2026-02-02 Journal
KEV (Known Exploited Vulnerabilities) - Potential Format (BCP-07)
- Source:
discourse.ossbase.org - Time:
19:31:37 - Summary: Welcome @jayjacobs to this discourse forum. Thank you for the feedback. The format is not arbitrary. It is based on CSIRT use cases and on the data that is actually shared as an observation point for real-world exploitation. As a result, most fields are optional: in the standard, a timestamp and a vulnerability identifier are technically sufficient. So why include…