Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

I don't give a shit about CVEs

57,032 Aufrufe • vor 1 Monat •via X (Twitter)

47 Kommentare

Profilbild von vx-underground
vx-undergroundvor 1 Monat

Who are you and how did you get inside my computer

Profilbild von solst/ICE of Astarte
solst/ICE of Astartevor 1 Monat

Hel p ehlp hellp I found out why they call him smelly get me out of here

Profilbild von inversecos
inversecosvor 1 Monat

wtf I thought you were a hot anime girl 🥲

Profilbild von solst/ICE of Astarte
solst/ICE of Astartevor 1 Monat

uwu

Profilbild von inversecos
inversecosvor 1 Monat

uwu (heart broken) 😣

Profilbild von solst/ICE of Astarte
solst/ICE of Astartevor 1 Monat

or on YT:

Profilbild von solst/ICE of Astarte
solst/ICE of Astartevor 1 Monat

See they don’t want you to care anyway. You can’t afford to care about each one.

Profilbild von solst/ICE of Astarte
solst/ICE of Astartevor 1 Monat

Hell yeah fuck advertisers anyway, I’ll make even more videos like this

Profilbild von The Deal Director
The Deal Directorvor 1 Monat

@AstarteSecurity Several cybersecurity vendors have requested a strike on YouTube against this video.

Profilbild von solst/ICE of Astarte
solst/ICE of Astartevor 1 Monat

@AstarteSecurity Some are even attempting a drone strike on its author

Profilbild von The Deal Director
The Deal Directorvor 1 Monat

@AstarteSecurity They are not called CROWDSTRIKE for no reason.

Profilbild von Laurence
Laurencevor 1 Monat

not even this one? 🥺

Profilbild von solst/ICE of Astarte
solst/ICE of Astartevor 1 Monat

Woaw

Profilbild von menzo
menzovor 1 Monat

Umm i don’t think 7 billion cve’s were published in the first 3 seconds that i’ve watched the video. There are only like 350k cataloged cve’s so you must be incorrect 🤓

Profilbild von Deus Lemmus『旅鼠神』
Deus Lemmus『旅鼠神』vor 1 Monat

This assumes popes remain monotonic.

Profilbild von solst/ICE of Astarte
solst/ICE of Astartevor 1 Monat

A critical blunder in my analysis, apologies

Profilbild von PandaRE 🐼 🇺🇦
PandaRE 🐼 🇺🇦vor 1 Monat

I love the background lights

Profilbild von solst/ICE of Astarte
solst/ICE of Astartevor 1 Monat

It’s tiny string lights around the shelf! And a few Philips hue

Profilbild von Denis Loginoff ⚡️
Denis Loginoff ⚡️vor 1 Monat

I wish compliance folks and auditors understood this 🙈

Profilbild von solst/ICE of Astarte
solst/ICE of Astartevor 1 Monat

Part of my frustration is large partners (usually banks etc) will often email you asking if you’re vulnerable to a specific cve. And it seems so short sighted.

Profilbild von Denis Loginoff ⚡️
Denis Loginoff ⚡️vor 1 Monat

Yep. Or like we had to do FedRAMP and were asked to address all possible CVEs, no matter how low, in Docker images used by services 🤦‍♂️ And for those that didn't even have fixes yet, to painstakingly document why each and every one didn't apply to us 😬

Profilbild von spencer
spencervor 1 Monat

Dude same. 99% don’t and won’t ever matter

Profilbild von Malayke
Malaykevor 1 Monat

Couldn't agree more. We're sitting on ~500k critical/high vulns right now—patching them all is just impossible. We have to shift our focus to detecting and blocking them in time when they actually get exploited.

Profilbild von solst/ICE of Astarte
solst/ICE of Astartevor 1 Monat

^^^^^ exactly this

Profilbild von Bethel Egwuchukwu
Bethel Egwuchukwuvor 1 Monat

Feels like we've spent years getting better at counting problems instead of reducing the damage they can actually cause.

Profilbild von Het Mehta
Het Mehtavor 1 Monat

me too

Profilbild von pnut
pnutvor 1 Monat

Slowly, but surely, security programs will have to understand what they’re keeping alive and why and scope down. It will cost too much otherwise.

Profilbild von Dead Cell
Dead Cellvor 1 Monat

CVEs by Pope...

Profilbild von Melvin Kitnick 🏴‍☠️
Melvin Kitnick 🏴‍☠️vor 1 Monat

im in cybersec for 20 years now, i hated CVEs since the beginning and recently had to submit some vulnerabilities to vendors and i now hate the process even more than i did before, truly an awful experience

Profilbild von solst/ICE of Astarte
solst/ICE of Astartevor 1 Monat

I’ve seen teams get derailed by solely focusing on CVE chasing and not the bigger picture (both red and blue teams)

Profilbild von Melvin Kitnick 🏴‍☠️
Melvin Kitnick 🏴‍☠️vor 1 Monat

CVE chasing is the new trend after Cert chasing during covid i suppose lmao

Profilbild von LunacySoft
LunacySoftvor 1 Monat

@CyberSecAJ 💯 agree the problem is no one shares this view …. Everyone wants to believe it’s not going to happen to them and that if it not broke don’t fix it and it’s terrible

Profilbild von Juan Snow
Juan Snowvor 1 Monat

I’m bringing up the pope index on the next all hands call!

Profilbild von Karan
Karanvor 1 Monat

cve are useless untill they are exploitable

Profilbild von Phi
Phivor 1 Monat

This is you??

Profilbild von 𝕡𝕨𝕟𝕚𝕖
𝕡𝕨𝕟𝕚𝕖vor 1 Monat

I legit thought you were a kawaii anime girl.

Profilbild von Brian Phillips
Brian Phillipsvor 1 Monat

Spot on - focus the process and response over obsessing over vulns. Still patch them..but don't make that the make or break point.

Profilbild von Psycho 🎭
Psycho 🎭vor 1 Monat

having a cve it's just something to flex with like "yoo i got a cve on a Microsoft lol" but like being real with u having a database of cves cataloged it helps a lot the security industry

Profilbild von solst/ICE of Astarte
solst/ICE of Astartevor 1 Monat

Yeah true I agree. It helps to have them, it’s good to catalog failures. But it becomes a misleading metric to build a security program around.

Profilbild von Psycho 🎭
Psycho 🎭vor 1 Monat

yeee I mean it helps a lot in that context of cataloging but it's commonly used to flex with if u have one, to compete who got the most quantity with cves and to be considered a pro by other professionals in the field etc that's why they usually put it in their curriculum as well

Profilbild von V3RM1N
V3RM1Nvor 1 Monat

well said!

Profilbild von Barrell Titor
Barrell Titorvor 1 Monat

It doesn't matter what vulnerabilities most of my selfhosted software has since I don't expose them to the internet 🤷‍♂️

Profilbild von trespaul
trespaulvor 1 Monat

ok so im genuinely surprised you're not the girl in your pfp

Profilbild von SHIFKEY
SHIFKEYvor 1 Monat

camera angle, focus depth, lighting 🤌 ya lookin good here

Profilbild von 🔲🔳
🔲🔳vor 1 Monat

Bro what are you talking about? CVEs by Pope? You can find actual metrics at Avg CVSS v3.1 score is 6.9, only like 11% are critical severity Avg CVEs per day is 212.9 Defense-in-depth doesn't mean shit if your whole infra is running vulnerable software

Profilbild von Seandakid
Seandakidvor 1 Monat

AI

Profilbild von Sebastian Buzdugan
Sebastian Buzduganvor 1 Monat

cves matter when the vulnerable code is reachable in prod, not when scanners scream

Ähnliche Videos