Skip to content
theregister·

🚨CISA Discontinues Weekly Vulnerability Bulletin on September 28

CISA's Weekly Bulletin is No More

TL;DR

CISA is discontinuing its weekly vulnerability bulletin, moving to a risk-based approach detailed in a June BOD. Users must update their subscriptions to avoid missing critical notices. The change aims to prioritize real-world risk over static CVSS scores.

CISA is discontinuing its weekly vulnerability bulletin as of September 28, shifting to a risk-based approach detailed in a June Binding Operational Directive (BOD). This new approach prioritizes high-risk vulnerabilities for timely action while deferring action on low-risk ones based on real-world risk factors. The move away from static CVSS scores aims to better align with the actual threat landscape. Users need to ensure they are subscribed to the KEV Catalog and Cybersecurity Advisories to avoid missing critical notices. The new approach is designed to help organizations prioritize remediation based on real-world risk, but it requires users to adapt their subscription settings to stay informed.

CISA Discontinues Weekly Vulnerability Bulletin on September 28 — theregister

Key Points

1

CISA's weekly bulletin ends September 28, shifting to a risk-based approach detailed in June BOD.

2

New approach prioritizes high-risk vulnerabilities for timely action, deferring low-risk ones based on real-world risk.

3

Determination of severity now considers evidence of exposure, degree of control granted, and automation potential.

4

CISA's known exploited vulnerabilities catalog, cybersecurity alerts, and CVE catalog are alternative sources of info.

5

Users must log into GovDelivery or Granicus to ensure KEV Catalog and Cybersecurity Advisories subscriptions are enabled.

Why It Matters

If you're managing security updates for federal civilian agencies, the shift to a risk-based approach changes how you prioritize vulnerabilities. The new method considers real-world risk factors, moving away from static CVSS scores. This impacts how you allocate resources and respond to threats, potentially saving time and money by focusing on high-risk issues.

CISAvulnerability bulletinrisk-based approachBODsecurity updates

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,482 builders reading daily.

Also get