تخطي إلى المحتوى الرئيسي
Cyber News Dark Reading 3 days ago

Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI

Da
Dark Reading

The National Institute of Standards and Technology (NIST) is seeking guidance on the future of the National Vulnerability Database (NVD) and to what degree AI should be integrated into its management of the service and the enrichment of data on software flaws.

On Aug. 12, the US agency posted a request for public comment on six areas of the NVD's operations — including the vulnerability management process and risk prioritization — as well as the overall vision for the repository of vulnerability data. The "Request for Information (RFI) on Modernizing the National Vulnerability Database in the Age of Artificial Intelligence" comes as the agency is dealing with a massive influx of vulnerabilities, partly caused by AI enabling researchers to investigate and discover flaws at a faster pace.

"Today's vulnerability management ecosystem is rapidly evolving and is characterized by AI-enabled cyber tools and accelerated technology delivery cycles," the agency stated in the RFI. "Malicious actors may seek to leverage AI systems to discover and exploit vulnerabilities at scale and to support post-exploitation activities. The inadequacies of traditional vulnerability management approaches, which center on periodic scanning, static prioritization, and manual remediation, are increasingly apparent."

Related:'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture

NIST specifically asks how AI and other automated mechanisms can be used to improve contextual risk prioritization, and if AI systems have a role in automated vulnerability remediation. The RFI is the latest effort instituted by the agency to keep up with a growing backlog of vulnerabilities, a problem that has been exacerbated by cuts to NIST and its programs in the past 18 months. In April, the US agency announced it would prioritize enrichment for vulnerabilities that appear on CISA's Known Exploited Vulnerabilities (KEV) list, flaws in software in use by the federal government, and security issues in critical software as defined by Executive Order 14028.

View Original Report

This intelligence was aggregated from Dark Reading.

Read on Source