What is Hackers' Pub?

Hackers' Pub is a place for software engineers to share their knowledge and experience with each other. It's also an ActivityPub-enabled social network, so you can follow your favorite hackers in the fediverse and get their latest posts in your feed.

0
0
0

I boosted several posts about this already, but since people keep asking if I've seen it....

MITRE has announced that its funding for the Common Vulnerabilities and Exposures (CVE) program and related programs, including the Common Weakness Enumeration Program, will expire on April 16. The CVE database is critical for anyone doing vulnerability management or security research, and for a whole lot of other uses. There isn't really anyone else left who does this, and it's typically been work that is paid for and supported by the US government, which is a major consumer of this information, btw.

I reached out to MITRE, and they confirmed it is for real. Here is the contract, which is through the Department of Homeland Security, and has been renewed annually on the 16th or 17th of April.

usaspending.gov/award/CONT_AWD

MITRE's CVE database is likely going offline tomorrow. They have told me that for now, historical CVE records will be available at GitHub, github.com/CVEProject

Yosry Barsoum, vice president and director at MITRE's Center for Securing the Homeland, said:

“On Wednesday, April 16, 2025, funding for MITRE to develop, operate, and modernize the Common Vulnerabilities and Exposures (CVE®) Program and related programs, such as the Common Weakness Enumeration (CWE™) Program, will expire. The government continues to make considerable efforts to support MITRE’s role in the program and MITRE remains committed to CVE as a global resource.”

MITRE | SOLVING PROBLEMS
FOR A SAFER WORLD"
April 15, 2025
Dear CVE Board Member,
We want to make you aware of an important potential issue with MITRE’s enduring
support to CVE.
On Wednesday, April 16, 2025, the current contracting pathway for MITRE to develop,
operate, and modernize CVE and several other related programs, such as CWE, wil
expire. The government continues to make considerable efforts to continue MITRE’
role in support of the program
If a break in service were to occur, we anticipate multiple impacts to CVE, including
deterioration of national vulnerability databases and advisories, tool vendors, incident
response operations, and all manner of critical infrastructure.
MITRE continues to be committed to CVE as a global resource. We thank you as a
member of the CVE Board for your continued partnership.
Sincerely,
Yosry Barsoum
VP and Director
Center for Securing the Homeland (CSH)
7515 Colshire Drive ® McLean, VA 22102-7539 ® (703) 983-6000
0
0
0
0
0
0
0
0
0
0
0
0
0

people, THIS is big and you need it in front of management RIGHT NOW.

MITRE has informed the CVE board members that effective TONIGHT, funding to run CVE and CWE is effectively gone. The US federal government contracts MITRE to run these programs including both management, operations, and infrastructure.

This not only could but almost certainly will result in disruptions to CVE and CWE including a halt of all operations if new contracts/funding are not secured.

MITRE ‘ SOLVING PROBLEMS FOR A SAFER WORLD" April 15, 2025 
Dear CVE Board Member, 
We want to make you aware of an important potential issue with MITRE’s enduring support to CVE. On Wednesday, April 16, 2025, the current contracting pathway for MITRE to develop, operate, and modernize CVE and several other related programs, such as CWE, will expire. The government continues to make considerable efforts to continue MITRE's role in support of the program If a break in service were to occur, we anticipate multiple impacts to CVE, including deterioration of national vulnerability databases and advisories, tool vendors, incident response operations, and all manner of citical infrastructure. MITRE continues to be committed to CVE as a global resource. We thank you as a member of the CVE Board for your continued partnership. 

Sincerely, Yosry Barsoum 
VP and Director
Center for Securing the Homeland (CSH)
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0

美術の展示などで、倫理的な(?)問い直しが展示の外から行われたときに、どう対応するのか。杉田敦さんがひたすら逡巡しつづける記事なんだけど、なんかすごくわかるというか...。 自分をある意味部外者として位置付けてそのように振る舞っていれば、自己の責任は問われることはないのだけど、自分が意識していない不誠実というものは無数にあって、自分が当事者でない場所なんてない。 https://www.art-it.asia/top/contributertop/admin_ed_columns/265067/

0
0
0

I boosted several posts about this already, but since people keep asking if I've seen it....

MITRE has announced that its funding for the Common Vulnerabilities and Exposures (CVE) program and related programs, including the Common Weakness Enumeration Program, will expire on April 16. The CVE database is critical for anyone doing vulnerability management or security research, and for a whole lot of other uses. There isn't really anyone else left who does this, and it's typically been work that is paid for and supported by the US government, which is a major consumer of this information, btw.

I reached out to MITRE, and they confirmed it is for real. Here is the contract, which is through the Department of Homeland Security, and has been renewed annually on the 16th or 17th of April.

usaspending.gov/award/CONT_AWD

MITRE's CVE database is likely going offline tomorrow. They have told me that for now, historical CVE records will be available at GitHub, github.com/CVEProject

Yosry Barsoum, vice president and director at MITRE's Center for Securing the Homeland, said:

“On Wednesday, April 16, 2025, funding for MITRE to develop, operate, and modernize the Common Vulnerabilities and Exposures (CVE®) Program and related programs, such as the Common Weakness Enumeration (CWE™) Program, will expire. The government continues to make considerable efforts to support MITRE’s role in the program and MITRE remains committed to CVE as a global resource.”

MITRE | SOLVING PROBLEMS
FOR A SAFER WORLD"
April 15, 2025
Dear CVE Board Member,
We want to make you aware of an important potential issue with MITRE’s enduring
support to CVE.
On Wednesday, April 16, 2025, the current contracting pathway for MITRE to develop,
operate, and modernize CVE and several other related programs, such as CWE, wil
expire. The government continues to make considerable efforts to continue MITRE’
role in support of the program
If a break in service were to occur, we anticipate multiple impacts to CVE, including
deterioration of national vulnerability databases and advisories, tool vendors, incident
response operations, and all manner of critical infrastructure.
MITRE continues to be committed to CVE as a global resource. We thank you as a
member of the CVE Board for your continued partnership.
Sincerely,
Yosry Barsoum
VP and Director
Center for Securing the Homeland (CSH)
7515 Colshire Drive ® McLean, VA 22102-7539 ® (703) 983-6000
0
0
0
0
1
0
0
0

Winter Storm Warning, Eastern Aleutians, 2025-04-15 12:13 AKDT.

WHAT...Heavy snow and blowing snow expected. Total snow accumulations of 8 to 20 inches, lowest amounts at sea level. Northerly wind gusts as high as 50 to 65 mph. Visibility reduced to one-half mile or less at times.

WHERE...Eastern Aleutians.

WHEN...Until 1 AM AKDT Thursday.

IMPACTS...Travel could be very difficult. Areas of blowing snow could significantly reduce visibility. Strong winds could result in significant drifting of snow.

ADDITIONAL DETAILS...Snow and gusty winds will continue with the worst conditions this afternoon through Wednesday morning. Precipitation rates will likely diminish through the latter half of Wed; however, gusty northerly winds, snow showers, and poor visibility could linger into early Thursday morning. The storm is tracking slightly farther east. As such, snow totals may be reduced slightly for Unalaska and slightly higher for Akutan given this eastward shift of the storm and core of heaviest precipitation.

https://forecast.weather.gov/MapClick.php?zoneid=AKZ785


0

Winter Weather Advisory, Kuskokwim Delta Coast and Nunivak Island, 2025-04-15 12:13 AKDT.

WHAT...Snow and blowing snow expected. Total snow accumulations of 3 to 7 inches. Winds gusting as high as 45 mph. Visibility as low as one half mile.

WHERE...Kuskokwim Delta Coast and Nunivak Island.

WHEN...From 9 PM this evening to 5 PM AKDT Wednesday.

IMPACTS...Travel could be very difficult. Areas of blowing snow could significantly reduce visibility.

ADDITIONAL DETAILS...Snow and gusty winds will develop this evening and continue through Wednesday. Temperatures will warm into the lower 30s from south to north through Wednesday morning, limiting the potential for blowing snow. However, snow rates will increase during this time. Temperatures will eventually climb into the mid 30s by late Wed morning around Kuskokwim Bay and by Wed afternoon for the far northwest Kuskokwim Delta coast. Any lingering snow will likely mix with then change to all rain along the entire coast by Wednesday afternoon.

https://forecast.weather.gov/MapClick.php?zoneid=AKZ755


0
1

Winter Weather Advisory, Interior Kuskokwim Delta, 2025-04-15 12:13 AKDT.

WHAT...Snow and blowing snow expected. Total snow accumulations of 3 to 7 inches. Winds gusting as high as 45 mph. Visibility as low as one half mile.

WHERE...Interior Kuskokwim Delta.

WHEN...From 9 PM this evening to 11 AM AKDT Wednesday.

IMPACTS...Travel could be very difficult. Areas of blowing snow could significantly reduce visibility.

ADDITIONAL DETAILS...Snow and gusty winds will develop this evening and continue through early Wednesday morning. Temperatures will warm into the lower 30s as the snow begins, limiting the potential for blowing snow. However, snow rates will increase during the overnight and early morning hours. Temperatures will eventually climb into the mid 30s by mid-morning Wed across the Kuskokwim Delta. Any lingering snow will likely mix with then change to all rain along the entire coast by late Wednesday morning.

https://forecast.weather.gov/MapClick.php?zoneid=AKZ756


0
1
0
33
0
0
0

In today's mastodon.social update, we're testing a few minor quality of life improvements to the web interface: Every list of accounts now has a shortcut to add or remove an account from lists; clicking a hashtag in a post now brings up a menu with a shortcut to browse posts in that hashtag specifically by the author, and a new featured tab on profiles to make featured hashtags and posts easier to find and navigate.

0
15
0
0

Congratulations to Jason Cong, the holder of the Volgenau Chair for Engineering Excellence at the UCLA Henry Samueli School of Engineering and Applied Science , on receiving the 2024 ACM Charles P. “Chuck” Thacker Breakthrough in Computing Award!

Cong is recognized for fundamental contributions to the design and automation of field-programmable systems and customizable computing.

Learn more: awards.acm.org/about/2024-thac

Jason Cong Receives the ACM Breakthrough in Computing Award
0

久しぶりに、fedibird.comの招待コード出しておきますね。

fedibird.comは招待制になっており、通常の登録フォームからは登録できません。

このいずれかのリンクを辿って登録してください。
fedibird.com/invite/dbJvjMZt
fedibird.com/invite/cfSVzLDe
fedibird.com/invite/puHdbPZA
fedibird.com/invite/aMoksX2y

リンクからアクセスして登録する画面にならない場合は、その招待リンクは無効になっています。他のリンクをお試しください。

1

In today's mastodon.social update, we're testing a few minor quality of life improvements to the web interface: Every list of accounts now has a shortcut to add or remove an account from lists; clicking a hashtag in a post now brings up a menu with a shortcut to browse posts in that hashtag specifically by the author, and a new featured tab on profiles to make featured hashtags and posts easier to find and navigate.

0
15
0

fedibirdは今、環境整備のフェーズで、サーバ構成とか開発環境とかあれこれやってます。目立った進捗が見られない時期ですが、大事なところなので、少しお時間頂きますよー

0
1
0

Regardless of what happens with CVE/NVD, the PSF will continue publishing advisories for CPython through our OSV database and to the security-announce@python.org mailing list.

Please subscribe to those data sources to guarantee delivery of vulnerability data about CPython.

github.com/psf/advisory-databa

0
0
1
0