VulnCon 2025: NVD Scraps Industry Consortium Plan, Raising Q...
Blog post from Socket
At VulnCon 2025, the National Institute of Standards and Technology (NIST) announced the abandonment of its planned industry consortium for the National Vulnerability Database (NVD) due to legal and resource challenges, opting instead for more informal collaborations. This decision has sparked criticism from industry experts who feel it undermines efforts to reform the NVD's processes and transparency. NIST also acknowledged its struggle to manage an increasing backlog of Common Vulnerabilities and Exposures (CVEs), leading to the implementation of temporary measures such as "gap filling" to expedite processing, though this has raised concerns about data quality. Despite these governance challenges, NIST outlined several technical improvements, including enhanced data integration, search functionalities, and automation efforts, while facing criticisms over the fragmented state of vulnerability data across different ecosystems. The presentation aimed to convey progress but left some attendees questioning the openness and extent of the proposed changes.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.