Vulnerability Management

CISA discontinues weekly vulnerability bulletin

Cybersecurity and Infrastructure Security Agency CISA logotype displayed on smartphone

The Cybersecurity and Infrastructure Security Agency (CISA) announced it will discontinue its weekly vulnerability bulletin at the end of September. This change is part of CISA's transition from managing vulnerabilities based on severity to a more modern, risk-based approach, with further coverage provided by The Register.

The shift aligns with CISA's June Binding Operational Directive (BOD), which guides federal civilian agencies in prioritizing security updates based on real-world risk rather than solely on static CVSS scores. Factors like evidence of exploitation, degree of control granted, and automation potential are now considered. While CISA directs users to its known exploited vulnerabilities catalog, cybersecurity alerts, advisories, and the CVE catalog for ongoing information, the discontinuation of the weekly bulletin may leave some professionals concerned about missing critical updates.

This move comes as the volume of reported vulnerabilities continues to grow, partly due to AI-assisted research, and the CVE ecosystem faces challenges with bogus reports. Users who relied on the weekly bulletin must now actively subscribe to other CISA resources to stay informed.

Source: The Register

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds