Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      The state of DevOps and AI: Not just hype

      September 1, 2025

      A Breeze Of Inspiration In September (2025 Wallpapers Edition)

      August 31, 2025

      10 Top Generative AI Development Companies for Enterprise Node.js Projects

      August 30, 2025

      Prompting Is A Design Act: How To Brief, Guide And Iterate With AI

      August 29, 2025

      Look out, Meta Ray-Bans! These AI glasses just raised over $1M in pre-orders in 3 days

      September 2, 2025

      Samsung ‘Galaxy Glasses’ powered by Android XR are reportedly on track to be unveiled this month

      September 2, 2025

      The M4 iPad Pro is discounted $100 as a last-minute Labor Day deal

      September 2, 2025

      Distribution Release: Linux From Scratch 12.4

      September 1, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Enhanced Queue Job Control with Laravel’s ThrottlesExceptions failWhen() Method

      September 2, 2025
      Recent

      Enhanced Queue Job Control with Laravel’s ThrottlesExceptions failWhen() Method

      September 2, 2025

      August report 2025

      September 2, 2025

      Fake News Detection using Python Machine Learning (ML)

      September 1, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Installing Proxmox on a Raspberry Pi to run Virtual Machines on it

      September 2, 2025
      Recent

      Installing Proxmox on a Raspberry Pi to run Virtual Machines on it

      September 2, 2025

      Download Transcribe! for Windows

      September 1, 2025

      Microsoft Fixes CertificateServicesClient (CertEnroll) Error in Windows 11

      September 1, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Tech & Work»CVE Program rescued at the last minute after concerns over losing its government funding

    CVE Program rescued at the last minute after concerns over losing its government funding

    April 16, 2025

    The fate of the CVE Program—a database that catalogs publicly disclosed security vulnerabilities—was unknown over the past 24 hours. 

    Yesterday, it was leaked that the maintainer of the CVE Program, MITRE, sent a letter to CVE board members, saying that funding for the CVE program was set to expire today, April 16. 

    “If a break in service were to occur, we anticipate multiple impacts to CVE, including deterioration of national vulnerability databases and advisories, tool vendors, incident response operations, and all manner of critical infrastructure,” the letter said.

    Most of the funding comes from the U.S. Cybersecurity and Infrastructure Security Agent (CISA), which at the time the letter was published has not renewed the contract. Fortunately, this morning, CISA did renew its contract with MITRE, ensuring the continuation of the CVE program.  

    Ariadne Conill, co-founder and distinguished engineer at Edera, commented that the loss of the program would be catastrophic. “Every vulnerability management strategy around the world today is heavily dependent and structured around the CVE system and its identifiers,” she said. 

    In addition, a new foundation has been formed to further ensure the “long-term viability, stability, and independence of the program.” 

    The CVE Foundation was founded by active CVE board members, who have been working on this for the past year because they were concerned about the program being reliant on a single government sponsor. 

    “CVE, as a cornerstone of the global cybersecurity ecosystem, is too important to be vulnerable itself,” said Kent Landfield, an officer of the Foundation. “Cybersecurity professionals around the globe rely on CVE identifiers and data as part of their daily work—from security tools and advisories to threat intelligence and response. Without CVE, defenders are at a massive disadvantage against global cyber threats.”

    The CVE Foundation plans to release more information over the next several days about its structure, transition planning, and opportunities for involvement. 

    The post CVE Program rescued at the last minute after concerns over losing its government funding appeared first on SD Times.

    Source: Read More 

    news
    Facebook Twitter Reddit Email Copy Link
    Previous ArticleSymbiotic Security launches AI tool for detecting and fixing vulnerabilities in code
    Next Article How to Access Oracle Fusion Cloud Apps Data from Snowflake

    Related Posts

    Tech & Work

    The state of DevOps and AI: Not just hype

    September 1, 2025
    Tech & Work

    A Breeze Of Inspiration In September (2025 Wallpapers Edition)

    August 31, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    CVE-2025-54832 – OPEXUS FOIAXpress Arbitrary State/Territory Modification Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    I highly recommend this Lenovo laptop, and it’s nearly 50% off

    News & Updates

    CVE-2025-7521 – PHPGurukul Vehicle Parking Management System SQL Injection Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-9751 – Campcodes Online Learning Management System SQL Injection

    Common Vulnerabilities and Exposures (CVEs)

    Highlights

    Wing FTP Server Remote Code Execution (CVE-2025-47812) Exploited in the Wild

    July 10, 2025

    Wing FTP Server Remote Code Execution (CVE-2025-47812) Exploited in the Wild

    Summary
    TL;DR: Huntress saw active exploitation of Wing FTP Server remote code execution (CVE-2025-47812) on a customer on July 1, 2025. Organizations running Wing FTP Server should update to the fixe …
    Read more

    Published Date:
    Jul 10, 2025 (14 hours, 11 minutes ago)

    Vulnerabilities has been mentioned in this article.

    CVE-2025-46579 – GoldenDB DDE Injection Vulnerability

    April 27, 2025

    Learn A1 Level Spanish

    May 17, 2025

    CVE-2025-36632 – Tenable Agent Local Privilege Escalation (LPE)

    June 16, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.