Wade Hansen, MBA⚡️’s Post

View profile for Wade Hansen, MBA⚡️, graphic

USAF Intel Vet | Problem Solver | Partnership Builder

Vulnerability management is tough duty This article enumerates deficiencies in relying on a single, government-funded repository for vulnerability intelligence. The private sector is a better option. "The danger in having a central database of vulnerabilities is that it focuses attention on the content. ‘Vulnerabilities and their details can be found here.’ By implication, if a vulnerability isn’t included, it isn’t a vulnerability. This is simply wrong. Threat intelligence firm Flashpoint noted in March 2024 it was aware of 100,000 vulnerabilities with no CVE number and consequently no inclusion in NVD. More worryingly, it said that 330 of these vulnerabilities (with no CVE number) had been exploited in the wild."

CVE and NVD - A Weak and Fractured Source of Vulnerability Truth

CVE and NVD - A Weak and Fractured Source of Vulnerability Truth

securityweek.com

To view or add a comment, sign in

Explore topics