惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Blog — PlanetScale
Blog — PlanetScale
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Vercel News
Vercel News
B
Blog
腾讯CDC
P
Proofpoint News Feed
Google DeepMind News
Google DeepMind News
N
Netflix TechBlog - Medium
L
LangChain Blog
F
Fortinet All Blogs
T
The Blog of Author Tim Ferriss
人人都是产品经理
人人都是产品经理
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
I
InfoQ
IT之家
IT之家
酷 壳 – CoolShell
酷 壳 – CoolShell
aimingoo的专栏
aimingoo的专栏
D
DataBreaches.Net
Stack Overflow Blog
Stack Overflow Blog
The Cloudflare Blog
Last Week in AI
Last Week in AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 三生石上(FineUI控件)
T
Tailwind CSS Blog

SiliconANGLE

Will agentic AI governance run amok? The lesson of Asimov’s Three Laws - SiliconANGLE AI + quantum, Amazon vs. Starlink and the wide-open US-China internet battle - SiliconANGLE Team Cymru launches Total Insights Feed to replace legacy threat intelligence lists - SiliconANGLE NanoClaw partners with Vercel to deliver one-click approvals for AI agents working on sensitive tasks - SiliconANGLE AI Mode in Chrome adds split-screen view to enhance the web search experience - SiliconANGLE Resolve AI raises $40M at $1.5B valuation to optimize production environments - SiliconANGLE How Zscaler and OpenAI turn zero-trust security into an AI accelerator - SiliconANGLE OpenAI ratchets up Codex's agentic capabilities to rival Claude Code - SiliconANGLE Anthropic launches Claude Opus 4.7 with coding, visual reasoning improvements - SiliconANGLE Slash raises $100M at a $1.4B valuation to expand AI-powered banking platform for online businesses - SiliconANGLE Canva unveils Canva AI 2.0, recasting its platform as an agentic system for work - SiliconANGLE Data center, consumer device chips boost TSMC’s revenue - SiliconANGLE Mission-critical security cannot be bolted on, says Oracle - SiliconANGLE Agentic infrastructure reshapes enterprise AI - SiliconANGLE Data quality, and data freedom, foundational for AI success - SiliconANGLE Data trust is a bedrock in successful, scalable AI outcomes - SiliconANGLE Google introduces new agentic AI-ready tools and resources for Android developers  - SiliconANGLE Agentic AI orchestration separates winners from laggards - SiliconANGLE Data-driven tools turning the tide against human trafficking - SiliconANGLE Achieving trusted AI development goes beyond 'vibes' - SiliconANGLE Impinj boosts edge computing power in updated R700 RAIN RFID reader - SiliconANGLE Certinia powers professional services with AI - SiliconANGLE Antioch prepares to accelerate simulated testing for autonomous robots after raising $8.5M - SiliconANGLE Developer tooling startup Expo nabs $45M investment - SiliconANGLE Solidroad lands $25M to bring AI to customer support interactions - SiliconANGLE DuploCloud lands compliance and AI governance certifications as enterprise buyers tighten scrutiny - SiliconANGLE Lua lands $5.8M to help businesses build and manage AI agent workforces - SiliconANGLE Best of frenemies: Oracle's and AWS' clouds unite with dedicated, private connectivity - SiliconANGLE Cisco goes to the races with new Churchill Downs multiyear partnership - SiliconANGLE Susecon 2026 will tackle the future of open-source platforms - SiliconANGLE
NIST shifts National Vulnerability Database to risk-based...
by Duncan Riley · 2026-04-16 · via SiliconANGLE

NIST shifts National Vulnerability Database to risk-based triage as CVE submissions hit record levels

The U.S. National Institute of Standards and Technology today announced an overhaul of how it processes cybersecurity vulnerabilities in its National Vulnerability Database .

NIST is abandoning its longstanding goal of fully analyzing every submitted Common Vulnerability and Exposure in favor of a risk-based triage model that prioritizes the most dangerous flaws. The change, which took effect today, is the result of the sheer volume of CVE submissions that NIST has been receiving and the number is high. Between 2020 and 2025, CVE submissions surged 263% and in the first quarter of this year, they were nearly one-third higher than the same period last year.

NIST enriched nearly 42,000 CVEs in 2025, up 45% year-over-year, but the increase in output has not been enough to keep pace with growing submissions. Under the new model, NIST will now only fully enrich CVEs that meet one of three criteria.

The criteria needed for a CVE to make the cut include a vulnerability being listed in the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, CVEs that affect software used within the federal government, and CVEs that affect software classified as critical under Executive Order 14028.

With the new model, NIST is aiming to enrich KEV catalog entries within one business day of receipt.

Other CVEs reported, though, are not going away. They will still be listed in the NVD but will be categorized as “Not Scheduled,” meaning NIST will not automatically add the severity scores and product data that security teams rely on to prioritize patching.

The agency is also addressing a significant backlog that has built up since early 2024. All CVEs with an NVD publish date before March 1, 2026, that remain unenriched will be moved into the “Not Scheduled” category, with NIST considering them for enrichment only as resources allow. CVEs already in the KEV catalog are excluded from that sweep.

The new model includes two additional procedural changes. NIST will no longer routinely issue its own severity score for CVEs where the submitting CVE Numbering Authority has already provided one. That will eliminate duplicate analysis, and modified CVEs will also only be reanalyzed if a change materially affects the enrichment data rather than automatically on every update.

Though NIST doesn’t directly blame the rise of CVE submissions on artificial intelligence, it’s one key driver behind the surge in CVE submissions, according to Vincenzo Iozzo, co-founder and chief executive of identity threat detection and response provider SlashID Inc.

“We’ve seen a dramatic spike in AI-reported valid vulnerabilities. According to reports, last year alone, the number of reported vulnerabilities more than doubled,” Iozzo told SiliconANGLE via email. “As a result, the new NIST policy is sensible and the categories still covered are the most critical ones.”

Also, he added, “large language models are approaching the point where they are good enough to allow individual organizations to prioritize and contextualize vulnerabilities in their environment, reducing the need for enriched CVEs.”

Shane Fry, chief technology officer at cybersecurity solutions company RunSafe Security Inc., believes that “the announcement is a signal to the industry that the era of waiting for a CVE score before acting has come to an end.”

“Vulnerability visibility is imperfect, but organizations that use a diverse set of vulnerability data sources will have more reliable insight into vulnerabilities and which ones they are affected by,” said Fry. “More importantly, organizations need to assume unknown vulnerabilities already exist in their software and deploy protections that can prevent exploitation before a patch — or a CVE score — is ever available.”

Photo: NIST

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.

About SiliconANGLE Media

SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.