|
|
Log in / Subscribe / Register

CISA extends funding to the CVE program (BleepingComputer)

Sergiu Gatlan reports that the US government has extended funding for the Common Vulnerabilities and Exposures (CVE) program, following yesterday's reports that funding would run out as of April 16.

"The CVE Program is invaluable to cyber community and a priority of CISA," the U.S. cybersecurity agency told BleepingComputer. "Last night, CISA executed the option period on the contract to ensure there will be no lapse in critical CVE services. We appreciate our partners' and stakeholders' patience."

The article also mentions the launch of a CVE Foundation, to transition the CVE program to a dedicated foundation and eliminate "a single point of failure in the vulnerability management ecosystem", as well as a European vulnerability database (EUVD) backed by the European Union Agency for Cybersecurity (ENISA). Details on these initiatives are scant at the moment, and it is unclear whether restoration of funding will have any impact on these efforts.



to post comments

Cannot depend on a single government anymore

Posted Apr 16, 2025 17:45 UTC (Wed) by proski (guest, #104) [Link] (2 responses)

The US government wants to be that random person in Nebraska from https://xkcd.com/2347/

Now it's time to check if any worldwide digital infrastructure depends on any service financed by the US government and create replacements that cannot be yanked overnight in the name of "efficiency".

Cannot depend on a single government anymore

Posted Apr 17, 2025 8:32 UTC (Thu) by Lennie (subscriber, #49641) [Link] (1 responses)

The way would say it: the US _wanted_ to be the random person in Nebraska, so they can have the most influence on it and not create a dependence on others. The current administration seems to think the US should not do this. I personally think it's not a smart move, but I'm fine with things become less dependent on a single player.

I was wondering about buoys in the oceans used to detect earthquakes (and thus tsunamis) and organizations like U.S. Geological Survey who collect the data and make it available (to the world), there are other countries around the world who do this, but I don't know how complete their information is.

Cannot depend on a single government anymore

Posted Apr 17, 2025 9:34 UTC (Thu) by MortenSickel (subscriber, #3238) [Link]

For the last part, the CTBTO's (Comprehensive Test Ban Treaty Organisation) data from seismology and hydrophones has also been used for tsunami warning for the last years
.
(And to make it a bit more relevant, they are using linux for their server systems and are developing linux software for data analysis and management for their waveform (Seismology, infrasound and hydrophones) and radionuclide technologies.)


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds