Загрузка видео...
Не удалось загрузить видео
I don't give a shit about CVEs
57,032 просмотров • 1 месяц назад •via X (Twitter)
Комментарии: 47

Who are you and how did you get inside my computer

Hel p ehlp hellp I found out why they call him smelly get me out of here

wtf I thought you were a hot anime girl 🥲

uwu

uwu (heart broken) 😣

or on YT:

See they don’t want you to care anyway. You can’t afford to care about each one.

Hell yeah fuck advertisers anyway, I’ll make even more videos like this

@AstarteSecurity Several cybersecurity vendors have requested a strike on YouTube against this video.

@AstarteSecurity Some are even attempting a drone strike on its author

@AstarteSecurity They are not called CROWDSTRIKE for no reason.

not even this one? 🥺

Woaw

Umm i don’t think 7 billion cve’s were published in the first 3 seconds that i’ve watched the video. There are only like 350k cataloged cve’s so you must be incorrect 🤓

This assumes popes remain monotonic.

A critical blunder in my analysis, apologies

I love the background lights

It’s tiny string lights around the shelf! And a few Philips hue

I wish compliance folks and auditors understood this 🙈

Part of my frustration is large partners (usually banks etc) will often email you asking if you’re vulnerable to a specific cve. And it seems so short sighted.

Yep. Or like we had to do FedRAMP and were asked to address all possible CVEs, no matter how low, in Docker images used by services 🤦♂️ And for those that didn't even have fixes yet, to painstakingly document why each and every one didn't apply to us 😬

Dude same. 99% don’t and won’t ever matter

Couldn't agree more. We're sitting on ~500k critical/high vulns right now—patching them all is just impossible. We have to shift our focus to detecting and blocking them in time when they actually get exploited.

^^^^^ exactly this

Feels like we've spent years getting better at counting problems instead of reducing the damage they can actually cause.

me too

Slowly, but surely, security programs will have to understand what they’re keeping alive and why and scope down. It will cost too much otherwise.

CVEs by Pope...

im in cybersec for 20 years now, i hated CVEs since the beginning and recently had to submit some vulnerabilities to vendors and i now hate the process even more than i did before, truly an awful experience

I’ve seen teams get derailed by solely focusing on CVE chasing and not the bigger picture (both red and blue teams)

CVE chasing is the new trend after Cert chasing during covid i suppose lmao

@CyberSecAJ 💯 agree the problem is no one shares this view …. Everyone wants to believe it’s not going to happen to them and that if it not broke don’t fix it and it’s terrible

I’m bringing up the pope index on the next all hands call!

cve are useless untill they are exploitable

This is you??

I legit thought you were a kawaii anime girl.

Spot on - focus the process and response over obsessing over vulns. Still patch them..but don't make that the make or break point.

having a cve it's just something to flex with like "yoo i got a cve on a Microsoft lol" but like being real with u having a database of cves cataloged it helps a lot the security industry

Yeah true I agree. It helps to have them, it’s good to catalog failures. But it becomes a misleading metric to build a security program around.

yeee I mean it helps a lot in that context of cataloging but it's commonly used to flex with if u have one, to compete who got the most quantity with cves and to be considered a pro by other professionals in the field etc that's why they usually put it in their curriculum as well

well said!

It doesn't matter what vulnerabilities most of my selfhosted software has since I don't expose them to the internet 🤷♂️

ok so im genuinely surprised you're not the girl in your pfp

camera angle, focus depth, lighting 🤌 ya lookin good here

Bro what are you talking about? CVEs by Pope? You can find actual metrics at Avg CVSS v3.1 score is 6.9, only like 11% are critical severity Avg CVEs per day is 212.9 Defense-in-depth doesn't mean shit if your whole infra is running vulnerable software

AI

cves matter when the vulnerable code is reachable in prod, not when scanners scream
Похожие видео
Sensitive content
I don't like that shit I don't want that shit I don't do that shit I don't need that shit I don't like that shit I don't want that shit I don't do that shit I don't need that shit I don't like that shit I don't want that shit I don't do that shit I don't need that shit I don't
Isaac
356,858 просмотров • 1 год назад
