|
1 | 1 | {
|
2 | 2 | "currentNews": [
|
| 3 | + { |
| 4 | + "id": 578, |
| 5 | + "newsType": "news", |
| 6 | + "title": "Almaviva Added as CVE Numbering Authority (CNA)", |
| 7 | + "urlKeywords": "Almaviva Added as CNA", |
| 8 | + "date": "2025-09-30", |
| 9 | + "description": [ |
| 10 | + { |
| 11 | + "contentnewsType": "paragraph", |
| 12 | + "content": "<a href='/PartnerInformation/ListofPartners/partner/Almaviva'>Almaviva S.p.A.</a> is now a <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCNA'>CVE Numbering Authority (CNA)</a> for vulnerabilities in Almaviva proprietary software solutions such as Joshua CybeRisk Vision, Jiano, Sofia, and Giotto, as well as Almaviva-developed IT solutions." |
| 13 | + }, |
| 14 | + { |
| 15 | + "contentnewsType": "paragraph", |
| 16 | + "content": "To date, <a href='/PartnerInformation/ListofPartners'>476 CNAs</a> (473 CNAs and 3 CNA-LRs) from <a href='/ProgramOrganization/CNAs'>40 countries</a> and 1 no country affiliation have partnered with the CVE Program. CNAs are organizations from around the world that are authorized to assign <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCVEID'>CVE Identifiers (CVE IDs)</a> and publish <a href='/ResourcesSupport/Glossary?activeTerm=glossaryRecord'>CVE Records</a> for vulnerabilities affecting products within their distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities. Almaviva is the 2nd CNA from Italy." |
| 17 | + }, |
| 18 | + { |
| 19 | + "contentnewsType": "paragraph", |
| 20 | + "content": "Almaviva’s Root is the <a href='/PartnerInformation/ListofPartners/partner/mitre'>MITRE TL-Root</a>." |
| 21 | + } |
| 22 | + ] |
| 23 | + }, |
| 24 | + { |
| 25 | + "id": 577, |
| 26 | + "newsType": "news", |
| 27 | + "title": "Join the CVE Program’s Automation Working Group (AWG)!", |
| 28 | + "urlKeywords": "Join the Automation Working Group AWG", |
| 29 | + "date": "2025-09-30", |
| 30 | + "description": [ |
| 31 | + { |
| 32 | + "contentnewsType": "paragraph", |
| 33 | + "content": "The <a href='/ProgramOrganization/WorkingGroups#AutomationWorkingGroupAWG'>CVE Automation Working Group (AWG)</a> plays a key role in shaping how the <a href='/'>CVE Program</a> uses technology to improve automation, streamline data exchange, and modernize services for the global vulnerability management community." |
| 34 | + }, |
| 35 | + { |
| 36 | + "contentnewsType": "paragraph", |
| 37 | + "content": "In the past, the AWG has driven impactful initiatives such as developing the <a href='/AllResources/CveServices'>CVE Services</a> API for <a href='/ResourcesSupport/Glossary?activeTerm=glossaryCNA'>CVE Numbering Authorities (CNAs)</a>, advancing the <a href='/AllResources/CveServices#CveRecordFormat'>CVE Record Data Format</a>, and supporting automation standards that strengthen interoperability across the ecosystem. Looking ahead, the group is focused on further modernizing CVE Program services, improving efficiency for CNAs, and expanding capabilities for data consumers worldwide." |
| 38 | + }, |
| 39 | + { |
| 40 | + "contentnewsType": "paragraph", |
| 41 | + "content": "To support broader participation across the international CVE community, the AWG is now testing two alternate meeting times on Tuesdays: <ul><li>9:00 AM ET (one week)</li><li>4:00 PM ET (the next week)</li></ul>" |
| 42 | + }, |
| 43 | + { |
| 44 | + "contentnewsType": "paragraph", |
| 45 | + "content": "If one of these sessions works better for your schedule, we’d love for you to join us! To start the process, simply sign up for the AWG groups.io email list by clicking here: <a href='mailto: [email protected]?subject=Request to Join CVE AWG'> [email protected]</a>. You will need a groups.io account to sign up." |
| 46 | + }, |
| 47 | + { |
| 48 | + "contentnewsType": "paragraph", |
| 49 | + "content": "The AWG is open to the public—your voice and expertise can help shape the future of CVE automation and we look forward to your participation!" |
| 50 | + }, |
| 51 | + { |
| 52 | + "contentnewsType": "image", |
| 53 | + "imageWidth": "", |
| 54 | + "href": "/news/CveAutomation.jpg", |
| 55 | + "altText": "CVE Program Automation" |
| 56 | + } |
| 57 | + ] |
| 58 | + }, |
| 59 | + { |
| 60 | + "id": 576, |
| 61 | + "newsType": "news", |
| 62 | + "title": "Minutes from CVE Board Teleconference Meeting on September 3 Now Available", |
| 63 | + "urlKeywords": "CVE Board Minutes from September 3", |
| 64 | + "date": "2025-09-30", |
| 65 | + "description": [ |
| 66 | + { |
| 67 | + "contentnewsType": "paragraph", |
| 68 | + "content": "The <a href='/ProgramOrganization/Board'>CVE Board</a> held a teleconference meeting on September 3, 2025. Read the <a href='https://marc.info/?l=cve-editorial-board&m=175890383805223&w=2' target='_blank'>meeting minutes summary</a>." |
| 69 | + }, |
| 70 | + { |
| 71 | + "contentnewsType": "paragraph", |
| 72 | + "content": "The CVE Board is the organization responsible for the strategic direction, governance, operational structure, policies, and rules of the CVE Program. The Board includes members from numerous cybersecurity-related organizations including commercial security tool vendors, academia, research institutions, government departments and agencies, and other prominent security experts, as well as end-users of vulnerability information." |
| 73 | + } |
| 74 | + ] |
| 75 | + }, |
| 76 | + { |
| 77 | + "id": 575, |
| 78 | + "newsType": "news", |
| 79 | + "title": "Minutes from CVE Board Teleconference Meeting on August 20 Now Available", |
| 80 | + "urlKeywords": "CVE Board Minutes from August 20", |
| 81 | + "date": "2025-09-30", |
| 82 | + "description": [ |
| 83 | + { |
| 84 | + "contentnewsType": "paragraph", |
| 85 | + "content": "The <a href='/ProgramOrganization/Board'>CVE Board</a> held a teleconference meeting on August 20, 2025. Read the <a href='https://marc.info/?l=cve-editorial-board&m=175866087004529&w=2' target='_blank'>meeting minutes summary</a>." |
| 86 | + }, |
| 87 | + { |
| 88 | + "contentnewsType": "paragraph", |
| 89 | + "content": "The CVE Board is the organization responsible for the strategic direction, governance, operational structure, policies, and rules of the CVE Program. The Board includes members from numerous cybersecurity-related organizations including commercial security tool vendors, academia, research institutions, government departments and agencies, and other prominent security experts, as well as end-users of vulnerability information." |
| 90 | + } |
| 91 | + ] |
| 92 | + }, |
3 | 93 | {
|
4 | 94 | "id": 574,
|
5 | 95 | "newsType": "news",
|
|
0 commit comments