Loading video...

Video Failed to Load

Go Home

I don't give a shit about CVEs

57,032 views • 1 month ago •via X (Twitter)

47 Comments

vx-underground's profile picture
vx-underground1 month ago

Who are you and how did you get inside my computer

solst/ICE of Astarte's profile picture
solst/ICE of Astarte1 month ago

Hel p ehlp hellp I found out why they call him smelly get me out of here

inversecos's profile picture
inversecos1 month ago

wtf I thought you were a hot anime girl 🥲

solst/ICE of Astarte's profile picture
solst/ICE of Astarte1 month ago

uwu

inversecos's profile picture
inversecos1 month ago

uwu (heart broken) 😣

solst/ICE of Astarte's profile picture
solst/ICE of Astarte1 month ago

or on YT:

solst/ICE of Astarte's profile picture
solst/ICE of Astarte1 month ago

See they don’t want you to care anyway. You can’t afford to care about each one.

solst/ICE of Astarte's profile picture
solst/ICE of Astarte1 month ago

Hell yeah fuck advertisers anyway, I’ll make even more videos like this

The Deal Director's profile picture
The Deal Director1 month ago

@AstarteSecurity Several cybersecurity vendors have requested a strike on YouTube against this video.

solst/ICE of Astarte's profile picture
solst/ICE of Astarte1 month ago

@AstarteSecurity Some are even attempting a drone strike on its author

The Deal Director's profile picture
The Deal Director1 month ago

@AstarteSecurity They are not called CROWDSTRIKE for no reason.

Laurence's profile picture
Laurence1 month ago

not even this one? 🥺

solst/ICE of Astarte's profile picture
solst/ICE of Astarte1 month ago

Woaw

menzo's profile picture
menzo1 month ago

Umm i don’t think 7 billion cve’s were published in the first 3 seconds that i’ve watched the video. There are only like 350k cataloged cve’s so you must be incorrect 🤓

Deus Lemmus『旅鼠神』's profile picture
Deus Lemmus『旅鼠神』1 month ago

This assumes popes remain monotonic.

solst/ICE of Astarte's profile picture
solst/ICE of Astarte1 month ago

A critical blunder in my analysis, apologies

PandaRE 🐼 🇺🇦's profile picture
PandaRE 🐼 🇺🇦1 month ago

I love the background lights

solst/ICE of Astarte's profile picture
solst/ICE of Astarte1 month ago

It’s tiny string lights around the shelf! And a few Philips hue

Denis Loginoff ⚡️'s profile picture
Denis Loginoff ⚡️1 month ago

I wish compliance folks and auditors understood this 🙈

solst/ICE of Astarte's profile picture
solst/ICE of Astarte1 month ago

Part of my frustration is large partners (usually banks etc) will often email you asking if you’re vulnerable to a specific cve. And it seems so short sighted.

Denis Loginoff ⚡️'s profile picture
Denis Loginoff ⚡️1 month ago

Yep. Or like we had to do FedRAMP and were asked to address all possible CVEs, no matter how low, in Docker images used by services 🤦‍♂️ And for those that didn't even have fixes yet, to painstakingly document why each and every one didn't apply to us 😬

spencer's profile picture
spencer1 month ago

Dude same. 99% don’t and won’t ever matter

Malayke's profile picture
Malayke1 month ago

Couldn't agree more. We're sitting on ~500k critical/high vulns right now—patching them all is just impossible. We have to shift our focus to detecting and blocking them in time when they actually get exploited.

solst/ICE of Astarte's profile picture
solst/ICE of Astarte1 month ago

^^^^^ exactly this

Bethel Egwuchukwu's profile picture
Bethel Egwuchukwu1 month ago

Feels like we've spent years getting better at counting problems instead of reducing the damage they can actually cause.

Het Mehta's profile picture
Het Mehta1 month ago

me too

pnut's profile picture
pnut1 month ago

Slowly, but surely, security programs will have to understand what they’re keeping alive and why and scope down. It will cost too much otherwise.

Dead Cell's profile picture
Dead Cell1 month ago

CVEs by Pope...

Melvin Kitnick 🏴‍☠️'s profile picture
Melvin Kitnick 🏴‍☠️1 month ago

im in cybersec for 20 years now, i hated CVEs since the beginning and recently had to submit some vulnerabilities to vendors and i now hate the process even more than i did before, truly an awful experience

solst/ICE of Astarte's profile picture
solst/ICE of Astarte1 month ago

I’ve seen teams get derailed by solely focusing on CVE chasing and not the bigger picture (both red and blue teams)

Melvin Kitnick 🏴‍☠️'s profile picture
Melvin Kitnick 🏴‍☠️1 month ago

CVE chasing is the new trend after Cert chasing during covid i suppose lmao

LunacySoft's profile picture
LunacySoft1 month ago

@CyberSecAJ 💯 agree the problem is no one shares this view …. Everyone wants to believe it’s not going to happen to them and that if it not broke don’t fix it and it’s terrible

Juan Snow's profile picture
Juan Snow1 month ago

I’m bringing up the pope index on the next all hands call!

Karan's profile picture
Karan1 month ago

cve are useless untill they are exploitable

Phi's profile picture
Phi1 month ago

This is you??

𝕡𝕨𝕟𝕚𝕖's profile picture
𝕡𝕨𝕟𝕚𝕖1 month ago

I legit thought you were a kawaii anime girl.

Brian Phillips's profile picture
Brian Phillips1 month ago

Spot on - focus the process and response over obsessing over vulns. Still patch them..but don't make that the make or break point.

Psycho 🎭's profile picture
Psycho 🎭1 month ago

having a cve it's just something to flex with like "yoo i got a cve on a Microsoft lol" but like being real with u having a database of cves cataloged it helps a lot the security industry

solst/ICE of Astarte's profile picture
solst/ICE of Astarte1 month ago

Yeah true I agree. It helps to have them, it’s good to catalog failures. But it becomes a misleading metric to build a security program around.

Psycho 🎭's profile picture
Psycho 🎭1 month ago

yeee I mean it helps a lot in that context of cataloging but it's commonly used to flex with if u have one, to compete who got the most quantity with cves and to be considered a pro by other professionals in the field etc that's why they usually put it in their curriculum as well

V3RM1N's profile picture
V3RM1N1 month ago

well said!

Barrell Titor's profile picture
Barrell Titor1 month ago

It doesn't matter what vulnerabilities most of my selfhosted software has since I don't expose them to the internet 🤷‍♂️

trespaul's profile picture
trespaul1 month ago

ok so im genuinely surprised you're not the girl in your pfp

SHIFKEY's profile picture
SHIFKEY1 month ago

camera angle, focus depth, lighting 🤌 ya lookin good here

🔲🔳's profile picture
🔲🔳1 month ago

Bro what are you talking about? CVEs by Pope? You can find actual metrics at Avg CVSS v3.1 score is 6.9, only like 11% are critical severity Avg CVEs per day is 212.9 Defense-in-depth doesn't mean shit if your whole infra is running vulnerable software

Seandakid's profile picture
Seandakid1 month ago

AI

Sebastian Buzdugan's profile picture
Sebastian Buzdugan1 month ago

cves matter when the vulnerable code is reachable in prod, not when scanners scream

Related Videos