Subscribe Sign in

CISA decides weekly vulnerability bulletin isn't necessary anymore

2 min read Rewritten in plain language

Security

Changed after publishing · 1 edit
  • the report was edited: 230 words added, 1 removed.

Outlets edit stories after they go out, usually without saying so. We keep what we saw the first time.

Show what we removed Rules applied: A1 A2 A3×4 A9 D2×4 D3×5 D4 E3×3 all 30 rules
  • Agency's shift from static CVSS scores to risk-based prioritization sends the old format packing September 28
  • CISA announced on Wednesday that its weekly vulnerability bulletin would stop going out on Monday, September 28, saying the move was part of its shift from managing vulnerabilities based on severity to “a modern, risk-based approach.”
  • The June BOD, in a sense, moves covered federal civilian agencies away from relying on static CVSS scores alone when prioritizing vulnerabilities, which helps explain why CISA might want to eliminate the weekly bulletin.
  • Patches are addressing rapidly numbers of vulnerabilities every time they roll out thanks to AI-assisted security research, while the National Vulnerability Database is still facing a large backlog and the broader CVE ecosystem is having to sift through bogus AI-generated reports to identify genuine vulnerabilities.
  • The announcement mentions that those who need to stay up to date on vulnerability information should instead rely on CISA’s known exploited vulnerabilities catalog, its cybersecurity alerts and advisories, and the CVE catalog itself.

5 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

Headline check

There is nothing in this headline a machine can check against the report: no figure, no name and no quotation.

Nothing was measured here, so nothing is claimed. How this is checked

Read the full reportHide the full report2 min

Agency's shift from static CVSS scores to risk-based prioritization sends the old format packing September 28

If you rely on the Cybersecurity and Infrastructure Security Agency’s weekly vulnerability bulletin to keep you up to date on the latest threats, we have bad news. It’s being discontinued at the end of September.

CISA announced on Wednesday that its weekly vulnerability bulletin would stop going out on Monday, September 28, saying the move was part of its shift from managing vulnerabilities based on severity to “a modern, risk-based approach.”

That approach, as CISA explains, is detailed in a June Binding Operational Directive (BOD) that explains how covered federal civilian agencies should prioritize security updates based on real-world risk rather than treating all vulnerabilities and systems equally.

“This Directive evolves upon CISA’s known exploited vulnerabilities catalog and increases mission readiness across the federal government by efficiently prioritizing high-risk vulnerabilities for timely action, while deferring action against low-risk vulnerabilities,” the agency explained in June.

Evidence of exposure and exploitation, degree of control granted by exploitation, and whether exploitation of the vulnerability can be automated are all part of what goes into determining severity, according to a remediation table included in the June announcement.

The June BOD, in a sense, moves covered federal civilian agencies away from relying on static CVSS scores alone when prioritizing vulnerabilities, which helps explain why CISA might want to eliminate the weekly bulletin. The agency didn’t explain, however, why it chose to scrap the bulletin rather than adapt it to the BOD's new standards.

One possibility could be that the list of new vulnerabilities is getting too big to fit into a weekly email. Patches are addressing rapidly numbers of vulnerabilities every time they roll out thanks to AI-assisted security research, while the National Vulnerability Database is still facing a large backlog and the broader CVE ecosystem is having to sift through bogus AI-generated reports to identify genuine vulnerabilities.

CISA doesn’t want security professionals to abandon CVEs altogether, however. The announcement mentions that those who need to stay up to date on vulnerability information should instead rely on CISA’s known exploited vulnerabilities catalog, its cybersecurity alerts and advisories, and the CVE catalog itself.

That means anyone who currently receives and relies on the weekly bulletin needs to log into the GovDelivery or Granicus account and ensure the KEV Catalog and Cybersecurity Advisories subscriptions are enabled. Notices could be missed if not, and CISA isn’t too concerned about the potential hiccups this might cause.

“CISA remains committed to strengthening national cyber defense and helping organizations prioritize remediation based on real-world risk,” the agency said. It doesn’t believe cutting off a regular method of notifying users of critically ranked vulnerabilities falls inside that new risk paradigm, even if the scores are static. ®

You are reading our version, not theirs. This is The Register's report with its verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
The Registeras they published this story 15.6 9 38 -0.9 45.3
Mundane Readneutralized from The Register 11.1 8 38 -0.9 45.3

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works