diff --git a/src/assets/data/CNAsList.json b/src/assets/data/CNAsList.json index 942a1be27..04889dcda 100644 --- a/src/assets/data/CNAsList.json +++ b/src/assets/data/CNAsList.json @@ -12368,16 +12368,16 @@ "country": "USA" }, { - "shortName": "GE_GP", + "shortName": "GE_Vernova", "cnaID": "CNA-2022-0009", - "organizationName": "General Electric (Gas Power)", - "scope": "GE (Gas Power) issues only.", + "organizationName": "GE Vernova", + "scope": "All GE Vernova products.", "contact": [ { "email": [ { "label": "Email", - "emailAddr": "GEPowerCVD@ge.com" + "emailAddr": "GEV.PSIRT@ge.com" } ], "contact": [], @@ -12388,7 +12388,7 @@ { "label": "Policy", "language": "", - "url": "https://www.ge.com/gas-power/products/digital-and-controls/cybersecurity/vulnerability-response" + "url": "https://www.gevernova.com/gas-power/products/digital-and-controls/cybersecurity/vulnerability-response" } ], "securityAdvisories": { @@ -12396,7 +12396,7 @@ "advisories": [ { "label": "Advisories", - "url": "https://www.ge.com/gas-power/products/digital-and-controls/cybersecurity/security-advisories" + "url": "https://www.gevernova.com/gas-power/products/digital-and-controls/cybersecurity/security-advisories" } ] }, @@ -12969,8 +12969,8 @@ "advisories": [ { "label": "Advisories", - "url": "https://gitee.com/opengauss/security" - } + "url": "https://opengauss.org/en/security-advisories/" + } ] }, "resources": [], @@ -13531,7 +13531,7 @@ { "label": "Policy", "language": "", - "url": "https://www.opennms.com/contact/" + "url": "https://www.opennms.com/security/" } ], "securityAdvisories": { @@ -18738,7 +18738,7 @@ { "label": "Policy", "language": "", - "url": "https://github.com/chipsalliance/Caliptra/security" + "url": "https://github.com/chipsalliance/Caliptra/security/policy" } ], "securityAdvisories": { @@ -18746,7 +18746,7 @@ "advisories": [ { "label": "Advisories", - "url": "https://github.com/chipsalliance/Caliptra/security" + "url": "https://github.com/chipsalliance/Caliptra/security/advisories" } ] }, @@ -25493,7 +25493,7 @@ "shortName": "Saviynt", "cnaID": "CNA-2025-0011", "organizationName": "Saviynt Inc.", - "scope": "Vulnerabilities discovered in Saviynt products or vulnerabilities reported to Saviynt Labs that are not in another CNA’s scope.", + "scope": "Vulnerabilities discovered in Saviynt products.", "contact": [ { "email": [ @@ -25600,5 +25600,118 @@ ] }, "country": "Canada" + }, + { + "shortName": "IDT-DNA", + "cnaID": "CNA-2025-0013", + "organizationName": "Integrated DNA Technologies, Inc.", + "scope": "Vulnerabilities within IDT-manufactured products, software, and services that are in-service.", + "contact": [ + { + "email": [ + { + "label": "Email", + "emailAddr": "ProductSecurity@idtdna.com" + } + ], + "contact": [], + "form": [] + } + ], + "disclosurePolicy": [ + { + "label": "Policy", + "language": "", + "url": "https://www.idtdna.com/pages/support/vulnerability-disclosure-process/" + } + ], + "securityAdvisories": { + "alerts": [], + "advisories": [ + { + "label": "Advisories", + "url": "https://www.idtdna.com/pages/support/vulnerability-disclosure-process/known-vulnerabilities" + } + ] + }, + "resources": [], + "CNA": { + "isRoot": false, + "root": { + "shortName": "icscert", + "organizationName": "Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS)" + }, + "roles": [ + { + "helpText": "", + "role": "CNA" + } + ], + "TLR": { + "shortName": "CISA", + "organizationName": "Cybersecurity and Infrastructure Security Agency (CISA)" + }, + "type": [ + "Vendor" + ] + }, + "country": "USA" + }, + { + "shortName": "TMUS", + "cnaID": "CNA-2025-0014", + "organizationName": "T-Mobile US", + "scope": "All T-Mobile US products (including end-of-life/end-of-service products), as well as vulnerabilities in third-party software/hardware discovered by T-Mobile US that are not in another CNA’s scope.", + "contact": [ + { + "email": [ + { + "label": "Email", + "emailAddr": "security@t-mobile.com" + } + ], + "contact": [], + "form": [] + } + ], + "disclosurePolicy": [ + { + "label": "Policy", + "language": "", + "url": "https://bugcrowd.com/engagements/t-mobile" + } + ], + "securityAdvisories": { + "alerts": [], + "advisories": [ + { + "label": "Advisories", + "url": "https://t-mobile.github.io/" + } + ] + }, + "resources": [], + "CNA": { + "isRoot": false, + "root": { + "shortName": "icscert", + "organizationName": "Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS)" + }, + "roles": [ + { + "helpText": "", + "role": "CNA" + } + ], + "TLR": { + "shortName": "CISA", + "organizationName": "Cybersecurity and Infrastructure Security Agency (CISA)" + }, + "type": [ + "Vendor", + "Researcher" + ] + }, + "country": "USA" } ] \ No newline at end of file diff --git a/src/assets/data/events.json b/src/assets/data/events.json index 01d0be3ba..64bd4cdee 100644 --- a/src/assets/data/events.json +++ b/src/assets/data/events.json @@ -34,7 +34,7 @@ "displayOnHomepageOrder": 1, "title": "CVE/FIRST VulnCon 2025", "location": "Raleigh, North Carolina, USA & Virtual", - "description": "VulnCon 2025 is co-sponsored by the CVE Program and FIRST and is open to the public.

SPECIAL MESSAGE FOR CVE NUMBERING AUTHORITIES (CNAs):
VulnCon 2025 takes the place of this year’s Spring CVE Global Summit.

Registration:
Now open. Details here.
Registration fees include four days of coffee breaks and buffet lunches, one networking reception hosted at the McKimmon Center, and applicable meeting materials. Note that discounted rates are not being offered for this event regardless of membership or speaking status.

An offsite social event is planned for Tuesday, April 8, from 19:00-21:00 in downtown Raleigh. Location to be announced in January. You may purchase a ticket during your main registration or access a separate purchase form link found in your registration email confirmation. Tickets are US $30.00 per person.

Program Overview:
* Monday, April 7 — Training Day 1, Vendor Tables, Welcome Reception
* Tuesday, April 8 — Training Day 2, Vendor Tables, Off-site Social Event
* Wednesday, April 9 — Plenary, Breakouts, Vendor Tables
* Thursday, April 10 — Plenary, Breakouts, Vendor Tables

Agenda:
A detailed agenda will be available in March 2025.

Venue:
McKimmon Center,
North Carolina State University
,
1101 Gorman St.,
Raleigh, North Carolina 27606
USA

Call for Papers:
Closed on January 31, 2025. Details here.

Purpose:
The purpose of VulnCon is to collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken back to individual programs for action to benefit the vulnerability management ecosystem.

A key goal of the conference is to understand what important stakeholders and programs are doing within the vulnerability management ecosystem and best determine how to benefit the ecosystem broadly.", + "description": "VulnCon 2025 is co-sponsored by the CVE Program and FIRST and is open to the public.

SPECIAL MESSAGE FOR CVE NUMBERING AUTHORITIES (CNAs):
VulnCon 2025 takes the place of this year’s Spring CVE Global Summit.

Agenda:
Available here.

Registration:
Open. Details here.
Registration fees include four days of coffee breaks and buffet lunches, one networking reception hosted at the McKimmon Center, and applicable meeting materials. Note that discounted rates are not being offered for this event regardless of membership or speaking status.

An offsite social event is planned for Tuesday, April 8, from 19:00-21:00 in downtown Raleigh. Location to be announced in January. You may purchase a ticket during your main registration or access a separate purchase form link found in your registration email confirmation. Tickets are US $30.00 per person.

Program Overview:
* Day 1: Monday, April 7 — Plenary, Vendor Tables, Welcome Reception
* Day 2: Tuesday, April 8 — Plenary, Vendor Tables, Off-site Social Event
* Day 3: Wednesday, April 9 — Plenary, Breakouts, Vendor Tables
* Day 4: Thursday, April 10 — Plenary, Breakouts, Vendor Tables

Venue:
McKimmon Center,
North Carolina State University
,
1101 Gorman St.,
Raleigh, North Carolina 27606
USA

Call for Papers:
Closed on January 31, 2025. Details here.

Purpose:
The purpose of VulnCon is to collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken back to individual programs for action to benefit the vulnerability management ecosystem.

A key goal of the conference is to understand what important stakeholders and programs are doing within the vulnerability management ecosystem and best determine how to benefit the ecosystem broadly.", "permission": "public", "url": "https://www.first.org/conference/vulncon2025/", "date": { diff --git a/src/assets/data/metrics.json b/src/assets/data/metrics.json index 16e797eb2..a72a107d7 100644 --- a/src/assets/data/metrics.json +++ b/src/assets/data/metrics.json @@ -1137,7 +1137,7 @@ }, { "month": "March", - "value": "TBA" + "value": "2" }, { "month": "April", diff --git a/src/assets/data/news.json b/src/assets/data/news.json index fa4773b7d..84c4ec783 100644 --- a/src/assets/data/news.json +++ b/src/assets/data/news.json @@ -1,7 +1,178 @@ { "currentNews": [ + { + "id": 496, + "newsType": "news", + "title": "T-Mobile US Added as CVE Numbering Authority (CNA)", + "urlKeywords": "T-Mobile US Added as CNA", + "date": "2025-03-11", + "description": [ + { + "contentnewsType": "paragraph", + "content": "T-Mobile US is now a CVE Numbering Authority (CNA) for all T-Mobile US products (including end-of-life/end-of-service products), as well as vulnerabilities in third-party software/hardware discovered by T-Mobile US that are not in another CNA’s scope." + }, + { + "contentnewsType": "paragraph", + "content": "To date, 447 CNAs (444 CNAs and 3 CNA-LRs) from 40 countries and 1 no country affiliation have partnered with the CVE Program. CNAs are organizations from around the world that are authorized to assign CVE Identifiers (CVE IDs) and publish CVE Records for vulnerabilities affecting products within their distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities. T-Mobile US is the 240th CNA from USA." + }, + { + "contentnewsType": "paragraph", + "content": "T-Mobile US’s Root is the CISA ICS Root." + } + ] + }, + { + "id": 495, + "newsType": "news", + "title": "Integrated DNA Technologies Added as CVE Numbering Authority (CNA)", + "urlKeywords": "Integrated DNA Technologies Added as CNA", + "date": "2025-03-11", + "description": [ + { + "contentnewsType": "paragraph", + "content": "Integrated DNA Technologies, Inc. (IDT) is now a CVE Numbering Authority (CNA) for vulnerabilities within IDT-manufactured products, software, and services that are in-service." + }, + { + "contentnewsType": "paragraph", + "content": "To date, 446 CNAs (443 CNAs and 3 CNA-LRs) from 40 countries and 1 no country affiliation have partnered with the CVE Program. CNAs are organizations from around the world that are authorized to assign CVE Identifiers (CVE IDs) and publish CVE Records for vulnerabilities affecting products within their distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities. Integrated DNA Technologies is the 239th CNA from USA." + }, + { + "contentnewsType": "paragraph", + "content": "Integrated DNA Technologies’ Root is the CISA ICS Root." + } + ] + }, + { + "id": 494, + "newsType": "news", + "title": "GE Vernova CNA Has Replaced General Electric (Gas Power) CNA", + "urlKeywords": "GE Vernova CNA Replaced General Electric Gas Power CNA", + "date": "2025-03-11", + "description": [ + { + "contentnewsType": "paragraph", + "content": "As of March 11, 2025, the General Electric (Gas Power) CVE Numbering Authority (CNA), which became a CVE Program partner in 2022, has been replaced by the GE Vernova CNA. The GE Vernova CNA’s scope is: “All GE Vernova products.”" + }, + { + "contentnewsType": "paragraph", + "content": "To date, 445 CNAs (442 CNAs and 3 CNA-LRs) from 40 countries and 1 no country affiliation have partnered with the CVE Program. GE Vernova’s Root is the CISA ICS Root." + } + ] + }, + { + "id": 493, + "displayOnHomepageOrder": 3, + "newsType": "blog", + "title": "Vulnerability Data Enrichment for CVE Records: 246 CNAs on the Enrichment Recognition List for March 10, 2025", + "urlKeywords": "CNA Enrichment Recognition List Update", + "date": "2025-03-11", + "author": { + "name": "CVE Program", + "organization": { + "name": "CVE Program", + "url": "" + }, + "title": "", + "bio": "" + }, + "description": [ + { + "contentnewsType": "image", + "imageWidth": "", + "href": "/news/CnaEnrichmentRecognitionList.png", + "altText": "Increasing the Value of the CVE Record - CNA Enrichment Recognition List" + }, + { + "contentnewsType": "paragraph", + "content": "The “CNA Enrichment Recognition List” for March 10, 2025, is now available with 246 CNAs listed. Published every two weeks on the CVE website, the list recognizes those CVE Numbering Authorities (CNAs) that are actively providing enhanced vulnerability data in their CVE Records. CNAs are added to the list if they provide Common Vulnerability Scoring System (CVSS) and Common Weakness Enumeration (CWE™) information 98% of the time or more within the two-week period of their last published CVE Record." + }, + { + "contentnewsType": "paragraph", + "content": "For more about the recognition list, see “Recognition for CNAs Actively Providing Vulnerability Data Enrichment for CVE Records.” To learn more about vulnerability information types like CVSS and CWE, see the CVE Record User Guide. View the most current CNA Enrichment Recognition List on the CVE website Metrics page here." + }, + { + "contentnewsType": "paragraph", + "content": "CNA Enrichment Recognition List for March 10, 2025, with 246 CNAs listed: " + } + ] + }, + { + "id": 492, + "displayOnHomepageOrder": 2, + "newsType": "blog", + "title": "Full Agenda Now Available for CVE/FIRST VulnCon 2025 on April 7-10, 2025!", + "urlKeywords": "Full Agenda for CVE FIRST VulnCon 2025", + "date": "2025-03-11", + "author": { + "name": "CVE Program", + "organization": { + "name": "CVE Program", + "url": "" + }, + "title": "", + "bio": "" + }, + "description": [ + { + "contentnewsType": "image", + "imageWidth": "", + "href": "/news/VulnCon2025.png", + "altText": "CVE/FIRST VulnCon 2025, April 7-10, 2025", + "captionText": "VulnCon 2025 Agenda" + }, + { + "contentnewsType": "paragraph", + "content": "The CVE Program and FIRST will co-host VulnCon 2025 at the McKimmon Center in Raleigh, North Carolina, USA, on April 7-10, 2025. The full agenda is available now on this conference web page or view the schedule by day." + }, + { + "contentnewsType": "paragraph", + "content": "Monday, April 7View day 1 schedule
Tuesday, April 8View day 2 schedule
Wednesday, April 9View day 3 schedule
Thursday, April 10View day 4 schedule" + }, + { + "contentnewsType": "paragraph", + "content": "

Virtual and In-Person Registration Options

" + }, + { + "contentnewsType": "paragraph", + "content": "CVE Numbering Authorities (CNAs) — VulnCon 2025 takes the place of the 2025 Spring CVE Global Summit." + }, + { + "contentnewsType": "paragraph", + "content": "Registration, both virtual and in-person, is open on the VulnCon 2025 conference registration page hosted on the FIRST website." + }, + { + "contentnewsType": "paragraph", + "content": "Discounted rates are not offered for this event regardless of membership or speaking status. Registration fees for in-person attendance include four days of coffee breaks and buffet lunches, one networking reception hosted at the McKimmon Center, and applicable meeting materials.

An offsite social event is planned for Tuesday, April 8, from 19:00-21:00 in downtown Raleigh. Location to be announced in January. You may purchase a ticket during your main registration or access a separate purchase form link found in your registration email confirmation. Tickets are $30 per person.

" + }, + { + "contentnewsType": "paragraph", + "content": "

Venue

" + }, + { + "contentnewsType": "paragraph", + "content": "McKimmon Center
North Carolina State University
1101 Gorman St.
Raleigh, North Carolina 27606
USA" + }, + { + "contentnewsType": "paragraph", + "content": "

Learn More About VulnCon 2025

" + }, + { + "contentnewsType": "paragraph", + "content": "The purpose of the VulnCon — which is open to the public — is to collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken back to individual programs for action to benefit the vulnerability management ecosystem. A key goal of the conference is to understand what important stakeholders and programs are doing within the vulnerability management ecosystem and best determine how to benefit the ecosystem broadly." + }, + { + "contentnewsType": "paragraph", + "content": "For the most up-to-date information, visit the CVE/FIRST VulnCon 2025 conference page hosted on the FIRST website." + }, + { + "contentnewsType": "paragraph", + "content": "We look forward to seeing you at this exciting community event and encourage you to register today!" + } + ] + }, { "id": 491, + "displayOnHomepageOrder": 1, "newsType": "blog", "title": "Please Complete Our “CVE Data Usage and Satisfaction Survey” by April 4, 2025", "urlKeywords": "CVE Data Usage and Satisfaction Survey", @@ -953,7 +1124,7 @@ }, { "contentnewsType": "paragraph", - "content": "Discounted rates are not offered for this event regardless of membership or speaking status. Registration fees for in-person attendance include four days of coffee breaks and buffet lunches, one networking reception hosted at the McKimmon Center, and applicable meeting materials.

An offsite social event is planned for Tuesday, April 8, from 19:00-21:00 in downtown Raleigh. Location to be announced in January. You may purchase a ticket during your main registration or access a separate purchase form link found in your registration email confirmation. Tickets are $30 per person.

" + "content": "Discounted rates are not offered for this event regardless of membership or speaking status. Registration fees for in-person attendance include four days of coffee breaks and buffet lunches, one networking reception hosted at the McKimmon Center, and applicable meeting materials.

An offsite social event is planned for Tuesday, April 8, from 19:00-21:00 in downtown Raleigh. Location to be announced in January. You may purchase a ticket during your main registration or access a separate purchase form link found in your registration email confirmation. Tickets are $30 per person.

" }, { "contentnewsType": "paragraph", @@ -990,6 +1161,10 @@ { "contentnewsType": "paragraph", "content": "We look forward to seeing you at this exciting community event and encourage you to register today!" + }, + { + "contentnewsType": "paragraph", + "content": "Note: This article was modified on March 11, 2025, to update the dates and deadlines for standard and late in-person admissions." } ] }, diff --git a/src/views/About/Metrics.vue b/src/views/About/Metrics.vue index 7e96aa603..d27169cf3 100644 --- a/src/views/About/Metrics.vue +++ b/src/views/About/Metrics.vue @@ -295,8 +295,8 @@

CNA Enrichment Recognition List

-

Last Updated:
- Total CNAs: 240

+

Last Updated:
+ Total CNAs: 246