• jwiggler
    link
    fedilink
    English
    010 days ago

    It looks like funding is back on https://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-program-funding-cut-what-it-means-and-what-to-do-next/

    However, in an eleventh hour turnaround, the U.S. Cybersecurity and Infrastructure Security Agency said it had extended the contract with MITRE. “The CVE Program is invaluable to cyber community and a priority of CISA. Last night, CISA executed the option period on the contract to ensure there will be no lapse in critical CVE services,” a CISA spokesperson told me over email. "We appreciate our partners’ and stakeholders’ patience.”

    • @[email protected]
      link
      fedilink
      010 days ago

      I can only imagine the exhausting discussions and coaching and pleading that involved, until they managed to hammer the importance of it into their heads, in jellybean-sized simplified explanations, I presume.

      Reminds me of the exasperated virologists standing behind Trump as he preached about injecting bleach.

  • @[email protected]
    link
    fedilink
    010 days ago

    As with a lot of things, the CVE program needs to decentralise, or be replaced by one that is.

    Until then it’s not safe from being taken down.