We Speak CVE

We Speak CVE

Download on the App Store

We Speak CVE episodes

  • Enhancing CVE Records as an Authorized Data Publisher

    Kent Landfield of McAfee and Art Manion of CERT/CC discuss how the CVE Program’s upcoming release of JSON 5.0 will allow for additional and related information to be added to CVE Records after they have been published by CVE Numbering Authorities (CNAs). These additions — such as risk scores, affected product lists, versions, references, translations, etc. — will be made by “Authorized Data Publishers (ADPs),” which will be organizations authorized within the CVE Program to enrich the records. Also discussed are the benefits of enriched CVE Records to downstream users and the overall vulnerability management community, the use of Stakeholder-specific Vulnerability Categorization (SSVC), and plans and expectations for the upcoming ADP pilot.

    28 min
  • How Red Hat's Active Participation Helps Improve the CVE Program

    Shannon Sabens of CrowdStrike chats with Peter Allor, Fábio Olivé, and Martin Prpic of Red Hat, which is a long-time CVE Numbering Authority (CNA). The benefits of actively participating as a member of the CVE community are discussed, especially in the CVE Working Groups, which allows Red Hat to directly contribute to enhancing CVE automation and quality, as well as strategic planning for future improvements.

    Specific topics include Red Hat being a resource for other CNAs, particularly for open-source vendors and projects; the industry-wide value of the upcoming CVE Record JSON Schema to be a universal vulnerability representation; automation of CNA processes and the upcoming release of CVE Services 2.0; Red Hat’s development of a free API, cvelib, for use by all CNAs that can help them interact with the automated services; and more.

    CVE® - https://www.cve.org/
    Red Hat - https://www.redhat.com/
    CrowdStrike - https://www.crowdstrike.com/
    CVE Working Groups - https://www.cve.org/ProgramOrganization/WorkingGroups
    How to become a CNA - https://www.cve.org/PartnerInformation/Partner#HowToBecomeAPartner

    25 min
  • CVE Myths versus Facts

    Episode 9 – Three CVE Board members provide the truth and facts about the following myths about the CVE Program: 
     
     Myth #1: The CVE Program is run entirely by the MITRE Corporation
     Myth #2: The CVE Program is controlled by software vendors
     Myth #3: The CVE Program doesn’t cover enough types of vulnerabilities
     Myth #4: The CVE Program is responsible for assigning vulnerability severity scores 
     
     CVE Program – https://www.cve.org
     CVE Board – https://www.cve.org/ProgramOrganization/Board 

    28 min
  • CVE Working Groups, What They Are and How They Improve CVE

    Our eighth episode is all about how community members actively engage in the six CVE Working Groups (WGs) to help improve quality, automation, processes, and other aspects of the CVE Program as it continues to grow and expand. The chairs and co-chairs of each WG, each of whom is an active member of the CVE community, chat about their WG’s overall mission, current work, and future plans.

    Discussion begins with the Transition (TWG), a temporary WG focused on managing the numerous modernization, automation, and process transitions currently underway in the CVE Program. Each of the five main WGs are then discussed in turn: Strategic Planning (SPWG), CNA Coordination (CNACWG), Quality (QWG), Automation (AWG), and Outreach and Communications (OCWG).

    How and why to participate, and the impact individuals can make on the program, are also included.

    CVE WG details and membership info – https://cve.mitre.org/working_groups.html
    CNAs – https://cve.mitre.org/cve/cna.html
    How to become a CNA – https://cve.mitre.org/cve/cna.html#become_a_cna
    CVE Board – https://cve.mitre.org/community/board/index.html
    CVE Program – https://cve.mitre.org
     

    27 min
  • Managing Modernization and Automation Changes in the CVE Program

    Episode 7 – Kelly Todd of the CVE Program speaks with Lisa Olson of Microsoft about managing the modernization and automation changes currently underway in the CVE Program. Topics include the efforts of the newly formed CVE Transition Working Group (Lisa, a CVE Board member, is co-chair); automation of CVE ID assignment and CVE Record publishing for CVE Numbering Authorities (CNAs), including the availability of free APIs and other improvements on the way; the upcoming new version release of JSON for the CVE Record format to enhance the data associated with a record; the upcoming availability of program metrics for the CVE community, as well as customized dashboards for use by CNAs; the upcoming launch of a new and more modern CVE website using a new url, cve.org; among other program improvements. In addition, Lisa discusses the benefits of partnering with the CVE Program as a CNA and of being a member of the global CNA community.

    CVE® - https://cve.mitre.org/
    Microsoft - https://www.microsoft.com/
    MSRC - https://microsoft.com/msrc
    CVE Working Groups - https://cve.mitre.org/working_groups.html
    How to become a CNA - https://cve.mitre.org/cve/cna.html#become_a_cna

    23 min
  • How the New CVE Record Format Is a Game Changer

    Episode 6 – Shannon Sabens of CrowdStrike chats with Chandan Nandakumaraiah of Palo Alto Networks about how the very basic legacy format of CVE Records is being transformed for the future by adding many new optional content fields such as multiple severity scores, credit for researchers, additional languages, ability for community contributions, etc., to make CVE Records even more valuable. The use of JSON for the new format and how that enables automation for both CNA publishers and CVE content consumers are also discussed, as are the use and availability of the CVE Program’s automated CVE Numbering Authority (CNA) tools for 24/7 CVE ID assignment, CVE Record publishing, and CVE Record updating over time. In addition, Chandan discusses the highly useful and free online Vulnogram tool for CNAs that he developed, as well as the benefits of partnering with the CVE Program as a CNA and how participating in the CVE Working Groups (WG), especially the Quality (Chandan is co-chair) and Automation WGs, helps position CVE for a more automated and productive future.
     
    CVE®  - https://cve.mitre.org/
    Palo Alto Networks - https://www.paloaltonetworks.com/ 
    CrowdStrike - https://www.crowdstrike.com/
    Vulnogram - https://vulnogram.github.io/
    How to become a CNA - https://cve.mitre.org/cve/cna.html#become_a_cna
    CVE Working Groups - https://cve.mitre.org/working_groups.html 

    26 min
  • Engaging with CVE's Automated CNA Services

    Episode 5 – David Waltermire of NVD speaks with Milind Kulkarni of NVIDIA and Kris Britton of the CVE Program to discuss the CVE Program's automated CVE Numbering Authority (CNA) services. Topics include the automation architecture being developed and deployed by the CVE Automation Working Group (AWG); the benefits of using JSON for the CVE Record format; how automation simplifies and increases the speed of CNA processes; the currently deployed CVE ID Reservation (IDR) service; the upcoming release of the CVE Record Submission and Upload (RSUS) service; and future automation plans. 

    CVE automated services on GitHub - https://github.com/CVEProject 
    CVE AWG - https://cve.mitre.org/working_groups.html#awg
    NVD - https://nvd.nist.gov/
    NVIDIA - https://www.nvidia.com/
    How to become a CNA - https://cve.mitre.org/cve/cna.html#become_a_cna

    32 min
  • Interview with Larry Cashdollar - A Researcher's Perspective

    Episode 4 – Kelly Todd of the CVE Program interviews security researcher Larry Cashdollar about how he got started researching vulnerabilities and his experiences over the years, how he became the CVE Program’s first-ever independent vulnerability researcher CVE Numbering Authority (CNA), best practices, and the benefits of being able to assign his own CVE IDs to the vulnerabilities he discovers.
     
    CVE - https://cve.mitre.org/
    Larry Cashdollar - https://twitter.com/_larry0

    21 min
  • Partnering with the CVE Program

    Episode 3 - Shannon Sabens of CrowdStrike speaks with Jo Bazar of the CVE Program, Erin Alexander of CISA ICS, and Tomo Itou of JPCERT/CC about the structure and objectives of the CVE Numbering Authority (CNA) program, what it means to be a Root and a CNA, the benefits of partnering with the CVE Program, and recommendations for organizations considering becoming a Root or CNA.
     
    CVE - https://cve.mitre.org/ 
    CISA - https://www.cisa.gov/ 
    CrowdStrike - https://www.crowdstrike.com/
    JPCERT/CC - https://www.jpcert.or.jp/vh/index.html
    How to become a CNA - https://cve.mitre.org/cve/cna.html#become_a_cna

    19 min
  • How MongoDB Manages Its CVEs

    Episode 2 - Chris Sandulow, Boris Sieklik, and Lena Smart from MongoDB discuss their internal processes for managing CVEs, the importance of CVSS scoring to their customers, the benefits experienced from partnering with the CVE Program as a CVE Numbering Authority (CNA), and recommendations for other organizations considering becoming a CNA. 

    24 min

About We Speak CVE

From the publisher's feed

A free podcast about cybersecurity, vulnerability management, and the CVE Program.

More shows like We Speak CVE

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,324 Listeners

The NPR Politics Podcast by NPR

The NPR Politics Podcast

25,759 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,010 Listeners

Uncanny Valley | WIRED by WIRED

Uncanny Valley | WIRED

506 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,055 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

Hard Fork by The New York Times

Hard Fork

5,549 Listeners