CISA announced it will stop publishing its weekly vulnerability summary bulletins starting Sept. 28, directing organizations instead to its Known Exploited Vulnerabilities catalog, security advisories, and vendor alerts. The agency says the change reflects its push for risk-based vulnerability prioritization rather than relying on severity scores alone, amid a surge in disclosed vulnerabilities partly driven by AI-assisted flaw hunting.
darkreading.com
· 2026-09-17
ESET Labs discovered that the Russia-aligned group UAC-0099 embedded a nuclear-weapon-related phrase into malicious VBScript code targeting a Ukrainian victim. The text was designed to trigger AI safety filters, causing security tools' language models to refuse analysis of the surrounding malicious code, a technique researchers are calling GuardBreaker.
darkreading.com
· 2026-09-11
NIST has responded to a surge in vulnerability disclosures by reclassifying about 30,000 CVEs published before March 2026 as 'Not Scheduled,' effectively deprioritizing their enrichment. The move comes as Action1's 2026 report shows disclosed vulnerabilities in enterprise software jumped 92% in 2025, with critical and high-severity flaws each up 103% and remote-code-execution bugs up 128%.
bleepingcomputer.com
· 2026-08-28