Skip to main content

Funding Expires for Key Cyber Vulnerability Database

  • April 16, 2025
  • 1 reply
  • 8 views

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

April 15, 2025 By Brian Krebs 

 

A critical resource that cybersecurity professionals worldwide rely on to identify, mitigate and fix security vulnerabilities in software and hardware is in danger of breaking down. The federally funded, non-profit research and development organization MITRE warned today that its contract to maintain the Common Vulnerabilities and Exposures (CVE) program — which is traditionally funded each year by the Department of Homeland Security — expires on April 16.

A letter from MITRE vice president Yosry Barsoum, warning that the funding for the CVE program will expire on April 16, 2025.

Tens of thousands of security flaws in software are found and reported every year, and these vulnerabilities are eventually assigned their own unique CVE tracking number (e.g. CVE-2024-43573, which is a Microsoft Windows bug that Redmond patched last year).

There are hundreds of organizations — known as CVE Numbering Authorities (CNAs) — that are authorized by MITRE to bestow these CVE numbers on newly reported flaws. Many of these CNAs are country and government-specific, or tied to individual software vendors or vulnerability disclosure platforms (a.k.a. bug bounty programs).

 

>>Full Article<<

1 reply

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

MITRE CVE Program Gets Last-Hour Funding Reprieve

 

The US government’s cybersecurity agency CISA has “executed the option period on the contract” to keep the vulnerability catalog operational.

 

April 16, 2025 By Ryan Naraine 

 

The US government’s cybersecurity agency CISA says there will be no lapse in critical CVE services provided by the MITRE Corporation.

Just hours after the MITRE Corporation warned that the expiration of federal funding for the CVE Program would cause major disruptions, CISA announced it has “executed the option period on the contract” to keep the vulnerability catalog operational.

“The CVE Program is invaluable to the cyber community and a priority of CISA. Last night, CISA executed the option period on the contract to ensure there will be no lapse in critical CVE services. We appreciate our partners’ and stakeholders’ patience,” the agency said in a brief statement.

 

>>Full Article<<


Reply