Tag: nist
131 articles

Vulnerability Management Scrambles to Keep Pace with AI-Driven Discovery
The National Vulnerability Database (NVD) is undergoing a major overhaul as it struggles to keep up with a staggering 30,000 reclassified vulnerabilities, now marked as "Not Scheduled" for further analysis, amid a surge in AI-driven discoveries. This change aims to help manage the overwhelming backlog through selective processing and automation.

US Agencies Embrace DevSecOps with Shift-Left Approach
The US Army's Acting CIO, Gabe Chiulli, is leading the charge to revolutionize software delivery by embracing a shift-left approach to DevSecOps, aiming to merge commercial speed with government security needs. By setting a new framework, Chiulli is paving the way for industry collaboration and rapid innovation.

CMMC Pause Doesn't Halt Compliance Imperative
The pause on CMMC Phase 2.0 doesn't let you off the compliance hook - you still need to prioritize protecting controlled unclassified information (CUI) within your environment. Keep moving forward with necessary security measures to ensure CUI protection, as requirements remain in place despite validation delays.

NIST Identifies Security Gaps in Multi-Cloud Environments
NIST warns that multi-cloud environments, which use two or more cloud service providers, pose unique cybersecurity and compliance risks, despite helping organizations reduce reliance on a single provider and maintain operations during outages or cyber-attacks. A recent NIST report aims to tackle these challenges by providing a structured problem statement and shared vocabulary to inform future research and solution design.

Sharpening Cybersecurity Standards
Don't let your guard down now - Katie Arrington stresses that now is not the time to relax cybersecurity standards, especially after self-attestation failed to protect the war industrial base. The Cybersecurity Maturity Model Certification was created to ensure verification and accountability.

Google Cloud Accelerates Post-Quantum Security Push with 2027 Milestone
Google Cloud is proactively bolstering its defenses against future quantum computer threats, aiming to complete a major milestone in its post-quantum security migration by 2027. The tech giant has mapped out a multi-year plan to adopt quantum-resistant cryptography, tackling key risks in data security and digital signatures.

Lazarus Exploits Windows Zero-Day with Post-Quantum Key Exchange Tactics
Lazarus hackers have taken a cutting-edge approach, using a post-quantum key exchange to secure their command channel before exploiting a Windows zero-day vulnerability in a targeted campaign against defense and aerospace companies. They leveraged Kyber/ML-KEM, a key encapsulation scheme designed to withstand quantum computer attacks, to generate fresh key material and evade detection.

NIST Seeks Input on NVD Overhaul Amid AI-Driven Cybersecurity Shift
The US government's quest to modernize the National Vulnerability Database is underway, and it's seeking your input - with an October 13 deadline to share innovative ideas on how to bring this critical cybersecurity resource into the automation age. NIST wants to hear your forward-looking perspectives on how to scale the NVD and supercharge its support for automated security workflows.

NIST Seeks Overhaul of Vulnerability Database for AI-Driven Era
The National Institute for Standards and Technology is calling for a major revamp of its National Vulnerability Database to better tackle software vulnerabilities in the AI-driven era. It's seeking public input on how to modernize the database and its processes to stay ahead of emerging threats.

Python Ecosystem Integrates Post-Quantum Encryption Standards
The Python ecosystem just got a major boost in security with the integration of post-quantum encryption standards, making it easier to future-proof your systems. The popular pyca/cryptography library now supports ML-KEM and ML-DSA, the NIST-standard primitives for secure key establishment and digital signatures.

CMMC Pause Spurs Urgent Gap Assessments
The Department of Defense's sudden pause on CMMC Phase 2 has created an urgent need for gap assessments, especially for small and non-traditional businesses struggling to meet compliance requirements. This 60-day review aims to ease the burden, but existing obligations, including Phase 1 self-assessment requirements, remain in force.

Cyberattacks Expose Gaps in Organizational Readiness
Most organizations are unprepared to tackle a major cyberattack, with a staggering 73% admitting they'd struggle to respond effectively if one hit tomorrow. The real challenge lies not in having the right tools and plans, but in getting them to work seamlessly together under pressure.

AI Models Expose Vulnerabilities in Historic Cryptographic Algorithms
Can AI models uncover weaknesses in centuries-old cryptographic algorithms? A new benchmark, CryptanalysisBench, puts large language models to the test, challenging them to discover real cryptanalytic attacks against historical and contemporary schemes.

AI Model Exposes Weaknesses in Key Encryption Algorithms
An AI system has made a groundbreaking discovery, uncovering significant weaknesses in key encryption algorithms that even the experts didn't know existed. By working together with a human researcher, the AI was able to find a mathematical shortcut that halves the effective strength of HAWK, a digital-signature scheme being considered for post-quantum cryptography.

Claude AI Exposes Faster Attacks on Post-Quantum Cryptography Scheme HAWK, AES
Anthropic's Claude AI has made a groundbreaking discovery, cracking a post-quantum cryptography scheme in just three hours and 42 minutes on a 96-core server. The AI, specifically Mythos Preview, uncovered a hidden symmetry that paved the way for a direct key-recovery path.

NIST Launches AI Evaluation Platform to Gauge Model Performance
The National Institute of Standards and Technology has launched a game-changing AI evaluation platform that provides a safe and isolated environment for developers to test and gauge the performance of their AI models. This innovative tool offers a set of common metrics and blind data to help researchers gain objective insights into their models' capabilities.

SSO Security Requires Proactive Defense Against Credential Attacks
A single compromised SSO account can become a master key, unlocking a vast array of sensitive services and putting millions of individuals at risk, as seen in the 2025 University of Pennsylvania breach where 1.2 million people's data was stolen. Proactive defense against credential attacks is crucial to protecting your organization's security.

Wyden Urges Feds to Phase Out Insecure Public-Facing VPNs
Senator Ron Wyden is calling on federal agencies to ditch outdated, vulnerable VPNs and upgrade to modern, secure remote-access technology to protect against devastating cyberattacks. In a letter to top officials, he urged a coordinated effort to safeguard government employees' remote access and prevent further breaches.

Commerce's AI Standards Chief Exits Abruptly
Chris Fall, director of the Center for AI Standards and Innovation, is stepping down, and NIST Director Dr. Arvind Raman will take the reins as Acting Director. The sudden departure has raised eyebrows, but details remain scarce.

Credentials Face Quantum Threat Decades Ahead
The NSA has set a critical deadline: by January 1, 2027, new national security systems must support quantum-resistant algorithms to stay ahead of emerging threats. With deadlines stretching into the 2030s, organizations must plan now to protect their systems from the looming quantum threat.

NIST's Vulnerability Database Plagued by Duplication, Inefficiency
The National Vulnerability Database is facing a massive backlog crisis, with unprocessed security flaws doubling from 13,000 in June 2024 to over 27,000 by the end of 2025, and officials admit they lack a long-term plan to tackle the problem. Despite promising to clear the backlog by September 2024, the database continues to struggle with inefficiencies and a lapsed contract.

Drupal Warns of Highly Critical Vulnerability Requiring Immediate Patch
Drupal is warning of a highly critical vulnerability that requires immediate attention, urging site operators to clear their calendars for a crucial patch rollout on Wednesday, May 20, between 1700 and 2100 UTC. Exploits could be developed within hours or days, making swift action essential to protect your site.

AI Reshapes Cybersecurity With Renewed Focus on Fundamentals
Artificial intelligence is revolutionizing cybersecurity by refocusing efforts on timeless fundamentals, empowering agencies to make informed decisions with the help of established frameworks like the NIST Cybersecurity Framework. By layering new AI-related risks over existing ones, Cheri Pascoe, Director of the National Cybersecurity Center of Excellence at NIST, highlights the need for a strategic approach to tackle these emerging threats.

NIST Scales Back Vulnerability Ratings Amid Surge in Submissions
The National Institute of Standards and Technology is overhauling its vulnerability rating system, scaling back severity scores for lower-priority flaws as submissions surge. This change means some software flaws will no longer get a severity score, shifting focus to the most critical vulnerabilities.