NVD Remains Stalled on Enriching CVE's, Security Industry Cr...
Blog post from Socket
The National Institute of Standards and Technology (NIST) is facing criticism from the cybersecurity industry over delays in enriching Common Vulnerabilities and Exposures (CVE) records in the National Vulnerability Database (NVD), a crucial component of the nation's cybersecurity framework. These delays are attributed to an increase in software vulnerabilities and changes in interagency support, resulting in a significant backlog of unprocessed vulnerabilities. In response, NIST plans to establish a consortium to address these challenges, although this has been met with skepticism and calls for clearer communication. Security professionals have expressed concerns about the lack of transparency and are urging Congress to investigate and ensure sufficient resources for the NVD, even suggesting its potential transfer to the Cybersecurity and Infrastructure Security Agency (CISA). Meanwhile, third-party initiatives like Anchore's open-source "NVD Data Overrides" project are emerging to fill gaps left by the NVD's stalled enrichment efforts, though they lack the official severity scores that only the NVD can provide.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.