S6E11: Josh Bressers & Dan Lorenc - Untangling the NVD Chaos
Mar 22, 2024
auto_awesome
Experts discuss the drama around NVD and its impact on vulnerability management. They highlight concerns about lack of CVE enrichment and the grassroots effort to raise awareness. The podcast explores the underfunding and oversight of critical software ecosystem components. Future solutions from NIST/NVD, government, and industry are discussed to resolve the issue.
The delay in enriching CVEs by NVD impacts severity scores and product data, disrupting the vulnerability ecosystem.
Open source initiatives are filling gaps in vulnerability data, emphasizing community collaboration to improve matching logic and enhance cybersecurity infrastructure.
Deep dives
The Importance of Cyber Resilience
Cybersecurity professionals emphasize the significance of systems that can endure a diverse threat landscape by remaining trustworthy and secure to withstand cyber incidents.
Challenges with National Vulnerability Database (NVD)
There is concern over the NVD's delay in enriching CVEs, impacting severity scores and affected products data, leading to challenges in matching vulnerabilities and causing disruptions in the vulnerability ecosystem.
Open Source Solutions in Vulnerability Management
Efforts are underway in open source to address gaps left by NVD's hiatus, focusing on leveraging open source tools and community collaboration to augment vulnerability data and address matching logic issues.
Call for Collaboration and Industry Contributions
Amidst the complexity and challenges in the vulnerability management landscape, a plea for patience, understanding, and proactive involvement is made to help improve and reinforce critical cybersecurity infrastructure for a more resilient future.
- First off, for folks that don't know you can you give them a brief overview of your background/organizations?
- Josh, let's start with you. Can you explain some of what is going on with the drama around NVD and what happened that caught everyone's attention?
- Dan - I know you've raised concerns around the implications for the community when it comes to the lack of CVE enrichment, how do you see this impacting the vulnerability management ecosystem?
- Josh - Your team has started providing some accompanying resources to try and address the gap, can you tell us a bit about that?
Dan - You've spun up an open letter to congress and have kicked off a bit of a grass roots effort to raise awareness around the problem. How is it going so far and what are you hoping to accomplish with the letter?
- Why do you both think this is such a big deal, and how can something so critical to the entire software ecosystem be so underfunded, overlooked and taken for granted?
- What are some things you all hope to see in the future to resolve this, both from NIST/NVD and the Government but also from industry as well?
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode