After last month's CVE funding crisis, I started talking to experts on what went wrong and what's ahead.
By the end of my interviews, I learned that a chief rival to the CISA-funded MITRE-run program, the CVE Foundation, thinks it can have a CVE database not dependent on the US government up and running by December, with the support of dozens of private sector companies and four non-US governments.
Check out my latest CyberScoop piece. Thanks to Sasha Romanosky, Peter Allor, Jerry Gamblin, Ben Edwards, Jay Jacobs and Michael Roytman for their insight.
CVE Foundation eyes year-end launch following 11th-hour rescue of MITRE program
https://cyberscoop.com/cve-program-funding-crisis-cve-foundation-mitre/
FAA Sends UAS Beyond Visual Line of Sight NPRM to OMB – https://tinyurl.com/4afbbmch #Regulation #FAA #UAS
DOT Sends UAS Flight Restriction Application NPRM to OMB – https://tinyurl.com/mrye6asc #Regulation #cUAS #FAA
CFSN Detailed Analysis - Substack Daily Update – 5-13-25 – Free Content – https://tinyurl.com/3xxc3wa5
Short Takes – 5-13-25 – Cyber hygiene for OT – PFAS reporting changes IFR – FEMA Review Council Meeting – Aircraft and parts §232 investigation – Library of Congress conflict – EUVD – Roberts on MAGA vs Courts – https://tinyurl.com/8vxtcms
Review – 4 Advisories Published – 5-13-25 – NCCIC-ICS control system security advisories for products from ABB and Hitachi Energy (3) – Short version – https://tinyurl.com/yzxswvaz #icsSecurity
4 Advisories Published – 5-13-25 – NCCIC-ICS control system security advisories for products from ABB and Hitachi Energy (3) – I also look at recent change in CISA cybersecurity information distribution – https://tinyurl.com/nhte3bet Subscription required #icsSecurity
FortiGuard published 5 cybersecurity advisories and 7 updates - https://www.fortiguard.com/psirt
Schneider published 5 cybersecurity advisories and 3 updates - https://www.se.com/ww/en/work/support/cybersecurity/security-notifications.jsp NOTE: 1 is not listed on the Schneider site.
Today Siemens published 18 cybersecurity advisories and 15 updates – https://www.siemens.com/global/en/products/services/cert.html
Review – Bills Introduced – 5-12-25 – 17 bills – S 1708, improved rulemaking – Short version – https://tinyurl.com/4ew99n98 #Legislation
Bills Introduced – 5-12-25 – 17 bills – S 1708, improved rulemaking – MIP: S 1711, Chinese automotive technology – https://tinyurl.com/yvxtb8ts Subscription required #Legislation
CFSN Detailed Analysis - Substack Daily Update – 5-12-25 – Free Content – https://tinyurl.com/mr26yktr
Short Takes – 5-12-25 – Small business tariff fallout – NASA budget cuts have international fallout – DOGE spending controls – More flight disruptions probable – https://tinyurl.com/mr3kxdz3
Review – S 1249 Introduced – UAS Zoning Authority – Would provide some State and local government authority of UAS operations – Short version – https://tinyurl.com/3vxnsk46 #Legislation #UAS
Review – Committee Hearings – Week of 5-11-25 – Budget and Reconciliation dominating – DOD space operations – Reauthorization hearings on CISA information sharing, pipeline safety and FAA – Short version – https://tinyurl.com/4h76nrv9 #Hearings
Committee Hearings – Week of 5-11-25 – Budget and Reconciliation dominating – DOD space operations – Reauthorization hearings on CISA information sharing, pipeline safety and FAA – https://tinyurl.com/47d6fyju Subscription required #Hearings
CFSN Detailed Analysis - Substack Daily Update – 5-10-25 – Free Content – https://tinyurl.com/2suhnvuy
Short Takes – 5-10-25 – FAA report on Starship launch expansion – Polio related news – Measles outbreak – Gain of function EO - https://tinyurl.com/2583at5d
@azonenberg @gsuberland I saw a teardown of a disposable vape a while back. This thing was a full fledged Android device, with WiFi and Bluetooth, and the ability to install apps. You could tether it to your phone, listen to music, take phone calls ... and then bin it when the battery went flat.
Of course it also had the all-important GPIO + power transistor to let it dump a pile of energy into a low impedance load on demand ... almost like it was designed to be a perfect trigger for an IED.