CISA pledges to continue backing CVE Program after April funding fiasco
ID: 3e1994aa-0a36-5b04-921f-25e51bd1ec27
STIX ID: report--3e1994aa-0a36-5b04-921f-25e51bd1ec27
Feed Name: The Record from Recorded Future News
CISA leaders at Black Hat 2025 affirmed continued funding and planned improvements for the CVE Program after an April contract lapse scare, emphasizing CVE’s centrality to vulnerability identification while noting parallel efforts like the EU’s new database and the newly formed CVE Foundation advocating nonprofit, international governance. They discussed aims for richer CVE records, reauthorization of cyber information sharing, AI-enabled defense via JCDC playbooks and initiatives, and easier access to CISA cyber hygiene services, while warning about trends like vulnerability chaining and internet-exposed ICS; CISA reported contacting over 3,000 entities with an 80% success rate in removing exposed devices and highlighted internal modernization efforts including a full cloud migration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
