3 ms·
Edit suggests the contract has been renewed last minute. https://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-program-funding-cut-what-it-means-and-what
by alexmorley 1y ago
Edit suggests the contract has been renewed last minute.
https://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-program-funding-cut-what-it-means-and-what-to-do-next/ https://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-...
- Shank 1y agoAre there any non-Forbes sources that confirm this?
- marcusb 1y agoJust social media posts, with claims they received the info from CISA https://infosec.exchange/@metacurity/114347467581760027 https://infosec.exchange/@metacurity/114347467581760027 Supposedly, MITRE will make a statement today. Time will tell. Edit - it is MITRE, not CISA, which the poster expects to make a statement.
- ForOldHack 1y agoThis was 0 minutes ago. Glad to see how important CVE is to security personel.
- marcusb 1y ago? Metacurity’s post was like 90 minutes ago.
- shagie 1y agohttps://www.itpro.com/security/confusion-and-frustration-mitre-cve-oversight-ends-federal-contract-expiry https://www.itpro.com/security/confusion-and-frustration-mit... > However, in an updated statement, the agency revealed it intends to maintain the database in a bid to prevent a lapse in CVE services. > “The CVE Program is invaluable to the cyber community and a priority of CISA,” a spokesperson said. > “Last night, CISA executed the option period on the contract to ensure there will be no lapse in critical CVE services. We appreciate our partners’ and stakeholders’ patience.” Searching for that last passage: https://www.bleepingcomputer.com/news/security/cisa-extends-funding-to-ensure-no-lapse-in-critical-cve-services/ https://www.bleepingcomputer.com/news/security/cisa-extends-... > "The CVE Program is invaluable to cyber community and a priority of CISA," the U.S. cybersecurity agency told BleepingComputer. "Last night, CISA executed the option period on the contract to ensure there will be no lapse in critical CVE services. We appreciate our partners' and stakeholders' patience." And https://www.reuters.com/world/us/us-agency-extends-support-last-minute-cyber-vulnerability-database-2025-04-16/ https://www.reuters.com/world/us/us-agency-extends-support-l... > WASHINGTON, April 16 (Reuters) - U.S. officials have said at the last minute that they're extending support for a critical database of cyber weaknesses whose funding was due to run out on Wednesday. > The planned lapse in payments for the MITRE Corp's Common Vulnerabilities and Exposures database spread alarm across the cybersecurity community. The database, which acts as a kind of catalog for cyber weaknesses, plays a key role in enabling IT administrators to quickly flag and triage the myriad different bugs and hacks discovered daily.
- chris_wot 1y agoLet me guess, Elon's DOGE crew were part of this and screwed up yet another thing that is essential for U.S. security?
- shagie 1y agoMy {conspiracy | belief | suspicion} is that this was something that as part of the DoD they saw "Mitre Corporation" and that organization's relationship with MIT and were pulling funding for anything "elite liberal academia" (even distantly related) combined with the "we're pulling back from anything cybersecurity" ( https://news.ycombinator.com/item?id=43228029 https://news.ycombinator.com/item?id=43228029 ). (edit) I've run out of invocations of Hanlon's Razor and it needs a long rest before its recharged. (/edit) I don't believe it was a mistake - they wanted to pull its funding (and still intend to do). Note the wording of the statement: > Last night, CISA executed the option period on the contract to ensure there will be no lapse in critical CVE services. We are now in the option period. At some point in the future, that option period will expire.
- neodymiumphish 1y agoThis type of option exercise is extremely common in government contracts. I don’t think there’s much to read into on that front.
- shagie 1y agoThe option is common (its particulars of the award is at https://www.usaspending.gov/award/CONT_AWD_70RCSJ24FR0000019_7001_70RSAT20D00000001_7001 https://www.usaspending.gov/award/CONT_AWD_70RCSJ24FR0000019... ). The fact that the option needed to be done rather than DHS continuing to support CVE and related programs is an abandonment of the responsibilities of the organization to try to keep computer systems secure. https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities https://www.cisa.gov/news-events/directives/bod-22-01-reduci... A binding operational directive is a compulsory direction to federal, executive branch, departments and agencies for purposes of safeguarding federal information and information systems. Section 3553(b)(2) of title 44, U.S. Code, authorizes the Secretary of the Department of Homeland Security (DHS) to develop and oversee the implementation of binding operational directives. Federal agencies are required to comply with DHS-developed directives. ... Remediate each vulnerability according to the timelines set forth in the CISA-managed vulnerability catalog. The catalog will list exploited vulnerabilities that carry significant risk to the federal enterprise with the requirement to remediate within 6 months for vulnerabilities with a Common Vulnerabilities and Exposures (CVE) ID assigned prior to 2021 and within two weeks for all other vulnerabilities. These default timelines may be adjusted in the case of grave risk to the Federal Enterprise. If there's no catalog that the government is maintaining for "these things need to be fixed to run on federal systems" ... then how do you ensure that the federal computers are secure?
- plasma_beam 1y agoIt hasn't posted to FPDS yet:https://www.fpds.gov/ezsearch/fpdsportal?q=PIID%3A%2270RCSJ24FR0000018%22&templateName=1.5.3&indexName=awardfull&x=0&y=0&sortBy=SIGNED_DATE&desc=Y https://www.fpds.gov/ezsearch/fpdsportal?q=PIID%3A%2270RCSJ2... Assuming this is the correct contract, which it appears to be, it had an option period starting today through March of next year. DHS just needed to exercise the option.
- DeepYogurt 1y agoMain page news on https://www.cisa.gov/ https://www.cisa.gov/
- numpad0 1y agoWhy would that be important???
- throawayonthe 1y ago[dead]
- gtani 1y agoreddit thread w/sources seem credible but 11 months only and still dependent on single funder https://old.reddit.com/r/netsec/comments/1k0dodx/mitre_support_for_the_cve_program_is_due_to/ https://old.reddit.com/r/netsec/comments/1k0dodx/mitre_suppo...
- deleted 1y ago[deleted]