Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    It’s Donald Trump Versus MAGA on Data Centers

    September 20, 2026

    Why AI Isn’t Likely to Wipe Out Humanity With Bioweapons

    September 20, 2026

    Napster Is Back, and It Wants to Digitally Clone Teachers

    September 19, 2026
    Facebook X (Twitter) Instagram
    Trending
    • It’s Donald Trump Versus MAGA on Data Centers
    • Why AI Isn’t Likely to Wipe Out Humanity With Bioweapons
    • Napster Is Back, and It Wants to Digitally Clone Teachers
    • Join the WIRED World Fair in Miami on November 4
    • This Week’s Awesome Tech Stories From Around the Web (Through September 19)
    • Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening
    • Mathematicians Hate AI. They Can’t Quit It
    • Adopt This Data Center Plushie and Hear Its Piercing Scream
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»CISA orders federal agencies to “patch smarter”
    Cybersecurity

    CISA orders federal agencies to “patch smarter”

    kirklandc008@gmail.comBy kirklandc008@gmail.comJune 11, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    CISA's new KEV nomination form opens reporting to vendors and researchers
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a Binding Operational Directive that will change how the US federal government approaches vulnerability management.

    The directive arrives as the patching problem has become nearly unmanageable, driven by a surge in newly published vulnerabilities and by AI tools that are accelerating both security research and exploit development on the attacker side.

    Towards risk-based vulnerability management

    BOD 26-04 introduces a framework that allow federal civilian Executive Branch agencies to make risk-based decisions about what to fix and how fast.

    The decision rests on four factors: whether the vulnerability affects internet-facing systems, whether it appears in CISA’s Known Exploited Vulnerabilities catalog, whether it can be exploited in automated attacks, and whether exploitation gives attackers partial or total control of the affected system(s).

    A flaw that, for example, hands an attacker complete control of an internet-exposed system, is actively exploited, and can be exploited at scale represents the highest tier of urgency, requires agencies to remediate it within three and days check whether it has already been exploited in their environment.

    Remediation timelines mandated by the BOD (Source: CISA)

    CISA has been fortright about a notable gap in the framework’s scope: The directive concentrates on the network perimeter and does not impose the same urgency for addressing vulnerabilities inside the network core.

    That’s because threat actors don’t compromise core networks primarily through product vulnerabilities, the agency explained.

    “Instead, threat actors often use exploitable configurations and valid credentials — a technique known as living off the land (LOTL). LOTL is better addressed through other means, such as hardening system configurations, network segmentation, and phishing-resistant multi-factor authentication (MFA) enforcement.”

    Other signals worth watching

    While BOD 26-04 represents a meaningful leap forward from CVSS-severity-only patching, experts have also been advising that organizations consider other signals when deciding how quickly to patch.

    Cisco Talos’ Thorsten Rosendahl, for example, argues that each vulnerability’s dynamic EPSS score – that is, the probability that indicates how likely it will be exploited in the next 30 days, based on real-world signals – should be taken into consideration.

    Also, that organizations should consider checking Global CVE for a global understanding on which vulnerabilities are being exploited.

    Recently, NIST proposed yet another metric and asked the cybersecurity community to evaluate it: Likely Exploited Vulnerabilities (LEV), which is an estimate of how likely it is that a vulnerability has already been used in attacks.

    CISA, for its part, has said it will review the directive and update its implementation guidance on a rolling basis, “to account for changes in the general cybersecurity landscape.”

    Related video:

    Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

    agencies CISA Federal orders Patch Smarter
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    San Francisco Orders Meta to Stop ‘Allowing’ AI Child Abuse Ads

    September 10, 2026

    The Download: smarter AI in schools, and a robot “carnival” in Shanghai

    August 25, 2026

    How to encourage smarter AI use in the classroom

    August 24, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • It’s Donald Trump Versus MAGA on Data Centers
    • Why AI Isn’t Likely to Wipe Out Humanity With Bioweapons
    • Napster Is Back, and It Wants to Digitally Clone Teachers
    • Join the WIRED World Fair in Miami on November 4
    • This Week’s Awesome Tech Stories From Around the Web (Through September 19)

    It’s Donald Trump Versus MAGA on Data Centers

    September 20, 2026

    Why AI Isn’t Likely to Wipe Out Humanity With Bioweapons

    September 20, 2026

    Napster Is Back, and It Wants to Digitally Clone Teachers

    September 19, 2026

    Join the WIRED World Fair in Miami on November 4

    September 19, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.