#VulnerabilityManagement

2025-06-19

GCVE: Global CVE Allocation System

Enhancing Flexibility, Scalability, Autonomy, and Resilience in Vulnerability
Identification

Slides presented at a CSIRT meeting are now online.

πŸ“„ Slides (PDF) gcve.eu/presentation/gcve-eu-p

#gcve #cve #vulnerabilitymanagement #cybersecurity

CWE ProgramCWE_Program
2025-06-19

Learn about CWE’s most important problems and where they fit within the challenges faced by the broader / ecosystem in this video from

youtu.be/RcR-EFSptnQ

β€œHard Problems in CWE, and What it Tells us about Hard Problems in the Industry,” presentation from β€œCVE/FIRST VulnCon 2025.” Speaker: CWE Program Technical Lead Steve Christey Coley.
Finite StateFiniteState
2025-06-18

Most tools rely on declarations.

Finite State looks at what’s actually on the device & how it behaves.

πŸ“½οΈ Catch this moment from our webinar to see how execution-aware analysis changes the game.

info.finitestate.io/the-future

2025-06-18

Vulnerability discovered in ASUS Armoury Crate

Vulnerability: improper verification of driver caller

Impact: can be exploited to bypass authorization and escalate privileges to SYSTEM on Windows

Remediation: Updated to latest version

#cybersecurity #vulnerabilitymanagement #ASUS

bleepingcomputer.com/news/secu

2025-06-18

Whether you're:
πŸ‘¨β€πŸ’» a consultant in need of delivering high-quality reports faster
🏒 an internal team scaling risk management
πŸ“‘ or an MSSP managing various client pipelines

...our integrations help you move quicker, reduce risk, and prove value β€” without manual overhead.

Pentest-Tools.com connects seamlessly with:

βœ… Jira – auto-create tickets for high-risk findings
βœ… Slack / Teams – notify your team only when it matters
βœ… GitHub Actions – trigger scans in CI/CD before pushing code
βœ… Vanta / Nucleus – automate compliance & findings management
βœ… Webhooks / API – build custom workflows with full control
and more

πŸ”­ Explore integrations that match your workflow β†’ pentest-tools.com/features/int

#appsec #devsecops #vulnerabilitymanagement

2025-06-18

CIRCL - Coordinated Vulnerability Disclosure (CVD) Policy

An updated coordinated vulnerability disclosure policy has been published including a new service to report online vulnerabilities.

#cvd #vulnerabilitymanagement #vulnerability #csirt #cert #nis2 #cybersecurity

πŸ”— circl.lu/pub/coordinated-vulne

ICS Advisory ProjectAdvisoryICS@infosec.exchange
2025-06-18

ICS[AP] Dashboards are updated with the 4 new & 1 updated CISA Advisories released on 6/17/25:

Siemens: 1 New | 1 Updated
LS Electric: 1 New
Fuji Electric: 1 New
Dover Fueling Solutions (DFS): 1 New

www.icsadvisoryproject.com

#icssecurity
#otsecurity
#vulnerabilitymanagement

ICS Advisory ProjectAdvisoryICS@infosec.exchange
2025-06-18

Good Morning, Afternoon, or Evening, Everyone. CISA ICS Advisories Master File for 6/17/25 & the following year's CSV are updated:

CISA_ICS_ADV_2025_06_17.csv
CISA_ICS_ADV_2024_6_17_25.csv

Available @ ICS Advisory Project GitHub: github.com/icsadvprj

#opensource
#vulnerabilitymanagement
#icssecurity

CVE ProgramCVE_Program
2025-06-17

Toreon is now a CVE Numbering Authority (CNA) assigning CVE IDs for vulnerabilities discovered by or reported to Toreon that are not in another CNA’s scope

cve.org/Media/News/item/news/2

New CVE Program Partner
CVE ProgramCVE_Program
2025-06-17
2025-06-17

Β« Insufficient input validation leading to memory overread on the NetScaler Management Interface NetScaler ADCβ€―and NetScaler Gateway Β»

#citrix #vulnerabilitymanagement #vulnerability

vulnerability.circl.lu/vuln/CV

2025-06-17

Β« A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in the context of that SSH session. Β»

πŸ”— vulnerability.circl.lu/cve/CVE

#ssh #vulnerabilitymanagement #vulnerability

2025-06-17

Visual overview of GCVE: Global CVE Allocation System.

#gcve #vulnerabilitymanagement #vulnerability #cve #vulnerability

Overview of GCVE.eu Allocation Process
2025-06-15

GitLab has released software updates to address several vulnerabilities

Vulnerabilities: HTML injection; missing authorization; cross-site scripting

Vulnerability IDs: CVE-2025-4278, CVE-2025-5121, CVE-2025-2254

Impact: allows attackers to take over accounts; inject malicious jobs; act in the context of a legitimate user

Recommendation: update to version 18.0.2, 17.11.4, or 17.10.8

#cybersecurity #vulnerabilitymanagement #GitLab

bleepingcomputer.com/news/secu

2025-06-13

Adobe has released June 2025 software updates

The updates address 254 security flaws across Adobe's software portfolio, including Magento and Commerce

Administrators are advised to patch ASAP

#cybersecurity #Adobe #vulnerabilitymanagement

thehackernews.com/2025/06/adob

CVE ProgramCVE_Program
2025-06-13

854 CVE Records + severity scores when available in CISA’s Vulnerability Summary bulletin for the week of June 2, 2025

cisa.gov/news-events/bulletins

2025-06-13

If you're already a GNA, we've created a set of logos you can use to show that you're a GCVE Numbering Authority (GNA).

πŸ”— gcve.eu/logo/

πŸ”— If you want to become a GNA gcve.eu/about/#eligibility-and

#gna #gcve #vulnerabilitymanagement #cve

GNA - GCVE.eu logo
ICS Advisory ProjectAdvisoryICS@infosec.exchange
2025-06-13

ICS[AP] Dashboards are updated with the 10 new CISA Advisories released on 6/12/25:

Siemens: 6 New
AVEVA: 3 New
ValueHD, PTZOptics, multiCAM Systems, SMTAV: 1 New

www.icsadvisoryproject.com

#icssecurity
#otsecurity
#vulnerabilitymanagement

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst