Tootfinder

Opt-in global Mastodon full text search. Join the index!

@adulau@infosec.exchange
2026-08-09 08:26:26

Pretty cool idea from @… - a bot to analyse fucked up references from the CVE records.
@…
Maybe we could imagine an archive bot at the same time to ensure that the references don't get lost. Just like archive.org or similar. Maybe something for @… to look into.
#cve #vulnerability #gcve

@adulau@infosec.exchange
2026-08-09 09:24:28

Working on a first super beta implementation of @… BCP-11 "Community-Proposed Updates to Existing CVE Records"
To validate if the BCP-11 can be published.
#cve #gcve #vulnerability #opensource #opendata
Discussions discourse.ossbase.org/t/gcve-b

@adulau@infosec.exchange
2026-08-01 08:20:08

Sightings have long been a major topic of discussion in the CTI community, particularly in the field of vulnerability management. We have now published a GCVE BCP to standardise the format that has been implemented, tested and used operationally in Vulnerability-Lookup for some time.
Thanks to everyone (Cédric Bonhomme, Éireann Leverett, Andras Iklody, Sami Mokaddem and many more) who participated in discussions and worked on the implementation details of sightings over the past several years. These efforts had a strong focus on practical implementation, while BCP-12 specifically addresses sightings in the context of vulnerability management.
BCP-12 is still a draft open for review, but it already provides a strong foundation for existing implementations.
#cve #cra #gcve #vulnerabilitymanagement #cybersecurity #openstandard