Global Feed Post Login
Replying to Avatar Kevin Beaumont

One thing I’ve noticed is Mandiant now assign their own CVE like numbers to cloud provider vulnerabilities like this.

There really needs to be a properly, commonly agreed up system like CVE for this (not run by Google). I know there’s attempts at this, I hope they take off.

The illusion the cloud is magically secure is just that; an illusion. At the minute cloud providers are hiding behind lack of regulation, lack of transparency & deliberate subterfuge to protect shareholders. It’s not great.

Avatar
Rachel Rawlings 2y ago

nostr:npub17lgy0rj5a2nwpnyc4hup6ufpfz7wz6dzcgd3crm6fm2yd34dcz0qlk9uux I thought the CVE numbering system was already a project of MITRE and NIST.

Reply to this note

Please Login to reply.

Discussion

Avatar
Kevin Beaumont 2y ago

nostr:npub174tr94vmsgf9ldj6n9zd42jtmmajfnjw0tp9us5eewrtfm30w6pstacfav it doesn’t apply to cloud vulnerabilities (eg MS don’t even apply for them)

Thread collapsed