❌

Normal view

There are new articles available, click to refresh the page.
Yesterday — 24 September 2026Main stream

CISA outlines improvement plan for CVE program

23 September 2026 at 20:31

The Cybersecurity and Infrastructure Security Agency published a paper Wednesday that lays out its plan for improving the Common Vulnerabilities and Exposures (CVE) program, a contract for which nearly ended last year before a last-minute reprieve.

The white paper outlines the components of a “Quality Era” for the program, widely used as the definitive clearinghouse for data on vulnerabilities in software and other products, even as the number of CVEs surges. 

“CISA remains committed to leading, growing and sustaining the CVE Program into the foreseeable future, just as we’ve done for more than 25 years without fail,” said Chris Butera, acting executive assistant director for cybersecurity. “Informed by CVE community feedback, this whitepaper communicates CISA’s effort to support and enable stronger participation and governance, a program-wide maturation effort.”

The CVE program has been in a “Growth Era,” according to CISA. Over 67,000 new CVEs have been published in 2026 as of last week, and the National Institute of Standards and Technology National Vulnerability Database program has seen a 263% increase in CVE submissions between 2020 and 2025. Artificial intelligence has furthered the rise.

“These pressures intensify quality challenges across the CVE ecosystem,” the white paper states. “While faster discovery and reporting can improve the value of vulnerability information when records are complete, consistent, timely, and actionable, the same acceleration can expose gaps in processes, tooling, coordination, and accountability — especially when the quality of the submissions is uneven.” 

The plan calls for advancing data quality across four key dimensions: transparent and effective program governance, broad and active participation across the global software community, data infrastructure that supports CVE operational functions and reliable CVE record content.

Some vulnerability experts have questioned whether other organizations should take over CISA’s stewardship, given budget cuts at the agency.

Butera invited further feedback from the CVE community on the white paper, which stems from an earlier strategy document on the future of the program.

Some CVE experts that CyberScoop spoke to were supportive of what CISA wants to achieve, but skeptical about elements of the white paper.

“We’ve been working around long-standing quality issues in CVE reports for decades. Incomplete or inconsistent records create real downstream work for the security tools, developers, and organizations trying to determine whether they’re actually affected and what to do next,” said Sonatype’s co-founder and chief technology officer Brian Fox. “So it’s good to see CISA acknowledge that quality has to extend beyond the record itself to governance, infrastructure, and participation across the ecosystem.”

But, he added, “I’ll believe we’ve entered a ‘Quality Era’ when we can see the improvement in the actual data and in the decisions that data enables.”

Tom Alrich, who leads the OWASP PURL Expansion Working Group that’s focused on establishing a protocol for creating Product URLs for commercial software, said CISA’s white paper ignores a particularly important and growing issue.

“I support everything mentioned. I also support the flag, motherhood and apple pie,” he said. “However, nothing in there is going to affect the CVE program’s most important problem: that a huge and growing percentage of new CVE records don’t contain a machine-readable software identifier.”

Caitlin Condon, VulnCheck’s vice president of security research, said that “CISA and the CVE program are well-positioned to both observe challenges in this space and to create (and enforce) standards that explicitly state what ‘quality’ means in CVE records.”

But she said the white paper was more the basis for a future framework than a full-fledged framework in itself.

“Many of the potential success metrics suggested in the document can be measured today, but simply aren’t shared publicly,” Condon said. “In future iterations on the framework, I’d hope to see more transparency on CVE metrics as they stand today, along with reasoning on why those metrics are the right ones (versus simply the things that are easiest to measure qualitatively or quantitatively).”

The post CISA outlines improvement plan for CVE program appeared first on CyberScoop.

Before yesterdayMain stream

AI-assisted security tools are finding more bugs, but the threat level has not changed

28 July 2026 at 11:08

AI systems like Anthropic’s Project Glasswing and Microsoft’s MDASH are aiding in the discovery of vulnerabilities, filling the ever-growing pool of defects that defenders have to address before exploitation occurs. Yet, through the first half of 2026, these vulnerabilities were no more or less likely to be exploited than all vulnerabilities disclosed during that period, VulnCheck said in a report Tuesday. 

Concerns remain high about AI-discovered vulnerabilities fueling more attacks, but VulnCheck’s review of exploitation data shows that those fears are unfounded, at least so far. 

Patrick Garrity, security researcher at VulnCheck and report author, identified 1,061 vulnerabilities attributed to AI-assisted discovery during the first six months of the year. Of those vulnerabilities discovered by AI, 14 ( 1.3%) were exploited in the wild, a breakdown that aligns with the exploitation rate researchers observed across all vulnerabilities during the same period. 

“While AI-assisted vulnerability discovery clearly has value for both attackers and defenders, the data does not suggest that AI discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods,” Garrity wrote.

While AI’s contribution to actively exploited vulnerabilities was muted in the first half of the year, it’s too soon to assume that trend will continue. Moreover, none of these major vulnerability-hunting models were running for that full period. Project Glasswing rolled out in April, while Microsoft’s MDASH and OpenAI’s Daybreak were both unveiled in May.

The upward trend in Microsoft’s monthly Patch Tuesday indicates how much the floodgates might open through the remainder of the year as AI models discover more vulnerabilities. The company’s July security update contained an all-time-record of 622 vulnerabilities, besting the previous record-breaking June update with 206 vulnerabilities.

VulnCheck’s state of exploitation report also found that vulnerabilities were exploited much faster after CVE publication, speeding up from an average of 120 days in 2025 to 80 days during the first half of the year.

The intelligence firm also determined which technology categories were actively exploited most often. Content management systems accounted for nearly one-third of the 495 known exploited vulnerabilities VulnCheck identified during the first half of 2026. Network edge devices were responsible for almost 14%, followed by operating systems at nearly 9%, server software at 8%, and AI products — an emerging attack surface — at almost 6%.

The post AI-assisted security tools are finding more bugs, but the threat level has not changed appeared first on CyberScoop.

SonicWall customers under threat as attackers exploit 2 zero-days

15 July 2026 at 14:51

SonicWall customers are attempting to dodge another security challenge as attackers are exploiting a pair of zero-day vulnerabilities that have been confirmed by the vendor. 

The company publicly disclosed the vulnerabilities — CVE-2026-15409 and CVE-2026-15410 — in a security advisory Tuesday. SonicWall credited an employee with discovering the defects, but it hasn’t said when the discovery occurred or the earliest known instance of exploitation. 

Rapid7 researchers told CyberScoop both vulnerabilities were first exploited June 22. “From the cases that our team has observed, the goal is likely ransomware, though we have prevented the actors from achieving exfiltration and encryption,” said Seth Lazarus, senior manager of detection and response services at Rapid7.

Overlapping tactics, techniques and procedures from the attacks observed by Rapid7 indicate the same threat group or attacker discovered and exploited the zero-days, Lazarus added.

SonicWall did not answer questions about the impacts of these attacks thus far, and the company hasn’t attributed the attacks to a known group or described the attacker’s origins and motivations.

The vendor did, however, confirm to CyberScoop that both vulnerabilities have been chained together for exploitation. The vulnerabilities affecting SonicWall SMA1000 appliances, including a max-severity defect that allows attackers to make authenticated requests and a 7.2-rated vulnerability that allows authenticated command injection.

“When these two are chained, an attacker can go from zero access to a complete system compromise for the affected appliance,” said Landon Rice, senior exploit developer at VulnCheck.

Ben Harris, founder and CEO at watchTowr, said two characteristics of the vulnerabilities fuel a sense of dread. “Both were exploited as zero-days before fixes were available, and together they offer a plausible path to remote-code execution from the internet,” he said.

The Cybersecurity and Infrastructure Security Agency added both zero-days to its known exploited vulnerabilities catalog Tuesday. 

SonicWall encouraged customers to patch the vulnerabilities by upgrading to the latest software version, which it released upon disclosure, and shared some indicators of compromise to help customers hunt for potential malicious activity on their systems.

“Speed of response was a priority for us,” said Bret Fitzgerald, senior director of global communications at SonicWall. “Within days of becoming aware of the issue, our team had developed a script that we can run on behalf of affected customers to assist with resolution, and mitigation efforts are already underway.”

SonicWall and third-party researchers haven’t said how many SonicWall customers are impacted by the exploited vulnerabilities, but the vendor did say it already investigated multiple cases of active exploitation. 

Fitzgerald said the company monitors about one million sensors globally and “SMA1000 appliances represent a very small subset of that footprint, less than 5,000 units.”

SonicWall said support staff are also helping customers work through instances of suspicious activity, warning that patching alone is not sufficient. 

The vendor and its customers have been hit by a barrage of actively exploited zero-days and previously disclosed defects in SonicWall devices for years. In 2025, an undisclosed state-sponsored threat actor intruded the company’s cloud environment and stole firewall configurations of every SonicWall customer. 

Seventeen defects affecting the vendor’s products have been added to CISA’s known exploited vulnerabilities catalog since late 2021. Ten of those defects are known to be used in ransomware campaigns, according to CISA, including a wave of about 40 Akira ransomware attacks between mid-July and early August.

“As always,” Harris said, “when something is confirmed as already exploited in the wild, patching is the bare minimum, and breach should be assumed.”

The post SonicWall customers under threat as attackers exploit 2 zero-days appeared first on CyberScoop.

❌
❌