Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. CISA fired most of the people who were helping report KEVs so now they expect us to do it for them.

CISA fired most of the people who were helping report KEVs so now they expect us to do it for them.

Scheduled Pinned Locked Moved Uncategorized
9 Posts 4 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • cr0w@infosec.exchangeC This user is from outside of this forum
    cr0w@infosec.exchangeC This user is from outside of this forum
    cr0w@infosec.exchange
    wrote last edited by
    #1

    CISA fired most of the people who were helping report KEVs so now they expect us to do it for them. Nope.

    Access Denied

    favicon

    (www.cisa.gov)

    h2onolan@infosec.exchangeH cr0w@infosec.exchangeC nyanbinary@infosec.exchangeN abt1181@ioc.exchangeA 4 Replies Last reply
    1
    0
    • R relay@relay.infosec.exchange shared this topic
    • cr0w@infosec.exchangeC cr0w@infosec.exchange

      CISA fired most of the people who were helping report KEVs so now they expect us to do it for them. Nope.

      Access Denied

      favicon

      (www.cisa.gov)

      h2onolan@infosec.exchangeH This user is from outside of this forum
      h2onolan@infosec.exchangeH This user is from outside of this forum
      h2onolan@infosec.exchange
      wrote last edited by
      #2

      @cR0w imagine gathering the goodwill from an entire community and then setting it on fire.

      cr0w@infosec.exchangeC 1 Reply Last reply
      0
      • h2onolan@infosec.exchangeH h2onolan@infosec.exchange

        @cR0w imagine gathering the goodwill from an entire community and then setting it on fire.

        cr0w@infosec.exchangeC This user is from outside of this forum
        cr0w@infosec.exchangeC This user is from outside of this forum
        cr0w@infosec.exchange
        wrote last edited by
        #3

        @h2onolan These are wild times.

        1 Reply Last reply
        0
        • cr0w@infosec.exchangeC cr0w@infosec.exchange

          CISA fired most of the people who were helping report KEVs so now they expect us to do it for them. Nope.

          Access Denied

          favicon

          (www.cisa.gov)

          cr0w@infosec.exchangeC This user is from outside of this forum
          cr0w@infosec.exchangeC This user is from outside of this forum
          cr0w@infosec.exchange
          wrote last edited by
          #4

          Even worse, they don't even host the report form. It's through Qualtrics.

          CISA KEV Nomination Form

          This form allows external users to submit a Common Vulnerabilities and Exposures (CVE) entry for consideration to be added to the Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) Catalog. The KEV Catalog highlights vulnerabilities that are actively exploited and pose significant risk to organizations. By nominating a CVE, you help CISA identify and prioritize vulnerabilities that require urgent attention and remediation across critical infrastructure and enterprise environments.

          favicon

          (cisasurvey.gov1.qualtrics.com)

          1 Reply Last reply
          1
          0
          • cr0w@infosec.exchangeC cr0w@infosec.exchange

            CISA fired most of the people who were helping report KEVs so now they expect us to do it for them. Nope.

            Access Denied

            favicon

            (www.cisa.gov)

            nyanbinary@infosec.exchangeN This user is from outside of this forum
            nyanbinary@infosec.exchangeN This user is from outside of this forum
            nyanbinary@infosec.exchange
            wrote last edited by
            #5

            @cR0w you know, ... whispers "gayint gcna"

            cr0w@infosec.exchangeC 1 Reply Last reply
            0
            • nyanbinary@infosec.exchangeN nyanbinary@infosec.exchange

              @cR0w you know, ... whispers "gayint gcna"

              cr0w@infosec.exchangeC This user is from outside of this forum
              cr0w@infosec.exchangeC This user is from outside of this forum
              cr0w@infosec.exchange
              wrote last edited by
              #6

              @nyanbinary That's way too much work.

              1 Reply Last reply
              0
              • cr0w@infosec.exchangeC cr0w@infosec.exchange

                CISA fired most of the people who were helping report KEVs so now they expect us to do it for them. Nope.

                Access Denied

                favicon

                (www.cisa.gov)

                abt1181@ioc.exchangeA This user is from outside of this forum
                abt1181@ioc.exchangeA This user is from outside of this forum
                abt1181@ioc.exchange
                wrote last edited by
                #7

                @cR0w LOL US gov infosec is a fucking joke. A few years ago tried to do something for a government HackerOne bounty and even with web hacking being the weakling of my hacking skills (far better and more specialized in DRM reverse engineering, for example) I *nearly* broke into the external access portal of a pretty spicy government system that was within the bounty scope lmao. I did manage to get the page to profusely misbehave on command too. No bounty of course but yeah.... Still showed it was sketchy as hell they were IIRC like one step or server setting away from having to probably paying out 5 figures for a severe vuln report.

                cr0w@infosec.exchangeC 1 Reply Last reply
                0
                • abt1181@ioc.exchangeA abt1181@ioc.exchange

                  @cR0w LOL US gov infosec is a fucking joke. A few years ago tried to do something for a government HackerOne bounty and even with web hacking being the weakling of my hacking skills (far better and more specialized in DRM reverse engineering, for example) I *nearly* broke into the external access portal of a pretty spicy government system that was within the bounty scope lmao. I did manage to get the page to profusely misbehave on command too. No bounty of course but yeah.... Still showed it was sketchy as hell they were IIRC like one step or server setting away from having to probably paying out 5 figures for a severe vuln report.

                  cr0w@infosec.exchangeC This user is from outside of this forum
                  cr0w@infosec.exchangeC This user is from outside of this forum
                  cr0w@infosec.exchange
                  wrote last edited by
                  #8

                  @ABT1181 Good old contractors. And now look how much is Wordpress.

                  abt1181@ioc.exchangeA 1 Reply Last reply
                  1
                  0
                  • cr0w@infosec.exchangeC cr0w@infosec.exchange

                    @ABT1181 Good old contractors. And now look how much is Wordpress.

                    abt1181@ioc.exchangeA This user is from outside of this forum
                    abt1181@ioc.exchangeA This user is from outside of this forum
                    abt1181@ioc.exchange
                    wrote last edited by
                    #9

                    @cR0w Lol WordPress needs a lot of care from people with much more web coding skill than me... That shit if you dont set it up right is so easy to compromise regardless of your skill level. Have had a few people use me for security testing in hopes to save a buck on cybersecurity for their sites and they all got pwned by basic holes in under 5 minutes lol. Also abused a WordPress language switcher glitch and one dumb authentication bug to log out the admin of JINR's (Russian version of CERN) public facing web site server 4 years ago from the comfort of a college dorm laundry room using nothing but my cell phone without even being actually logged in to her account in any way. As for the failed attempt at gov bug bounty, my god that was a fully custom stack fuckmess full of terrible security decisions and they simply got lucky that I couldn't quite get shit to report but someone more skilled at web specific stuff than me could likely find a way in lol.

                    1 Reply Last reply
                    0
                    Reply
                    • Reply as topic
                    Log in to reply
                    • Oldest to Newest
                    • Newest to Oldest
                    • Most Votes


                    • Login

                    • Login or register to search.
                    • First post
                      Last post
                    0
                    • Categories
                    • Recent
                    • Tags
                    • Popular
                    • World
                    • Users
                    • Groups