正在加载视频...

视频加载失败

I don't give a shit about CVEs

57,032 次观看 • 1 个月前 •via X (Twitter)

47 条评论

vx-underground 的头像
vx-underground1 个月前

Who are you and how did you get inside my computer

solst/ICE of Astarte 的头像
solst/ICE of Astarte1 个月前

Hel p ehlp hellp I found out why they call him smelly get me out of here

inversecos 的头像
inversecos1 个月前

wtf I thought you were a hot anime girl 🥲

solst/ICE of Astarte 的头像
solst/ICE of Astarte1 个月前

uwu

inversecos 的头像
inversecos1 个月前

uwu (heart broken) 😣

solst/ICE of Astarte 的头像
solst/ICE of Astarte1 个月前

or on YT:

solst/ICE of Astarte 的头像
solst/ICE of Astarte1 个月前

See they don’t want you to care anyway. You can’t afford to care about each one.

solst/ICE of Astarte 的头像
solst/ICE of Astarte1 个月前

Hell yeah fuck advertisers anyway, I’ll make even more videos like this

The Deal Director 的头像
The Deal Director1 个月前

@AstarteSecurity Several cybersecurity vendors have requested a strike on YouTube against this video.

solst/ICE of Astarte 的头像
solst/ICE of Astarte1 个月前

@AstarteSecurity Some are even attempting a drone strike on its author

The Deal Director 的头像
The Deal Director1 个月前

@AstarteSecurity They are not called CROWDSTRIKE for no reason.

Laurence 的头像
Laurence1 个月前

not even this one? 🥺

solst/ICE of Astarte 的头像
solst/ICE of Astarte1 个月前

Woaw

menzo 的头像
menzo1 个月前

Umm i don’t think 7 billion cve’s were published in the first 3 seconds that i’ve watched the video. There are only like 350k cataloged cve’s so you must be incorrect 🤓

Deus Lemmus『旅鼠神』 的头像
Deus Lemmus『旅鼠神』1 个月前

This assumes popes remain monotonic.

solst/ICE of Astarte 的头像
solst/ICE of Astarte1 个月前

A critical blunder in my analysis, apologies

PandaRE 🐼 🇺🇦 的头像
PandaRE 🐼 🇺🇦1 个月前

I love the background lights

solst/ICE of Astarte 的头像
solst/ICE of Astarte1 个月前

It’s tiny string lights around the shelf! And a few Philips hue

Denis Loginoff ⚡️ 的头像
Denis Loginoff ⚡️1 个月前

I wish compliance folks and auditors understood this 🙈

solst/ICE of Astarte 的头像
solst/ICE of Astarte1 个月前

Part of my frustration is large partners (usually banks etc) will often email you asking if you’re vulnerable to a specific cve. And it seems so short sighted.

Denis Loginoff ⚡️ 的头像
Denis Loginoff ⚡️1 个月前

Yep. Or like we had to do FedRAMP and were asked to address all possible CVEs, no matter how low, in Docker images used by services 🤦‍♂️ And for those that didn't even have fixes yet, to painstakingly document why each and every one didn't apply to us 😬

spencer 的头像
spencer1 个月前

Dude same. 99% don’t and won’t ever matter

Malayke 的头像
Malayke1 个月前

Couldn't agree more. We're sitting on ~500k critical/high vulns right now—patching them all is just impossible. We have to shift our focus to detecting and blocking them in time when they actually get exploited.

solst/ICE of Astarte 的头像
solst/ICE of Astarte1 个月前

^^^^^ exactly this

Bethel Egwuchukwu 的头像
Bethel Egwuchukwu1 个月前

Feels like we've spent years getting better at counting problems instead of reducing the damage they can actually cause.

Het Mehta 的头像
Het Mehta1 个月前

me too

pnut 的头像
pnut1 个月前

Slowly, but surely, security programs will have to understand what they’re keeping alive and why and scope down. It will cost too much otherwise.

Dead Cell 的头像
Dead Cell1 个月前

CVEs by Pope...

Melvin Kitnick 🏴‍☠️ 的头像
Melvin Kitnick 🏴‍☠️1 个月前

im in cybersec for 20 years now, i hated CVEs since the beginning and recently had to submit some vulnerabilities to vendors and i now hate the process even more than i did before, truly an awful experience

solst/ICE of Astarte 的头像
solst/ICE of Astarte1 个月前

I’ve seen teams get derailed by solely focusing on CVE chasing and not the bigger picture (both red and blue teams)

Melvin Kitnick 🏴‍☠️ 的头像
Melvin Kitnick 🏴‍☠️1 个月前

CVE chasing is the new trend after Cert chasing during covid i suppose lmao

LunacySoft 的头像
LunacySoft1 个月前

@CyberSecAJ 💯 agree the problem is no one shares this view …. Everyone wants to believe it’s not going to happen to them and that if it not broke don’t fix it and it’s terrible

Juan Snow 的头像
Juan Snow1 个月前

I’m bringing up the pope index on the next all hands call!

Karan 的头像
Karan1 个月前

cve are useless untill they are exploitable

Phi 的头像
Phi1 个月前

This is you??

𝕡𝕨𝕟𝕚𝕖 的头像
𝕡𝕨𝕟𝕚𝕖1 个月前

I legit thought you were a kawaii anime girl.

Brian Phillips 的头像
Brian Phillips1 个月前

Spot on - focus the process and response over obsessing over vulns. Still patch them..but don't make that the make or break point.

Psycho 🎭 的头像
Psycho 🎭1 个月前

having a cve it's just something to flex with like "yoo i got a cve on a Microsoft lol" but like being real with u having a database of cves cataloged it helps a lot the security industry

solst/ICE of Astarte 的头像
solst/ICE of Astarte1 个月前

Yeah true I agree. It helps to have them, it’s good to catalog failures. But it becomes a misleading metric to build a security program around.

Psycho 🎭 的头像
Psycho 🎭1 个月前

yeee I mean it helps a lot in that context of cataloging but it's commonly used to flex with if u have one, to compete who got the most quantity with cves and to be considered a pro by other professionals in the field etc that's why they usually put it in their curriculum as well

V3RM1N 的头像
V3RM1N1 个月前

well said!

Barrell Titor 的头像
Barrell Titor1 个月前

It doesn't matter what vulnerabilities most of my selfhosted software has since I don't expose them to the internet 🤷‍♂️

trespaul 的头像
trespaul1 个月前

ok so im genuinely surprised you're not the girl in your pfp

SHIFKEY 的头像
SHIFKEY1 个月前

camera angle, focus depth, lighting 🤌 ya lookin good here

🔲🔳 的头像
🔲🔳1 个月前

Bro what are you talking about? CVEs by Pope? You can find actual metrics at Avg CVSS v3.1 score is 6.9, only like 11% are critical severity Avg CVEs per day is 212.9 Defense-in-depth doesn't mean shit if your whole infra is running vulnerable software

Seandakid 的头像
Seandakid1 个月前

AI

Sebastian Buzdugan 的头像
Sebastian Buzdugan1 个月前

cves matter when the vulnerable code is reachable in prod, not when scanners scream

相关视频