Tech News
← Home  ·  All topics

Vulnerability Management

3 GoKawiil briefs on this topic

CISA to end weekly vulnerability bulletins, pushes risk-based approach instead

CISA announced it will stop publishing its weekly vulnerability summary bulletins starting Sept. 28, directing organizations instead to its Known Exploited Vulnerabilities catalog, security advisories, and vendor alerts. The agency says the change reflects its push for risk-based vulnerability prioritization rather than relying on severity scores alone, amid a surge in disclosed vulnerabilities partly driven by AI-assisted flaw hunting.

ESET Finds Hackers Using Fake Nuclear Prompts to Blind AI Malware Scanners

ESET Labs discovered that the Russia-aligned group UAC-0099 embedded a nuclear-weapon-related phrase into malicious VBScript code targeting a Ukrainian victim. The text was designed to trigger AI safety filters, causing security tools' language models to refuse analysis of the surrounding malicious code, a technique researchers are calling GuardBreaker.

NIST's NVD Backlog Fix Leaves 30,000 CVEs Unscored, Raising Enterprise Risk

NIST has responded to a surge in vulnerability disclosures by reclassifying about 30,000 CVEs published before March 2026 as 'Not Scheduled,' effectively deprioritizing their enrichment. The move comes as Action1's 2026 report shows disclosed vulnerabilities in enterprise software jumped 92% in 2025, with critical and high-severity flaws each up 103% and remote-code-execution bugs up 128%.