Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 19 submissions in the queue.
posted by hubie on Saturday May 17 2025, @02:50PM   Printer-friendly

Arthur T Knackerbracket has processed the following story:

The European Vulnerability Database (EUVD) is now fully operational, offering a streamlined platform to monitor critical and actively exploited security flaws amid the US struggles with budget cuts, delayed disclosures, and confusion around the future of its own tracking systems.

As of Tuesday, the full-fledged version of the website is up and running.

"The EU is now equipped with an essential tool designed to substantially improve the management of vulnerabilities and the risks associated with it," ENISA Executive Director Juhan Lepassaar said in a statement announcing the EUVD. 

"The database ensures transparency to all users of the affected ICT products and services and will stand as an efficient source of information to find mitigation measures," Lepassaar continued.

The European Union Agency for Cybersecurity (ENISA) first announced the project in June 2024 under a mandate from the EU's Network and Information Security 2 Directive, and quietly rolled out a limited-access beta version last month during a period of uncertainty surrounding the United States' Common Vulnerabilities and Exposures (CVE) program

More broadly, Uncle Sam has been hard at work slashing CISA and other cybersecurity funding while key federal employees responsible for the US government's secure-by-design program have jumped ship

Plus, on Monday, CISA said it would no longer publish routine alerts - including those detailing exploited vulnerabilities - on its public website. Instead, these updates will be delivered via email, RSS feeds, and the agency's account on X.

With all this, a cybersecurity professional could be forgiven for doubting the US government's commitment to hardening networks and rooting out vulnerabilities.

Enter the EUVD. The EUVD is similar to the US government's National Vulnerability Database (NVD) in that it identifies each disclosed bug (with both a CVE-assigned ID and its own EUVD identifier), notes the vulnerability's criticality and exploitation status, and links to available advisories and patches.

Unlike the NVD, which is still struggling with a backlog of vulnerability submissions and is not very easy to navigate, the EUVD is updated in near real-time and highlights both critical and exploited vulnerabilities at the top of the site.

The EUVD provides three dashboard views: one for critical vulnerabilities, one for those actively exploited, and one for those coordinated by members of the EU CSIRTs network.

Information is sourced from open-source databases as well as advisories and alerts issued by national CSIRTs, mitigation and patching guidelines published by vendors, and exploited vulnerability details.

ENISA is also a CVE Numbering Authority (CNA), meaning it can assign CVE identifiers and coordinate vulnerability disclosures under the CVE program. Even as an active CNA, however, ENISA seems to be in the dark about what's next for the embattled US-government-funded CVE program, which is only under contract with MITRE until next March.

The launch announcement notes that "ENISA is in contact with MITRE to understand the impact and next steps following the announcement on the funding to the Common Vulnerabilities and Exposures Program."


Original Submission

This discussion was created by hubie (1068) for logged-in users only, but now has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1)
  • (Score: 3, Insightful) by Anonymous Coward on Saturday May 17 2025, @03:20PM (17 children)

    by Anonymous Coward on Saturday May 17 2025, @03:20PM (#1404092)

    That is so bogus! So now I'm expected to sign up (bow down) to Xitter for official government bulletins and info? We have shredded our constitution and handed the government to criminal psychopaths

    • (Score: 5, Interesting) by Anonymous Coward on Saturday May 17 2025, @03:58PM (14 children)

      by Anonymous Coward on Saturday May 17 2025, @03:58PM (#1404094)

      Via email.

      As TFS said:

      Plus, on Monday, CISA said it would no longer publish routine alerts - including those detailing exploited vulnerabilities - on its public website. Instead, these updates will be delivered via email, RSS feeds, and the agency's account on X.

      Which is no change at all for me. I've been receiving emails from CISA with vulnerability notifications for years. That's not changing.

      I get at least two or three updates a day -- no commercial services required. And if you're concerned about tracking, you can always use an anonymous email account or tor/VPN to access the RSS feed.

      There are plenty of things to take the Trump Administration to task for. Whether it be the disregard for the rule of law, the blatant corruption, the hollowing out of our economy and at least a half-dozen other types of cartoonish cruelty and criminality.

      As such, there's plenty to complain and protest about and no need to make shit up.

      And you can use the European Vulnerability Database (EUVD) instead too.

      The Trump Administration is destroying the stuff that makes America great. Let's focus on that instead of pissing and moaning about not updating a website every couple hours. That's a minor policy change with minimal impact on the vast majority of folks.

      There are *real* issues that should be addressed, as these authoritarian scumbags need to be stopped. This ain't one of them.

      • (Score: 5, Informative) by PiMuNu on Saturday May 17 2025, @04:06PM (3 children)

        by PiMuNu (3823) on Saturday May 17 2025, @04:06PM (#1404097)

        >The Trump Administration is destroying the stuff that makes America great.

        In the first quarter of Trump's administration, he has taken GDP from +2.4 pc growth to -0.3 pc contraction.

        https://www.bea.gov/news/2025/gross-domestic-product-1st-quarter-2025-advance-estimate [bea.gov]

        Regardless of your politics, that is a real train wreck.

        • (Score: 0, Interesting) by Anonymous Coward on Saturday May 17 2025, @04:37PM (2 children)

          by Anonymous Coward on Saturday May 17 2025, @04:37PM (#1404104)

          Regardless of your politics, that is a real train wreck.

          Not for everybody. The perps are being given all the spoils, to splurge in the up coming Trump Gaza Hotel and Casino. (a reminder to those who think we lost in Vietnam [hyatt.com]). A train wreck for some is paradise, love, and money for others

          • (Score: 2) by janrinok on Sunday May 18 2025, @08:03AM (1 child)

            by janrinok (52) Subscriber Badge on Sunday May 18 2025, @08:03AM (#1404162) Journal
            There are also 2 Hyatt Regency hotels in Moscow. I wouldn't say anyone won that war.
            • (Score: 0) by Anonymous Coward on Sunday May 18 2025, @04:35PM

              by Anonymous Coward on Sunday May 18 2025, @04:35PM (#1404225)

              What war are you talking about? The "cold war"? Clearly we won that one too, or there would be no Hyatts, McDonald's, or Apple, etc in Moscow.

              This "train wreck" people are talking about is totally dependent on the POV.

      • (Score: 3, Insightful) by Anonymous Coward on Saturday May 17 2025, @05:09PM (9 children)

        by Anonymous Coward on Saturday May 17 2025, @05:09PM (#1404107)

        Which is no change at all for me. I've been receiving emails from CISA with vulnerability notifications for years. That's not changing.

        The perfect anecdote illustrating the total lack of regard for people that lack those luxuries.

        Every piece of information from the government should be posted on a .gov website without exception. Emails and socio media should be absolutely secondary.

        Yes, it's the multitude of "little" things that make them big. Just like the multitudes of individuals, through their votes, that make the government, in its entirety, what it is today

        • (Score: 2, Troll) by Frosty Piss on Saturday May 17 2025, @05:39PM (2 children)

          by Frosty Piss (4971) on Saturday May 17 2025, @05:39PM (#1404108)

          Every piece of information from the government should be posted on a .gov website without exception.

          This is an EU program.

          • (Score: 4, Insightful) by Anonymous Coward on Saturday May 17 2025, @05:41PM

            by Anonymous Coward on Saturday May 17 2025, @05:41PM (#1404109)

            Yeah, one we need to use because the US government is destroying its service

          • (Score: 5, Insightful) by Deep Blue on Saturday May 17 2025, @08:56PM

            by Deep Blue (24802) on Saturday May 17 2025, @08:56PM (#1404125)

            What are you talking about? He is talking about the US Government and US government's National Vulnerability Database (NVD), and i agree with AC on this. Similary the EU data needs to be in a similar structure on EU websites, not some random social media account.

        • (Score: 0, Disagree) by Anonymous Coward on Saturday May 17 2025, @07:19PM (4 children)

          by Anonymous Coward on Saturday May 17 2025, @07:19PM (#1404112)

          Every piece of information from the government should be posted on a .gov website without exception. Emails and socio media should be absolutely secondary.

          The stuff you're complaining is and will continue to be exactly as you *demand*:
          https://www.cisa.gov/about/contact-us/subscribe-updates-cisa [cisa.gov]

          Is there anything else you'd like? A pony perhaps?

          Jackass.

          And, as others have mentioned, TFA is about the European version, not the US version. So feel free to use that instead.

          And yet you complain, despite the fact that the US version makes the same stuff it always has publicly available on their website [cisa.gov].

          But since I'm not an authoritarian scumbag, I won't tell you to shut it. By all means, continue to remove all doubt [quoteinvestigator.com].

          • (Score: 4, Interesting) by Deep Blue on Saturday May 17 2025, @08:58PM (3 children)

            by Deep Blue (24802) on Saturday May 17 2025, @08:58PM (#1404126)

            So you are saying

            Plus, on Monday, CISA said it would no longer publish routine alerts - including those detailing exploited vulnerabilities - on its public website

            is not true?

            • (Score: 0) by Anonymous Coward on Saturday May 17 2025, @11:17PM (2 children)

              by Anonymous Coward on Saturday May 17 2025, @11:17PM (#1404137)

              So you are saying

              Plus, on Monday, CISA said it would no longer publish routine alerts - including those detailing exploited vulnerabilities - on its public website

              is not true?

              Well, kind of. Yeah. Now.

              From this El Reg bit [theregister.com] (linked in TFS):

              Updated to add on May 13

              Just a day after announcing it was changing the way it sent out alerts, CISA has changed its mind and reverted back to its old system of putting everything on its website.

              "We recognize this has caused some confusion in the cyber community," the site now reads. "As such, we have paused immediate changes while we re-assess the best approach to sharing with our stakeholders."

              As can be confirmed here [cisa.gov].

              What a difference a day (well four days, now) makes.

              The El Reg bit does make a point of detailing how various federal agencies are being "encouraged" to move to X (nee twitter), which is highly inappropriate.

              That said, the target audience for these CISA notifications are generally InfoSec and industry folks. As such, email/RSS is likely *preferred* by the vast majority of users. I know I prefer it that way -- you give me the fire hose and let me decide what's important for my use case(s).

              Anyway, yes it's stupid to take this stuff off their website. And yes, this makes government information less available. But getting these guys to send you this information multiple times a day, and/or allow you to check an RSS feed whenever you feel like it isn't enough? Well, you're in luck. As the change has been rolled back. Hooray for you!

              I'll point out again that the same thing (a browser) is required to get email and/or RSS feeds as is required to visit CISA's website. But that's not important any more as you and the seven other people, who don't already subscribe via email or use the RSS feed, will still be able to get the same information on the CISA website.

              • (Score: 4, Insightful) by Deep Blue on Sunday May 18 2025, @09:57AM (1 child)

                by Deep Blue (24802) on Sunday May 18 2025, @09:57AM (#1404171)

                They still need to be on a website, because not everyone should need to keep their own record of what they have received through RSS or email. What if you need to look up some older CVE when you weren't subscriped yet or lose your records? Does the RSS and Email have all the details about the CVE or are they some kind of a summary?

                Good that they rolled back.

                • (Score: 0) by Anonymous Coward on Sunday May 18 2025, @05:27PM

                  by Anonymous Coward on Sunday May 18 2025, @05:27PM (#1404235)

                  Does the RSS and Email have all the details about the CVE or are they some kind of a summary?

                  No. Because the CVE/NVD databases are separate (and aside from the subject matter, completely unrelated) from CISA's alerts/notifications. While CISA notifications often reference CVEs, they are not the source or the repository for the CVE database. That' a different set of folks unrelated to CISA.

        • (Score: 0, Disagree) by Anonymous Coward on Saturday May 17 2025, @07:27PM

          by Anonymous Coward on Saturday May 17 2025, @07:27PM (#1404115)

          The perfect anecdote illustrating the total lack of regard for people that lack those luxuries.

          luxuries? What luxuries?

          A web browser? Wait, don't you need one of those to view the CISA website?

          Web browsers allow you to create *free* email addresses from which to receive and view CISA alerts. Web browsers also have free RSS feed readers (Chrome [chromeunboxed.com], Firefox [mozilla.org]) from which you can view all CISA notifications/alerts on their website

          Please do explain what you mean by "luxuries" in this context that allow you to view the CISA website without a browser that also enables email and RSS feed access. Please, do tell.

    • (Score: 2) by driverless on Sunday May 18 2025, @10:46AM (1 child)

      by driverless (4770) on Sunday May 18 2025, @10:46AM (#1404178)

      (bow down) to Xitter

      Damn, that's almost, but not quite, close enough to the Greek pronunciation that it'd come out as "shitter"... (probably more like "hitter").

      • (Score: 0) by Anonymous Coward on Sunday May 18 2025, @11:01PM

        by Anonymous Coward on Sunday May 18 2025, @11:01PM (#1404277)

        close enough to the Greek pronunciation

        I was thinking more Spanish (or even Mayan) than Greek, but yeah, "shitter" is the correct pronunciation of what these people are.

  • (Score: 5, Touché) by FuzzyTheBear on Saturday May 17 2025, @10:30PM

    by FuzzyTheBear (974) on Saturday May 17 2025, @10:30PM (#1404131)

    The less we rely on Americans and it's agencies , companies and government, the better off we are. Their politicians are mentally unstable and the resulting uncertainties , the whims of a child in fact , are disqualifying them is a lot of ways. Canadians like me are totally okay for a world that leaves the USA behind and changing the big picture radically to reflect the change Information security is too important to be left in their hands. Musk showed us anyone can get in mainframes and steal data for their personal benefits. For all things computer and information related we're better off and more secure without them. Time to turn to a future that leaves the USA behind for good. Let em swim in the swamp , they voted for it

  • (Score: 2) by deimios on Sunday May 18 2025, @06:55AM (1 child)

    by deimios (201) on Sunday May 18 2025, @06:55AM (#1404156) Journal

    If you have an RSS or even a mailing list you can just plop an RSS reader onto the site or a script that scrapes the mailing list and posts it to the site.
    WTF is so special about that site that they cannot easily publish to it?

    • (Score: 2, Touché) by Anonymous Coward on Sunday May 18 2025, @05:21PM

      by Anonymous Coward on Sunday May 18 2025, @05:21PM (#1404233)

      WTF is so special about that site that they cannot easily publish to it?

      Well, when you fire most of the employees and then start criminal investigations against those same folks, I'm guessing it's difficult to find folks who are willing to work there. So it may be difficult since there's no one there to do, well, anything.

      Well, that and the current administration's aversion to security of any kind, cyber or otherwise.

(1)