NIST Marks Pre-2018 CVEs as 'Deferred' to Focus on Recent Vulnerabilities

The National Institute of Standards and Technology (NIST) has announced that all Common Vulnerabilities and Exposures (CVEs) published before January 1, 2018, will now be marked with a "Deferred" status within the National Vulnerability Database (NVD). This change aims to optimize resources by focusing on newer vulnerabilities amid a significant increase in reported security issues. CVEs labeled as "Deferred" will display a banner indicating this status, and while NIST will not prioritize updates for these older records, it will still review and process requests for metadata updates as resources allow. Notably, vulnerabilities listed in the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog will continue to receive attention regardless of their publication date.  

https://gbhackers.com/nist-declares-pre-2018-cves-will-be-labeled-as-deferred

Comments

Popular posts from this blog

Secure Vibe Coding Guide: Best Practices for Writing Secure Code

KEVIntel: Real-Time Intelligence on Exploited Vulnerabilities

OWASP SAMM Skills Framework Enhances Software Security Roles