
ICS Advisory Project @AdvisoryICS@infosec.exchange · Jul 24, 2026

ICS[AP] Dashboards are updated with the 7 CISA Advisories released on 7/23/2026:

Johnson Controls Inc.: 2 New MZ Automation GmbH: 2 New Pronetiqs: 1 New Rockwell Automation: 1 New Weintek: 1 New

www.icsadvisoryproject.com #icssecurity #otsecurity #vulnerabilitymanagement

0
0
0
Yazoul - Cybersecurity Alerts @Matchbook3469@infosec.exchange · Jul 22, 2026
🔴 New security advisory: CVE-2026-16232 affects multiple systems. • Impact: Remote code execution or complete system compromise possible • Risk: Attackers can gain full control of affected systems • Mitigation: Patch immediately or isolate affected systems Full breakdown: https://www.yazoul.net/advisory/cve/cve-2026-16232-check-point-smartconsole-auth-bypass-exploited #InfoSec #VulnerabilityManagement #CyberSec
0
0
1
ICS Advisory Project @AdvisoryICS@infosec.exchange · Jul 21, 2026

ICS[AP] Dashboards are updated with the 10 CISA Advisories released on 7/21/2026:

Siemens: 5 New Rockwell Automation: 4 New Tycon Systems: 1 New

www.icsadvisoryproject.com #icssecurity #otsecurity #vulnerabilitymanagement

0
0
0
ICS Advisory Project @AdvisoryICS@infosec.exchange · Jul 21, 2026
ICS[AP] updated CISA ICS Advisories Master File for 7/21/2026 & the following year's CSVs: CISA_ICS_ADV_2026_7_21_26.csv Available @ ICS[AP] GitHub: https://github.com/icsadvprj/ICS-Advisory-Project/tree/main #opensource #vulnerabilitymanagement #icssecurity
0
0
0
Cedric @cedric@social.circl.lu · Jul 20, 2026
282,000+ VEX records are now in Vulnerability-Lookup 🎉 🔎 https://vulnerability.circl.lu/vex SUSE just joined Red Hat and Microsoft as a VEX source — so from any CVE you can see whether a vendor says a product is affected, fixed, or not affected. VEX statements are attached directly to each vulnerability and available via the open API. 🧑‍💻 https://github.com/vulnerability-lookup/vulnerability-lookup #VEX #CSAF #VulnerabilityManagement #OpenSource #InfoSec #GCVE #CVE #CYberSecurity #Vulnerability
0
0
1
FIRST.org @firstdotorg@infosec.exchange · Jul 17, 2026
🎙️ New FIRST Impressions Podcast Episode: Chris Butera (CISA) Recorded live at #FIRSTCON26 in Denver, this episode features Chris Butera, acting Executive Assistant Director for Cybersecurity at CISA, the local host of the conference. Chris joins the podcast to discuss the future of the #CVEprogram, software supply chain security, AI-specific SBOMs, end-of-support risk management, and the importance of strong collaboration between government and industry. If you’re interested in vulnerability management, AI security, supply chain resilience, or the evolving cybersecurity ecosystem, this is an episode you won’t want to miss! 🎧 Tune in to hear how CISA is helping shape the future of cyber defense and vulnerability coordination across the global community. #FIRSTCON26 #FIRSTImpressions #CISA #Cybersecurity #CVE #SBOM #AISecurity #SupplyChainSecurity #VulnerabilityManagement https://media.first.org/podcasts/FIRST_Impressions-butera26.mp3
0
0
0
ICS Advisory Project @AdvisoryICS@infosec.exchange · Jul 17, 2026
ICS[AP] Dashboards are updated with the 9 CISA Advisories released on 7/16/2026: Rockwell Automation: 5 New AutomationDirect: 1 New NASA: 1 New SALTO: 1 New Siemens: 1 New www.icsadvisoryproject.com #icssecurity #otsecurity #vulnerabilitymanagement
0
0
0