20 episodes

A free podcast about cybersecurity, vulnerability management, and the CVE Program.

We Speak CVE CVE Program

    • Technology

A free podcast about cybersecurity, vulnerability management, and the CVE Program.

    Expected Impact of the CNA Rules 4.0

    Expected Impact of the CNA Rules 4.0

    Host Shannon Sabens speaks with Art Manion and Kent Landfield, all three of whom are CVE Board members and CVE Working Group (WG) chairs, about the all-new “CVE® Numbering Authority (CNA) Operational Rules Version 4.0.” Topics discussed include the new fundamental concept embedded throughout the rules called the “right of refusal”; how CVE assignment is technology neutral (i.e., cloud, artificial intelligence, etc.); end-of-life assignments; the dispute process; how CNAs can add addition...

    • 37 min
    Swimming in Vulns (or, Fun with CVE Data Analysis)

    Swimming in Vulns (or, Fun with CVE Data Analysis)

    Host Shannon Sabens of CrowdStrike chats with Benjamin Edwards and Sander Vinberg, both of Bitsight, about analyzing vulnerability data in the CVE List. This is a follow-on to their “CVE Is The Worst Vulnerability Framework (Except For All The Others)” talk at CVE/FIRST VulnCon 2024.Topics discussed include the types of vulnerabilities and vulnerability intelligence they reviewed and the different ways they approached the data; how CVE is a really good framework for compiling information abou...

    • 43 min
    Meet the 3 New CVE Board Members

    Meet the 3 New CVE Board Members

    In this episode — recorded live at “CVE/FIRST VulnCon 2024” — CVE Board member and CVE podcast host Shannon Sabens of CrowdStrike chats with the three newest CVE Board members: Madison Oliver of GitHub Security Lab, Tod Beardsley of Austin Hackers Anonymous (AHA!), and MegaZone of F5 who joins as the new CVE Numbering Authority (CNA) Liaison to the Board.Topics include how and why each new member joined the board, the impact that participating in CVE Working Groups had on their decisions to b...

    • 25 min
    CVE Records States and Tags

    CVE Records States and Tags

    Host Shannon Sabens speaks with Art Manion and Kent Landfield, all three of whom are CVE Board members and CVE Working Group (WG) chairs, about CVE Records. Discussion topics include the CVE Record Lifecycle, the three “states” of CVE Records (RESERVED, PUBLISHED, and REJECTED), the current “tags” in use with CVE Records (EXCLUSIVELY-HOSTED-SERVICE; UNSUPPORTED-WHEN-ASSIGNED; and DISPUTED), the difference between the REJECTED state and the DISPUTED tag, how a DISPUTED tag can be tempora...

    • 33 min
    The Council of Roots

    The Council of Roots

    Learn how CVE Numbering Authority (CNA) partners—ranging from large to small organizations, proprietary and open-source products or projects, disparate business sectors, and different geographic locations—are overseen and supported within the CVE Program by “Top-Level Roots” and “Roots.” Topics include the roles and responsibilities of the two different types of Roots; how their work benefits the CNAs under their care; how they recruit new CNA partners, including suggestions for addressing up...

    • 48 min
    How the New CVE Record Format Will Benefit Consumers

    How the New CVE Record Format Will Benefit Consumers

    Shannon Sabens of CrowdStrike and Kent Landfield of Trellix, both of whom are CVE Board members and CVE Working Group chairs, speak about how the new CVE Record format — with its new structured data format and optional information fields — will benefit and provide enhanced value to consumers of CVE content moving forward. Specific topics discussed include how the new CVE Record format will enable more complete vulnerability information to be captured early on in the advisory process and ...

    • 25 min

Top Podcasts In Technology

TED Tech
TED Tech
All-In with Chamath, Jason, Sacks & Friedberg
All-In Podcast, LLC
Lex Fridman Podcast
Lex Fridman
Rabbit Hole
The New York Times
What's Next|科技早知道
声动活泼
Darknet Diaries
Jack Rhysider

You Might Also Like

Darknet Diaries
Jack Rhysider
Hard Fork
The New York Times
The Daily
The New York Times
Hidden Brain
Hidden Brain, Shankar Vedantam
Fareed Zakaria GPS
CNN