<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: QUICK NOTE: A potential shutdown or disruption of the CVE database—maintained by MITRE in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/78857#M7466</link>
    <description>&lt;P&gt;I appreciate your insights and for sharing your time with us&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/411576483"&gt;@Spirnia&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Apr 2025 14:50:22 GMT</pubDate>
    <dc:creator>Kyaw_Myo_Oo</dc:creator>
    <dc:date>2025-04-16T14:50:22Z</dc:date>
    <item>
      <title>QUICK NOTE: A potential shutdown or disruption of the CVE database—maintained by MITRE</title>
      <link>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/78853#M7463</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;A potential shutdown or disruption of the CVE (Common Vulnerabilities and Exposures) database—maintained by MITRE (&lt;A href="https://cve.mitre.org/)—" target="_blank" rel="noopener"&gt;https://cve.mitre.org/)—&lt;/A&gt;is rightly raising alarms across the cybersecurity community. While this may sound like a technical issue, it has SERIOUS implications for business risk, operational resilience, and national security.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.bleepingcomputer.com/news/security/mitre-warns-that-funding-for-critical-cve-program-expires-today/" target="_blank" rel="noopener"&gt;MITRE warns that funding for critical CVE program expires today&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If the CVE database were to become unavailable or unreliable, what alternative sources of vulnerability information do you believe cybersecurity professionals would need to rely on? What are the potential pros and cons of these alternatives?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.nextgov.com/cybersecurity/2025/04/cisa-extends-mitre-backed-cve-contract-hours-its-lapse/404601/" target="_blank" rel="noopener"&gt;Updated info :&amp;nbsp;CISA extends MITRE-backed CVE contract hours before its lapse&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Share your perspectives and insights. I'm eager to hear more insights from other members of the community&lt;/P&gt;&lt;P&gt;Let's make this a vibrant exchange of ideas. All perspectives welcome!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 14:49:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/78853#M7463</guid>
      <dc:creator>Kyaw_Myo_Oo</dc:creator>
      <dc:date>2025-04-16T14:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: QUICK NOTE: A potential shutdown or disruption of the CVE database—maintained by MITRE</title>
      <link>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/78855#M7464</link>
      <description>&lt;P&gt;It will be interesting to hear some alternative solutions, if our government chooses to not roll back this incredibly short-sighted decision.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 12:17:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/78855#M7464</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2025-04-16T12:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: QUICK NOTE: A potential shutdown or disruption of the CVE database—maintained by MITRE</title>
      <link>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/78856#M7465</link>
      <description>&lt;P&gt;If funding doesn't come through...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are alternatives to consider.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NIST has the National Vulnerability Database, NVD:&amp;nbsp;&lt;A href="https://nvd.nist.gov/vuln/search" target="_blank"&gt;https://nvd.nist.gov/vuln/search&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And there's also&amp;nbsp;&lt;A href="https://www.cve.org/" target="_blank"&gt;https://www.cve.org/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 12:33:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/78856#M7465</guid>
      <dc:creator>Spirnia</dc:creator>
      <dc:date>2025-04-16T12:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: QUICK NOTE: A potential shutdown or disruption of the CVE database—maintained by MITRE</title>
      <link>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/78857#M7466</link>
      <description>&lt;P&gt;I appreciate your insights and for sharing your time with us&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/411576483"&gt;@Spirnia&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 14:50:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/78857#M7466</guid>
      <dc:creator>Kyaw_Myo_Oo</dc:creator>
      <dc:date>2025-04-16T14:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: QUICK NOTE: A potential shutdown or disruption of the CVE database—maintained by MITRE</title>
      <link>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/78858#M7467</link>
      <description>&lt;P&gt;Dear All,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;CISA’s announcement of the Tuesday night extension came just hours after a subset of the CVE Board said it plans to break off to maintain the program under a new body called the CVE Foundation.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;“Since its inception, the CVE Program has operated as a U.S. government-funded initiative, with oversight and management provided under contract,” the foundation’s announcement said. “While this structure has supported the program’s growth, it has also raised longstanding concerns among members of the CVE Board about the sustainability and neutrality of a globally relied-upon resource being tied to a single government sponsor.”&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Nextgov/FCW has asked MITRE for comment. It’s &lt;STRONG&gt;unclear how long the current extension will remain valid&lt;/STRONG&gt; before CISA must initiate a new contract process in line with federal laws.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.nextgov.com/cybersecurity/2025/04/cisa-extends-mitre-backed-cve-contract-hours-its-lapse/404601/" target="_blank" rel="noopener nofollow noreferrer"&gt;Updated info :&amp;nbsp;CISA extends MITRE-backed CVE contract hours before its lapse&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 15:02:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/78858#M7467</guid>
      <dc:creator>Kyaw_Myo_Oo</dc:creator>
      <dc:date>2025-04-16T15:02:12Z</dc:date>
    </item>
    <item>
      <title>Re: QUICK NOTE: A potential shutdown or disruption of the CVE database—maintained by MITRE</title>
      <link>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/78862#M7468</link>
      <description>&lt;P&gt;From CISA's twitter account, April 16:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ericgeater_0-1744822414445.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/9643i04F4041204CC5DBC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ericgeater_0-1744822414445.jpeg" alt="ericgeater_0-1744822414445.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 16:53:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/78862#M7468</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2025-04-16T16:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: QUICK NOTE: A potential shutdown or disruption of the CVE database—maintained by MITRE</title>
      <link>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/78865#M7469</link>
      <description>&lt;P&gt;Thanks for sharing&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/136236425"&gt;@ericgeater&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 17:38:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/78865#M7469</guid>
      <dc:creator>Kyaw_Myo_Oo</dc:creator>
      <dc:date>2025-04-16T17:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: QUICK NOTE: A potential shutdown or disruption of the CVE database—maintained by MITRE</title>
      <link>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/78895#M7474</link>
      <description>&lt;P&gt;I just received this from an alternate source;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://euvd.enisa.europa.eu/" target="_blank"&gt;https://euvd.enisa.europa.eu/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An alternate to CVE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 13:29:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/78895#M7474</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2025-04-17T13:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: QUICK NOTE: A potential shutdown or disruption of the CVE database—maintained by MITRE</title>
      <link>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/78930#M7475</link>
      <description>&lt;P&gt;Your contribution is appreciated&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/715155969"&gt;@dcontesti&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Apr 2025 06:40:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/78930#M7475</guid>
      <dc:creator>Kyaw_Myo_Oo</dc:creator>
      <dc:date>2025-04-18T06:40:46Z</dc:date>
    </item>
    <item>
      <title>Re: QUICK NOTE: A potential shutdown or disruption of the CVE database—maintained by MITRE</title>
      <link>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/80077#M7495</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/411576483"&gt;@Spirnia&lt;/a&gt;&amp;nbsp;Thanks for suggesting the potential alternatives, but this affects both of the items you suggested.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NIST NVD - it is my understanding from reading &lt;A title="CVEs and the NVD Process" href="https://nvd.nist.gov/general/cve-process" target="_blank" rel="noopener"&gt;this page &lt;/A&gt;&amp;nbsp;that the NVD 'enriches' data from the CVE Database, so it may not be a replacement.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cve.org is the program that the OP is refering.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Perhaps a better alternative is&amp;nbsp;&lt;A href="https://euvd.enisa.europa.eu/" target="_blank" rel="noopener"&gt;https://euvd.enisa.europa.eu/,&lt;/A&gt;&amp;nbsp;but let's hope the &lt;A href="https://www.thecvefoundation.org/" target="_blank" rel="noopener"&gt;CVE Foundation&lt;/A&gt; gets off the ground as a non-profit so no government could shutdown the service.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 13:50:00 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/QUICK-NOTE-A-potential-shutdown-or-disruption-of-the-CVE/m-p/80077#M7495</guid>
      <dc:creator>learningdaily</dc:creator>
      <dc:date>2025-05-08T13:50:00Z</dc:date>
    </item>
  </channel>
</rss>

