Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Jean-Baptiste Maillet

@jbm@infosec.exchange
  • Open on infosec.exchange

Hardcore embedded C/C++ caveman.
Supply chain cybersecurity, SBOM , vulnerability management.
#embedded #linux #oss #psirt

29 Followers
51 Following
30 Posts
Joined March 31, 2024
he/him:
embedded:
linux:
oss:
psirt:

Posts

Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · 4d ago
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @nyanbinary@infosec.exchange
(@nyanbinary@infosec.exchange @adulau@infosec.exchange plus @jgamblin@infosec.exchange and @todb@infosec.exchange in the loop)
1
1
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · 4d ago
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
RE: https://mastodon.social/@bouletcorp2/117061351342436113 Dilemme moral de l'utilisateur d'intelligence artificielle.
0
0
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · 4d ago
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @adulau@infosec.exchange
@adulau@infosec.exchange @nyanbinary@infosec.exchange @fuckeduprefs_bot@infosec.exchange @gcve@social.circl.lu I remember @jgamblin@infosec.exchange did a study about that a few years ago: https://jerrygamblin.com/2023/04/03/cve-reference-rot/ (2023) With some trending statistics it could be interesting to monitor how the phenomenon evolve.
jerrygamblin.com

CVE Reference Rot

2
1
1
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Aug 06, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @joshbressers@infosec.exchange
@joshbressers@infosec.exchange @wdormann@infosec.exchange a slop honeypot? 😈
0
0
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Jul 30, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @allanfriedman@infosec.exchange
@allanfriedman@infosec.exchange I think it's a mistake to add the component license to the minimum requirements. Different concern, use cases and workflow (licenses do not change with every release nor component version), different consumers (cyber vs IP), and none of the job of the CISA nor any other orgs listed as co-authors. At work, I fight every week with people mixing SBOM for cyber and SBOM for license. I don't have time to lose with that, "if you want a license SBOM or license info in the SBOM take care of it, because I won't do it for you". So tired of that.
0
0
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Jul 29, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @jbm@infosec.exchange
@mrmasterkeyboard@mastodon.social @CVE_Program@mastodon.social this on the other hand is more significant: https://medium.com/@cve_program/cve-program-launches-frontier-ai-researcher-cna-pilot-2e96645448eb
Medium

CVE Program Launches Frontier AI Researcher CNA Pilot

On July 28, 2026, the CVE™ Program launched the “Frontier AI Researcher CVE Numbering Authorities (CNAs) Pilot,” an initial six-month…

0
0
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Jul 29, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @mrmasterkeyboard@mastodon.social
@mrmasterkeyboard@mastodon.social @CVE_Program@mastodon.social don't panic (nor get overexcited): it's for CVE on *their own* products. Not for CVE discovered on *other's people* products using their tools. TL;DR this is not a researcher CNA, nothing to see here.
0
1
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Jul 29, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @michelin@hachyderm.io
@michelin@hachyderm.io @andrewnez@mastodon.social @gvwilson@mastodon.social @fedora@fosstodon.org Red Hat uses a dual CPE/PURL model for its VEX. See: https://www.redhat.com/en/blog/vulnerability-exploitability-exchange-vex-beta-files-now-available https://www.redhat.com/fr/blog/redefining-security-data-red-hats-new-vex-experience-heading-red-hat-summit-2026
Vulnerability Exploitability eXchange (VEX) beta files now available
www.redhat.com

Vulnerability Exploitability eXchange (VEX) beta files now available

Red Hat Product Security is pleased to announce that official Red Hat vulnerability data is now available in a new format called the Vulnerability Exploitability eXchange (VEX).

0
0
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Jul 27, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @pgl@infosec.exchange
@pgl@infosec.exchange @jayjacobs@infosec.exchange for reference, @zmanion@infosec.exchange and @jayjacobs@infosec.exchange presentation from VulnCon in April: https://www.first.org/conference/vulncon26/program#pA-Paradigm-Shift-in-Vulnerability-Identity-Why-Vulnerability-Databases-Struggle https://www.youtube.com/watch?v=3_s61rBvIVo&list=PLBAUUhONOrO_yESOH6JnwWBoRdDRVXDr0&index=23 Great pres, AFAIC 2026 best so far.
0
0
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Jun 04, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange

RE: @CVE_Program@mastodon.social

2,000+ CVE in a CISA weekly bulletin? Unless I'm mistaken this is the all-time record (so far). 🤯
#cve

0
0
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Jun 02, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @gcve@social.circl.lu
@gcve@social.circl.lu I am not sure I get it. (CPEs suck big time and I hate them with a deep passion, but PURLs have a much more limited scope, so I have to live with CPEs for the foreseeable future. This being said...) ...The main problem I see with CPE are not "CPE out of thin air", or "in some dictionary", just for the pleasure of listing CPE. The pb is G/CVE 1/ without any CPE, 2/ or without useful CPE, 3/ or with an incorrect CPE. This is what I have to deal with daily. I don't understand how this CPE editor is helping in this regard. Is there some link to vulns that I'd de missing?
0
1
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Jun 01, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange

RE: @andrewnez@mastodon.social

Some pearls of wisdom here. 😂

My favs:
* Defense in depth: coding.
* Attack surface: your code.
* Blast radius: everyone else’s code.
* Shift left: make it the developer’s problem.
* Compensating control: we didn’t fix it.
* Risk acceptance: we didn’t fix it, in writing.

1
0
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Jun 01, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange

A juicy report that, sadly, won't teach you much if you're in the vulnerability management business.

At least, you can say:
"see? I told you" 🤬

https://cyberscoop.com/nist-nvd-audit-mismanagement-duplication/?utm_campaign=CyberScoop%20-%20Edito

0
0
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · May 22, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange

Anyone can now declare a KEV to the CISA.
#CISA #KEV

0
2
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · May 05, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @adulau@infosec.exchange
@adulau@infosec.exchange "NVD syndrome". Everybody was fine with the API-less NVD, hapilly duplicating the whole dataset using super simple and elegant data feed system. NVD launches an API (plus announce loudly they are going to retire the feeds - which they hopefully never did)... ..it does not hold the charge from dumb users.
1
0
1
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · May 05, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @jbm@infosec.exchange
@andrewnez@mastodon.social ...or (answering to myself), if you use CWE data from CVE, this is *already* a map of the NVD slice, by input definition, silly me... :blobfacepalm:
0
1
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · May 05, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @andrewnez@mastodon.social
@andrewnez@mastodon.social very cool. I've been looking for a CWE cheat sheet, this might be it. 👍 Would you consider making a version limited to "CWE-1003: Weaknesses for Simplified Mapping of Published Vulnerabilities", aka the "CWE NVD slice", that is to say not the whole 900+ CWE shebang, but only the 130 CWE actually used for CVE? 🙏 Refs: https://nvd.nist.gov/vuln/categories https://cwe.mitre.org/data/definitions/1003.html
0
1
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Apr 24, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @joshbressers@infosec.exchange
@joshbressers it's never been parody. Just precognition.
1
0
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Apr 22, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @adulau@infosec.exchange
@adulau @gcve @circl je ne suis pas sur de comprendre. 1/ L'EUVD s'appuie sur vulnerability-lookup. 2/ GCVE s'appuie aussi sur vulnerability-lookup. 3/ vulnerability-lookup est sponsorise par l'UE. (jusque la j'ai bon?) Par contre: 4/ GCVE aussi est sponsorise par l'UE??? 😮 5/ Il y a un lien entre l'EUVD et GCVE??? 😮 Les tombent m'en bras! J'avais pas compris ca du tout. Possible de confirmer/infirmer/clarifier? PS: j'ai suivi la VulnCon la semaine derniere, il y a eu 2 pres' avec des representant de l'ENISA, et a moins que j'ai ete inattentif, il n'a pas ete question de ca (ni de GCVE en general, ce qui est domage mais un autre sujet).
2
1
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Apr 09, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange

I'll be at the VulnCon next week (remotely that is, from Paris).
Maybe we'll met in the chats?
https://www.first.org/conference/vulncon26/
#vulncon26

CVE Program & FIRST VulnCon 2026
FIRST — Forum of Incident Response and Security Teams

CVE Program & FIRST VulnCon 2026

Save the Date: CVE/FIRST VulnCon 2026 & Annual CNA Summit - Scottsdale (US), April 13–16, 2026

0
0
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Apr 08, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @adulau@infosec.exchange
@adulau @gcve @circl not that I could participate anyway 😕 , but this is just on the week of the VulnCon (https://www.first.org/conference/vulncon26/) that is part of my yearly schedule. Of course, it will always conflict with "someone other thing" anyway.
3
0
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Mar 25, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @adulau@infosec.exchange
@adulau @cedric while you're at it with severity and CWE classification, did you ever considered CPE too? Like: "CPE guesser, but AI based". A trick would be to AI-guess-timate the CPE for a vuln, *but* the CPE would need to be an existing one in the NVD (apart from the version, that is). (And I don't see anything wrong with Free Jazz :blobsunglasses: )
1
2
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Mar 09, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @adulau@infosec.exchange
@adulau@infosec.exchange "The distribution of cost and responsibility must be fair across the U.S. and allies who share our democratic values" reminds me of US NATO discourse.
1
0
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Feb 10, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @adulau@infosec.exchange
@adulau yep, discord s*cks. Nonetheless, it is the same as CNA vs GCNA, the LI vs mastodon, pixelfed vs instagram etc. Life, on a general perspective, s*cks. I'm pretty sure you noticed that already? (still, we exist) https://www.youtube.com/watch?v=SJUhlRoBL8M #discord
1
0
0
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Feb 10, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @jbm@infosec.exchange
@vladh@merveilles.town also, for your "other resources", you might want to have a look at: https://github.com/owasp-dep-scan/blint from the OWASP https://github.com/aph10/BIDS from Anthony Harrison, a FOSDEM presenter Both address a specific use case: SBOMs, mostly for cybersec.
1
1
1
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Feb 10, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @jbm@infosec.exchange
@vladh@merveilles.town also, going down to this rabbit hole, don't you think that in the end everything depends on the libc, and then the kernel? (I have no idea how non-Linux based works)
1
1
1
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Feb 10, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @vladh@merveilles.town
@vladh@merveilles.town more seriously, a couple of things: Actually, embedded people do not care that much about _binary_ stuff, because we build everything from sources. In long and complex supply chain of providers, for 10+ years products, this was not necessarily the case in _some_ industries. But as for me, it's been 25 years of source code only... ...except for very small payloads, in the order of kbytes, for drivers chipsets (wifi, bluetooth,...).
0
1
1
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Feb 09, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @vladh@merveilles.town
@vladh@merveilles.town me embedded caveman. Lot of C. This good. Me like.
1
0
1
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Feb 05, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @vladh@merveilles.town
@vladh@merveilles.town hopefully, I don't have these. Because as an embedded caveman I build *everything from sources*. In some cases it's actually a plus. 😁 (Then, there is still the "build time" vs "runtime" dep part, OK.)
0
1
1
0
Open post
jbm
Jean-Baptiste Maillet @jbm@infosec.exchange · Jan 27, 2026
Jean-Baptiste Maillet
@jbm@infosec.exchange

Hardcore embedded C/C++ caveman. Supply chain cybersecurity, SBOM , vulnerability management. #embedded #linux #oss #psirt

infosec.exchange
Replying to @adulau@infosec.exchange
@adulau unfortunately I won't be able to make it this year 😕 If I could, I would have liked to discuss *identifiers* (CPE, PURL, ...). Yes, I know and 100% agree this is a topic in itself, that cannot be discussed in a 1/2h presentation at FOSDEM, nor in 1h, nor in 2h, but would deserve full workshop(s), (and obviously I do not expect any of these in a private 1-to-1 sessions) but the topic remain on the table, I have my view on this and I'd like to have yours. (Nonetheless, available anytime for a quick and short chat about this) (Anytime, except for the next 2-3 weeks I'm in full task force mode right now)
1
0
0
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:04:11 UTC