Friday, 9 October 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
› Hunter Bell celebrates in Team GB's 'glam' female track success› Chelsea latest: Caicedo features in friendly as midfielder steps up recovery› Swiss Darts Trophy 2026: Schedule, draw, dates as Bunting defends his title› 'It's about time!' - F1 drivers excited amid Rwanda GP rumours› 'Stick together, enjoy the ride and smile' - Haaland's message to Man City fans› Campbell would end retirement to fight Benn: 'He was insulting me!'› Russell, Antonelli to race with different specs amid Mercedes upgrade concern› 'It wasn't good enough' - Hamilton reveals 'huge' talks over Ferrari blunder› Southampton boss Eckert welcomes 'clarity' after Spygate suspended FA ban› Papers: Fee Man Utd could receive for wantaway JJ Gabriel revealed› Hunter Bell celebrates in Team GB's 'glam' female track success› Chelsea latest: Caicedo features in friendly as midfielder steps up recovery› Swiss Darts Trophy 2026: Schedule, draw, dates as Bunting defends his title› 'It's about time!' - F1 drivers excited amid Rwanda GP rumours› 'Stick together, enjoy the ride and smile' - Haaland's message to Man City fans› Campbell would end retirement to fight Benn: 'He was insulting me!'› Russell, Antonelli to race with different specs amid Mercedes upgrade concern› 'It wasn't good enough' - Hamilton reveals 'huge' talks over Ferrari blunder› Southampton boss Eckert welcomes 'clarity' after Spygate suspended FA ban› Papers: Fee Man Utd could receive for wantaway JJ Gabriel revealed
Technology

CISA decides weekly vulnerability bulletin isn't necessary anymore

The Register ·
CISA decides weekly vulnerability bulletin isn't necessary anymore

If you rely on the Cybersecurity and Infrastructure Security Agency’s weekly vulnerability bulletin to keep you up to date on the latest threats, we have bad news.

It’s being discontinued at the end of September.

CISA announced on Wednesday that its weekly vulnerability bulletin would stop going out on Monday, September 28, saying the move was part of its shift from managing vulnerabilities based on severity to “a modern, risk-based approach.” That approach, as CISA explains, is detailed in a June Binding Operational Directive (BOD) that explains how covered federal civilian agencies should prioritize security updates based on real-world risk rather than treating all vulnerabilities and systems equally.

“This Directive evolves upon CISA’s known exploited vulnerabilities catalog and increases mission readiness across the federal government by efficiently prioritizing high-risk vulnerabilities for timely action, while deferring action against low-risk vulnerabilities,” the agency explained in June.

Evidence of exposure and exploitation, degree of control granted by exploitation, and whether exploitation of the vulnerability can be automated are all part of what goes into determining severity, according to a remediation table included in the June announcement.

The June BOD, in a sense, moves covered federal civilian agencies away from relying on static CVSS scores alone when prioritizing vulnerabilities, which helps explain why CISA might want to eliminate the weekly bulletin.

The agency didn’t explain, however, why it chose to scrap the bulletin rather than adapt it to the BOD's new standards.

One possibility could be that the list of new vulnerabilities is simply getting too big to fit into a weekly email.

Patches are addressing rapidly growing numbers of vulnerabilities every time they roll out thanks to AI-assisted security research, while the National Vulnerability Database is still facing a massive backlog and the broader CVE ecosystem is increasingly having to sift through bogus AI-generated reports to identify genuine vulnerabilities.

CISA doesn’t want security professionals to abandon CVEs altogether, however.

The announcement mentions that those who need to stay up to date on vulnerability information should instead rely on CISA’s known exploited vulnerabilities catalog, its cybersecurity alerts and advisories, and the CVE catalog itself.

That means anyone who currently receives and relies on the weekly bulletin needs to log into the GovDelivery or Granicus account and ensure the KEV Catalog and Cybersecurity Advisories subscriptions are enabled.

Critical notices could be missed if not, and CISA clearly isn’t too concerned about the potential hiccups this might cause.

Read the full article on The Register ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.

More from The Register

See all ›

More in Technology

See all ›