Couverture de We Speak CVE

We Speak CVE

We Speak CVE

De : CVE Program
Écouter gratuitement

À propos de ce contenu audio

A free podcast about cybersecurity, vulnerability management, and the CVE Program.

© 2026 We Speak CVE
Economie Politique et gouvernement
Épisodes
  • CVE Record Disputes Explained
    Mar 24 2026

    In this episode of the “We Speak CVE” podcast, MITRE’s CVE and CWE Project Lead Alec Summers chats with Yves Younan of Cisco, Alex Kreilein of Qualys, Pedro Sampaio of Red Hat, and Anthony Singleton of the MITRE Top-Level Root, about the CVE Record dispute process.

    Topics include how the dispute policy came to exist and the two types of CVE Record disputes; a walk-through of the process for disputing a CVE Record, including what steps to take and what to expect; why some disputes persist indefinitely; whether all CVE Record disputes need to be resolved; why some disputes remaining visible to the downstream consumer is healthy; an overview of how the CVE Record Dispute Policy was created and how it continues to updated over time; how the CVE Program continuously seeks community input on the dispute process; and more.

    Resources mentioned in the podcast include:

    • CVE Record Disputes Explained blog
    • CVE Program Dispute Policy (PDF)
    • Dispute Policy Feedback survey form
    • CVE Record Disputes panel discussion at VulnCon 2026
    Afficher plus Afficher moins
    30 min
  • The CVE Consumer Working Group (CWG)
    Oct 14 2025

    “We Speak CVE” podcast host Shannon Sabens chats with CVE Consumer Working Group (CWG) co-chairs, Jay Jacobs and Bob Lord, and CVE™ Project Lead Alec Summers, about how the CWG was created to address the needs and perspectives of those who use CVE data — ranging from enterprise security teams to tool developers and managed security service providers — recognizing that their requirements and pain points often differ from those of upstream data providers.

    Topics include the CWG’s goals to systematically capture and organize consumer feedback, identify common and unique challenges across different user types, and inform improvements in the CVE Program; the diversity and international participation among sign-ups, including organizations outside the usual sphere, such as medical companies; and the concept of “patch smarter, not harder,” stressing the importance of prioritization and high-quality data to help defenders manage the overwhelming volume of vulnerabilities. In addition, listeners are encouraged to join the CWG for meetings scheduled to accommodate global involvement and help participate in shaping the future of CVE.

    Afficher plus Afficher moins
    21 min
  • 25 Years of CVE and What’s Next
    Feb 4 2025

    Host Shannon Sabens speaks with fellow CVE Board members Kent Landfield and Madison Oliver and CVE Program Lead Alec Summers about the 25th anniversary of the CVE Program. Topics include the history of the program, the program today, and what’s next.

    Afficher plus Afficher moins
    47 min
Aucun commentaire pour le moment