logo

CISA's 'vulnrichment' aims to fix the NVD

ID: 068fbe67-9bd0-548e-abc8-6760581db550

STIX ID: report--068fbe67-9bd0-548e-abc8-6760581db550

Feed Name: ReversingLabs Blog

Date Published: 2024-05-15

Date Updated: 2026-04-29

Author: [email protected] (Jaikumar Vijayan)

...
...

CISA announced a vulnerability enrichment program to add CVSS, CPE, CWE, and KEV context to CVEs using an SSVC-based model, stepping in after NIST scaled back NVD enrichment; more than 1,300 CVEs have been processed to support risk-based prioritization. The agency also expanded its Malware Nex-Gen file analysis service to all U.S. organizations amid rising vulnerability exploitation reported by industry, underscoring the need to enhance modern vulnerability and malware defense practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.