NIST curtails CVE analysis due to vulnerability surge (csoonline.com)
- NIST reduces manual processing of reported security vulnerabilities.
- Volume of CVE reports outpaces existing institutional capacity.
- Heightened reliance on private sector for vulnerability risk scoring.
"The U.S. National Institute of Standards and Technology (NIST) is scaling back its depth of analysis for Common Vulnerabilities and Exposures (CVEs) as the volume of reports exceeds operational capacity. This shift signals a move away from exhaustive centralized vetting toward a prioritized model, increasing the burden on industry to perform their own risk assessments. This reduction in standardized oversight poses risks for critical infrastructure security across the transatlantic digital ecosystem, requiring greater reliance on private-sector threat intelligence and automated validation tools."
no comments yet.