CISA decides weekly vulnerability bulletin isn't necessary anymore
Agency's shift from static CVSS scores to risk-based prioritization sends the old format packing September 28
The Cybersecurity and Infrastructure Security Agency (CISA) is discontinuing its weekly vulnerability bulletin, effective September 28. This change is part of CISA's shift towards a risk-based approach in managing vulnerabilities. The directive, issued in June, emphasizes prioritizing security updates based on real-world risk rather than treating all vulnerabilities equally.
Factors like evidence of exposure and exploitation, degree of control granted, and whether exploitation can be automated are considered when determining severity. While CISA acknowledges the growing number of vulnerabilities and the need for AI-assisted security research, it doesn't explain why it chose to discontinue the bulletin instead of adapting it to the new standards.
Users relying on the bulletin should now rely on CISA's known exploited vulnerabilities catalog, cybersecurity alerts and advisories, and the CVE catalog.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.