Wow. CVE database is in serious trouble, tomorrow.
The cyber industry as a whole is in trouble also really, it’s the elephant in the room - the collapse of the White House’s support for cybersecurity is obvious and pronounced due to widespread cutbacks.
Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •My take on the CVE contract issue for businesses: don’t overreact, wait and see what impacts are.
The NVD backlog was already pretty crazy.. the US gov has gotta put real funding into this area if it wants to retain control of cyber standards.
Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •To widen it out - CVE is the globally recognised system orgs use for vulnerability management.
Every vulnerability management product uses CVEs. Vulnerability management is a core part of cybersecurity - often, the most important part.
Additionally, CVE is written into several US government standards that orgs have to follow.
So the US Government not funding it is a major and historic own goal.
Kevin Beaumont
in reply to Kevin Beaumont • • •Matt Blaze
in reply to Kevin Beaumont • • •Andrew C. Dingman
in reply to Matt Blaze • • •Kevin Beaumont
in reply to Kevin Beaumont • • •Metacurity (@metacurity@infosec.exchange)
Infosec ExchangeKevin Beaumont
in reply to Kevin Beaumont • • •MITRE-backed cyber vulnerability program to lose funding Wednesday
David DiMolfetta (Nextgov/FCW)Kevin Beaumont
in reply to Kevin Beaumont • • •NoVa govcon firm Mitre to lay off 442 employees after DOGE cuts contracts
Beth JoJack (Virginia Business)Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •CVE Foundation
www.thecvefoundation.orgKevin Beaumont
in reply to Kevin Beaumont • • •GCVE.eu
gcve.euKevin Beaumont
in reply to Kevin Beaumont • • •CISA have, at the last minute, extended the MITRE CVE contract. “The CVE Program is invaluable to cyber community and a priority of CISA. Last night, CISA executed the option period on the contract to ensure there will be no lapse in critical CVE services. We appreciate our partners’ and stakeholders’ patience.” HT @metacurity
It’s unclear how long it has been extended for.
Debbie Goldsmith 🏳️⚧️♾️🇺🇦 reshared this.
Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •Metacurity (@metacurity@infosec.exchange)
Infosec ExchangeKevin Beaumont
in reply to Kevin Beaumont • • •CVE extension to March 16th 2026
See y’all March 15th 2026 for the last minute renewal 🫡😅
usaspending.gov/award/CONT_AWD…
USAspending.gov
www.usaspending.govKevin Beaumont
in reply to Kevin Beaumont • • •MITRE’s statement is interesting as they included trademark and copyright symbols on terms like CVE.. one to watch as people try to start their own systems.
mastodon.social/@bagder/114349…
Kevin Beaumont
in reply to Kevin Beaumont • • •CVE Foundation - Frequently Asked Questions
www.thecvefoundation.org