Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Alexandre Dulaunoy

@adulau@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff.

The other side is at @a@paperbay.org (photography, art and free software at large)

#infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

2803 Followers
3453 Following
50 Posts
Joined November 06, 2022
Website:
https://www.foo.be
GitHub:
https://github.com/adulau
Matrix:
@adulau:matrix.circl.lu
ORCID:
https://orcid.org/0000-0002-5437-4652
PGP FP:
6BB5 6353 1D99 F112 4C00 8C4F 815D 4786 1ECB 73D5
Other Mastodon:
https://paperbay.org/@a
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
The Radio Image Framing Protocol (RIFP) 1.0 is an experimental, extensible standard for sending images over low-rate radio links. The default rifp-cpfsk-4800 profile uses binary continuous-phase FSK and can be deployed around 433.92 MHz where local regulation permits it. RIFP itself is not tied to 433 MHz or to FSK and can be used in any frequency bands. I'm still exploring various low-cost options for a device that can receive and display images on an e-ink screen in emergency areas or similar environments. :github: Python implementation https://github.com/adulau/rifp Internet-Draft https://www.ietf.org/archive/id/draft-dulaunoy-rifp-00.html#radio #fax #433mhz #opensource
github.com
56
6
47
1
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 1mo ago

I just released ptrclassify is a small, dependency-free Python library and CLI that infers likely IP usage from reverse-DNS PTR hostnames.

It is intentionally heuristic and multi-label. PTR naming is operator-controlled and is not authoritative evidence of how an address is actually used. The output therefore includes a confidence score, the text that matched, and the rule IDs that produced each label.

To summarize, the library is trying to guess usage (and a bit location) of an IP address based on its PTR records. It's based on a set of rules which can be updated easily.

#osint #cybersecurity #ptrclassify #opensource #dns

:github: https://github.com/adulau/ptrclassify
:python: module https://pypi.org/project/ptrclassify/

infosec.exchange
16
0
10
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 1mo ago
From a research paper to running open-source code in just a few days. We (with @cedric@fosstodon.org) have been experimenting in Vulnerability-Lookup with the concept of Local Exploit Hazard, based on the recent research paper “Modeling Local Exploit Hazard — A Bayesian Framework for Quantifying Exploit Risk and Operational Efficiency” by Stephen Shaffer and Laura Cristiana Voicu. The idea addresses an important question in vulnerability management: Not simply “How dangerous is this vulnerability globally?” but “How much exploitation risk does this vulnerability represent in my environment?” Instead of introducing yet another static vulnerability score, the model starts from exploit likelihood such as EPSS and combines it with local security controls, CVSS attack vectors, vulnerability age and KEV policy to estimate an exploitation hazard. We implemented an experimental version in Vulnerability-Lookup and connected it directly to operational workflows. For the full details: https://www.vulnerability-lookup.org/2026/08/11/local-exploit-hazard/ #cve #gcve #vulnerabilitymanagement #vulnerability #opensource #opendata@circl@social.circl.lu
vulnerability-lookup.org

From a Research Paper to Running Code: Experimenting with Local Exploit Hazard in Vulnerability-Lookup

One of the interesting characteristics of open-source security tooling is that it gives us a relatively direct path from research to experimentation. On 27 July 2026, Stephen Shaffer and Laura Voicu published the first version of Modeling Local Exploit Hazard — A Bayesian Framework for Quantifying Exploit Risk and Operational Efficiency on arXiv. The paper proposes turning global exploit-likelihood estimates such as EPSS into a local exploit hazard that can account for an organization’s co

18
2
13
1
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 1mo ago

GCVE BCP-07, the Known Exploited Vulnerability (KEV) Assertion Format, has been updated to version 2.2. A key addition is the formalisation of the GCVE KEV Directory, a simple machine-readable directory allowing organisations to announce where their KEV catalogues and exploitation assertions are published.

We particularly encourage software and hardware vendors to publish their own KEV catalogues. Vendors are often in the best position to confirm exploitation affecting their products, and publishing this information in a machine-readable form can significantly improve vulnerability prioritisation for users, CSIRTs and vulnerability-management platforms.

For more details https://gcve.eu/2026/09/01/gcve-bcp-07-updated-a-directory-for-known-exploited-vulnerability-catalogues/

#GCVE #GNA #vulnerabilityintelligence #opensource #KEV #cybersecurity

@gcve@social.circl.lu

gcve.eu
7
0
7
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 1mo ago

GCVE Workshop - 22 September 2026 (14:00-18:00), Luxembourg Before The Vulnopticon Conference

We are pleased to announce a GCVE workshop on 22 September 2026, from 14:00 to 18:00, hosted at the CIRCL/LHC offices in Luxembourg, just before the VulnOpticon conference.

The workshop is free and open to everyone, but registration is required.

🔗 https://gcve.eu/2026/09/01/gcve-workshop-22-september-2026-1400-1800-luxembourg-before-the-vulnopticon-conference/

#cve #gcve #luxembourg #cybersecurity #vulnerabilitymanagement

gcve.eu
5
0
9
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 1mo ago

Doing some statistics on the persistence of information published on security and threat intelligence blogs. A surprising number of the domains in the list below are NXDOMAIN nowadays.

Don't assume that security information and threat intelligence will remain accessible over time, especially when it is hosted by large private entities.

Some are simply mistyped, while others reflect DNS changes over time that eventually left the original URLs broken.

Stability and persistence of information is hard on Internet.

#threatintelligence #threatintel #infosec #cybersecurity

  app.response.ncr.com
blog.0x3a.com
blog.anomali.com
blog.cert.societegenerale.com
blog.cylance.com
blog.deniable.org
blog.ioactive.com
blog.jpcert.or.jp
blog.kleissner.org
blog.malwareclipboard.com
blog.malwaretracker.com
blog.passivetotal.org
blog.safebit.mn
blog.team-cymru.org
blog.zimperium.com
blogs.rsa.com
cdn.securelist.com
community.saas.hpe.com
ddos.arbornetworks.com
dnsdb.isc.org
edu.arabsgate.com
info.baesystemsdetica.com
info.isightpartners.com
insider.domaintools.com
ioc.forensicartifacts.com
iranthreats.github.i
joedd.joesecurity.org
lab.anchiva.com
labs.alienvault.com
labs.lastline.com
labs.snort.org
labsblog.f-secure.com
luminosity.link
malware.sekoia.fr
morphick.net
motherboard.vice.com
ocelot.li
permalink.gmane.org
r.virscan.org
remchp.com
research.riskiq.net
resources.infosecinstitute.com
sandbox.deepviz.com
sec.sexy
securityblog.s21sec.com
securityblog.switch.ch
securitydaily.org
sub0day.com
tif.mcafee.com
wepawet.iseclab.org
www.cve.mitre.org
www.cyintanalysis.com
www.cyphort.com
www.icebrg.io
www.infosecdailynews.com
www.isightpartners.com
www.lexsi.com
www.novetta.com
www.packetmail.net
www.root9b.com
www.skycure.com
www.threatexpert.com
www.vxsecurity.sg
infosec.exchange
4
1
4
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 1mo ago

I spent many hours in vulnogram today and to be honest. I'm glad that a colleague started to work on a replacement called vulniverse. Still early beta but it's promising.

#opensource #vulniverse #cybersecurity #cve #gcve

:github: work in progress https://github.com/vulnerability-lookup/vulniverse

infosec.exchange
6
0
6
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 1mo ago

ptrclassify is a small, dependency-free Python library and CLI that infers likely IP usage and location from reverse-DNS PTR hostnames.

Version 0.3 released including new rules and CSV tool.

#ptrclassify #infosec #cybersecurity

🔗 https://github.com/adulau/ptrclassify

infosec.exchange
3
0
3
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Replying to
MISP Galaxy Threat Actor Explorer v1.0.0 released https://github.com/adulau/threat-actor-explorer #cti #cybersecurity #misp #threatintelligence #threatintel@misp@misp-community.org
GitHub

GitHub - adulau/threat-actor-explorer: A Threat-Actor explorer (browser-local) from the MISP galaxy dataset

A Threat-Actor explorer (browser-local) from the MISP galaxy dataset - adulau/threat-actor-explorer

7
0
5
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 1mo ago
Pretty cool idea from @nyanbinary@infosec.exchange - a bot to analyse fucked up references from the CVE records. @fuckeduprefs_bot@infosec.exchange Maybe we could imagine an archive bot at the same time to ensure that the references don't get lost. Just like archive.org or similar. Maybe something for @gcve@social.circl.lu to look into. #cve #vulnerability #gcve
6
5
4
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 1mo ago

Proposed changes in the CVE program CNA document

"Update 4.2.6 from SHOULD to MUST: "CNAs MUST assign different CVE IDs to separate Vulnerabilities""

🔗 https://github.com/CVEProject/cve-documents/issues/47#issuecomment-5515748024

#cve #vulnerabilitymanagement #cybersecurity

github.com
2
1
2
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 4mo ago

Not sure I’m allowed to leak this yet, but the new MISP dashboard is kind of crazy.

We didn’t just refresh the old one, we rewrote it completely, and it comes with a whole set of new features and capabilities that change the game quite a bit.

#misp #cti #dashboard #opensource

@misp@misp-community.org

infosec.exchange
20
6
20
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Pivotick is an open-source network graph library to facilitate pivoting. Version 1.4.0 has been released and also includes a security fix. Release notes https://github.com/Pivotick/Pivotick/releases/tag/v1.4.0 Documentation https://pivotick.github.io/Pivotick/ Vulnerability fixed in 1.4.0 https://vulnerability.circl.lu/vuln/gcve-1-2026-20151 Gallery https://pivotick.github.io/Pivotick/gallery.html#opensource #infovis #graph #networkgraph #visual
github.com
6
0
5
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Wireshark for the web (webasm) Open, dissect and analyse .pcap / .pcapng capture files entirely in your web browser. Online - local in your browser https://stricaud.github.io/wpcapng/ Sourc code - https://github.com/stricaud/wpcapng #nids #pcap #networkanalysis #wireshark
stricaud.github.io

wpcapng — Wireshark for the web

Open, dissect and analyse pcap/pcapng files entirely in your browser. Nothing is uploaded.

6
0
12
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 3mo ago
« Once an organisation accepts that the difficult software will be bought elsewhere, internal teams slowly lose the habit of building. Procurement becomes a substitute for strategy. Legal review becomes a substitute for leadership. Risk management becomes a substitute for execution. » https://foo.be/2026/06/Sovereignty-Is-Engineered-Not-Procured.html #sovereignty #europe #opensource
foo.be
9
0
9
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 4mo ago

What’s the difference between an API and an agent?

An API is consistent, deterministic, and scoped.
An agent is probabilistic, non-deterministic, and occasionally chaotic.

An agent adds some spice to your life.

Will you choose the boring, predictable life or the cool, chaotic one?

#ai #ia

infosec.exchange

Infosec Exchange

9
4
5
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Replying to
@muddle@infosec.exchange I updated the format to facilitate the use of smaller packer radio protocols. https://author-tools.ietf.org/iddiff?url1=draft-dulaunoy-rifp-00&url2=draft-dulaunoy-rifp-01&difftype=--html Thanks for the feedback.
author-tools.ietf.org
3
0
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
So finally Kimi-k3 is not really open-source https://huggingface.co/moonshotai/Kimi-K3/blob/main/LICENSE I'm a bit disappointed. #kimi #ai #opensource
LICENSE · moonshotai/Kimi-K3 at main
huggingface.co

LICENSE · moonshotai/Kimi-K3 at main

We’re on a journey to advance and democratize artificial intelligence through open source and open science.

3
3
3
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Replying to
@diffractie@glitterkitten.co.uk I think the major issue is the lack of authentication as these are often used for forensic investigations.
3
0
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 3mo ago
We are exploring some ambitious ideas around reducing external dependencies and relying more on our own libraries across MISP and related tooling. Over the past year, we have been working on a replacement network graph library for the new MISP interface and things are getting really interesting. Pivotick is already used in around ten open-source tools, including CTI Transmute, AIL Project, and Rulezet. It has also recently been integrated into the new MISP UI, OverMind. The library is, of course, open source and comes with extensive documentation, including AI-parseable documentation to make integration easier. We have just released Pivotick v1.2.0. https://pivotick.github.io/Pivotick/ https://github.com/Pivotick/Pivotick #infovis #cybersecurity #opensource
pivotick.github.io

Pivotick

Pivotick documentation

4
0
2
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 3mo ago
We just released cve-search v6.0.1 - it is a security and maintenance release. All users are strongly encouraged to upgrade. Thanks to @oh2fih@infosec.exchange for the remediation fix and release support. Thanks to George Chen for the report about the security vulnerability. #cve #gcve #cybersecurity 🔗 https://github.com/cve-search/cve-search/releases/tag/v6.0.1
github.com
4
1
7
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 3mo ago
Looking at the current distributed.net statistics on the current RC5-72 brute force, this actually puts some key-size discussions into perspective. #cryptography #crypto #symmetric #cybersecurity
3
1
2
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 3mo ago
An idea for next year workshop @passthesaltcon@infosec.exchange - open source license for developers? It could be a nice opportunity because it seems to be a never ending learning process. #opensource
3
0
1
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Replying to
@westonsteimel@hachyderm.io @darakian@fosstodon.org That’s great feedback. We will also update the FAQ about this on gcve.eu. Technically is just documenting more (than hiding the information behind a closed-door dispute process) and every users/orgs can decide which source they take. Vulnerability-lookup software stack already includes it. @gcve@social.circl.lu
2
2
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Have you seen any evidence of the famous « collect encrypt data and decrypt later » in incident response ? Until now, I haven’t. #pqc #crypto #cryptography #dfir
1
1
1
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Replying to
@muddle@infosec.exchange The protocol is not two-way. It's unidirectional. Repeated frame transfer is basically the loop to send continuously the frame to ensure that a receiver get the manifest and all the frame for the image.
1
2
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Replying to
@westonsteimel@hachyderm.io Thanks for contributing too. It’s an early draft to be implemented in the gcve open source toolset. Ideas and feedback more than welcome! @gcve@social.circl.lu
1
1
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 3mo ago
Replying to
@bzg@floss.social @zacchiro@mastodon.xyz You might be interested in vulnerability-lookup https://github.com/vulnerability-lookup/vulnerability-lookup which is much more advanced and complete for the global vulnerability ecosystem. @oh2fih@infosec.exchange
GitHub

GitHub - vulnerability-lookup/vulnerability-lookup: Vulnerability-Lookup facilitates quick correlation of vulnerabilities from various sources, independent of vulnerability IDs, and streamlines the management of Coordinated Vulnerability Disclosure (CVD).

Vulnerability-Lookup facilitates quick correlation of vulnerabilities from various sources, independent of vulnerability IDs, and streamlines the management of Coordinated Vulnerability Disclosure ...

1
0
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Replying to
@tyzbit@toot.now There are different ones at different level of open-source but there are some which are indeed including all the training recipes including dataset and even checkpointing: https://github.com/NVIDIA-NeMo/Nemotron Nemotron is maybe one of the good example.https://github.com/allenai/olmo-core Olmo is another example. There are many more but those are actually working ones and other already reproduced the training process.
github.com
0
1
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Replying to
@hrbrmstr@mastodon.social and they forget 70% of other vulnerabilities thinking only CVE exists 🫣 We still kindly accept nice PR on vulnerability-lookup and we won’t be killed by a VC 😇 https://vulnerability.circl.lu/ https://github.com/vulnerability-lookup/vulnerability-lookup
vulnerability.circl.lu
0
0
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
I don’t like playing the futurologist, but after seeing AI companies warn EU institutions about the supposed risks of open-weight models, I suspect some are lobbying to regain control over genuine open source and open-weight AI. Don’t fall into the trap: the greater danger lies in opaque, proprietary models, not open-source ones. #opensource #ai #cybersecurity
0
2
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 3mo ago
We started rulezet project after identifying a clear gap in open source tooling for detection rules management: the ability to operate synchronised instances while still allowing each organisation to maintain its own autonomous rule repository. Rulezet addresses this need as an open source platform for managing, sharing, and synchronising detection rules. Each organisation can run its own standalone instance and decide independently which other instances, communities, or repositories it wants to synchronise with. The latest release reached a significant milestone to make it more operational for other DFIR tools. Online version: https://rulezet.org/ Release notes: https://github.com/rulezet/rulezet-core/releases/tag/1.6.1 #dfir #opensource #cybersecurity
rulezet.org
0
0
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Replying to
@darakian@fosstodon.org The model is very different. Dispute are totally fine in GCVE and we don’t need to reach a consensus or having a GNA of last resort. The information is there along with the different point of view. It’s just like git. Forking is just fine and beneficial for the system. @westonsteimel@hachyderm.io @gcve@social.circl.lu
0
4
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 3mo ago
@aristot73@infosec.exchange I'm not into this kind of sport. But here, it might be different ;-) Should we expect the harbor of Antwerp to be bombed soon. @bert_hubert@mastodon.nl
0
0
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 4mo ago
Replying to
@iglocska@infosec.exchange Sorry but we cannot hide this any longer. @misp@misp-community.org
0
0
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 3mo ago
Replying to
@vickyjo@mastodon.social I ran workshops on this topic in the early 2000s, yet the mistake of creating a custom license remains surprisingly common. It would be useful to document the most frequent pitfalls and explain how they can harm a community, reduce adoption, and ultimately weaken a new open-source project. @passthesaltcon@infosec.exchange
0
0
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Replying to
@muddle@infosec.exchange I already received question about LoRa which is pretty common for ESP32 chips. As LoRA is packet base and not IQ based, I might need to add a type for fragmented manifest over small PDU.
0
1
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 1mo ago
Replying to
@welch@fosstodon.org Cool. If you have any question about GCVE or/and vulnerability-lookup, feel free. @jbm@infosec.exchange @nyanbinary@infosec.exchange @jgamblin@infosec.exchange @todb@infosec.exchange
0
1
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Replying to
@djh@chaos.social The paper said open-source but on HuggingFace, it's a different story. You have to be approved to be able to look at the repository... doesn't seem very open-source.
0
1
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Replying to
@CCC@social.bau-ha.us Did we ask for same data for US citizens ?
0
1
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 4mo ago

I’m wondering why @dnsoarc@mastodns.net is limiting potential new contributions to their project just because they are AI-assisted.

Many valuable tools support development today, including code review and security review. The copyright argument feels similar to the one behind CLAs: an unsuccessful attempt to control the origin of the code, or even the author’s ability to re-implement a specific idea with or without external tools.

#ai #opensource #copyright

https://codeberg.org/DNS-OARC#artificial-intelligence-and-large-language-model-contributions-policy

infosec.exchange

Infosec Exchange

0
3
2
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Replying to
@flo@mi.cmbg.ws This remembers me the old lobbying from Microsoft in late nineties explaining that free software and copyleft will kill the software industry. At the end, open-source/free software was a major economical driver during the past 30 years.
0
0
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Replying to on social.gompa.me
@neal@social.gompa.me All is documented as BCP including IDs allocation https://gcve.eu/bcp/ If you have any question feel free. @bernardq@ehlo.exim.org
gcve.eu
0
0
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Replying to
@tyzbit@toot.now We are actually digging quite a lot in the topic. Academic papers claiming open source models and then you cannot get access to the original recipe is driving me nuts too. The reproducibility is usually hard to evaluate if you don’t have some H100 cards laying in your racks… but I see that more and more models are releasing details to reproduce the training steps. I remain optimism for the future while the model training will become more accessible on smaller hardware.
0
0
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
A new version of the BCP-11 "Community Contribution Fragments for Existing CVE Records" proposal has been published. https://discourse.ossbase.org/t/gcve-bcp-11-community-proposed-updates-to-existing-cve-records/1110/8#p-1495-gcve-bcp-11-community-contribution-fragments-for-existing-cve-records-1 This new version is a major refactoring of the originally proposed format. Feel free to comment, update or propose changes. An implementation will follow when the BCP-11 reach a more stable state. #gcve #cve #cybersecurity #vulnerabilitymanagement@gcve@social.circl.lu
discourse.ossbase.org
0
0
1
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Replying to
@iglocska@infosec.exchange Just like all the fauxpen starting with "Open" in their names. @djh@chaos.social
0
1
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
Replying to
@darakian@fosstodon.org This one is a special case GNA. The GNA itself combine the proposals. But it doesn’t block other GNA to publish their point of view. There is no dispute resolution in GCVE as each GNA can publish their point of view including opposition. Via relationships https://gcve.eu/bcp/gcve-bcp-05/#potential-relationship-verbs-for-vulnerability-identifiers @westonsteimel@hachyderm.io @gcve@social.circl.lu
gcve.eu
0
1
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 2mo ago
The GCVE Lab is an open space for experimenting with new ideas, tools, formats, and services related to the Global CVE Allocation System initiative. The lab allows the GCVE community to explore promising concepts without immediately imposing the stability, compatibility, and operational requirements expected from the core GCVE infrastructure. Open to comments/ideas. #gcve #cve #cybersecurityhttps://discourse.ossbase.org/t/gcve-lab-proposal/1117 https://gcve.eu @gcve@social.circl.lu @gcve@discourse.ossbase.org
GCVE Lab - Proposal
ossbase.org

GCVE Lab - Proposal

GCVE Lab Draft proposal The GCVE Lab is an open space for experimenting with new ideas, tools, formats, and services related to the Global CVE Allocation System. The lab allows the GCVE community to explore promising concepts without immediately imposing the stability, compatibility, and operational requirements expected from the core GCVE infrastructure. Some experiments may eventually become official GCVE tools or services. Others may remain research prototypes, inspire different projects,

0
0
0
0
Open post
Alexandre Dulaunoy @adulau@infosec.exchange
· 1mo ago

CVSS and WRONG models are just the same.

#cvss #infosec

infosec.exchange
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:32:39 UTC