CVE Oversight and Media Metrics โ Shimmy Says EP10
In todayโs ๐๐๐ผ-๐ฝ๐ฎ๐ฟ๐ ๐ฒ๐ฝ๐ถ๐๐ผ๐ฑ๐ฒ, we examine two critical forces reshaping the technology and marketing landscapes:
๐ฃ๐ฎ๐ฟ๐ ๐ญ: ๐๐ฉ๐ ๐ฎ๐ป๐ฑ ๐๐ฒ๐ฑ๐ฒ๐ฟ๐ฎ๐น ๐ข๐๐ฒ๐ฟ๐๐ถ๐ด๐ต๐
Can the federal government be trusted to manage the CVE database? We examine the risks, accountability gaps, and the future of vulnerability disclosure.
๐ฃ๐ฎ๐ฟ๐ ๐ฎ: ๐๐ด๐ฒ๐ป๐ฐ๐ถ๐ฒ๐ ๐ฎ๐ป๐ฑ ๐ ๐ฒ๐ฑ๐ถ๐ฎ: ๐ง๐ต๐ฒ ๐ก๐ฒ๐ ๐ฅ๐๐น๐ฒ๐
PR and banner ads are no longer enough. Agencies must deliver performance. Publishers must drive results. The landscape is shifting toward joint KPIs, strategic content, and outcome-focused partnerships.
Transcript
Hey everyone, it's me, Alan Shimo, and you're watching another episode of Shimmy Says here on LinkedIn Live. Um, I got a double barreled LinkedIn Shimmy says for you today. 'cause I had two things I wanted to talk about.
Um, I wanna lead off today talking about something near and dear to me. As a person who's been involved in the security community cybersecurity community for 25 plus years, 30 years, um, there was quite a kerfuffle in the community this week when it came out that the future of the CVE database program was in danger. For those of you who don't know, the CVE database has been maintained for as long as it's been around from the good folks at Mitre.
M-I-T-R-E. Mitre is sort of a quasi-governmental public private partnership kind of company that does a lot of work around the government. They usually work closely with NIST among others, but they've maintained the CVE since I, as I said, since there's been a CVE.
The CVE is where every known vulnerability discovered by researchers around the world is given a specific identifying number and the information, the relevant information for that vulnerability. What, you know, what is the vulnerability, how to detect it, how to remediate it, how to protect it, who discovered it, what, what systems are susceptible to it. The important thing about it is that the whole world, almost the whole world in cybersecurity depends on that CVE database to identify and then, you know, scan for and, and manage vulnerabilities.
Now, there are a lot of, don't get me wrong, there are a lot of people who, uh, have problems with the CVE database. Are we, are we giving vulnerabilities too high, what we call A-C-V-S-S score too high a criticality store, uh, score? Is it maintained correctly?
Is, is the whole notion of CVEs even viable? Because you have to look at it every vulnerability in the environment in which it exists. Does it have, is it accessible?
Is it exploitable, et cetera, et cetera. But nevertheless, almost the entire vulnerability management system and industry has coalesced around CVEs now for 15 or 20 years, 20 years easily. And we got a letter, although there was a letter published from the, uh, president or head of Mitre, that their contract with the government to maintain the CVE database expires as of April 16th.
And that as of April 15th, there was no offer or contract extension forthcoming. And that, therefore, on April 16th, Mara would have to cease maintaining the CV database, take it down, and probably lay off something like in the area of 400 people who work on this, this set, the just sent the security community into an uproar. So many good people who I know, Brian Krebs and Dave Lewis and I, I can't even just a long my LinkedIn feed was full of it.
Um, you know, spoke out what a disaster this could be. Again, if you don't know, what happens is the CVE, which is maintained by Mitre, is an upstream for something else called the National Vulnerability Database, the NVDB. And that's maintained by nist.
And quite frankly, you know what, over the last couple years, I guess due to budget constraints and other issues, um, there's been a lot of complaints about how respons NIST is in maintaining the, the national vulnerability database to the point where a lot of people are really upset and don't find it as useful as it was. CVE on the other hand, wasn't the Mitre folks, you know, did a decent job with it anyway, so it looked like the CVE was gonna go kaput as of April 16th, literally at the 11th hour. I don't know where that term 11th hour comes from, but literally at the 11th hour, the good folks at csaw, which you, you know, cisa, the people behind Chris Krebs, who's being persecuted now for doing his job back on the Trump, the first Trump administration, uh, the folks who have been responsible for really facilitating, for the first time in my memory, a great public private partnership to address cybersecurity.
CSA has come through and funded the CVE program for at least the next 11 months. And that's great. Kudos to cs a thank you to TOA for doing it.
I don't know if Mitre will be able to get back the people who are being laid off or what have you, but, you know, some damage has been done, but at least CVE itself is going to be up there for 11 months. At the same time though, it was announced that, uh, a new group is formed called the CVE Foundation. It's, uh, a private, and there might be some public entities involved, but private, uh, foundation that's gonna undertake to perhaps either take over the existing CVE database or start a shadow and then replace it at some point.
My initial thought on that was well redundant. I don't know if I trust it, you know, is it better to have the government doing it? But on further reflection with what goes on in our government today, I, now I'm gonna stand up and say the CVE Foundation is the way to go.
The same way the Linux Foundation and the Eclipse Foundation and the Apache Foundation have done amazing jobs in bringing open source software to the very heights that it is today. I believe a not-for-profit foundation that has a partnership and is funded by industry and, and others, is a better option to maintain this critical asset for the security industry. Because quite frankly, we cannot trust the US government to do this anymore.
There's already talk of ceases budget being cut drastically. Uh, there's already talk of all of these agencies that Dogue is going in when they come out of it, the security of them is gutted. We can't afford an asset like CVE to be gutted.
We can't afford CVE to become a political football. Between the last administration, the next administration, the president administration and our security cybersecurity posture hangs in the balance. This isn't a football, this is a na, this is an international asset that pe that's security folks around the world, around the world rely on.
And if the government can't do this reliably, someone else has to step up. So, you know what, I'm on here telling you, I am behind this CVE foundation. I want to go check out who's behind it.
I'm going to go see if we can become part of it or help in any way. And I urge you, all my security friends out there to go do the same thing. We cannot, we, it's a sad state of affairs, but these kinds of critical resources, we just can't trust the to politics.
We can't trust to a government that doesn't seem to, to care about it. We need, we need better and we can do better. Um, that's my first episode for Shimmy.
Says today, stay tuned in about, I don't know, 30 seconds, 60 seconds. I'm gonna be back with part two. Hey everyone, it's Shimmy and I'm back for part two.
Like, if you didn't have enough, um, I wanted to talk about something else today. It's not as high as I is important maybe to you, uh, as my last conversation here regarding the CVE database. But it's an important thing to me, and it's an important thing to all of my friends out here who work for PR agencies, marketing agencies, markcom agencies, as well as those of us in the media.
And that is this, both media companies and, and communications agencies need to learn to dance to a new rhythm. I, I wrote an article, it's, it should be, I, and I posted it here on LinkedIn rather than any of our text drunk sites because I, I want it to be more of a industry-wide thing, not just text drunk. But, uh, the article link should show up in the comments here on the, uh, on our LinkedIn live and we'll attach it to everything else where we, we play these videos.
The article was something like, uh, you know, media and, uh, agencies learning to dance to a new rhythm. The idea here is the world has changed. And those of us in media know this, and I think those of us in the agencies know this as well.
When I first got involved in media probably 12, 15 years ago, you know, the role of a PR agency and they were called PR agencies, was very clear. They were engaged by their customers to get coverage for their customers. It was usually earned media as it was called.
They would pitch stories, ideas, byline articles, what have you. And we in the media would then pick which stories kind of made sense for our audience. And we had time and room for, and, and there was this relationship.
We got to know who the agencies were. They knew where, who they'd to reach out to, to, to get placement for their clients and make no mistakes. You know, they, they charge their clients back then anywhere from five to $12,000 a month for getting them this exposure.
Tier one media, trade media, et cetera. Well, funny things have happened today. Clients don't want just media placement.
They want real impact. They want measurable impact. They want lead generation.
They want marketing, full fledged marketing. So many PR agencies have turned into full on marketing agencies or comm agencies, if you will, communication agencies. And they want more than just, you know, let me give you this story under embargo and let me know if you wanna run with that.
They need more. Their customers are demanding more. And so the, the very nature of these agencies have changed.
On the other hand, on the other side of the street, media has changed. You know, a lot of media companies, their whole business model was founded on, you know, getting a lot of views, running a lot of banners, and that's how they made money, right? From, from readership, if you will, at, at Tech Storm.
You know, quite frankly, we never, we found that tech people don't like clicking on banners. So we've never, you know, put a lot of, of our stock into banners. But we do sell the fact that we have a community, that we talk to a specific audience, whether it's cybersecurity or DevOps, cloud native platform engineering, uh, AI or what have you.
And we do events, you know, uh, learning events like webinars. In our virtual events. We do custom content.
We do content distribution as well as creation. But also as being a real media company, we report the news. Our job is, at the end of the day, is to give the people who consume our content, what they need to succeed in their tech role.
That's us here at Tech Shark. However, you know, the world's different. As I said, in order for us to fulfill that mission, we have to make enough money to keep the lights on.
And that means we have to do more things that are sponsored, more things that are revenue generating. We don't make any money, per se, from banner ads or that type of thing. You, if you're not in media in an agency and watching this, you know, you probably get more emails and contacts from media companies 'cause they're trying to bring you in knowing who you are in order to monetize their business model.
Media companies can't afford to just do earned placements anymore. Not unless those placements are somehow really newsworthy and not just a way of marketing the agency's clients. And so agencies reach out to me.
I'm, I'm inundated with pitches every day. 98% of 'em I can't help with, I can't do anything with because I've gotta do things that are gonna keep the lights on here and agencies have to do things that are gonna keep their lights on. So increasingly we're learning to do different dance moves, as I call it, moving to a different rhythm.
We are undertaking content creation and distribution that results in better metrics, better information that the agency can pass along to their customer. Uh, in order for this to succeed though, you have to have a really tight trusting partnership between the agency and the media outlet. And that's something that I've been trying to work on here at Techstrong.
And also, you know, as part of RUM and our analyst team and research team advisory and uh, intelligence portal, we've been trying to also, 'cause we recognize that there is a unique relationship between agencies and media. And the better we work together, the better results we can deliver to our mutual clients. And so I've been working, I've been working with friends like Michelle Schaefer at Merri and of course my good friend Jennifer Gio at, at W2 and, and, um, Wilson, Craig and his wife and, uh, my Share and, and, and many other agencies that I've had the chance to meet and get to know over the years.
But that is the future of this, uh, industry agencies and media. We need to dance a different dance. It doesn't make a difference who leads.
It's whether we're in rhythm. And so I'm calling on my agency friends out there if you wanna work with Textron, if you wanna work with Futur, reach out to reach out to me personally. Reach out to us and let's figure out how we, how we, you know, make beautiful music together in this new age that demands that we work better clo closer, tighter than we ever have before.
It's not an adversarial position. We're not looking to get money from everything you do. We understand what the agency's, uh, mission is and what the pressures are under what pressures you are under.
We want you to understand the pressure we're under. Let's work together to make it happen. So check out that article I wrote, if you are interested, reach out to me here on LinkedIn even.
Let's talk about ways we can do more together. Until next week though, guys, that's the end of this episode. These double, this double barrel episode of Shimmy says, um, if you're celebrating this weekend, maybe Easter or still Passover or just Spring, enjoy your celebration.
I'll be at RSA in just maybe a week and a half, two weeks. I'm real excited if you're at RSA, come by and say hello. We have a great event on Monday all day, our 10th annual DevSecOps event, which will be AI and cyber and AppDev.
And then I'll be at, uh, broadcast Alley in Moscone West all week. So check it out there. But for now, this is Alan Shimmel.
Shimmy says, have a great day. Everyone Says.





