{"id":58564,"date":"2025-04-25T22:19:09","date_gmt":"2025-04-25T22:19:09","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\/"},"modified":"2025-04-25T22:19:09","modified_gmt":"2025-04-25T22:19:09","slug":"amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\/","title":{"rendered":"Amid CVE funding fumble, &#8216;we were mushrooms, kept in the dark,&#8217; says board member"},"content":{"rendered":"<p>Kent Landfield, a founding member of the Common Vulnerabilities and Exposures (CVE) program and member of the board, learned through social media that the system he helped create was just hours away from losing funding.<\/p>\n<p>&#8220;Another board member gave me a call and said: &#8216;What the heck?'&#8221; Landfield recalled in an interview with <em>The Register<\/em>, although &#8220;heck&#8221; wasn&#8217;t exactly the term used, he added.<\/p>\n<p>&#8220;But I went, and looked at the letter and said: &#8216;Wait a minute, that should be in my inbox, because it is addressed to the board,'&#8221; Landfield said.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"condor\" data-xsm=\",fluid,mpu,\" data-sm=\",fluid,mpu,\" data-md=\",fluid,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>He&#8217;s referring to the April 15 letter seen around the world after being <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/bsky.app\/profile\/tib3rius.bsky.social\/post\/3lmulrbygoe2g\">shared<\/a> on Bluesky. It opened with, &#8220;Dear CVE Board Member,&#8221; and was signed by Yosry Barsoum, MITRE&#8217;s vice president and director at the Center for Securing the Homeland.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"falcon\" data-xmd=\",fluid,mpu,leaderboard,\" data-lg=\",fluid,mpu,leaderboard,\" data-xlg=\",fluid,billboard,superleaderboard,mpu,leaderboard,\" data-xxlg=\",fluid,billboard,superleaderboard,brandwidth,brandimpact,leaderboard,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D426raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<div class=\"adun_eagle_desktop_story_wrapper\">\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"mid\" data-raptor=\"eagle\" data-xxlg=\",mpu,dmpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<\/p><\/div>\n<p>Not-for-profit outfit MITRE, based in Massachusetts and Virginia, has had a contract with the US government to <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/www.cve.org\/ProgramOrganization\/Structure\">operate the CVE program<\/a> since its inception in 1999. The program has become the de facto standard for uniquely identifying and tracking security holes in products and projects, and is used by experts, organizations, and government bodies around the world to ensure that they&#8217;re all talking about the same specific bugs.<\/p>\n<blockquote class=\"pullquote\" readability=\"6\">\n<p>Quite honestly, we were mushrooms. Kept in the dark<\/p>\n<\/blockquote>\n<p>In last week&#8217;s letter, Barsoum told the board that funding from Uncle Sam for MITRE to run the program <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2025\/04\/16\/homeland_security_funding_for_cve\/\" rel=\"noopener\">had not been renewed<\/a>.<\/p>\n<p>For Landfield and other board members, along with the general public, this was a complete surprise.&nbsp;The <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/www.cve.org\/ProgramOrganization\/Board\">CVE board<\/a> is made up of representatives from governments, academia, antivirus makers, the infosec world, and more, who steer and advise the program while MITRE handles the day-to-day operations.<\/p>\n<p>&#8220;Through open and collaborative discussions, the board provides critical input regarding the data sources, product coverage, coverage goals, operating structure, and the strategic direction of CVE,&#8221; its charter states.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"falcon\" data-xsm=\",fluid,mpu,\" data-sm=\",fluid,mpu,\" data-md=\",fluid,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D426raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>&#8220;Quite honestly, we were mushrooms,&#8221; CVE board member Peter Allor told <em>The Register<\/em>. &#8220;Kept in the dark.&#8221;<\/p>\n<p>While this wasn&#8217;t the first time government funding issues had come up during the program&#8217;s over 25-year history, &#8220;we weren&#8217;t really told about them,&#8221; Landfield said.&nbsp;<\/p>\n<p>&#8220;It was a contract negotiation between the federal government and MITRE, and we were not in a position of governing as a board, we were mainly there as a high-level guidance and advisor to instruct the program on how things needed to work,&#8221; he explained.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" id=\"story_eagle_xsm_sm_md_xmd_lg_xlg\" data-pos=\"mid\" data-raptor=\"eagle\" data-xsm=\",mpu,dmpu,\" data-sm=\",mpu,dmpu,\" data-md=\",mpu,dmpu,\" data-xmd=\",mpu,dmpu,\" data-lg=\",mpu,dmpu,\" data-xlg=\",mpu,dmpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>By now, everyone knows how this story ends \u2014 or at least continues for 11 months.<\/p>\n<p>The US govt&#8217;s Cybersecurity and Infrastructure Security Agency, aka CISA, on Wednesday <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2025\/04\/16\/cve_program_funding_save\/\" rel=\"noopener\">said<\/a> it had &#8220;executed the option period on the contract to ensure there will be no lapse in critical CVE services.&#8221; The CVE board only found this out by reading the <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/news-events\/news\/cisa-statement-cve-program\">statement<\/a> online.<\/p>\n<p>The contract, however, only runs through March 2026, <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2025\/04\/18\/splintering_cve_bug_tracking\/\" rel=\"noopener\">calling into question<\/a> its long-term sustainability \u2014 and exposing the inherent weakness of a global resource being funded by a single government sponsor. A single sponsor rapidly alienating allies around the globe, to boot.<\/p>\n<p>&#8220;The US government needs to move this out from their sole funding and control for this global and collective problem regarding vulnerabilities and the enumeration of records,&#8221; Allor <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/www.linkedin.com\/posts\/peterallor_cve-foundation-activity-7318246468492943364-ZlUx\">said<\/a> in a LinkedIn post.&nbsp;<\/p>\n<h3 class=\"crosshead\">Meet the CVE Foundation<\/h3>\n<p>Behind the scenes, some members of the CVE board had been discussing these issues for almost a year: How do they ensure long-term funding and neutrality for the program? And how do they increase the resources necessary to ensure vulnerability information reaches network defenders in time to protect all of us?<\/p>\n<p>All of these discussions took place in private up until last Wednesday. Enter a new initiative: The CVE Foundation. Its goal is to ensure that CVE remains a neutral, publicly available vulnerability resource with long-term funding from multiple groups. Most, but not all, of its <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/www.thecvefoundation.org\/frequently-asked-questions#h.9m8gc6uee480\">members<\/a> come from the CVE board.<\/p>\n<p>&#8220;Confusion resulting from the April 15, 2025 letter addressed to the CVE board has compelled us to plan for contingency with a sense of urgency to prevent disruptions to global cybersecurity defensive operations,&#8221; the new group <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/www.thecvefoundation.org\/home\">said<\/a> in an April 16 statement.&nbsp;<\/p>\n<p>That&#8217;s a lot sooner than they had hoped.<\/p>\n<p>&#8220;We did not have this set up to pull the trigger at this point in time,&#8221; Allor said.<\/p>\n<p>But so far, the response has been surprisingly swift and positive. In less than a week&#8217;s time since announcing the foundation, &#8220;the interesting part is the amount of people, organizations, governments, reaching out, [saying] &#8216;We want to help. Can we donate?&#8217; It actually took our breath away,&#8221; he added.<\/p>\n<p>Allor declined to name the governments or the organizations that pledged funding, but added the governments are &#8220;not in North America.&#8221;&nbsp;<\/p>\n<blockquote class=\"pullquote\" readability=\"5\">\n<p>We have to stop looking at it like a pond. Look at it like an ocean<\/p>\n<\/blockquote>\n<p>There&#8217;s a place for everyone at this new CVE Foundation table, according to Allor: MITRE, CISA, private industry folks, and governments. &#8220;This should be global,&#8221; he said. &#8220;We have to stop looking at it like a pond. Look at it like an ocean.&#8221;<\/p>\n<p>CISA declined to answer questions for this story, including if the agency would be willing to let the foundation be the new &#8220;<a target=\"_blank\" href=\"https:\/\/www.thecvefoundation.org\/frequently-asked-questions\" rel=\"nofollow noopener\">long-term home<\/a>&#8221; for the CVE program. A CISA spokesperson directed <em>The Register<\/em> to an April 23 statement from Matt Hartman, CISA acting executive assistant director for cybersecurity, that says, in part:<\/p>\n<p>And continues:<\/p>\n<p>The CVE Foundation, in a subsequent statement, noted that its members &#8220;stand in alignment with CISA and this commitment to working together to ensure a resilient, trusted, and innovative CVE Program.&#8221;<\/p>\n<p>Other initiatives have successfully moved from the US government to a publicly managed service, according to the foundation: &#8220;DARPA turning the ARPANET into the internet, IANA managing protocol assignments, and ICANN managing internet names and addresses, which all started with the government being the single source of funding.&#8221;<\/p>\n<p>The CVE program can and should follow these examples, the foundation believes, and move &#8220;from a single-funding stream to a diversified funding model, which we believe will only strengthen the program and enable a stable, durable, internationally trusted program that works for the good of global consumers and organizations,&#8221; the statement continues.<\/p>\n<p>&#8220;This is not a coup,&#8221; said Landfield, who is also a member of the CVE Foundation. &#8220;These are people who have been in this program for 26 years, in some cases, and so we want to work to make this better. These are passionate individuals that really do want this to succeed more than anything else on the planet.&#8221;<\/p>\n<p>Some members of the CVE Foundation met CISA on Thursday. &#8220;The talks were positive and encouraging,&#8221; the foundation <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/www.thecvefoundation.org\/news\">said<\/a> in a statement. &#8220;All parties wish to keep the conversation and progress moving forward.&#8221; \u00ae<\/p>\n<p> READ MORE <a href=\"https:\/\/go.theregister.com\/feed\/www.theregister.com\/2025\/04\/25\/cve_board_funding\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>What next for US-bankrolled vulnerability tracker? It&#8217;s edging closer to a more independent, global future Kent Landfield, a founding member of the Common Vulnerabilities and Exposures (CVE) program and member of the board, learned through social media that the system he helped create was just hours away from losing funding.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-58564","post","type-post","status-publish","format-standard","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Amid CVE funding fumble, &#039;we were mushrooms, kept in the dark,&#039; says board member 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Amid CVE funding fumble, &#039;we were mushrooms, kept in the dark,&#039; says board member 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2025-04-25T22:19:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Amid CVE funding fumble, &#8216;we were mushrooms, kept in the dark,&#8217; says board member\",\"datePublished\":\"2025-04-25T22:19:09+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\\\/\"},\"wordCount\":1136,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_security\\\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\\\/\",\"name\":\"Amid CVE funding fumble, 'we were mushrooms, kept in the dark,' says board member 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_security\\\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\",\"datePublished\":\"2025-04-25T22:19:09+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\\\/#primaryimage\",\"url\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_security\\\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\",\"contentUrl\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_security\\\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Amid CVE funding fumble, &#8216;we were mushrooms, kept in the dark,&#8217; says board member\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Amid CVE funding fumble, 'we were mushrooms, kept in the dark,' says board member 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\/","og_locale":"en_US","og_type":"article","og_title":"Amid CVE funding fumble, 'we were mushrooms, kept in the dark,' says board member 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2025-04-25T22:19:09+00:00","og_image":[{"url":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Amid CVE funding fumble, &#8216;we were mushrooms, kept in the dark,&#8217; says board member","datePublished":"2025-04-25T22:19:09+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\/"},"wordCount":1136,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\/#primaryimage"},"thumbnailUrl":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\/","url":"https:\/\/www.threatshub.org\/blog\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\/","name":"Amid CVE funding fumble, 'we were mushrooms, kept in the dark,' says board member 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\/#primaryimage"},"thumbnailUrl":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","datePublished":"2025-04-25T22:19:09+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\/#primaryimage","url":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","contentUrl":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/cso&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2aA1rpOt0zMaNA0OFMdRQ4gAAAE4&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/amid-cve-funding-fumble-we-were-mushrooms-kept-in-the-dark-says-board-member-2\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Amid CVE funding fumble, &#8216;we were mushrooms, kept in the dark,&#8217; says board member"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/58564","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=58564"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/58564\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=58564"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=58564"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=58564"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}