The EU Created Their Own CVE Program – ThreatWire

This video covers recent cybersecurity news, including a Lockbit website hack, the Meta vs. NSO group lawsuit, and the launch of the EU Vulnerability Database by the EU. It also provides a personal update from Alli Diamond about her career situation and ongoing projects.

Keypoints :

  • Lockbit’s dark web website was hacked, revealing sensitive data including Bitcoin wallets and user credentials, but their decryptors and core data remained unaffected.
  • The Meta lawsuit against NSO Group resulted in a court victory for Meta, with NSO ordered to pay $167 million in damages for spyware used against WhatsApp users, including journalists and activists.
  • NSO Group’s Pegasus spyware can infect smartphones via calls without user interaction, and the company claims it only sells to authorized government agencies for fighting serious crimes.
  • The EU launched the European Vulnerability Database (EUVD) as part of its NIS-2 cybersecurity framework, aiming to support vulnerability disclosure alongside the existing CVE program.
  • ENISA, the EU Agency for Cybersecurity, clarified that the EUVD is designed to complement the CVE system, not compete with it, and they became a CVE Numbering Authority in January 2024.
  • Alli Diamond shared her personal career update, explaining her current job situation, her passion for cybersecurity, and her ongoing efforts to find a new full-time software engineering role.
  • The video emphasizes the importance of cybersecurity awareness and encourages viewers to follow Alli’s journey and stay vigilant against cyber threats.