The US Cybersecurity and Infrastructure Security Agency (CISA) has decided to discontinue its weekly vulnerability bulletins, effective Sept. 28.
In a brief announcement this week, CISA described it decision as consistent with its broader move to get organizations to shift from severity-based vulnerability management to risk-based prioritization. It's a focus that the agency has been emphasizing in recent months as vulnerability disclosures have soard, in part because organizations are increasingly using AI to hunt for security flaws in software and other IT technologies.
In its most recent monthly security update, for instance, Microsoft disclosed close to 1,000 vulnerabilities, a volume that was significantly higher than its typical monthly totals until very recently. Other software vendors have been disclosing higher vulnerability volumes in recent months in a trend that analysts expect will only intensify in the short term before plateauing.
Related:Anthropic CEO: Time to Shift From Improving to Controlling AI
A Changing Focus on Risk vs Severity
The surge has left many organizations grappling with a rapidly growing backlog of vulnerabilities and increased the pressure on them to prioritize remediation based on real-world risk rather than relying solely on CVSS scores.
"Newly recorded vulnerabilities will remain available on CVE.org," CISA said, "and users should rely on CISA's Known Exploited Vulnerability (KEV) Catalog, CISA Cybersecurity Alerts and Advisories, and vendor security alerts for actionable, risk‑based updates."
CISA's emphasis on risk-based vulnerability prioritization over severity-based vulnerability management is a welcome development, says Hom Bahmanyar, global enablement officer at Ridge Security Technology Inc. It reinforces the fact that organizations that rely primarily on CVSS severity scores to prioritize vulnerabilities often miss the broader risk context that should drive remediation decisions.
The agency's decision is consistent with its advice that organizations consider exploit automation, technical impact, asset exposure, and KEV status, Bahmanyar adds. "Given the continued rise of AI-driven cyberattacks and the potential for adversaries to automate attacks at greater scale and speed, CISA's move toward a more contextual, risk-based vulnerability prioritization approach is a significant and welcome step forward," he says.
Besides the growing impossibility of addressing every single new vulnerability — bug bounty platforms like Bugcrowd, HackerOne and TrendAI's Zero Day Initiative have reported submissions as doubling and even tripling recently — another factor is also at play.
... continue reading