Tuesday, 17 Jun 2025
  • My Feed
  • My Interests
  • My Saves
  • History
  • Blog
Subscribe
News Outlet
  • Home
  • Opinion

    Ex-Fox News star Steve Hilton launches run for governor in California with goal of taking on Kamala Harris

    By
    Lawanda Howe

    Memo to indies: Here’s how you can major party-proof politics for decades

    By
    Bernard Keane

    Joe Biden should stay out of politics for the good of his party, says former aide to Jill

    By
    Rhian Lubin

    As strongmen rhetoric infects our politics, has Andrew Tate’s gateway content helped pave the way?

    By
    Caroline Zielinski

    Mike Berners-Lee: Why dishonesty is destroying the planet | WTCTW Podcast

    By
    Johnathon Menjivar

    ‘You have to accept her life is not her own’: Ruth Davidson and partner Jen reflect on life in politics

    By
    Luz Drews
  • Politics
    The politics behind Starmer’s decision to scrap NHS England

    The politics behind Starmer’s decision to scrap NHS England

    By
    Elida Michaud
    Electioncast: Three battleground seats to watch

    Electioncast: Three battleground seats to watch

    By
    Crystal Andrews
    Politics LIVE: Keir Starmer warns businesses of ‘economic impact’ from Trump tariffs

    Politics LIVE: Keir Starmer warns businesses of ‘economic impact’ from Trump tariffs

    By
    Clora Lupo
    Séance politics: Is it unpatriotic for Turnbull to question AUKUS?

    Séance politics: Is it unpatriotic for Turnbull to question AUKUS?

    By
    Bernard Keane
    What does the Le Pen verdict mean for the future of French politics?

    What does the Le Pen verdict mean for the future of French politics?

    By
    Diego Wrona
    Don’t panic! But there’s young women with phones in Parliament! And it creates a better politics

    Don’t panic! But there’s young women with phones in Parliament! And it creates a better politics

    By
    Holly Rankin
  • Health
    Knots Landing star tragically dies aged 63

    Knots Landing star tragically dies aged 63

    By
    Lyndia Redner
    Blake Lively and Ryan Reynolds’ lookalike family member steals the show at star-studded gala

    Blake Lively and Ryan Reynolds’ lookalike family member steals the show at star-studded gala

    By
    Nancie Pekar
    Demi Moore showcases incredibly slender frame after revealing she ‘tortured’ her body

    Demi Moore showcases incredibly slender frame after revealing she ‘tortured’ her body

    By
    Gaylene Motsinger
    Six Million Dollar Man Lee Majors turns 86

    Six Million Dollar Man Lee Majors turns 86

    By
    Rebecka Stoval
    Former NBA star revealed as the world’s highest paid athlete — despite retiring years ago

    Former NBA star revealed as the world’s highest paid athlete — despite retiring years ago

    By
    Tyisha Kazmierczak
    ‘Divine’ Tom Ford perfume that ‘receives so many compliments’ now £62 in flash sale

    ‘Divine’ Tom Ford perfume that ‘receives so many compliments’ now £62 in flash sale

    By
    Georgianna Drews
  • Business
    California Overtakes Japan to Become World’s Fourth-Largest Economy — But Challenges Loom

    California Overtakes Japan to Become World’s Fourth-Largest Economy — But Challenges Loom

    By
    Raleigh Paris
    Nissan Bleeds $5.26 Billion in Losses: Why The Japanese Automaker Is Struggling to Restructure

    Nissan Bleeds $5.26 Billion in Losses: Why The Japanese Automaker Is Struggling to Restructure

    By
    Alejandro Pekar
    Pope Francis’s Death Sparks Frenzy For Papal Thrillers — Why Millions Are Watching ‘Conclave’

    Pope Francis’s Death Sparks Frenzy For Papal Thrillers — Why Millions Are Watching ‘Conclave’

    By
    Tama Lupo
    Quick Facts About Leanna Lenee: Age, Career, Relationship with Travis Hunter, and More

    Quick Facts About Leanna Lenee: Age, Career, Relationship with Travis Hunter, and More

    By
    Bong Mongold
    ‘Final Wish’: Heartwarming Reason Why Pope Francis Chose Santa Maria Maggiore For His Burial

    ‘Final Wish’: Heartwarming Reason Why Pope Francis Chose Santa Maria Maggiore For His Burial

    By
    Tomi Kazmierczak
    China Will Teach Kids AI Across the Country

    China Will Teach Kids AI Across the Country

    By
    Laine Grumbles
  • 🔥
  • Business
  • Marketing
  • Investment
  • World
  • Health
  • Discover
  • Politics
  • Opinion
  • Innovation
Font ResizerAa
News OutletNews Outlet
  • My Saves
  • My Interests
  • My Feed
  • History
  • Travel
  • Opinion
  • Politics
  • Health
  • Technology
  • World
Search
  • Personalized
    • My Feed
    • My Saves
    • My Interests
    • History
  • Bookmarks
  • News
    • Opinion
    • Politics
    • Technology
    • Travel
    • Health
    • World
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
InnovationScienceTechnology

CVE fallout: The splintering of the standard vulnerability tracking system has begun

Jessica Lyons
Last updated: April 18, 2025 9:54 am
Jessica Lyons
Share
CVE fallout: The splintering of the standard vulnerability tracking system has begun
SHARE

Comment The splintering of the global system for identifying and tracking security bugs in technology products has begun.

Earlier this week, the widely used Common Vulnerabilities and Exposures (CVE) program faced doom as the US government discontinued funding for MITRE, the non-profit that operates the program. Uncle Sam U-turned at the very last minute, and promised another 11 months of cash to keep the program going.

Meanwhile, the EU is rolling its own.

The European Union Agency for Cybersecurity (ENISA) developed and maintains this alternative, which is known as the EUVD, or the European Union Vulnerability Database. The EU mandated its creation under the Network and Information Security 2 Directive, and ENISA announced it last June.

The EUVD is similar to the US government’s NVD, or National Vulnerability Database, in that it organizes disclosed bugs by their CVE-assigned unique ID, documents their impact, and links to advisories and patches.

Interestingly, the Euro database also uses its own EUVD IDs to track security bugs as well as CVE-managed identifiers and GSD IDs, the latter of which are issued by the (what appears to be now-defunct) Global Security Database operated by the Cloud Security Alliance.

Although the EUVD has been gestating for nearly a year, the uncertainty around the CVE program is set to push the European effort into the spotlight as a replacement, fallback, or alternative for CVE. ENISA is, we note, a partner of CVE; specifically, it’s a CVE numbering authority.

“The objective of the EUVD is to ensure a high level of interconnection of publicly available information coming from multiple sources,” a spokesperson for ENISA told us. “The EUVD is in beta version, so due to testing you might find it offline at certain times, and will launch publicly soon. ENISA is working with EU member states and the European Commission on a way forward to ensure the resilience of the vulnerability systems.”

The EUVD “will hopefully gain more traction so that Europe can achieve self-sustainability in this domain as well,” Marcus Söderblom, an infosec consultant at IT services giant Atea said this week.

Ben Radcliff, senior director of cyber operations at infosec services provider Optiv, told The Register Thursday that the CVE funding fiasco revealed a serious flaw: Dependence on the largesse of a single, and now volatile, government.

“Continued dependency on funding from CISA might put pressure on the organization to act and operate with less impartiality and political agnosticism,” he added. “One of the key promises of EUVD is that it will be multi-nationally sponsored, ostensibly avoiding that pitfall.”

Or, it could present another pitfall: Separate bug tracking systems for the US and Europe. Like imperial versus metric, only worse.

“While it’s likely that there will be coordination between the US NVD and the EUVD such that records available in one database mirror those in the other, I do expect that regional regulatory governance will tend to favor one vulnerability database over another,” Tim Mackey, head of software supply chain risk strategy at app security firm Black Duck, told The Register.

The timing of the EU database’s emergence “cannot be ignored as a coincidence,” Flashpoint vulnerability analyst Brian Martin said on a Thursday webinar. “To me, it signals a global lack of trust in the US government’s commitment to ensuring the continuity of CVE.”

Meanwhile, another “global” system for identifying and numbering security flaws, the Global CVE Allocation System or GCVE, sprang from CVE’s almost-ashes. “But that essentially looks like it’s one person on a GitHub project,” Martin said.

In addition to these two, there’s also the new CVE Foundation, a non-profit formed to bring the CVE program under its auspices and eliminate a “single point of failure in the vulnerability management ecosystem.”

And, of course, MITRE will continue operating the CVE program per usual under its contract with the Feds — at least for the next 11 months.

“There’s no understanding or guarantee about what will happen after that point,” Flashpoint vulnerability analyst Kecia Hoyt said on the webinar. “Maybe we can go enjoy our weekend at this point, but I don’t want to be here having this conversation a year from now, and nothing’s changed.” 

What’s in a name?

Having a standardized system for identifying vulnerabilities is extremely important, and helps keep everyone — companies, vulnerability researchers, developers, governments — on the same page. If someone says CVE-2017-5754, for example, there’s no question they are talking about Intel’s Meltdown, which did also show up in a handful of Arm CPU cores.

This common language helps avoid what we currently have with cybercrime-groups, where various government agencies and private-sector threat intel firms all have their own naming conventions — is it Cozy Bear, Midnight Blizzard, or APT 29? And how loosely linked are Salt Typhoon, Famous Sparrow, and Earth Estries? 

“I say Scattered Spider, you say Oktapus,” Hoyt said, referring to two names for the collective of what’s suspected to be young US and UK criminals known for their ransomware heists of Las Vegas casinos.

  • CVE program gets last-minute funding from CISA – and maybe a new home
  • Uncle Sam kills funding for CVE program. Yes, that CVE program
  • Europe’s cloud customers eyeing exit from US hyperscalers
  • EU may target US tech giants in tariff response
  • Time to ditch US tech for homegrown options, says Dutch parliament
  • Euro techies call for sovereign fund to escape Uncle Sam’s digital death grip

“There’s a whole lot of different terminology thrown around, and are we talking about the same thing? Does this report equal that report? That’s really what CVE and did for the vulnerability space,” she added.

So now the question becomes: Will someone, a government, or a collective industry group, step in and provide a more permanent, universal system? Or will the entire vulnerability management system break off into a million pieces with companies, governments, and community-based orgs all naming and tracking vulnerabilities independently of each other. And if that’s the case: Who to trust?

“Having an independent government solution for this vulnerability catalog, versus a larger corporate or global organization, might seem like a good idea,” Hoyt said, but added that “the former creates that single point of failure we’re all experiencing.” 

However, putting a large company or even a coalition of tech giants in charge means “the possibility of bias and jeopardizing neutrality,” she noted. ®

Read More

Share This Article
Email Copy Link Print
Previous Article From Gift to Abandoned Pet: Why This Major UK Pet Chain Is Taking Rabbits Off Shelves This Easter From Gift to Abandoned Pet: Why This Major UK Pet Chain Is Taking Rabbits Off Shelves This Easter
Next Article Katy Perry’s Two Biggest Regrets After Blue Origin Flight: ‘I Should’ve Kept It Private’ Katy Perry’s Two Biggest Regrets After Blue Origin Flight: ‘I Should’ve Kept It Private’
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recipe Rating




Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
XFollow
InstagramFollow
LinkedInFollow
MediumFollow
QuoraFollow
- Advertisement -
Ad image

You Might Also Like

RIP, Google Privacy Sandbox
InnovationScienceTechnology

RIP, Google Privacy Sandbox

By
Thomas Claburn
Hisense QLED TVs are just LED TVs, lawsuit claims
InnovationScienceTechnology

Hisense QLED TVs are just LED TVs, lawsuit claims

By
Thomas Claburn
Euro techies call for sovereign fund to escape Uncle Sam’s digital death grip
InnovationScienceTechnology

Euro techies call for sovereign fund to escape Uncle Sam’s digital death grip

By
Dan Robinson
We heard you like HBM – Nvidia’s Blackwell Ultra GPUs have 288 GB of it
InnovationScienceTechnology

We heard you like HBM – Nvidia’s Blackwell Ultra GPUs have 288 GB of it

By
Tobias Mann
News Outlet
Facebook Twitter Youtube Rss Medium

About US


News Outlet : Your instant connection to breaking stories and live updates. Stay informed with our real-time coverage across politics, tech, entertainment, and more. Your reliable source for 24/7 news.

Top Categories
  • World
  • Opinion
  • Politics
  • Tech
  • Health
  • Travel
Usefull Links
  • Advertise with US
  • Complaint
  • Privacy Policy
  • Cookie Policy
  • Submit a Tip

© 2025 News Outlet Network.  All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?