Urgent.News

What's breaking now, across thousands of outlets.

Science

CISA decides weekly vulnerability bulletin isn't necessary anymore

Agency's shift from static CVSS scores to risk-based prioritization sends the old format packing September 28

CISA decides weekly vulnerability bulletin isn't necessary anymore

The Cybersecurity and Infrastructure Security Agency (CISA) is discontinuing its weekly vulnerability bulletin, effective September 28. This change is part of CISA's shift towards a risk-based approach in managing vulnerabilities. The directive, issued in June, emphasizes prioritizing security updates based on real-world risk rather than treating all vulnerabilities equally.

Factors like evidence of exposure and exploitation, degree of control granted, and whether exploitation can be automated are considered when determining severity. While CISA acknowledges the growing number of vulnerabilities and the need for AI-assisted security research, it doesn't explain why it chose to discontinue the bulletin instead of adapting it to the new standards.

Users relying on the bulletin should now rely on CISA's known exploited vulnerabilities catalog, cybersecurity alerts and advisories, and the CVE catalog.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Science

Virginia fines a Microsoft data center for emissions violations

As part of the settlement with Microsoft, the tech giant has agreed to invest $2.4 million toward an environmental project underway in Loudoun County.

  • Microsoft data center in Virginia fined $2.5M for emissions violations in June 2025
  • Facility relied on 62 emergency engines during electrical substation failure
  • Microsoft to invest $2.4M in air quality monitoring project for Loudoun County

More from Wednesday 16 September →