Topic: cve program
-
Microsoft Pays $2.3M for Cloud, AI Security Flaws
Microsoft's 2026 Zero Day Quest hacking contest awarded $2.3 million for over 80 high-severity flaws found in its cloud and AI platforms, with participation from a global community. The contest is part of Microsoft's Secure Future Initiative, launched to overhaul its security culture following a ...
Read More » -
ENISA Aims for CVE Program Leadership Role
The EU's ENISA is being onboarded by the U.S. CISA to become a top-level root CVE Numbering Authority (TL-Root CNA), aiming for this status in 2026 or early 2027 to join CISA and MITRE as a core manager of the global vulnerability catalog. Achieving TL-Root status would grant ENISA a strategic ro...
Read More » -
CISA Expands AI Role in Cybersecurity Program
A senior CISA leader has called for major AI developers like OpenAI and Anthropic to become more formally involved in the Common Vulnerabilities and Exposures (CVE) program to help manage the growing volume of security flaws. Leading AI labs have recently released advanced models, such as Anthrop...
Read More » -
CISA Enlists Partners to Strengthen CVE Program's Future
The US Cybersecurity and Infrastructure Security Agency (CISA) has reaffirmed its commitment to the Common Vulnerabilities and Exposures (CVE) program, securing its funding through March 2026 and emphasizing its role as a public good for global cybersecurity defense. CISA plans to modernize the C...
Read More » -
CISA Unveils New CVE Program Roadmap for Enhanced Cybersecurity
CISA has launched a strategic roadmap to transition the CVE program into a "Quality Era," emphasizing its public, vendor-neutral nature and warning against privatization. The agency is exploring diversified funding and stronger leadership, potentially indicating a shift in administrative roles, w...
Read More »