Home / Companies / Socket / Blog / Post Details
Content Deep Dive

NIST Announces Major Contract to Clear NVD Backlog by Septem...

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
994
Company Posts That Month
13
Language
English
Hacker News Points
-
Post removed?
No
Summary

Following reports that over 50% of known exploited vulnerabilities (KEVs) remained unenriched since mid-February, the National Institute of Standards and Technology (NIST) announced a major contract to address the backlog in the National Vulnerability Database (NVD) by the end of the fiscal year. NIST has engaged additional processing support and formalized an agreement with the Cybersecurity and Infrastructure Security Agency (CISA) to process Common Vulnerabilities and Exposures (CVEs), aiming to return to pre-February processing rates. Despite these efforts, NIST has faced criticism for a lack of transparency regarding the backlog's cause and its consortium plan, with cybersecurity professionals calling for congressional oversight and urging organizations to diversify their sources of CVE data. The agency's plan includes modernizing the NVD to handle the increasing volume of vulnerabilities, but skepticism remains due to previous communication failures and the perceived loss of credibility in the software security community.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.