We Speak CVE

Swimming in Vulns (or, Fun with CVE Data Analysis)


Listen Later

Host Shannon Sabens of CrowdStrike chats with Benjamin Edwards and Sander Vinberg, both of Bitsight, about analyzing vulnerability data in the CVE List. This is a follow-on to their “CVE Is The Worst Vulnerability Framework (Except For All The Others)” talk at CVE/FIRST VulnCon 2024.

Topics discussed include the types of vulnerabilities and vulnerability intelligence they reviewed and the different ways they approached the data; how CVE is a really good framework for compiling information about, and communicating effectively about, vulnerabilities; how increasing the number of CVE Numbering Authorities (CNAs) through federation has improved the quantity and quality of data produced by the program over time; how the overall quality of CVE List data will improve for the entire vulnerability management ecosystem as more CNAs include CVSS, CWE, CPE, etc., information when their CVE Records are published; and much, much, more! 

 

...more
View all episodesView all episodes
Download on the App Store

We Speak CVEBy CVE Program

  • 5
  • 5
  • 5
  • 5
  • 5

5

3 ratings


More shows like We Speak CVE

View all
Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,548 Listeners

The NPR Politics Podcast by NPR

The NPR Politics Podcast

25,843 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,010 Listeners

Uncanny Valley | WIRED by WIRED

Uncanny Valley | WIRED

500 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,049 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

137 Listeners

Hard Fork by The New York Times

Hard Fork

5,524 Listeners