-
19 votes
-
Cancellations of Chinese freight ships begin as bookings plummet
8 votes -
MITRE support for the Common Vulnerabilities and Exposures (CVE) program will expire tomorrow
A letter to CVE board members posted to bluesky a few hours ago reveals that MITRE funding for the Common Vulnerabilities and Exposures (CVE) program is about to expire. Haven't found any good...
A letter to CVE board members posted to bluesky a few hours ago reveals that MITRE funding for the Common Vulnerabilities and Exposures (CVE) program is about to expire. Haven't found any good articles that cover this news story yet, but it's spreading like wildfire over on bluesky.
Of course this doesn't mean that the CVE program will immediately cease to exist, but at the moment MITRE funding is absolutely essential for its longterm survival.
In a nutshell CVEs are a way to centrally organize, rate, and track software vulnerabilities. Basically any publicly known vulnerability out there can be referred to via their CVE number. The system is an essential tool for organizations worldwide to keep track of and manage vulnerabilities and implement appropriate defensive measures. Its collapse would be devestating for the security of information systems worldwide.
How can one guy in a position of power destroy so much in such a short amount of time..? I hope the EU will get their shit together and fund independent alternatives for all of these systems being butchered at the moment...
Edit/Update 20250415 21:10 UTC:
It appears Journalist David DiMolfetta confirmed the legitimacy of the letter with a source a bit over an hour ago and published a corresponding article on nextgov 28 minutes ago.Edit/Update 20250415 21:25 UTC:
Brian Krebs also talked to MITRE to confirm this news. On infosec.exchange he writes:I reached out to MITRE, and they confirmed it is for real. Here is the contract, which is through the Department of Homeland Security, and has been renewed annually on the 16th or 17th of April.
MITRE's CVE database is likely going offline tomorrow. They have told me that for now, historical CVE records will be available at GitHub, https://github.com/CVEProjectEdit/Update 20250415 21:37 UTC:
Abovementioned post has been supplemented by Brian Krebs 5 Minutes ago with this comment:Hearing a bit more on this. Apparently it's up to the CVE board to decide what to do, but for now no new CVEs will be added after tomorrow. the CVE website will still be up.
Edit/Update 20250416 08:40 UTC:
First off here's one more article regarding the situation by Brian Krebs - the guy I cited above, as well as a YouTube video by John Hammond.In more positive news: first attempts to save the project seem to emerge. Tib3rius posted on Bluesky about half an hour ago, that a rogue group of CVE board members has Launched a CVE foundation to secure the project's future. It's by no means a final solution, but it's at least a first step to give some structure to the chaos that has emerged, and a means to manage funding from potential alternative sources that will hopefully step up to at least temporarily carry the project.
Edit/Update 20250416 15:20 UTC:
It appears the public uproar got to them. According to a nextgov article by David DiMolfetta the contract has been extended by 11 months on short notice just hours before it expired...Imo the events of the past 24 hours will leave their mark. It has become very clear that relying on the US government for such critical infrastructure is not a sustainable approach. I'm certain (or at least I hope) that other governments (i.e. EU) will draw appropriate consequences and build their own infrastructure to take over if needed. The US is really giving up their influence on the world at large at an impressive pace.
55 votes -
US Veterans Affairs mental health therapists’ script: ‘I cannot guarantee complete confidentiality’
24 votes -
Apple airlifts 600 tons of iPhones from India 'to beat' Donald Trump tariffs, sources say
18 votes -
Explaining the Donald Trump tariff in the US
18 votes -
Second measles death reported in Texas
41 votes -
Second child dies in US measles outbreak as cases continue to rise
9 votes -
The new US tariffs - weird formulas, risks, and the coming trade war
34 votes -
‘The terror is real’: an appalled US tech industry is scared to criticize Elon Musk
36 votes -
Romance author Ali Hazelwood cancels UK tours over doubt she could 'safely' return to US
23 votes -
President Donald Trump's tariff formula contains math error that mistakenly quadruples rate on every country, says American Enterprise Institute
43 votes -
Nintendo delays Switch 2 pre-orders in US due to tariffs and "evolving market conditions"
45 votes -
Denmark's Maersk buys Panama Canal railway – deal loosens US control of train link at a time when Donald Trump is seeking to ‘take back’ trade waterway
16 votes -
How have US food prices changed? Our tracker can give you a sense.
13 votes -
Thanks to recent US law, Elon Musk and Taylor Swift can now hide details of their private jets
29 votes -
What is the truth about risks and benefits of seed oils?
19 votes -
As NASA faces cuts, China reveals ambitious plans for planetary exploration
16 votes -
Delete the workforce
11 votes -
US government workers and military planners love Signal now
30 votes -
Denmark issues a new travel advisory for the US that warns transgender and non-binary people to contact the American embassy before departure
25 votes -
US federal judge blocks Donald Trump administration from banning transgender people from military service
33 votes -
From Stonewall to now: US LGBTQ+ elders on navigating fear in dark times
25 votes -
Wyoming pays $150,000 to settle lawsuit over botched prosecution of hemp farmers
12 votes -
You can join thousands telling US President Donald Trump what they think of his anti-trans passport policies. Here’s how.
19 votes -
Donald Trump says he opened California’s water. Local officials say he nearly flooded them.
30 votes -
From Tuberculosis to HIV/AIDS to cancer, disease tracking has always had a political dimension, but it’s the foundation of US public health
9 votes -
Robert F. Kennedy Jr. and US influencers bash seed oils, baffling nutrition scientists
52 votes -
Tariffs do not in general help trade deficits
25 votes -
US Department of Justice again files demand to break up Google’s search monopoly
27 votes -
Utah becomes first US state to pass bill making app stores verify ages - Governor has not yet signed the bill
18 votes -
US tariff war risks sinking world into new Great Depression, International Chamber of Commerce warns
57 votes -
Diversity, Equity, and Inclusion is disappearing in Hollywood. Was it ever really here?
9 votes -
Robert F. Kennedy, Jr.: Texas measles outbreak is call to action for all of us. MMR vaccine is crucial to avoiding potentially deadly disease.
34 votes -
Billed as promoting European products rather than boycotting US ones, Danish supermarket chain Salling Group has a special label for goods from Europe during March
24 votes -
Across the world, conservation projects reel after abrupt US funding cuts
10 votes -
Under Donald Trump, US government scientists told they need clearance to meet with Canadian counterparts
23 votes -
Those of us who work in gender medicine are not going anywhere
19 votes -
Top American banks have left the net zero climate alliance
20 votes -
US documents say Project 2025’s creators The Heritage Foundation want to dox Wikipedia’s volunteer editors of pages related to Palestine conflict using powerful tools
33 votes -
In the US, multi-level barrage of book bans is ‘unprecedented’, says PEN America
15 votes -
The full story of the US Federal Aviation Administration's hiring scandal
15 votes -
US President signs order restricting gender-affirming treatments for anyone under 19
42 votes -
National Science Foundation freezes grant review in response to US President Donald Trump executive orders
13 votes -
Donald Trump signs actions to pull US out of Paris climate agreement, intends to promote fossil fuels and mineral mining
32 votes -
NASA moves swiftly to end Diversity, Equity, and Inclusion programs, ask US employees to “report” violations
30 votes -
National Institutes of Health ordered by US President Trump admin to enact 'immediate and indefinite' travel suspension
37 votes -
US President Donald Trump’s gender order won’t affect existing passports — unless they’re renewed
16 votes -
US President Donald Trump to issue executive orders to end birthright citizenship, limit gender identity — incoming official
67 votes -
Patrick Radden Keefe: Author of Say Nothing and Empire of Pain talks about journalism career, upcoming TV series, and covering Donald Trump as a journalist
6 votes