this post was submitted on 16 Apr 2025
1114 points (98.4% liked)

Technology

68916 readers
4797 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

Because vulnerability management has nothing to do with national security, right?

top 50 comments
sorted by: hot top controversial new old
[–] you_are_it@lemmy.sdf.org 16 points 1 day ago

Are you guys free yet?

[–] sugar_in_your_tea@sh.itjust.works 100 points 2 days ago (2 children)

Updated to add at 1700 UTC, April 16

In an 11th-hour reprieve, the US government last night agreed to continue funding the CVE program.

Not sure how much more whiplash I can take...

[–] ameancow@lemmy.world 68 points 2 days ago (2 children)

They want us to all tune out. This is all by design so we don't know what's real or not anymore, then they can get away with even more and nobody will care.

This is what they've been doing for years and years, this is just more of the same.

[–] tehn00bi@lemmy.world 19 points 2 days ago (2 children)

I’m not sure about “they” the US government, but it’s absolutely a Russian/ Authoritarian state playbook.

[–] ameancow@lemmy.world 10 points 2 days ago* (last edited 1 day ago)

Oh absolutely 100% this has had foreign involvement, the KGB handbook (literally) describes how to plant chaotic agents into a democratic nation's population to boost both sides of every social debate or argument. The digital age made this the easiest tactic in the world and every nation that's been "annexed" by Russia experienced this sowing of absolute weaponized bullshit and hate.

edit: several tankies follow me around downvoting my every comment and throwing tankie memes at me because they seeth when someone says that Russia did a bad thing. It's quite charming, they can't do much else because they're blocked.

load more comments (1 replies)
[–] MrScottyTay@sh.itjust.works 4 points 1 day ago

I think a lot of it is too get and propogate misinformation because some people won't hear about the 180s and still talk about as if they happened

load more comments (1 replies)
[–] Kbobabob@lemmy.world 169 points 2 days ago* (last edited 2 days ago) (10 children)

CVE program – the centralized Common Vulnerabilities and Exposures database of product security flaws

Just in case

Edit: I'm glad I wasn't the only one that didn't know. When the headline reads like everyone should know I felt a little dumb for a second.

[–] FlashMobOfOne@lemmy.world 44 points 2 days ago

Thank you. I've never heard this acronym before, myself.

load more comments (9 replies)
[–] nightm4re@feddit.org 10 points 1 day ago

My European friends here: do whatever you can to make EUVD a viable alternative. It's a vulnerability database led by the European Union Agency for Cybersecurity enisa. Since their website is relatively new, you can help by providing feedback though this survey. Yes, the CVE funding has been continued for another year. But a sustainable approach to vulnerability management cannot be dependent on a single government-owned / funded entity any longer! I wish the board members all the best in transferring CVE to a new umbrella organization, but now is a great time to also consider global alternatives.

[–] Formfiller@lemmy.world 16 points 1 day ago

It’s because the entire administration is a vulnerability

[–] OCATMBBL@lemmy.world 59 points 2 days ago (16 children)

We as a society need to start defining our damn acronyms. Stop assuming everyone knows what every acronym is, because they do not.

[–] LengAwaits@lemmy.world 6 points 1 day ago

Lucky for you the linked article explains the acronym!

Wait, you're not one of those people who only reads headlines, are you?

load more comments (15 replies)
[–] JigglySackles@lemmy.world 74 points 2 days ago (13 children)

REPUBLICANS. Not some nebulous "uncle sam". Republicans are turning off funding. They deserve 100% of the blame because they are 100% the cause.

[–] EarthShipTechIntern@lemm.ee 6 points 1 day ago (1 children)

Repugnicunts own the white house & house because Democraps in power didn't do their jobs the last four years. Russian influence in elections? Obvious, yet not abated by NSA. Misinformation by Fox & Facebook, X? Also obvious. Also not abated (let's go after TikTok!).

Blatant treason? No problem, we'll let him take presidency after we DON'T CHECK THE VOTING IRREGULARITIES in VOTES COLLECTED BY THE LARGEST CONTRIBUTER TO TRUMP'S CAMPAIGN.

DNC is a shit-heap.

AOC & Sanders are lovely exceptions.

load more comments (1 replies)
load more comments (12 replies)
[–] anomnom@sh.itjust.works 82 points 2 days ago

It’s not Uncle Sam, or the USA shutting this down. It’s the Republican Administration. They’ve been empowered by the Republican led Congress to shut down anything it doesn’t like, understand, or benefit from.

[–] PunkRockSportsFan@fanaticus.social 17 points 1 day ago* (last edited 1 day ago) (2 children)

They dont want national security.

They want to steal your property and destroy the country so they can reform it in their image.

[–] rottingleaf@lemmy.world 7 points 1 day ago

Rather they want new vulnerabilities to go right to the market and remain unknown for longer, because that makes the surveillance and other criminal activity by the government easier.

load more comments (1 replies)
[–] Australis13@fedia.io 296 points 2 days ago (8 children)

One can only conclude that either this is the latest step in a deliberate effort to sabotage the functioning of the US (and by extension much of the west), or just another monumentally stupid idea brought to life by their limitless incompetence.

[–] db2@lemmy.world 138 points 2 days ago

They're Russian puppets, both things are true.

[–] umbrella@lemmy.ml 42 points 2 days ago (2 children)

us capitalism has nowhere else to expand. its eating itself now.

load more comments (2 replies)
[–] Iamnotafish@lemmy.ml 59 points 2 days ago* (last edited 2 days ago) (1 children)

I suspect that the administration that asked their people to stop focusing on Russia in the cyber space is deliberately trying to weaken our security posture in relation to said country. This confirms it. Edit: The starlink (fuck musk) leak directly to the Russians now double confirms this

[–] parody@lemmings.world 4 points 1 day ago (1 children)
load more comments (1 replies)
load more comments (5 replies)
[–] TonyTonyChopper@mander.xyz 52 points 2 days ago

Right before Windows 10 loses security updates too, what a coincidence. Wonder what the Russians are working on...

[–] PlantPowerPhysicist@discuss.tchncs.de 67 points 2 days ago (1 children)

The EU needs to start planning now (well, really, needed to start planning in 2016) to replace every critical system that relies in any way on the US government.

If you think of money invested vs. return on government programs like this, the benefit is incredible. That it's being discontinued is obvious proof that the US is run by the agents of its own destruction and cannot be relied upon in any way: not as a supplier of military equipment, or information technology, or economic codependency.

[–] AcidicBasicGlitch@lemm.ee 16 points 2 days ago (3 children)

They're doing so much of this shit quietly, but when you start to put each piece together it should be frightening to anyone that doesn't believe Russia is our BFF.

In late Feb, just after the whole Zelenskyy White House visit, Hegseth issued an order to Cyber Command to halt all planning against Russia including cybersecurity offensive strategies.

He gave the order to Commander Timothy Haugh, who is also head of the National Security Agency. Haugh told the outgoing director of operations, and cyber command begun putting together an official document of why this is a very bad idea.

I missed this completely until yesterday, but it turns out that Haugh and his NSA deputy were both suddenly ousted from their positions less than 2 weeks ago.

No reason was given they were just told "your services are no longer required." Apparently Laura Loomer requested Trump have them removed and made some vague accusations against them bc they had been installed under Biden.

I admit I hadn't heard of CVE program before today. Since we are BFFs now and Russia is "totally not a threat" to the U.S., I guess it's supposed to be ok because friends share everything. But wouldn't this also make us incredibly more vulnerable to China and any other country?

load more comments (3 replies)
[–] umbraroze@slrpnk.net 38 points 2 days ago

I was, like, w-what CVE program. I don't know of any "CVE" programs that could be shut down, so I don't know what that abbreviation refers to.

Unless...

...oh no. Fuck. The actual CVE program? And they're just gonna- Shit.

What.

How.

I don't know how many times I've said "America is fucked" when reading the news lately, and I should stop doing that, because that fact has now been so well established that there's no need to elaborate.

[–] Wimster@europe.pub 5 points 1 day ago

Oh my God, and then I think of all the hundreds of thousands of veterans who voted for Trump. You did a great job.

[–] sinceasdf@lemmy.world 23 points 2 days ago (2 children)

False alarm

Updated to add at 1700 UTC, April 16 In an 11th-hour reprieve, the US government last night agreed to continue funding the CVE program.

[–] dantheclamman@lemmy.world 18 points 2 days ago (1 children)

I don't think it's a false alarm, in the sense that it is totally reasonable to be alarmed. They are cutting crucial stuff before they know what it is. There are a lot of things being cut where we're only going to understand the impact years from now.

load more comments (1 replies)
[–] towerful@programming.dev 22 points 2 days ago (1 children)
[–] C45513@lemm.ee 11 points 2 days ago

stable geniuses

[–] ccbrown@programming.dev 5 points 1 day ago

Terrifying. Unfortunately it’s difficult to explain to laypeople why the CVE system is so important. Our nation’s leaders certainly won’t get it. Hopefully the experts are able to get through to them when it’s time to renew again. And maybe we can reduce our government dependence a bit by then.

[–] solarvector@lemmy.dbzer0.com 44 points 2 days ago

For most people the consequences of this action will be too far away to understand the connection, so it's a pretty good target for the US Republican party.

[–] Rookeh@startrek.website 38 points 2 days ago* (last edited 2 days ago)

2017: covfefe

2025: cvefefe

[–] sp3ctr4l@lemmy.dbzer0.com 113 points 2 days ago (4 children)

On the bright side, at least our upcoming American cyberpunk dystopia is now more likely to feature a greater prevelance of lone wolf, broke, two bit hackers as a semi-viable lifestyle/'career path'...

load more comments (4 replies)
[–] FauxPseudo@lemmy.world 69 points 2 days ago (4 children)

This has a CVE score of 10. The next Security Now podcast episode is going to be lit.

load more comments (4 replies)
[–] cheese_greater@lemmy.world 119 points 2 days ago (6 children)

Ruzza just creamed their pants

load more comments (6 replies)
[–] oysvendsen@lemmy.world 4 points 1 day ago

😳 Is the program entirely funded by the US government?

What can EU and other governments/businesses do about this? Or what are they doing?

[–] SocialMediaRefugee@lemmy.world 12 points 2 days ago
[–] dan69@lemmy.world 58 points 2 days ago (3 children)

Adds cybersecurity to resume** Finally gets hired..

load more comments (3 replies)
[–] Yoga@lemmy.ca 43 points 2 days ago

Imagine being one of the tech billionaires who Trump bankrolled and he does this- basically handing out wrenches for people to throw.

[–] sik0fewl@lemmy.ca 46 points 2 days ago

Can't wait until I don't have to upgrade software anymore!

load more comments
view more: next ›