Skip to content
CISA decides weekly vulnerability bulletin isn't necessary anymore

CISA decides weekly vulnerability bulletin isn't necessary anymore

Theregister • September 16, 2026

Agency's shift from static CVSS scores to risk-based prioritization sends the old format packing September 28

Google Pixel phones pwned in zero-click attacks 2 hours ago

Google Pixel phones pwned in zero-click attacks

More JFrog Artifactory bugs under attack, and all 3 have patches 5 days ago

More JFrog Artifactory bugs under attack, and all 3 have patches

Serial Microsoft 0-day hunter drops yet another Defender exploit 7 days ago

Serial Microsoft 0-day hunter drops yet another Defender exploit

US claims Chinese AI companies’ core AI strategy is distilling American models 7 days ago

US claims Chinese AI companies’ core AI strategy is distilling American models

CISA: Most exploited vulnerabilities should have been eradicated decades ago 19 days ago

CISA: Most exploited vulnerabilities should have been eradicated decades ago

If you rely on the Cybersecurity and Infrastructure Security Agency’s weekly vulnerability bulletin to keep you up to date on the latest threats, we have bad news. It’s being discontinued at the end of September.

CISA announced on Wednesday that its weekly vulnerability bulletin would stop going out on Monday, September 28, saying the move was part of its shift from managing vulnerabilities based on severity to “a modern, risk-based approach.”

That approach, as CISA explains, is detailed in a June Binding Operational Directive (BOD) that explains how covered federal civilian agencies should prioritize security updates based on real-world risk rather than treating all vulnerabilities and systems equally.

“This Directive evolves upon CISA’s known exploited vulnerabilities catalog and increases mission readiness across the federal government by efficiently prioritizing high-risk vulnerabilities for timely action, while deferring action against low-risk vulnerabilities,” the agency explained in June.

Evidence of exposure and exploitation, degree of control granted by exploitation, and whether exploitation of the vulnerability can be automated are all part of what goes into determining severity, according to a remediation table included in the June announcement.

The June BOD, in a sense, moves covered federal civilian agencies away from relying on static CVSS scores alone when prioritizing vulnerabilities, which helps explain why CISA might want to eliminate the weekly bulletin. The agency didn’t explain, however, why it chose to scrap the bulletin rather than adapt it to the BOD's new standards.

One possibility could be that the list of new vulnerabilities is simply getting too big to fit into a weekly email. Patches are addressing rapidly growing numbers of vulnerabilities every time they roll out thanks to AI-assisted security research, while the National Vulnerability Database is still facing a massive backlog and the broader CVE ecosystem is increasingly having to sift through bogus AI-generated reports to identify genuine vulnerabilities.

CISA doesn’t want security professionals to abandon CVEs altogether, however. The announcement mentions that those who need to stay up to date on vulnerability information should instead rely on CISA’s known exploited vulnerabilities catalog, its cybersecurity alerts and advisories, and the CVE catalog itself.

That means anyone who currently receives and relies on the weekly bulletin needs to log into the GovDelivery or Granicus account and ensure the KEV Catalog and Cybersecurity Advisories subscriptions are enabled. Critical notices could be missed if not, and CISA clearly isn’t too concerned the potential hiccups this might cause.

“CISA remains committed to strengthening national cyber defense and helping organizations prioritize remediation based on real-world risk,” the agency said. Clearly, it doesn’t believe cutting off a regular method of notifying users of critically ranked vulnerabilities falls inside that new risk paradigm, even if the scores are static. ®

CISA decides weekly vulnerability bulletin isn't necessary anymore

Agency's shift from static CVSS scores to risk-based prioritization sends the old format packing September 28

OpenAI's new agents are happy to chat selling you things

Advertisers can now ask ChatGPT to help create their ChatGPT ads, because what's more relatable than an ad crafted by a bot?

HPE makes its “unified storage” claim real as B10000 R6 hits GA

PARTNER CONTENT: Pairs block and adjacent file workloads with independent scaling of performance and capacity

Google Pixel phones pwned in zero-click attacks

CISA gives federal agencies just 3 days to patch

Open weights are not open source: Why AI's favorite label is under dispute

Downloading a model is increasingly easy. Understanding how it was made, or changing a system at its root, is another matter

Enterprises are sweating legacy IT assets as AI investment grows

Hardware such as mainframes found to hold the data and business logic needed to build those AI services

SAAS Salesforce staggers back to feet after global outage

Salesforce staggers back to feet after global outage

databases Oracle celebrates banner quarter with another round of layoffs

Oracle celebrates banner quarter with another round of layoffs

NETWORKS Virgin Media offloads email services to third-party provider

Virgin Media offloads email services to third-party provider

CYBER-CRIME Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

software Another Microsoft team admits it’s struggling to handle flood of AI-generated code

Another Microsoft team admits it’s struggling to handle flood of AI-generated code

virtualization VMware defends ending downloads of SDK that helps VM backups – or migrations to rivals

VMware defends ending downloads of SDK that helps VM backups – or migrations to rivals

cyber-crime Spain gets its first taste of AI-aided cyber attack Data protection chiefs call for 'immediate review' of data protection models

Spain gets its first taste of AI-aided cyber attack

Data protection chiefs call for 'immediate review' of data protection models

SYSTEMS AI networking startups race to replace Nvidia's NVLink Intel spin-off Cornelis and newcomer Delos Data pitch open alternatives for scaling AI beyond the rack

AI networking startups race to replace Nvidia's NVLink

Intel spin-off Cornelis and newcomer Delos Data pitch open alternatives for scaling AI beyond the rack

AI AND ML Anthropic and OpenAI look to Uncle Sam to make them too big to fail American model devs are trying to convince Washington to cement their dominance

Anthropic and OpenAI look to Uncle Sam to make them too big to fail

American model devs are trying to convince Washington to cement their dominance

on-prem Datacenter developers want your backyard. FAS says negotiate harder Tax breaks, water, noise, decommissioning - report tells local officials what to nail down before signing

Datacenter developers want your backyard. FAS says negotiate harder

Tax breaks, water, noise, decommissioning - report tells local officials what to nail down before signing

LEGAL Nvidia's Groq acquihire is on the DOJ's radar, but it's already too late Even if regulators did somehow unwind the $20B deal, there's a growing list of alternatives ready to take Groq's place, no merger required

Nvidia's Groq acquihire is on the DOJ's radar, but it's already too late

Even if regulators did somehow unwind the $20B deal, there's a growing list of alternatives ready to take Groq's place, no merger required

Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Russians are posing as Signal support to launch phishing attacks

PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack

PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Black Hat and DEF CON

DEF CON Franklin project enlists hackers to harden critical infrastructure

Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

EQT buys majority in Swiss cybersecurity biz Acronis

Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career

Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight

On the plus side, infosec's a good bet for a long, stable career

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line

Acquisition gives open source CSS framework 'a stable long-term '

Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push

Switzerland tests a FOSS escape route from Microsoft 365

Swiss Army sticks a knife in American cloud apps with its own FOSS push

Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin

Feel peak Windows was 7? You might like Kumander Linux

Debian and Xfce – solid, sensible choices – with a pretty skin

Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted

Canonical shuttering some of its legacy chat channels

The Ubuntu Pastebin went in June, IRC gets demoted

Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Audacity audio-editing app no longer looks like it's from the early 2000s

The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast A real alternative to running some kind of FOSS Unix clone

Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast

A real alternative to running some kind of FOSS Unix clone

Extracted Entities

Countries (1)

MITRE ATT&CK (1)

Ransomware Groups (1)