NIST wants to overhaul its vulnerability database for the AI age
NIST issued a Federal Register RFI seeking public input on overhauling the National Vulnerability Database for AI-scale, machine-consumable security data.
NIST published a request for information arguing the National Vulnerability Database must adapt as LLMs increasingly find and exploit vulnerabilities at machine scale. The RFI seeks input on integrating automation into vulnerability reporting, faster dissemination to defenders, and transparency and auditability in AI-driven decisions. It follows the White House-backed Gold Eagle clearinghouse at Treasury and the VINCE program with Carnegie Mellon's Software Engineering Institute for AI-discovered vulnerability reports.
- RFI cites rising disclosure volume, inconsistent data quality and demand for near real-time enrichment.
- NIST asks how AI should support automated remediation and auditable decision-making.
- Effort follows Treasury's Gold Eagle clearinghouse and Carnegie Mellon SEI's VINCE for AI-discovered vulnerabilities.
Full article638 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
NIST is seeking public input to modernize the National Vulnerability Database to keep pace with AI-driven cyber threats and machine-scale security data.
Listen to this article
0:00
Learn more.
The National Institute for Standards and Technology is looking for input on how to overhaul its vulnerability reporting process to better meet the challenges of an “evolving cybersecurity landscape increasingly shaped by artificial intelligence and machine-consumable security data.”
In a request for information set to publish Wednesday in the Federal Register, NIST said its National Vulnerability Database, one of the primary ways the federal government coordinates with security researchers to identify and fix software vulnerabilities, must be updated for the AI age.
NIST is concerned that as large language models become more capable of finding and exploiting vulnerabilities at scale, the NVD’s process must be updated.
“The inadequacies of traditional vulnerability management approaches, which center on periodic scanning, static prioritization, and manual remediation, are increasingly apparent,” the RFI states.
NIST believes AI hacking tools are contributing to recent trends in vulnerability reporting. The NVD has seen increased volume and complexity of disclosed vulnerabilities, inconsistent data quality, increased reliance on automation and machine-readable security data, and “demand for near real-time vulnerability enrichment” from defenders facing faster threats.But NIST believes these challenges also present an “opportunity to transform the vulnerability management ecosystem” through proactive reforms and NVD innovation.
That’s where the public comes in. NIST is posing a series of questions that must be answered before a larger strategy can be developed. Many of their questions focus on better integrating automation – AI or otherwise – into the process.
The agency asked for insight on how defenders could better leverage automation in the vulnerability reporting process; which capabilities, products and processes would help more quickly disseminate information to stakeholders, how to build transparency and auditability into AI-driven decisionmaking, and what role AI should play in automated vulnerability remediation.
“NIST intends to support a future-ready vulnerability management ecosystem that is continuous, contextual, and automated, while enabling cybersecurity practices to respond appropriately to real-world threats and business priorities,” the RFI states.
The NIST effort to revamp its vulnerability database comes a month after the Trump administration rolled out a new federal clearinghouse, overseen by the Department of Treasury, for sharing AI threat information between government and the private sector called “Gold Eagle.”
It’s not clear how Treasury’s process will interact with NIST’s database. The White House also partnered with Carnegie Mellon’s Software Engineering Institute to create the Vulnerability Information and Coordination Environment, (VINCE) which will collect and distribute reports on AI-discovered vulnerabilities.
Latest Podcasts
Government
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/nist-national-vulnerability-database-ai-overhaul/