5 ms·
There is nothing in that article mentioning funding reductions. That article is about how the volume of software vulnerabilities are increasing, resulting in d
by RVuRnvbM2e 1y ago
There is nothing in that article mentioning funding reductions.
That article is about how the volume of software vulnerabilities are increasing, resulting in difficulty keeping up by the CVE and NVD projects.
Please stop spamming this thread with political spin.
- deleted 1y ago[deleted]
- deleted 1y ago[deleted]
- transpute 1y agoBoth CVE (MITRE contract) and NVD are funded by NIST, https://www.securitymagazine.com/articles/100795-understanding-the-impact-of-the-nist-nvd-backlog-on-msps https://www.securitymagazine.com/articles/100795-understandi... > Since February 2024, the National Institute of Standards and Technology’s (NIST) National Vulnerability Database (NVD) has encountered delays in processing vulnerabilities.. caused by factors such as software proliferation, budget cuts and changes in support.. NIST, an agency within the United States Commerce Department, saw its budget cut by nearly 12% this year.
- cma 1y agoReading that article closely it says nothing about an NVD budget cut, only a NIST one. They were trackijg the changes after NIST's budget was cut, not NVD's. As pointed out below, CISA announced a cut and then NIST more than made up for it by reallocating funds, for an NVD funding increase, even though NIST had their overall budget cut.
- transpute 1y agoOne of your references has budget numbers that are two orders (?!) of magnitude higher than the CISA number. Hopefully someone can chime in with granular historical data for NIST NVD and MITRE-via-NIST CVE funding.