CyberWire Daily

Leadership shakeup at CISA.

Feb 27, 2026
Jeff Williams, founder of OWASP and CTO of Contrast Security, explains shifts in how vulnerabilities are tracked globally. He discusses NIST’s CVE backlog, the EU’s new federated GCVE approach, and risks from multiple authorities. Short takes cover Wi‑Fi bypasses, EV charger flaws, a Juniper router patch, and a major data breach.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

CVE Program Is Critical National Infrastructure

  • The CVE program is the foundational backbone of global patching and vulnerability management.
  • Jeff Williams warns funding cuts and backlog at NIST/MITRE created dangerous delays that threaten timely patching and ecosystem trust.
ANECDOTE

Origins Of The CVE Program

  • NIST originally created the CVE program to exchange vulnerability data and assign identifiers and scores.
  • Jeff Williams recalls early 2000s researchers needed a way to tell users which vulnerabilities were critical versus minor.
INSIGHT

EU GCVE Will Complicate Global Vulnerability Tracking

  • The EU's GCVE adds a new, federated vulnerability authority alongside the U.S. CVE system.
  • Williams says multiple authorities and numbering authorities will create duplicates, friction, and deconfliction challenges for patching.
Get the Snipd Podcast app to discover more snips from this episode
Get the app