Загрузка видео...

Не удалось загрузить видео

На главную

I don't give a shit about CVEs

57,032 просмотров • 1 месяц назад •via X (Twitter)

Комментарии: 47

Фото профиля vx-underground
vx-underground1 месяц назад

Who are you and how did you get inside my computer

Фото профиля solst/ICE of Astarte
solst/ICE of Astarte1 месяц назад

Hel p ehlp hellp I found out why they call him smelly get me out of here

Фото профиля inversecos
inversecos1 месяц назад

wtf I thought you were a hot anime girl 🥲

Фото профиля solst/ICE of Astarte
solst/ICE of Astarte1 месяц назад

uwu

Фото профиля inversecos
inversecos1 месяц назад

uwu (heart broken) 😣

Фото профиля solst/ICE of Astarte
solst/ICE of Astarte1 месяц назад

or on YT:

Фото профиля solst/ICE of Astarte
solst/ICE of Astarte1 месяц назад

See they don’t want you to care anyway. You can’t afford to care about each one.

Фото профиля solst/ICE of Astarte
solst/ICE of Astarte1 месяц назад

Hell yeah fuck advertisers anyway, I’ll make even more videos like this

Фото профиля The Deal Director
The Deal Director1 месяц назад

@AstarteSecurity Several cybersecurity vendors have requested a strike on YouTube against this video.

Фото профиля solst/ICE of Astarte
solst/ICE of Astarte1 месяц назад

@AstarteSecurity Some are even attempting a drone strike on its author

Фото профиля The Deal Director
The Deal Director1 месяц назад

@AstarteSecurity They are not called CROWDSTRIKE for no reason.

Фото профиля Laurence
Laurence1 месяц назад

not even this one? 🥺

Фото профиля solst/ICE of Astarte
solst/ICE of Astarte1 месяц назад

Woaw

Фото профиля menzo
menzo1 месяц назад

Umm i don’t think 7 billion cve’s were published in the first 3 seconds that i’ve watched the video. There are only like 350k cataloged cve’s so you must be incorrect 🤓

Фото профиля Deus Lemmus『旅鼠神』
Deus Lemmus『旅鼠神』1 месяц назад

This assumes popes remain monotonic.

Фото профиля solst/ICE of Astarte
solst/ICE of Astarte1 месяц назад

A critical blunder in my analysis, apologies

Фото профиля PandaRE 🐼 🇺🇦
PandaRE 🐼 🇺🇦1 месяц назад

I love the background lights

Фото профиля solst/ICE of Astarte
solst/ICE of Astarte1 месяц назад

It’s tiny string lights around the shelf! And a few Philips hue

Фото профиля Denis Loginoff ⚡️
Denis Loginoff ⚡️1 месяц назад

I wish compliance folks and auditors understood this 🙈

Фото профиля solst/ICE of Astarte
solst/ICE of Astarte1 месяц назад

Part of my frustration is large partners (usually banks etc) will often email you asking if you’re vulnerable to a specific cve. And it seems so short sighted.

Фото профиля Denis Loginoff ⚡️
Denis Loginoff ⚡️1 месяц назад

Yep. Or like we had to do FedRAMP and were asked to address all possible CVEs, no matter how low, in Docker images used by services 🤦‍♂️ And for those that didn't even have fixes yet, to painstakingly document why each and every one didn't apply to us 😬

Фото профиля spencer
spencer1 месяц назад

Dude same. 99% don’t and won’t ever matter

Фото профиля Malayke
Malayke1 месяц назад

Couldn't agree more. We're sitting on ~500k critical/high vulns right now—patching them all is just impossible. We have to shift our focus to detecting and blocking them in time when they actually get exploited.

Фото профиля solst/ICE of Astarte
solst/ICE of Astarte1 месяц назад

^^^^^ exactly this

Фото профиля Bethel Egwuchukwu
Bethel Egwuchukwu1 месяц назад

Feels like we've spent years getting better at counting problems instead of reducing the damage they can actually cause.

Фото профиля Het Mehta
Het Mehta1 месяц назад

me too

Фото профиля pnut
pnut1 месяц назад

Slowly, but surely, security programs will have to understand what they’re keeping alive and why and scope down. It will cost too much otherwise.

Фото профиля Dead Cell
Dead Cell1 месяц назад

CVEs by Pope...

Фото профиля Melvin Kitnick 🏴‍☠️
Melvin Kitnick 🏴‍☠️1 месяц назад

im in cybersec for 20 years now, i hated CVEs since the beginning and recently had to submit some vulnerabilities to vendors and i now hate the process even more than i did before, truly an awful experience

Фото профиля solst/ICE of Astarte
solst/ICE of Astarte1 месяц назад

I’ve seen teams get derailed by solely focusing on CVE chasing and not the bigger picture (both red and blue teams)

Фото профиля Melvin Kitnick 🏴‍☠️
Melvin Kitnick 🏴‍☠️1 месяц назад

CVE chasing is the new trend after Cert chasing during covid i suppose lmao

Фото профиля LunacySoft
LunacySoft1 месяц назад

@CyberSecAJ 💯 agree the problem is no one shares this view …. Everyone wants to believe it’s not going to happen to them and that if it not broke don’t fix it and it’s terrible

Фото профиля Juan Snow
Juan Snow1 месяц назад

I’m bringing up the pope index on the next all hands call!

Фото профиля Karan
Karan1 месяц назад

cve are useless untill they are exploitable

Фото профиля Phi
Phi1 месяц назад

This is you??

Фото профиля 𝕡𝕨𝕟𝕚𝕖
𝕡𝕨𝕟𝕚𝕖1 месяц назад

I legit thought you were a kawaii anime girl.

Фото профиля Brian Phillips
Brian Phillips1 месяц назад

Spot on - focus the process and response over obsessing over vulns. Still patch them..but don't make that the make or break point.

Фото профиля Psycho 🎭
Psycho 🎭1 месяц назад

having a cve it's just something to flex with like "yoo i got a cve on a Microsoft lol" but like being real with u having a database of cves cataloged it helps a lot the security industry

Фото профиля solst/ICE of Astarte
solst/ICE of Astarte1 месяц назад

Yeah true I agree. It helps to have them, it’s good to catalog failures. But it becomes a misleading metric to build a security program around.

Фото профиля Psycho 🎭
Psycho 🎭1 месяц назад

yeee I mean it helps a lot in that context of cataloging but it's commonly used to flex with if u have one, to compete who got the most quantity with cves and to be considered a pro by other professionals in the field etc that's why they usually put it in their curriculum as well

Фото профиля V3RM1N
V3RM1N1 месяц назад

well said!

Фото профиля Barrell Titor
Barrell Titor1 месяц назад

It doesn't matter what vulnerabilities most of my selfhosted software has since I don't expose them to the internet 🤷‍♂️

Фото профиля trespaul
trespaul1 месяц назад

ok so im genuinely surprised you're not the girl in your pfp

Фото профиля SHIFKEY
SHIFKEY1 месяц назад

camera angle, focus depth, lighting 🤌 ya lookin good here

Фото профиля 🔲🔳
🔲🔳1 месяц назад

Bro what are you talking about? CVEs by Pope? You can find actual metrics at Avg CVSS v3.1 score is 6.9, only like 11% are critical severity Avg CVEs per day is 212.9 Defense-in-depth doesn't mean shit if your whole infra is running vulnerable software

Фото профиля Seandakid
Seandakid1 месяц назад

AI

Фото профиля Sebastian Buzdugan
Sebastian Buzdugan1 месяц назад

cves matter when the vulnerable code is reachable in prod, not when scanners scream

Похожие видео