CVEs ARE DYING - ThreatWire

preview_player
Показать описание
⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️

@endingwithali →

0:00 Intro
0:12 - The NVD is MIA
2:09 - Linux Foundation CVE Reporting Changed
4:16 - Cisco Acquires Splunk
4:20 - It’s Literally Black Market Extortion
6:06 - Is the AT&T Leak Real?
7:02 - OUTRO

LINKS
🔗 Story 1: The NVD is MIA
🔗 Story 2: Linux Foundation CVE Reporting Changed
This story had help with sourcing by Karl and Lacey! Thank you for the help!
🔗 Story 3: Cisco Acquires Splunk
🔗 Story 4: It’s Literally Black Market Extortion
🔗 Story 5: Is the AT&T Leak Real?

____________________________________________

Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.
Рекомендации по теме
Комментарии
Автор

The CVEs not being reported until they are fixed means vulnerabilities will exist without that information being provided to parties that need to deal with it until a fix is available.

ViolentOrchid
Автор

We had an IT recruiter come in to our college class and he basically said stop trying to beautify your resumes. Put the important things that qualify you for the job and your contact info at the top, and leave the work history and what not towards the bottom/ next page.

eeeeeeeeeeeeeeeeeeeeeeeee
Автор

This is a fantastic episode pointing to the fact that so many of these CVE's were at scale in years past. Today the level of sophistication of threats and a legitimate capability to keep up and categorize and process them in this model simply does not scale. Regardless of what happens a change to the model must take place.

mytechnotalent
Автор

they have already found all vulnerabilities in Windows, now they are going to completely find all the ones for linux. they know some cannot be fixed, and some can, but they are all aware all windows vulnerabilities, including future ones. this does not mean that they will stop their dedication to finding them. now that more people are using Linux including the great gamer migration and because of proton implementation within steam, the CVE's are now going up due to a shift in users on linux. steam os is based around linux, android is linux based, bluestacks, and they have had even more time to prepare now that windows has linux for windows. with the world turning more to Open source products it will be getting much worse. this is why you macs are going to see more CVE's also.

justinburris
Автор

amazing the amount of CVEs that have no fixes. I use them for work all the time. Gonna suck when they get rid of some of them.

robgandy
Автор

We held a funeral for Splunk this week.

cphrpunk
Автор

👀 Appreciate your honesty about never being on the DW. You’re not missing much. Best to stay away from black holes….

Rico
Автор

Incognito was a textbook exit-scam. This just as Nemesis market got blasted by the German FEDS.
ShinyHunters back at it again, AT&T malding and balding.

TFKAT
Автор

Thanks sueety🎉❤😊😊😊 Just ignore cowbell tee-shirt commenters.

Ms.Robot.
Автор

The stages of problem-solving for addressing the vulnerability problem, specifically in regards to the decline of CVEs, typically involve:

1. Identifying vulnerabilities
2. Evaluating vulnerabilities
3. Treating vulnerabilities
4. Reporting vulnerabilities

These stages are crucial in the vulnerability management process to effectively assess and mitigate security risks in IT infrastructure.

奧夫恰連科維塔利
Автор

Good info. Do you think automated scanners like SonarQube will incorporate these new CVE feeds?

cloudshock_dev
Автор

watching their video still feels like early 2000s

akashsrivastava
Автор

SORRY FOR BEING HOT AND SMART LMFAO GET EM!!

papa_sweep
Автор

Ally should interview @LaurieWired on camera. That would be an interview to remember.

ewasteredux
Автор

Somebody tell Linux patched CVEs are remediations not vulns. Duh.

jpo
Автор

Great job on the video! As CVEs continue to get more common with more and more bug bounty hunters out there every day, I really hope that the reporting structure continues to evolve. Hi Twitch Chat! Ali what does that pink sign behind you say? Also DRIP CHECK time Ali pog

thefrub
Автор

Incognito tried to extort me but they couldn't find my history.

tony_solar
Автор

Great follow up shirt, after last week ❤

jamespifher
Автор

Manager:
I look for a conpetant individual that is a criticsl thinker. Enough paper pushers and people who cant think for themselves, sick of printing silly meme-worthy motivational posters, just need people that dont need their hands to be held (at least not for more then a 2-3 weeks until they figure out where they fit in).

jamess
Автор

Seven words that make algorithms love You.

Jerhyn