# Human CVE
**Entity class:** Sociotechnical vulnerability concept
## Definition
A **human CVE** is a functional systems term for a dangerous, compromised, or strategically placed person whose access, placement, capability, intent, credentials, knowledge, or network position creates a known or inferable path through a sociotechnical system. [[wiki/Common Vulnerabilities and Exposures|CVE]] is the vulnerability-naming layer; the larger security function is discovering, characterizing, correlating, prioritizing, mitigating, and continuously reassessing the condition.
## Relevance to this collection
The exact mapping is: the person may be the [[wiki/Threat Source|threat source]] or [[wiki/Threat Actor|threat actor]]; the person may also carry or deliver the attack as an [[wiki/Attack Vector|attack vector]]; and trusted placement, permissions, reachable assets, and surrounding control failures form the [[wiki/Vulnerability|vulnerability-bearing condition]]. When these roles coincide, the individual becomes a living vulnerability node whose presence changes the attack surface.
The cross-domain foundation is developed in [[wiki/Common Vulnerabilities and Exposures|Common Vulnerabilities and Exposures]]. Cybersecurity vulnerability management, epidemiological [[wiki/Contact Tracing|contact tracing]], [[wiki/Biosurveillance|biosurveillance]], and predictive counterterrorism share a general sequence: identify a vulnerable entity, reconstruct exposures, infer hidden state, estimate propagation and consequence, prioritize intervention, and update the model. The [[wiki/Meyers Lab|Meyers Lab]]–[[wiki/Texas Advanced Computing Center|TACC]]–[[wiki/Dell Medical School|Dell Medical School]]–[[wiki/Austin Public Health|Austin Public Health]]–[[wiki/Defense Threat Reduction Agency|DTRA]] lineage supplies a documented systems genealogy for that convergence.
## Bidirectional interfaces and the living endpoint
[[wiki/Brain-Computer Interfaces|Bidirectional brain-computer interfaces]] make the concept more literal by joining computation to a writable biological endpoint. A read-only neural interface observes the biological system. A writable interface can also alter neural state through stimulation or neuromodulation. The protected object becomes a [[wiki/Cyber-Biological System|cyber-biological system]] in which information crosses the boundary in both directions.
This produces two human-CVE modes:
1. A dangerous configuration arises through cognition, capability, access, placement, credentials, environment, and network position.
2. A previously safe person-system becomes dangerous because an implant, adaptive model, permission layer, or [[wiki/Neural Command Channel|neural command channel]] is compromised.
The second case makes the individual simultaneously the victim, the compromised endpoint, and a possible vehicle of downstream harm. [[wiki/Brainjacking|Brainjacking]] is the published term for unauthorized control of implanted neuromodulation systems.
## Machine-readable vulnerability graph
The architecture tracks separate, persistent, connected objects:
**person or entity identity ↔ implant identity ↔ firmware and software CVEs ↔ model vulnerabilities ↔ access and credential state ↔ neural-state observations ↔ threat state ↔ incidents ↔ remediation and recovery state**
This graph inherits [[wiki/Continuous Vulnerability Intelligence|continuous vulnerability intelligence]] from cybersecurity and extends it through [[wiki/Human-Machine State Estimation|human-machine state estimation]] into [[wiki/Verified Neural Restoration|verified restoration]]. The operating sequence is:
**continuous vulnerability intelligence → continuous human-machine state estimation → predictive exploit detection → rapid containment → trusted remediation → verified restoration**
## Relationships
- **master collection:** [[collections/Terrorism, Counterterrorism, and the Intelligence Environment|Terrorism, Counterterrorism, and the Intelligence Environment]].
- **sociotechnical system:** [[wiki/Sociotechnical Attack Surface|Sociotechnical Attack Surface]].
- **neural extension:** [[wiki/Living CVE|Living CVE]], [[wiki/Neurosecurity|Neurosecurity]], and [[wiki/Bidirectional BCI Security|Bidirectional BCI Security]].
- **vulnerability stack:** [[wiki/National Vulnerability Database|NVD]], [[wiki/Known Exploited Vulnerabilities Catalog|KEV]], [[wiki/Software Bill of Materials|SBOM]], and [[wiki/Vulnerability Exploitability eXchange|VEX]].
- **cross-domain architecture:** [[wiki/Common Vulnerabilities and Exposures|Common Vulnerabilities and Exposures]], [[wiki/Contact Tracing|Contact Tracing]], and [[wiki/Memetic Contagion and Violent Extremism|Memetic Contagion and Violent Extremism]].
## Sources / Provenance
- [NIST Computer Security Resource Center, “Threat Source” glossary](https://csrc.nist.gov/glossary/term/threat_source) and [DCSA, *Exploitation of Insider Access*](https://www.dcsa.mil/Portals/128/Documents/CI/DCSA_CI_Best_Practices_booklet.pdf) (accessed 2026-09-23).
- [FDA, “Cybersecurity in Medical Devices Frequently Asked Questions”](https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity-medical-devices-frequently-asked-questions-faqs), accessed 2026-09-23.
- Xinyu Jiang et al., [“Cybersecurity in neural interfaces: Survey and future trends”](https://pubmed.ncbi.nlm.nih.gov/37883851/), 2023; Laurie Pycroft et al., [“Brainjacking”](https://pubmed.ncbi.nlm.nih.gov/27184896/), 2016.
**As of:** 2026-09-23