CISA announced it will retire its weekly vulnerability bulletin on September 28 as part of a shift to risk-based vulnerability management. The agency said defenders should rely more on real-world exploitation evidence through the KEV catalog, alerts, and advisories instead of severity scores alone. #CISA #KEV #BOD2604
Keypoints
- CISA will discontinue its weekly vulnerability bulletin on September 28.
- The move supports a risk-based approach to vulnerability management.
- The bulletin listed thousands of new flaws but did not prioritize them by real-world risk.
- BOD 26-04 requires federal agencies to focus on exploited and exposed vulnerabilities.
- CISA will continue sharing risk-focused guidance through the KEV catalog, alerts, and advisories.
Read More: https://www.securityweek.com/cisa-retires-weekly-vulnerability-bulletin-in-risk-based-pivot/