Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Jean-Baptiste Maillet

@jbm@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Hardcore embedded C/C++ caveman.
Supply chain cybersecurity, SBOM , vulnerability management.
#embedded #linux #oss #psirt

37 Followers
56 Following
30 Posts
Joined March 31, 2024
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 1mo ago
Replying to
@adulau@infosec.exchange @nyanbinary@infosec.exchange @fuckeduprefs_bot@infosec.exchange @gcve@social.circl.lu I remember @jgamblin@infosec.exchange did a study about that a few years ago: https://jerrygamblin.com/2023/04/03/cve-reference-rot/ (2023) With some trending statistics it could be interesting to monitor how the phenomenon evolve.
CVE Reference Rot
JerryGamblin.com

CVE Reference Rot

Reference Rot (also called linked rot) is when hyperlinks, over time, cease to point to their originally targeted file, web page, or server due to that resource being relocated to a new address or …

2
4
1
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 1mo ago
Replying to
(@nyanbinary@infosec.exchange @adulau@infosec.exchange plus @jgamblin@infosec.exchange and @todb@infosec.exchange in the loop)
1
2
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 2mo ago
Replying to
@joshbressers@infosec.exchange @wdormann@infosec.exchange a slop honeypot? 😈
1
0
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 2mo ago
Replying to
@michelin@hachyderm.io @andrewnez@mastodon.social @gvwilson@mastodon.social @fedora@fosstodon.org Red Hat uses a dual CPE/PURL model for its VEX. See: https://www.redhat.com/en/blog/vulnerability-exploitability-exchange-vex-beta-files-now-available https://www.redhat.com/fr/blog/redefining-security-data-red-hats-new-vex-experience-heading-red-hat-summit-2026
Vulnerability Exploitability eXchange (VEX) beta files now available
redhat.com

Vulnerability Exploitability eXchange (VEX) beta files now available

Red Hat Product Security is pleased to announce that official Red Hat vulnerability data is now available in a new format called the Vulnerability Exploitability eXchange (VEX).

1
1
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 6mo ago
Replying to
@adulau @gcve @circl not that I could participate anyway 😕 , but this is just on the week of the VulnCon (https://www.first.org/conference/vulncon26/) that is part of my yearly schedule. Of course, it will always conflict with "someone other thing" anyway.
CVE Program & FIRST VulnCon 2026
FIRST — Forum of Incident Response and Security Teams

CVE Program & FIRST VulnCon 2026

Save the Date: CVE/FIRST VulnCon 2026 & Annual CNA Summit - Scottsdale (US), April 13–16, 2026

3
0
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 5mo ago
Replying to
@adulau @gcve @circl je ne suis pas sur de comprendre. 1/ L'EUVD s'appuie sur vulnerability-lookup. 2/ GCVE s'appuie aussi sur vulnerability-lookup. 3/ vulnerability-lookup est sponsorise par l'UE. (jusque la j'ai bon?) Par contre: 4/ GCVE aussi est sponsorise par l'UE??? 😮 5/ Il y a un lien entre l'EUVD et GCVE??? 😮 Les tombent m'en bras! J'avais pas compris ca du tout. Possible de confirmer/infirmer/clarifier? PS: j'ai suivi la VulnCon la semaine derniere, il y a eu 2 pres' avec des representant de l'ENISA, et a moins que j'ai ete inattentif, il n'a pas ete question de ca (ni de GCVE en general, ce qui est domage mais un autre sujet).
2
1
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 4mo ago

RE: @andrewnez@mastodon.social

Some pearls of wisdom here. 😂

My favs:
* Defense in depth: coding.
* Attack surface: your code.
* Blast radius: everyone else’s code.
* Shift left: make it the developer’s problem.
* Compensating control: we didn’t fix it.
* Risk acceptance: we didn’t fix it, in writing.

mastodon.social

Andrew Nesbitt: "The Infosec Phrasebook https://nesbitt.io/2026/0…" - Mastodon

1
0
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 5mo ago
Replying to
@adulau@infosec.exchange "NVD syndrome". Everybody was fine with the API-less NVD, hapilly duplicating the whole dataset using super simple and elegant data feed system. NVD launches an API (plus announce loudly they are going to retire the feeds - which they hopefully never did)... ..it does not hold the charge from dumb users.
1
0
1
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 5mo ago
Replying to
@joshbressers it's never been parody. Just precognition.
1
0
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 6mo ago
Replying to
@adulau @cedric while you're at it with severity and CWE classification, did you ever considered CPE too? Like: "CPE guesser, but AI based". A trick would be to AI-guess-timate the CPE for a vuln, *but* the CPE would need to be an existing one in the NVD (apart from the version, that is). (And I don't see anything wrong with Free Jazz :blobsunglasses: )
1
2
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 7mo ago
Replying to
@adulau@infosec.exchange "The distribution of cost and responsibility must be fair across the U.S. and allies who share our democratic values" reminds me of US NATO discourse.
1
0
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 8mo ago
@adulau yep, discord s*cks. Nonetheless, it is the same as CNA vs GCNA, the LI vs mastodon, pixelfed vs instagram etc. Life, on a general perspective, s*cks. I'm pretty sure you noticed that already? (still, we exist) https://www.youtube.com/watch?v=SJUhlRoBL8M #discord
1
0
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 8mo ago
Replying to
@vladh@merveilles.town also, going down to this rabbit hole, don't you think that in the end everything depends on the libc, and then the kernel? (I have no idea how non-Linux based works)
1
1
1
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 8mo ago
Replying to
@vladh@merveilles.town also, for your "other resources", you might want to have a look at: https://github.com/owasp-dep-scan/blint from the OWASP https://github.com/aph10/BIDS from Anthony Harrison, a FOSDEM presenter Both address a specific use case: SBOMs, mostly for cybersec.
GitHub

GitHub - owasp-dep-scan/blint: blint is a Binary Linter that checks the security properties and capabilities of your executables. It can also generate a Software Bill-of-Materials (SBOM) for supported binaries.

blint is a Binary Linter that checks the security properties and capabilities of your executables. It can also generate a Software Bill-of-Materials (SBOM) for supported binaries. - owasp-dep-scan/...

1
1
1
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 8mo ago
Replying to
@adulau unfortunately I won't be able to make it this year 😕 If I could, I would have liked to discuss *identifiers* (CPE, PURL, ...). Yes, I know and 100% agree this is a topic in itself, that cannot be discussed in a 1/2h presentation at FOSDEM, nor in 1h, nor in 2h, but would deserve full workshop(s), (and obviously I do not expect any of these in a private 1-to-1 sessions) but the topic remain on the table, I have my view on this and I'd like to have yours. (Nonetheless, available anytime for a quick and short chat about this) (Anytime, except for the next 2-3 weeks I'm in full task force mode right now)
1
0
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 5mo ago
Replying to
@andrewnez@mastodon.social ...or (answering to myself), if you use CWE data from CVE, this is *already* a map of the NVD slice, by input definition, silly me... :blobfacepalm:
0
1
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 2mo ago
Replying to
@mrmasterkeyboard@mastodon.social @CVE_Program@mastodon.social this on the other hand is more significant: https://medium.com/@cve_program/cve-program-launches-frontier-ai-researcher-cna-pilot-2e96645448eb
medium.com
0
0
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 6mo ago

I'll be at the VulnCon next week (remotely that is, from Paris).
Maybe we'll met in the chats?
https://www.first.org/conference/vulncon26/
#vulncon26

CVE Program & FIRST VulnCon 2026
FIRST — Forum of Incident Response and Security Teams

CVE Program & FIRST VulnCon 2026

Save the Date: CVE/FIRST VulnCon 2026 & Annual CNA Summit - Scottsdale (US), April 13–16, 2026

0
0
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 4mo ago

RE: @CVE_Program@mastodon.social

2,000+ CVE in a CISA weekly bulletin? Unless I'm mistaken this is the all-time record (so far). 🤯
#cve

mastodon.social
0
0
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 4mo ago

A juicy report that, sadly, won't teach you much if you're in the vulnerability management business.

At least, you can say:
"see? I told you" 🤬

https://cyberscoop.com/nist-nvd-audit-mismanagement-duplication/?utm_campaign=CyberScoop%20-%20Edito

cyberscoop.com
0
0
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 4mo ago

Anyone can now declare a KEV to the CISA.
#CISA #KEV

infosec.exchange
0
2
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 1mo ago
RE: https://mastodon.social/@bouletcorp2/117061351342436113 Dilemme moral de l'utilisateur d'intelligence artificielle.
mastodon.social

-Boulet-: "Nouveau Rogaton - 08/08/2026 - "Génération Perdue…" - Mastodon

0
0
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 2mo ago
Replying to
@allanfriedman@infosec.exchange I think it's a mistake to add the component license to the minimum requirements. Different concern, use cases and workflow (licenses do not change with every release nor component version), different consumers (cyber vs IP), and none of the job of the CISA nor any other orgs listed as co-authors. At work, I fight every week with people mixing SBOM for cyber and SBOM for license. I don't have time to lose with that, "if you want a license SBOM or license info in the SBOM take care of it, because I won't do it for you". So tired of that.
0
0
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 2mo ago
Replying to
@pgl@infosec.exchange @jayjacobs@infosec.exchange for reference, @zmanion@infosec.exchange and @jayjacobs@infosec.exchange presentation from VulnCon in April: https://www.first.org/conference/vulncon26/program#pA-Paradigm-Shift-in-Vulnerability-Identity-Why-Vulnerability-Databases-Struggle https://www.youtube.com/watch?v=3_s61rBvIVo&list=PLBAUUhONOrO_yESOH6JnwWBoRdDRVXDr0&index=23 Great pres, AFAIC 2026 best so far.
0
0
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 5mo ago
Replying to
@andrewnez@mastodon.social very cool. I've been looking for a CWE cheat sheet, this might be it. 👍 Would you consider making a version limited to "CWE-1003: Weaknesses for Simplified Mapping of Published Vulnerabilities", aka the "CWE NVD slice", that is to say not the whole 900+ CWE shebang, but only the 130 CWE actually used for CVE? 🙏 Refs: https://nvd.nist.gov/vuln/categories https://cwe.mitre.org/data/definitions/1003.html
nvd.nist.gov
0
1
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 2mo ago
Replying to
@mrmasterkeyboard@mastodon.social @CVE_Program@mastodon.social don't panic (nor get overexcited): it's for CVE on *their own* products. Not for CVE discovered on *other's people* products using their tools. TL;DR this is not a researcher CNA, nothing to see here.
0
1
0
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 8mo ago
Replying to
@vladh@merveilles.town hopefully, I don't have these. Because as an embedded caveman I build *everything from sources*. In some cases it's actually a plus. 😁 (Then, there is still the "build time" vs "runtime" dep part, OK.)
0
1
1
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 8mo ago
Replying to
@vladh@merveilles.town more seriously, a couple of things: Actually, embedded people do not care that much about _binary_ stuff, because we build everything from sources. In long and complex supply chain of providers, for 10+ years products, this was not necessarily the case in _some_ industries. But as for me, it's been 25 years of source code only... ...except for very small payloads, in the order of kbytes, for drivers chipsets (wifi, bluetooth,...).
0
3
1
0
Open post
Jean-Baptiste Maillet @jbm@infosec.exchange
· 4mo ago
Replying to
@gcve@social.circl.lu I am not sure I get it. (CPEs suck big time and I hate them with a deep passion, but PURLs have a much more limited scope, so I have to live with CPEs for the foreseeable future. This being said...) ...The main problem I see with CPE are not "CPE out of thin air", or "in some dictionary", just for the pleasure of listing CPE. The pb is G/CVE 1/ without any CPE, 2/ or without useful CPE, 3/ or with an incorrect CPE. This is what I have to deal with daily. I don't understand how this CPE editor is helping in this regard. Is there some link to vulns that I'd de missing?
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:01:34 UTC