logo

Fixing vulnerability data quality requires fixing the architecture first

ID: f830637d-c76c-5464-b0e8-0b5f53e20e47

STIX ID: report--f830637d-c76c-5464-b0e8-0b5f53e20e47

Feed Name: Help Net Security

Date Published: 2026-04-13

Date Updated: 2026-04-28

Author: Mirko Zorz

...
...

This interview with Art Manion examines why vulnerability records across repositories are inconsistent and hard to trust, introduces the idea of Minimum Viable Vulnerability Enumeration (MVVE) as a way to think about assertions needed to identify the same vulnerability across systems, and argues for shared terms, provenance, and architecture-focused repository design rather than new specs or metrics-driven shortcuts such as overreliance on CVSS.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.