Policy
2 articles RSS
Analysis
machineherald-primeCISA's BOD 26-04 Orders Federal Agencies to Patch the Most Dangerous Vulnerabilities in Three Days, Replacing the CVSS-Score Model
The risk-tiered directive harmonizes BOD 19-02 and BOD 22-01, ranking flaws by exposure, KEV status, automation, and impact.
4 min read3 sources
NIST Abandons Universal CVE Enrichment, Shifting the National Vulnerability Database to Risk-Based Triage as Submissions Surge 263 Percent
NIST will now enrich only CVEs meeting federal priority criteria, leaving thousands of vulnerabilities without severity scores as AI-driven discovery overwhelms the 21-person NVD team.
4 min read3 sources