CISA ends weekly vulnerability bulletin in favour of risk-based approach

← Back to the feed

CISA ends weekly vulnerability bulletin in favour of risk-based approach

The Register · 1 hour ago

The US Cybersecurity and Infrastructure Security Agency (CISA) is scrapping its weekly vulnerability bulletin from Monday 28 September, as part of a shift away from severity-based scoring towards what it calls a "risk-based approach" to prioritising security fixes. The agency framed the change as building on its June Binding Operational Directive, which tells federal civilian agencies to focus on real-world exploitation risk rather than treating all vulnerabilities equally, but it has not explained why the bulletin itself could not simply be adapted to the new standard rather than axed outright.

Under the June directive, CISA weighs factors such as evidence of exploitation, the level of control a flaw grants an attacker, and whether exploitation can be automated, moving agencies away from relying solely on static CVSS scores. One likely driver is sheer volume: AI-assisted research is fuelling a rapid rise in disclosed vulnerabilities, while the National Vulnerability Database battles a backlog and the wider CVE ecosystem must now filter out bogus AI-generated reports. CISA says users should instead track its Known Exploited Vulnerabilities catalogue, cybersecurity advisories and the CVE catalogue, and current bulletin subscribers will need to manually enable those alternative subscriptions via GovDelivery or Granicus to avoid missing critical notices.

  • CISA ends its weekly vulnerability bulletin from 28 September
  • Move reflects shift to risk-based rather than CVSS severity scoring
  • Users must manually switch to KEV catalogue and advisory alerts instead

Software

Read the full article at the source →