Default Author Image

National Vulnerability Database (NVD) Shifts to Selective Enrichment as CVE Volume Surges

Under a new model announced by the National Institute of Standards and Technology, NVD will no longer enrich every CVE. Instead, enrichment efforts will focus on a defined subset, including vulnerabilities in ...
Default Author Image

What the NVD ‘Slowdown’ Means For You: How to Stay Ahead in Vulnerability Management

Flashpoint’s vulnerability intelligence is powered by an independent research team that is constantly on the hunt for the latest vulnerabilities. Although the National Vulnerability Database (NVD) may be experiencing disruptions, it has ...

Why the World’s Vulnerability Index Cannot Keep Up

The Common Vulnerabilities and Exposures (CVE) system has been called the backbone of modern cybersecurity. For decades, it's been the shared language connecting scanners, advisories, compliance frameworks, and government policy ...
Why Vulnerability Management Programs Need Visibility Into Over 300,000 Vulnerabilities

Why Vulnerability Management Programs Need Visibility Into Over 300,000 Vulnerabilities

Flashpoint has been identifying and collecting vulnerabilities as they become available—with VulnDB now covering over 300,000 vulnerabilities affecting all manners of IT, IoT, and third-party libraries and dependencies. The post Why Vulnerability ...
The Need for Deterministic Security

The Security Implications of Application Proliferation

The proliferation of applications in the wake of COVID and more employees than ever working from home should not be a surprise to anyone.  The worry though, is whether organizations have taken ...
The Need for Deterministic Security

Historic scientific notation bug foils WAF defenses

A new article in the Daily Swig discloses that security researchers have discovered that a historic vulnerability affecting both MySQL and MariaDB databases caused serious flaws for security technologies, specifically Web Application ...
On Track for Fifth Record Year in a Row for Vulnerabilities

On Track for Fifth Record Year in a Row for Vulnerabilities

Last year, K2 Cyber Security reported that the US-CERT Vulnerability Database hit a record number of vulnerabilities recorded for the fourth year in a row on December 15, 2020.  As of last ...

What Does the New CVSS 3.1 Scoring Model Mean for Enterprise Security?

With thousands of security vulnerabilities reported each month in products ranging from hardware devices to firmware to popular software apps, how does one prioritise what needs the most attention? From a business ...