news.mlab.sh
Back to the feed
threat-intel

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

Info
Summary

CISA is ending its weekly vulnerability bulletin in favor of a risk-based approach, shifting focus to actively exploited vulnerabilities through its KEV catalog. This change is intended to combat alert fatigue and improve prioritization for security teams, moving away from solely relying on CVSS scores.

The US Cybersecurity and Infrastructure Security Agency (CISA) announced on Wednesday that it’s retiring its weekly vulnerability bulletin. The bulletin provided a summary of new vulnerabilities recorded each week, including details such as product name, description of the flaw, severity, CVSS score, CVE identifier, and patch information. However, the sheer volume of vulnerabilities listed, sorted alphabetically, often overwhelmed security teams due to a lack of context and prioritization guidance. CISA stated this change aligns with Binding Operational Directive (BOD) 26‑04, which directs federal agencies to prioritize vulnerabilities based on real-world risk factors, including evidence of exploitation and exposure, rather than severity scores alone. The KEV catalog has become the primary reference point for defenders since 2021, offering a more targeted view of actively exploited vulnerabilities. This shift represents a broader industry trend away from solely relying on CVSS metrics, recognizing that a vulnerability's actual risk depends on its exploitation status and threat actor interest. Security operations centers (SOCs) will need to adapt to this new approach, relying on CISA’s KEV catalog, alerts, and advisories for vulnerability information.

Read the full article at SecurityWeek