CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot
CISA announced it will retire its weekly vulnerability bulletin on September 28 as part of a shift to risk-based vulnerability management. The agency said defenders should rely more on real-world exploitation evidence through the KEV catalog, alerts, and advisories instead of severity scores alone. #CISA #KEV #BOD2604

Keypoints

  • CISA will discontinue its weekly vulnerability bulletin on September 28.
  • The move supports a risk-based approach to vulnerability management.
  • The bulletin listed thousands of new flaws but did not prioritize them by real-world risk.
  • BOD 26-04 requires federal agencies to focus on exploited and exposed vulnerabilities.
  • CISA will continue sharing risk-focused guidance through the KEV catalog, alerts, and advisories.

Read More: https://www.securityweek.com/cisa-retires-weekly-vulnerability-bulletin-in-risk-based-pivot/