CISA decides weekly vulnerability bulletin isn't necessary anymore
The US cybersecurity agency CISA said it will stop publishing its weekly vulnerability bulletin from September 28. The reason is a shift from static CVSS scores to the risk-based approach described in a June BOD directive.
- Last bulletin issue will be published on September 28
- CISA moves from CVSS to real-risk assessment under BOD directive
- KEV catalog and CISA alerts recommended instead of the bulletin
- Priority given to exploited and automatable vulnerabilities
Read next
Policy