macmule retweetledi

🚨 As a former advisory board member to the CVE/OVAL initiatives, I’m sounding the alarm:
MITRE has confirmed that funding for the CVE and CWE programs will expire on April 16, 2025. These programs are the backbone of global vulnerability management and coordination, helping defenders and researchers speak a common language about risk.
Without CVE, we lose:
A universal framework for tracking software flaws
Coordinated disclosures across vendors and governments
A critical piece of national cybersecurity infrastructure
📉 According to official records, the contract via the Department of Homeland Security is set to expire imminently: usaspending.gov/award/CONT_AWD…
Yes, historical CVE records will remain accessible on GitHub: github.com/CVEProject/cve…
But active development, modernization, and oversight of the CVE and CWE systems are now at risk.
This isn't just a tech industry issue—it's a matter of national security.
“MITRE remains committed to CVE as a global resource,” said Yosry Barsoum, VP at MITRE. But commitment without funding isn’t enough.
We must act—before this foundational cybersecurity resource goes dark.
Gary S. Miliefsky
Publisher, Cyber Defense Magazine
Former CVE/OVAL Advisory Board Member
@miliefsky | @cyberdefensemag

English











