Hi folks,
Quite a few articles relating to the US government, the UN, and state-sponsored hacking this week. It's not unusual these days, but it definitely wasn't the case when I started the newsletter. It's interesting to see how, ten years or so ago, cybersecurity was a rather niche topic to the outside world. Where as now it's often front-and-center on the geopolitical stage. We have a ways to go, but at least the world's awareness has grown significantly.
With those ponderings of yours truly aside, enjoy the read my friends :-)
Cheers,
The National Vulnerability Database (NVD) is the central database where detailed information on vulnerabilities is analysed and offered for free. It's where CVE numbers come from, essentially, and a whole lot of security vendors rely on this information. I used it myself for several projects.
Lately, however, the NVD has mostly stopped adding new information, and nobody really knows why. The article explains some of the background on this, but we still don't know much. It seems to boil down to increased workload and stagnant budget, as I read it, which is understandable. The amount of CVE's has ballooned over the last few years, I always wondered how the NVD managed to keep up. I guess they can't anymore.
In order to fix the problems though, the head of the NVD wants to create a "consortium" of partners to tackle the issues as a group. This has led to criticism however, since adding more layers is not often the answer to productivity issues. To be continued.