I am a Vulnerability Analyst at the National Institute of Standards and Technology (NIST). There were 28,961 new CVEs published last year. I processed eleven per week.
I need to explain what enrichment is because, without it, the rest of this does not matter. A CVE is a numeric identifier that catalogs a new software vulnerability.
A CVE without enrichment is a number. CVE-2026-XXXXX. The number tells you a vulnerability exists. It does not tell you the severity. It does not tell you which products are affected. It does not tell you the attack vector. It doesn't indicate whether to patch on Tuesday or now. Every CISO in the country builds their patch-priority list using our enrichment data. We are the triage. Without us, the number is a fire alarm with no address.
28,961 alarms. I got to 572.
Every morning I open the queue. The queue is a spreadsheet. It was a spreadsheet when I started, and it is a spreadsheet now. Monday's queue has between 70 and 130 new entries, depending on whether someone found a batch of WordPress plugins over the weekend. I scroll to the top. I pick two. Sometimes three, if one is straightforward. I assign them to myself. I open the enrichment template. I begin.
The other 70 stay in the queue. Tuesday, they will be joined by 70 more. I will pick two.
The page looks the same.
I want to say that clearly. The NVD website, the one bookmarked on every security team's browser in every hospital and bank and water treatment plant and power utility in the country, loads the same way it loaded in 2023. Same interface. Same search. Same logo. There is no banner that says "this data is no longer current." There is no warning. There is no asterisk. The security team at a hospital in Ohio who checks NVD at 7 AM to decide which of their 340 unpatched systems to prioritize today is making life-and-death triage decisions using a database that stopped being maintained. They do not know it stopped being maintained.
The page looks the same.
We have not been defunded. I want to be precise about that. We have been "deprioritized." Our headcount has been "reallocated to other initiatives." Four analysts were moved to the AI Safety Measurement Initiative in January. AI safety measurement is the initiative that has funding. CVE enrichment is the initiative that protects the hospitals. The hospitals do not have an initiative.
My manager told me in February that we are "transitioning to a community-driven enrichment model." Community-driven means that vendors whose products have vulnerabilities will self-report the severity of those vulnerabilities. I sat in that meeting. I wrote it down. Oracle will now assess the criticality of its vulnerabilities. Microsoft will now assess how urgent it is to patch Microsoft. The fox will now audit the henhouse and submit the findings in JSON.
I still have my badge. I still have my login. I still open the spreadsheet. I still pick two. The queue has 9,247 unenriched CVEs as of this morning. Some of them are critical. I do not know which ones because they have not been enriched. That is what unenriched means. It means we do not know how dangerous they are because we stopped analyzing how dangerous they are.
The page looks the same.
The system that catalogs broken systems is itself broken. I catalog the brokenness. I have been cataloging it at a rate of two per day. At this rate, I will finish the current backlog in twelve years and seven months, not accounting for the 80 new entries that will arrive tomorrow, and the 80 after that, and the 80 after that.
I am a Vulnerability Analyst at the National Institute of Standards and Technology.
The page looks the same.
The data doesn't. Nobody told the hospitals.
That is my job. I am also not doing that.
(1/4) It has risen...
After 25 years of being locked away behind some of the most insane software/hardware protection I've ever seen for a $25 unlicensed console accessory, SEGA Dreamcast's DreamMovie has been unlocked, and is available for all!
DOWNLOAD
https://t.co/bNMs0XzWC0
Most hashing algorithms are designed to avoid collisions.
What if they weren’t?
Locality-sensitive-hashing (LSH) is a way to group similar inputs into the same “buckets” with high probability.
Collisions are maximized, not minimized.
If you have an .io domain you should read this.
When the British government announced last week that it was transferring sovereignty of an island in the Indian Ocean to the country of Mauritius, Gareth immediately realized its online implications: the end of the .io domain suffix. https://t.co/oyMCZQ6U3i
Mi querido Jorge Ramió da en abierto una masterclass sobre RSA. Os dejo por aquí los detalles para inscribiros :)
Masterclass sobre RSA del Dr. Jorge Ramió
Hola a tod@s:
Ya tenemos fecha para el Webinar "Curiosidades y sorpresas en las claves y la cifra con RSA" que no pude presentar en septiembre. Será este próximo martes 15 de octubre a las 16:30 horas de Chile (21:30 horas en España).
Web de la Masterclass:
https://t.co/k9Nrv7Sdm5
La inscripción es gratuita.
Para inscribirte, por favor accede a este link:
https://t.co/AZKMO4ru6h
¡Te espero!
Interested in some instructor led training covering the Azure security AZ-500 content? Thanks to a combination of Microsoft staff and our MCTs a collection of 17 videos is now available for free for you to get across the content - https://t.co/jxoKY5Sflu
Telegram no usa cifrado extremo a extremo (cloud chats). No es una aplicación recomendable si buscas confidencialidad de la información, pero... quizás te estés preguntando que pasa con los chat secretos. Hoy voy a hablar de algunas características menos conocidas...
1. Las diferentes funcionalidades criptográficas en Telegram están soportadas mediante el protocolo MTProto V2 - https://t.co/1PTCOf7Ih2
2. Los chat secretos definen una funcionalidad que permite establecer, cuando se fuerza un chat secreto, comunicaciones cifradas extremo a extremo entre dos interlocutores.
3. Se utiliza el algoritmo Diffie-Hellman para el intercambio de claves criptográficas que "protegerán" la información del chat secreto y los ficheros intercambiados en él.
4. Los servidores de Telegram siempre están en medio de la comunicación, incluido durante la negociación de las claves criptográficas. Los servidores obtienen una gran cantidad de información de metadatos: quién se conecta, cuándo se conecta, tamaño y tipo de archivos almacenados/intercambiados, etc.
5. Telegram proporciona los parametros g y p del algoritmo Diffie-Hellman. Lo interesante de estos valores es que no han cambiado en los últimos 7 años para cualquier canal secreto que se haya creado (https://t.co/vsLyOQcPst). ¿Es esto un problema de seguridad? Bueno, .... para empezar es una muy mala práctica criptográfica y segundo puede alimentar dudas sobre su generación o al ser valores fijos se pueda diseñar mecanismos específicos para acelerar el descifrado de Diffie-Hellman solo para esos valores y obtener las claves de cifrado intercambiadas.
Telegram es muy útil para muchas cosas pero en ninguna modalidad disponible debe utilizarse con garantías de confidencialidad. En este enlace te dejo más detalles de una investigación detallada que hice algún tiempo @rootedcon - https://t.co/Kopv2vZY9p
Este es uno de los diferentes ejemplos que incluyo en mi nuevo libro por si te interesa todo lo relacionado con la criptografía aplicada - https://t.co/MnBpol1RtY
The very awesome people from Microsoft DART have put together a collection of one-page Windows forensics guides to help you understand various artefacts you can use during your investigations. Check them out - https://t.co/HhBI1A6Rgt
The xz package tar's were backdoored. Only discovered because the backdoor slowed down sshd enough for Andres Freund to investigate.
Consider the case where the backdoor didn't cause perf issues... How long would this have gone undetected?
https://t.co/qO05dVP7vU
One of the most important skills in #DFIR is using a hex-editor. Therefore, I created a 40+ video series on how to use 010-editor, which is probably the best Hex Editor out there!
https://t.co/DqE1eo2pzh
@MikePBurgess While the terrorism threat level is POSSIBLE, if we had a threat level for espionage and foreign interference it would be at CERTAIN – the highest level on the scale.
We're naming names 🔥 because the harm is not hypothetical.
Today we share "Buying Spying", our new report diving into the commercial surveillance/spyware industry. We dive into the players, the campaigns, the spyware, & the harm it perpetuates.
https://t.co/D8Lx4wRrw6
1/ A technical writeup on @Meta’s @WhatsApp privacy issue:
WA leaks victim devices’ end-to-end encryption (E2EE) identity information (mobile device + up to 4 linked devices) to any user, by design, even if blocked and not in contacts.
https://t.co/ONmcdC3ZqC