Vulnerabilities Category?

I was resistant to the idea of a vuln category originally, trying to let things fall where they would naturally. It does seem like there’s enough CVE news that isn’t yet actionable that maybe we use a separate category as a destination until/unless the CVEs become exploited, at which point it’s Threat Intel. Or maybe it’s just Cyber News.

Thoughts?

My view is (possibly purist)

Threat + Vulnerability + Opportunity/Exploitability = Risk

Threats and Vulns are different things.

The actor details, and the way actors approach or exploit a vulnerability would be intel. TTPs, C2 nodes, ASNs etc.

I agree with this framing! But since one can turn into the other, and folks are gonna post about interesting vulns, do we want a dedicated place to park them, or is Cyber News sufficient?

I think it deserves its own category.

News will either be breaking news (breaches force disclosing vulns or intel, or unreleased intel via normal disclosure) or reporting context or opinion on a disclosed vulnerability.

Intel might become a vuln, but a vuln is unlikely to become intel. There may be intel surrounding exploitation, but that’s intel.

BUT if there’s RUMINT about a vuln (think F5 shenanigans), then that’s an unconfirmed vuln? (Tag?)

The vuln feed can be tagged with a CVE, KEV etc for proper sorting.

Possibly semantics but an important distinction for consistency moving forward.

I think vuln news is definitely a subset of cyber news but still feels distinct enough to have its own category. I like the idea of the category being like a staging ground/cross reference place for moving through actionable threat intel pipeline/watching. I like Odin’s framing as well. Would having its own category make wiki post handling easier?

It would in the sense that anything in the “Vulnerabilities” cat is definitionally not actionable, so we can deprioritize it, and know that anything in TI is actionable.

Something we need to establish is “When to Wiki” a topic—meaning it is changing enough that we need a primary post with all the relevant information up top. We’re still figuring out how we want the standards to look, and this is how it happens!

Is there an easy way to forklift a thread from one category to another?

If not we may want to consider what to do when a topic changes from vuln to threat. Maybe just pin a redirect to the top?

We can edit categories and tags easily, yes. we’ve already been doing this with unactionable news => intel when it becomes actionable.

Tells me vulns should be a category.

I would gently challenge vulnerabilities not being ‘actionable’ as such. But I think I know where your mind is at in contrast to intel. While technically both are reactive, you can action vulnerability management proactively in the same was as detecting threat intel indicators. What we don’t want to do is become yet another vulnerability database. The challenge is when is a vulnerability ‘significant’?.

Copy Fail being an excellent example at 7.8 CVSS - yet being one of the most significant vulnerabilities in a decade or more. Surface level, it’s authenticated and local priv escalation. Impact, however is massive, and the scale incalculable.

I would agree that TI of vulnerabilities being exploited takes precedent completely, with vulnerabilities being an almost ‘backlog’ type item. But determining significance won’t be straightforward. I think we just need clarity so as not to tie ourselves in knots chasing the impossible, or replicating work of existing services.

Apologies for borrowing a militarism but I see what we do regarding vulnerabilities is enriching said vulns as a ‘force multiplier’.

Will absolutely take your steer on the wiki piece, as it’s a brave new world to me being able to have this hybrid approach, and I’m slowly getting informed!

Eh?

I used the term “significant” to speak to @OdinSphere’s point about not wanting to become yet another vuln DB. There’s some feel to this, but severity and impact will inform the judgment call.