NIST Officially Stops Enriching Most CVEs as Vulnerability Volume Skyrockets
NIST is moving to a risk-based enrichment model for the National Vulnerability Database, formally abandoning its longstanding goal of analyzing every submitted CVE. Starting immediately, the NVD will only enrich vulnerabilities that appear in CISA's Known Exploited Vulnerabilities (KEV) catalog, software used by the federal government, or software designated as critical under Executive Order 14028. Everything else gets labeled "Not Scheduled." The announcement came during VulnCon, where NVD…
Soutenez Socket en consultant la ressource originale
Lire l'article original