July 23, 2024
Donald Rumsfeld is famous for talking about the “unknown unknowns.” Well, today we will be a little more specific and focus on some “knowns.”
Most listeners know that cyber threat companies regularly list vulnerabilities. Jay Wallace estimates VulnCheck alone has a list of 300,000 known threats.
The Cybersecurity & Infrastructure Security Agency (CISA) decided to help federal agencies narrow down this list. They put together a list of vulnerabilities that were specific to federal networks. For example, if no federal agency ever uses “XYZ” software, why should a federal information professional care about it? It is not and will never be on their systems.
The key to understanding the KVE is that CISA will not just put a vulnerability on a list and say, “Good luck.” They will post a patch to remediate the problem.
"CISA publishes the vulnerability when they know it has been exploited in the wild, there is patch advice issued by the vendor, then they will give a certain timeline for remediation"
Jay Wallace, Vulncheck Tweet
VulnCheck helps federal agencies with prioritization, proof of concept, and a community.
Prioritization: For example, VulnCheck can assist in setting up priorities or these varying threats.
Proof of Concept: >For example, during the interview, Jay Wallace mentions something called a Proof of Concept (PoC). VulnCheck can look like software combinations and determine if they can be a threat.
Community: VulnCheck has an active community where these threats are discussed. Just this year, the VulnCheck community has been active in many areas, including making information about vulnerabilities consumed in a more palatable manner.
Malicious actors know about vulnerabilities, and a responsible federal manager should become familiar with how to manage this vulnerability list.
If you enjoyed this episode, then you may want to listen to
EP-171 – Looking at Generative AI & Cybersecurity from a Global Perspective
Relevance: Discusses AI’s impact on cybersecurity, useful for contrasting evolving threats vs. known vulnerabilities.
EP-178 – Akamai & Identity Management
Relevance: Connects to securing identities and reducing vulnerability exposure across networks

Leave a Reply