logo

CVEs lose relevance: Get proactive — and think beyond vulnerabilities

ID: cfa8fc4e-5e83-5bf8-b388-1e37b64d3ff1

STIX ID: report--cfa8fc4e-5e83-5bf8-b388-1e37b64d3ff1

Feed Name: ReversingLabs Blog

Date Published: 2025-04-02

Date Updated: 2026-04-29

Author: [email protected] (Carolynn van Arsdale)

...
...

The report examines how NIST’s pause in NVD CVE enrichment in 2024 created a backlog and shifted enrichment to CNAs, prompting CISA’s “Vulnrichment” program to mitigate gaps, with data showing steep declines in NVD-enriched CVEs for npm and PyPI and estimates that most new vulnerabilities went unanalyzed. It concludes that vulnerability-centric, reactive approaches (including EPSS-based prioritization) are insufficient and urges organizations to adopt proactive software supply chain security, emphasizing binary analysis, reproducible builds, and detection of tampering, malware, and secrets exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.