cd /news/artificial-intelligence/nato-and-an-ai-startup-can-now-name-… · home topics artificial-intelligence article
[ARTICLE · art-91001] src=cyberscoop.com ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

NATO and an AI startup can now name and track software vulnerabilities

NATO's Cyber Security Centre and AI startup AISLE have joined the CVE program as numbering authorities under the ENISA Root, enabling them to assign unique identifiers to software vulnerabilities, the European Union Agency for Cybersecurity announced last week. The additions bring the total to 20 numbering authorities under ENISA, with 12 brought in by ENISA and eight transferred from the MITRE Root. Hans de Vries, ENISA's chief cybersecurity and operations officer, linked the growth to the emergence of Frontier AI models and their impact on vulnerability discovery and exploitation.

read2 min views1 publishedAug 10, 2026
NATO and an AI startup can now name and track software vulnerabilities
Image: Cyberscoop (auto-discovered)

NATO’s cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws, the European Union Agency for Cybersecurity announced last week.

The NATO Cyber Security Centre, part of the NATO Communications and Information Agency, and AISLE, a cybersecurity company with offices in San Francisco and Prague, joined as CVE numbering authorities under the ENISA Root. The CVE program assigns a unique record to each publicly disclosed security flaw so that governments, vendors and researchers have a common marker when referring to particular vulnerabilities.

Twenty numbering authorities now sit under the ENISA Root, with 12 brought in by ENISA itself and eight moving over from the MITRE Root, run by the U.S. nonprofit that has handled the program’s daily work for more than 20 years.

Hans de Vries, ENISA’s chief cybersecurity and operations officer, linked the growth to changes in how people find flaws.

“Recent developments in the global cybersecurity landscape, coupled with the emergence of Frontier AI models and their impact on vulnerability discovery and exploitation, have underscored the need to build strong vulnerability management infrastructure and capabilities,” he said in a statement. He said ENISA’s role helps build a “more globally representative, resilient, and scalable vulnerability identification ecosystem.”

The two new members show how bespoke each member is within its authority. The NATO Cyber Security Centre can now assign CVE IDs to eligible flaws across the NATO enterprise. The agency said that will make tracking more consistent and let the alliance share information with trusted partners sooner. The center guards NATO’s networks, watches for threats and coordinates the response when incidents hit.

Meanwhile, AISLE’s authorization is narrower. The company said in a July press release that the designation covers vulnerabilities discovered in its own products, allowing it to publish identifiers without waiting for a third-party authority to process a request.

Jaya Baloo, the company’s co-founder, described the step as “foundational” and said coordinated disclosure “starts with holding your own products to the same standard you expect of everyone else.” Separately from the designation, the company said its researchers have disclosed hundreds of vulnerabilities in widely used open-source software, including OpenSSL, Linux, Apache and OpenEMR, each coordinated through the relevant authority for that project.

The changes come as the CVE process continues to involve amid program upheaval and the torrent of vulnerabilities discovered by AI systems.

The CVE program, run by CISA, narrowly escaped a sudden demise when a last-minute, 11-month contract extension averted a shutdown in April 2025. Since then, several competing databases from European nonprofits and other private entities have been stood up in order to better coordinate how vulnerabilities are tracked, disclosed, and ultimately patched.

Earlier this year, The Computer Incident Response Center Luxembourg (CIRCL) launched the Global CVE Allocation System, or GCVE, as an alternative to the CVE program.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @nato cyber security centre 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/nato-and-an-ai-start…] indexed:0 read:2min 2026-08-10 ·