{"slug": "cisa-is-ending-its-monthly-vulnerability-bulletin", "title": "CISA is ending its monthly vulnerability bulletin", "summary": "The US Cybersecurity Infrastructure and Security Agency (CISA) will discontinue its weekly bulletin of known vulnerabilities on September 28, citing the recently introduced Binding Operational Directive (BOD 26-04), which requires US agencies to prioritize patching based on real-world risk factors such as evidence of exploitation in the wild rather than severity scores. CISA will continue publishing through its Known Exploited Vulnerabilities (KEV) catalog, Cybersecurity Alerts and Advisories, and Common Vulnerabilities and Exposures catalog, and is urging CISOs to follow vendors' and providers' own security bulletins. The change comes as CISA warned earlier this month about threat actors targeting AI-developed assets and using them to launch new attacks.", "body_md": "The rise in AI-generated security threats may just have generated one casualty: the death of the weekly bulletin of security threats from the US Cybersecurity Infrastructure and Security Agency (CISA).\n\nThe agency will [discontinue its weekly bulletin of known vulnerabilities from September 28](https://content.govdelivery.com/accounts/USDHSCISA/bulletins/42b055b). It said that it is taking this step because of the recently introduced [Binding Operational Directive (BOD 26-04)](https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk), which compels US agencies to prioritize patching vulnerabilities according to real-world risk factors. These will include evidence of vulnerabilities being identified in the wild, as opposed to the previous criterion of severity scores. It is not clear why the agency cannot continue to issue weekly bulletins while complying with the demands of BOD.\n\nWhat could be a more pressing issue for CISA is the proliferation of AI-generated threats. Earlier this month, the agency issued a [warning about bad actors](https://www.csoonline.com/article/4221307/threat-actors-are-coming-for-your-ai-assets-to-operationalize-their-use-of-ai.html) threatening AI-developed assets and using them to launch new attacks.\n\nThe agency is also encouraging CISOs to follow vendors’ and providers’ own security bulletins and updates in order to strengthen their defences.  Earlier this year, [CISA urged these vendors to work more closely with security researchers](https://www.csoonline.com/article/4197733/cisa-urges-software-vendors-to-formalize-vulnerability-disclosure-programs.html) to improve defences against cyberattacks.\n\nAlthough it is no longer issuing weekly bulletins, CISA will continue to issue other information through its Known Exploited Vulnerabilities (KEV), its Cybersecurity Alerts and Advisories and its Common Vulnerabilities and Exposures catalogs.", "url": "https://wpnews.pro/news/cisa-is-ending-its-monthly-vulnerability-bulletin", "canonical_source": "https://www.csoonline.com/article/4223933/cisa-is-ending-its-monthly-vulnerability-bulletin.html", "published_at": "2026-09-18 16:52:04+00:00", "updated_at": "2026-09-18 16:55:48.423159+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy"], "entities": ["CISA", "Binding Operational Directive 26-04", "Known Exploited Vulnerabilities", "Common Vulnerabilities and Exposures"], "alternates": {"html": "https://wpnews.pro/news/cisa-is-ending-its-monthly-vulnerability-bulletin", "markdown": "https://wpnews.pro/news/cisa-is-ending-its-monthly-vulnerability-bulletin.md", "text": "https://wpnews.pro/news/cisa-is-ending-its-monthly-vulnerability-bulletin.txt", "jsonld": "https://wpnews.pro/news/cisa-is-ending-its-monthly-vulnerability-bulletin.jsonld"}}