
Sign up to save your podcasts
Or


Kent Landfield of McAfee and Art Manion of CERT/CC discuss how the CVE Program’s upcoming release of JSON 5.0 will allow for additional and related information to be added to CVE Records after they have been published by CVE Numbering Authorities (CNAs). These additions — such as risk scores, affected product lists, versions, references, translations, etc. — will be made by “Authorized Data Publishers (ADPs),” which will be organizations authorized within the CVE Program to enrich the records. Also discussed are the benefits of enriched CVE Records to downstream users and the overall vulnerability management community, the use of Stakeholder-specific Vulnerability Categorization (SSVC), and plans and expectations for the upcoming ADP pilot.
Shannon Sabens of CrowdStrike chats with Peter Allor, Fábio Olivé, and Martin Prpic of Red Hat, which is a long-time CVE Numbering Authority (CNA). The benefits of actively participating as a member of the CVE community are discussed, especially in the CVE Working Groups, which allows Red Hat to directly contribute to enhancing CVE automation and quality, as well as strategic planning for future improvements.
Specific topics include Red Hat being a resource for other CNAs, particularly for open-source vendors and projects; the industry-wide value of the upcoming CVE Record JSON Schema to be a universal vulnerability representation; automation of CNA processes and the upcoming release of CVE Services 2.0; Red Hat’s development of a free API, cvelib, for use by all CNAs that can help them interact with the automated services; and more.
CVE® - https://www.cve.org/
Red Hat - https://www.redhat.com/
CrowdStrike - https://www.crowdstrike.com/
CVE Working Groups - https://www.cve.org/ProgramOrganization/WorkingGroups
How to become a CNA - https://www.cve.org/PartnerInformation/Partner#HowToBecomeAPartner
Episode 9 – Three CVE Board members provide the truth and facts about the following myths about the CVE Program:
Myth #1: The CVE Program is run entirely by the MITRE Corporation
Myth #2: The CVE Program is controlled by software vendors
Myth #3: The CVE Program doesn’t cover enough types of vulnerabilities
Myth #4: The CVE Program is responsible for assigning vulnerability severity scores
CVE Program – https://www.cve.org
CVE Board – https://www.cve.org/ProgramOrganization/Board
Our eighth episode is all about how community members actively engage in the six CVE Working Groups (WGs) to help improve quality, automation, processes, and other aspects of the CVE Program as it continues to grow and expand. The chairs and co-chairs of each WG, each of whom is an active member of the CVE community, chat about their WG’s overall mission, current work, and future plans.
Discussion begins with the Transition (TWG), a temporary WG focused on managing the numerous modernization, automation, and process transitions currently underway in the CVE Program. Each of the five main WGs are then discussed in turn: Strategic Planning (SPWG), CNA Coordination (CNACWG), Quality (QWG), Automation (AWG), and Outreach and Communications (OCWG).
How and why to participate, and the impact individuals can make on the program, are also included.
CVE WG details and membership info – https://cve.mitre.org/working_groups.html
CNAs – https://cve.mitre.org/cve/cna.html
How to become a CNA – https://cve.mitre.org/cve/cna.html#become_a_cna
CVE Board – https://cve.mitre.org/community/board/index.html
CVE Program – https://cve.mitre.org
Episode 7 – Kelly Todd of the CVE Program speaks with Lisa Olson of Microsoft about managing the modernization and automation changes currently underway in the CVE Program. Topics include the efforts of the newly formed CVE Transition Working Group (Lisa, a CVE Board member, is co-chair); automation of CVE ID assignment and CVE Record publishing for CVE Numbering Authorities (CNAs), including the availability of free APIs and other improvements on the way; the upcoming new version release of JSON for the CVE Record format to enhance the data associated with a record; the upcoming availability of program metrics for the CVE community, as well as customized dashboards for use by CNAs; the upcoming launch of a new and more modern CVE website using a new url, cve.org; among other program improvements. In addition, Lisa discusses the benefits of partnering with the CVE Program as a CNA and of being a member of the global CNA community.
CVE® - https://cve.mitre.org/
Microsoft - https://www.microsoft.com/
MSRC - https://microsoft.com/msrc
CVE Working Groups - https://cve.mitre.org/working_groups.html
How to become a CNA - https://cve.mitre.org/cve/cna.html#become_a_cna
Episode 6 – Shannon Sabens of CrowdStrike chats with Chandan Nandakumaraiah of Palo Alto Networks about how the very basic legacy format of CVE Records is being transformed for the future by adding many new optional content fields such as multiple severity scores, credit for researchers, additional languages, ability for community contributions, etc., to make CVE Records even more valuable. The use of JSON for the new format and how that enables automation for both CNA publishers and CVE content consumers are also discussed, as are the use and availability of the CVE Program’s automated CVE Numbering Authority (CNA) tools for 24/7 CVE ID assignment, CVE Record publishing, and CVE Record updating over time. In addition, Chandan discusses the highly useful and free online Vulnogram tool for CNAs that he developed, as well as the benefits of partnering with the CVE Program as a CNA and how participating in the CVE Working Groups (WG), especially the Quality (Chandan is co-chair) and Automation WGs, helps position CVE for a more automated and productive future.
CVE® - https://cve.mitre.org/
Palo Alto Networks - https://www.paloaltonetworks.com/
CrowdStrike - https://www.crowdstrike.com/
Vulnogram - https://vulnogram.github.io/
How to become a CNA - https://cve.mitre.org/cve/cna.html#become_a_cna
CVE Working Groups - https://cve.mitre.org/working_groups.html
Episode 5 – David Waltermire of NVD speaks with Milind Kulkarni of NVIDIA and Kris Britton of the CVE Program to discuss the CVE Program's automated CVE Numbering Authority (CNA) services. Topics include the automation architecture being developed and deployed by the CVE Automation Working Group (AWG); the benefits of using JSON for the CVE Record format; how automation simplifies and increases the speed of CNA processes; the currently deployed CVE ID Reservation (IDR) service; the upcoming release of the CVE Record Submission and Upload (RSUS) service; and future automation plans.
CVE automated services on GitHub - https://github.com/CVEProject
CVE AWG - https://cve.mitre.org/working_groups.html#awg
NVD - https://nvd.nist.gov/
NVIDIA - https://www.nvidia.com/
How to become a CNA - https://cve.mitre.org/cve/cna.html#become_a_cna
Episode 4 – Kelly Todd of the CVE Program interviews security researcher Larry Cashdollar about how he got started researching vulnerabilities and his experiences over the years, how he became the CVE Program’s first-ever independent vulnerability researcher CVE Numbering Authority (CNA), best practices, and the benefits of being able to assign his own CVE IDs to the vulnerabilities he discovers.
CVE - https://cve.mitre.org/
Larry Cashdollar - https://twitter.com/_larry0
Episode 3 - Shannon Sabens of CrowdStrike speaks with Jo Bazar of the CVE Program, Erin Alexander of CISA ICS, and Tomo Itou of JPCERT/CC about the structure and objectives of the CVE Numbering Authority (CNA) program, what it means to be a Root and a CNA, the benefits of partnering with the CVE Program, and recommendations for organizations considering becoming a Root or CNA.
CVE - https://cve.mitre.org/
CISA - https://www.cisa.gov/
CrowdStrike - https://www.crowdstrike.com/
JPCERT/CC - https://www.jpcert.or.jp/vh/index.html
How to become a CNA - https://cve.mitre.org/cve/cna.html#become_a_cna
Episode 2 - Chris Sandulow, Boris Sieklik, and Lena Smart from MongoDB discuss their internal processes for managing CVEs, the importance of CVSS scoring to their customers, the benefits experienced from partnering with the CVE Program as a CVE Numbering Authority (CNA), and recommendations for other organizations considering becoming a CNA.
From the publisher's feed
A free podcast about cybersecurity, vulnerability management, and the CVE Program.

43,324 Listeners

25,759 Listeners

2,010 Listeners

506 Listeners

8,055 Listeners

73 Listeners

138 Listeners

5,549 Listeners