Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search
 

Mr.WeRP

(1,098 posts)
Tue Apr 15, 2025, 03:31 PM Apr 2025

DOGE has terminated MITRE's CVE contract

This is the primary system for sharing software vulnerabilities and is used by the cybersecurity industry (I work in this field). Cutting funding on this is like ending your nuclear defense funding during the cold war. Good luck out there, our information systems just became a lot less safe.

As long as I have been in this field (more than 15 years now) MITRE has been the keeper via DARPA and other government funding. This is what keeps the bad guys at bay and is the primary tool for sharing attack vectors in the industry so the industry can keep up with the black hats who do collaborate on the dark web.

22 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
DOGE has terminated MITRE's CVE contract (Original Post) Mr.WeRP Apr 2025 OP
That is absolutely insane whopis01 Apr 2025 #1
And some want the problems that will follow (China, North Korea, USSR/Russia) erronis Apr 2025 #7
SMH... ultralite001 Apr 2025 #2
"...MITRE has been the keeper via DARPA and other government funding..." The keeper of what? ancianita Apr 2025 #3
Wish it were that simple. I'll guess that MITRE holds a contract and very high-level clearances. erronis Apr 2025 #10
None of this theft of systems security or money or data is simple. It's a massive operation, and as the ancianita Apr 2025 #21
That is used by industry and government to share cyber vulnerability info IronLionZion Apr 2025 #4
Another "oops" occasion I guess? SSJVegeta Apr 2025 #5
Open door policy WmChris Apr 2025 #6
I've been getting the CVEs every day with weekly wrapups. Wondering when this would happen. erronis Apr 2025 #8
Supply chain risk is real and those attacks have happened IronLionZion Apr 2025 #17
My brother used to work at MITRE decades ago IrishBubbaLiberal Apr 2025 #9
Totally KAOS LiberalArkie Apr 2025 #16
"The only possible 'reason' is to cause chaos." - No, it's to allow our enemies to access our resources. erronis Apr 2025 #18
OMG!!! blue-wave Apr 2025 #11
I have that thought several times a day, lately. n/t yellow dahlia Apr 2025 #20
Every doggone day I feel LESS secure and MORE vulnerable. A LOT more vulnerable. calimary Apr 2025 #12
OHTHANKGOD eggplant Apr 2025 #13
The goal appears to make the US very vulnerable to all kinds of attacks. Irish_Dem Apr 2025 #14
Treason orangecrush Apr 2025 #15
CSO Uncle Sam abruptly turns off funding for CVE program. Yes, that CVE program erronis Apr 2025 #19
Apparently, funding has been reinstated. Silent Type Apr 2025 #22

whopis01

(3,916 posts)
1. That is absolutely insane
Tue Apr 15, 2025, 03:43 PM
Apr 2025

I worked in the field when the CVE was first created back in late 90s / early 2000s.
It is a critical point of information distribution for security.

You do not get rid of a tool like that unless you want the problems that will follow.

erronis

(23,660 posts)
7. And some want the problems that will follow (China, North Korea, USSR/Russia)
Tue Apr 15, 2025, 05:54 PM
Apr 2025

I'm guessing the rump USSR is mainly calling the shots at the White House, but others are looking on with glee and greed.

ancianita

(43,286 posts)
3. "...MITRE has been the keeper via DARPA and other government funding..." The keeper of what?
Tue Apr 15, 2025, 05:29 PM
Apr 2025

Last edited Tue Apr 15, 2025, 09:41 PM - Edit history (1)

Maybe explain more about what/who MITRE and CVE are/do? Or CVE?

I found this on Wikipedia, but it seems as if there's likely, out of 9,000+ employees, some one or even a few thousand of them will hold things together for free. Because if MITRE and CVE are as important as you say, and they love this work and know it's a matter of national security, they'll find funding somewhere. Am I being naive? I mean, McLean is the real home of the CIA, not Langley. It's not as if the CIA doesn't have a black budget and can't recover from a $2 billion loss, right?

Do you have any other info about why DOGE wants to extract revenue from this particular part of our national security?

erronis

(23,660 posts)
10. Wish it were that simple. I'll guess that MITRE holds a contract and very high-level clearances.
Tue Apr 15, 2025, 06:00 PM
Apr 2025

When the dipshits in the current regime cancel that contract then all clearances become void.

Much of the security infrastructure in the government and throughout the corporate/academic world has been based on some trust. This has been shredded.

ancianita

(43,286 posts)
21. None of this theft of systems security or money or data is simple. It's a massive operation, and as the
Tue Apr 15, 2025, 09:48 PM
Apr 2025

NLRB whistleblower just said on Rachel, connected not just to DOGE, but to Starlink, and therefore, Russia. He has the forensics of 40 hits coming from a not-fake IP address in Russia within 15 minutes of unlogged breakins done by DOGE in the NLRB's securitized systems.

Muskovite isn't smart enough alone. His money buys a legion of smart. In the shadows of the dipshit theater of this administration are Legion of Doom operatives.

Thanks for your input, erronis.

IronLionZion

(51,148 posts)
4. That is used by industry and government to share cyber vulnerability info
Tue Apr 15, 2025, 05:37 PM
Apr 2025

they add new ones daily. It's an important resource for those in the cybersecurity field. America is becoming much less secure with this administration's "efficiency".

WmChris

(716 posts)
6. Open door policy
Tue Apr 15, 2025, 05:53 PM
Apr 2025

Let's open the door for all kinds of government and infrastructure failures due to lack of updated security data. The Moron and his henchmen are hell bent on turning us into the 3rd world shithole country that they can dominate with iron fists.

erronis

(23,660 posts)
8. I've been getting the CVEs every day with weekly wrapups. Wondering when this would happen.
Tue Apr 15, 2025, 05:56 PM
Apr 2025

And I fear that they may use this information channel to start spreading false warnings and encouraging software updates that are actually trojans.

IronLionZion

(51,148 posts)
17. Supply chain risk is real and those attacks have happened
Tue Apr 15, 2025, 06:38 PM
Apr 2025

Solar Winds attack happened during the last Trump administration. He cut cybersecurity funding that year too. Funny how that works

https://en.wikipedia.org/wiki/2020_United_States_federal_government_data_breach

https://en.wikipedia.org/wiki/Supply_chain_attack

 

IrishBubbaLiberal

(2,561 posts)
9. My brother used to work at MITRE decades ago
Tue Apr 15, 2025, 05:57 PM
Apr 2025

Wow, Cutting that contact is beyond insane.
The only possible ‘reason’ is to cause chaos.

AND

with DOGE/Musk causing this on purpose… this means…
Musk DOES NOT want ANYTHING OR ANYONE
to be able to EXPOSE software vulnerabilities.

software vulnerabilities THAT possibility DOGE tech goons
installed on purpose



extremely shortsighted to cut MITRE contracts

erronis

(23,660 posts)
18. "The only possible 'reason' is to cause chaos." - No, it's to allow our enemies to access our resources.
Tue Apr 15, 2025, 06:52 PM
Apr 2025

Many of us still opine that these actions are being done because of ineptitude, or perhaps some psychological problem, malevolence.

This is well orchestrated and has been worked on since before the 1st trump installation.

There's real purpose here and a goal that is in sight. The take-over of the US (and probably world-wide) democracy without firing a shot.

calimary

(89,841 posts)
12. Every doggone day I feel LESS secure and MORE vulnerable. A LOT more vulnerable.
Tue Apr 15, 2025, 06:10 PM
Apr 2025

Maybe he thinks this is good because increased vulnerability forces the peons on their knees to stay.

Cuz when we’re fearful and on our knees, we’re presumably easier to control cuz we’re less likely to put up a fight.

They THINK, that is. But what the bad guys think is all too often wrong (or wrong-headed).

eggplant

(4,179 posts)
13. OHTHANKGOD
Tue Apr 15, 2025, 06:12 PM
Apr 2025

I was sick of having to fix all of the vulnerabilities they keep identifying.

erronis

(23,660 posts)
19. CSO Uncle Sam abruptly turns off funding for CVE program. Yes, that CVE program
Tue Apr 15, 2025, 08:20 PM
Apr 2025
https://www.theregister.com/2025/04/16/homeland_security_funding_for_cve/

US government funding for the world's CVE program – the centralized Common Vulnerabilities and Exposures database of product security flaws – ends Wednesday.

The 25-year-old CVE program plays a huge role in vulnerability management. It is responsible overseeing the assignment and organizing of unique CVE ID numbers, such as CVE-2014-0160 and CVE-2017-5754, for specific vulnerabilities, in this case OpenSSL's Heartbleed and Intel's Meltdown, so that when referring to particular flaws and patches, everyone is agreed on exactly what we're all talking about.

It is used by companies big and small, developers, researchers, the public sector, and more as the primary system for identifying and squashing bugs. When multiple people find the same hole, CVEs are useful for ensuring everyone is working toward that one specific issue.

While the whole world's vulnerability management efforts aren't going to descend into chaos overnight, there is a concern that in a month or two they may. The lack of US government funding means that, unless someone else steps in to fill the gap, this standardized system for naming and tracking vulnerabilities may falter or shut down, new CVEs may no longer be published, and the program's website may go offline.

Latest Discussions»General Discussion»DOGE has terminated MITRE...