Mastodon Feed: Post

Mastodon Feed

Boosted by soatok@furry.engineer ("Soatok Dreamseeker"):
eloy@hsnl.social ("Eloy.") wrote:

people talk a lot about the "vulnpocalypse" this year, a supposedly new trend where there are too many CVEs to patch.

Here is a presentation slide by the Carnegie Mellon CERT Coordination Center from 2006. Two decades ago!

https://web.archive.org/web/20070714104234/http://www.cert.org/archive/pdf/CERTCC-DSS%5FTool.ppt.pdf

The busy system administrator What does it mean to have 5,990 vulnerabilities reported in 2005? Read the descriptions – 5,990 vulnerabilities @ 15 minutes = 187 days Affected by 10% of the vulnerabilities? Install patches – 599 vulnerabilities @ 1 hour = 75 days Reading reports and patching costs 187 + 75 = 262 days Which vulnerability should I patch first? DNS? Web server? Desktop systems? Network infrastructure?