3 ms·
The article suggests that this DDoS is incentivized by the resume-padding cachet of having a CVE to your name, a kind of Hacktoberfest-style cobra effect: > a
by SloopJon 2y ago
The article suggests that this DDoS is incentivized by the resume-padding cachet of having a CVE to your name, a kind of Hacktoberfest-style cobra effect:
> a recently growing pattern involves newbie security enthusiasts and bug bounty hunters ostensibly "collecting" CVEs to enrich their resume
Naturally, such a reporter would value higher severity reports.
I haven't really thought that much about the CVE process. It's kind of strange to me that Github, Snyk, and the NVD may all have different evaluations of a report. I guess decentralization is a feature, but one not without bugs.