New SharePoint auth bypass already being exploited hours after PoC went public

Posted in Commentary with tags on August 12, 2026 by itnerd

Rapid7 published a proof-of-concept exploit today for CVE-2026-55040, an authentication bypass in SharePoint’s JWT token validation that lets an attacker impersonate any user or admin without credentials. Threat intel firm Defused reported the exploit code was already hitting its honeypots the same day; it’s the second distinct on-prem SharePoint flaw to make news this week, after Monday’s ransomware-exploited deserialization bug.

More info here: CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)

Roman Sannikov, Global Research Coordinator, iCOUNTER said this:

“Microsoft patched CVE-2026-55040 in July. Rapid7 published a full technical write-up and working exploit code today, and Defused was already seeing that exact code hit its honeypots the same day. Hours passed between a researcher publishing proof-of-concept code and someone using it against real targets. No group has been identified yet, which tracks, at this stage it’s likely opportunistic scanning off the public PoC rather than a targeted campaign. This is exactly the kind of flaw that matters more as companies move away from plain passwords. CVE-2026-55040 breaks the token validation that’s supposed to replace passwords in the first place, and we’re seeing threat actors go after tokens and other forms of MFA directly instead of trying to phish or guess a credential. The bigger pattern is worth focusing reporting on: this is the second separate on-prem SharePoint flaw in the news this week. The story now is how many separate ways into the same platform are surfacing at once.”

This is fixed and people should update all the things. That would mitigate this issue completely. Otherwise pwnage will be guaranteed.

Half of UK tech leaders say outages threaten revenue

Posted in Commentary with tags on August 12, 2026 by itnerd

Research published by Zen Internet found that half of UK technology leaders believe network outages threaten revenue. The study surveyed 500 senior technology decision-makers across the UK.

The findings point to wider concern about the role of network resilience in business performance. More than half of respondents, 51%, said resilience was business-critical and that outages would significantly affect revenue, operations or customers. A further 94% said resilience was important to their organisation’s success.

Many technology leaders also said complexity within their IT estates was slowing change. Zen found that 78% said technology complexity was holding back transformation, with multiple vendors, platforms and contracts cited as major obstacles.

You can read the full story here: https://securitybrief.co.uk/story/half-of-uk-tech-leaders-say-outages-threaten-revenue

Commenting on this, Mayur Upadhyaya, CEO at APIContext, said: 

The fact that half of UK technology leaders now see outages as a threat to revenue shows how closely digital resilience and business performance have become linked.

Complexity doesn’t come from the number of systems you have. It comes from the number of dependencies between them. A payment, customer journey or identity transaction can cross multiple APIs, cloud services and third parties before it completes, and organisations don’t always have visibility across that entire chain.

AI and agentic adoption add another dimension. Increasingly, machines are executing those transactions, making decisions and retrying when something degrades. Machines can fail silently, and they fail at machine speed. That means a small degradation can propagate through dependent systems before an operational team even knows there is a problem.

The answer isn’t to slow innovation. It’s to recognise that resilience now means continuously verifying the critical transactions the business depends on, not simply monitoring the individual systems underneath them.”

Outages cripple or kill companies. So stopping outages should be the priority or bad things will happen.

Palo Alto Puts OpenAI Cyber Models to Work for Defenders

Posted in Commentary with tags on August 12, 2026 by itnerd

Today, Palo Alto Networks announced it will give defenders access to OpenAI’s leading cybersecurity-focused model, GPT-5.6 Daybreak, to help businesses find, test, and validate attack paths at machine speed. Until now, GPT-5.6 Daybreak has not been available for commercial use.

Frontier AI in cybersecurity has largely been seen as a threat defenders were racing against. Now, Palo Alto Networks’ Unit 42 is expanding its Frontier AI Defense service to bring advanced AI cyber models inside customer environments to actively simulate attacks and uncover hidden, previously unknown attack paths and create custom remediation plans before AI-enabled threat actors can exploit them.

What’s New 

Through our partnership with OpenAI, we’re expanding our Frontier AI Exposure Analysis capabilities to offer security teams: 

  • Leading cyber models: Apply the latest advanced cyber models to improve exposure discovery, testing and validation.
  • Multi-model harness: Use the right model for the right task to improve efficacy, expand coverage and optimize cost.
  • Exposure discovery: Find vulnerabilities, misconfigurations, leaked credentials, unmanaged attack surface and other posture gaps across applications and network assets.
  • Advanced adversary simulation: Actively test exploitability and validate end-to-end attack paths to understand how an attacker could compromise the environment.
  • Custom remediation plan: Prioritize the fixes that break the most important attack paths and feed those findings into existing IT, development and security workflows.

Focusing on known vulnerabilities and exploits doesn’t work anymore. Our Frontier AI Defense data found that 36% of exposures lacked known CVEs. Security teams must now match AI-powered attacks with machine-speed defense.

There’s also the blog post from Sam Rubin, SVP of Unit 42, with more details.

Canadian Hospital Pwned In Ransomware Attack

Posted in Commentary with tags on August 12, 2026 by itnerd

There has been a ransomware attack at a Manitoba hospital. CBC News has the details:

Shared Health said in a statement Monday it’s responding to what it called “a ransomware incident affecting certain facility maintenance systems.”

Patient care and clinical operations are not affected, the health authority said, urging anyone who needs to attend the hospital to do so.

Clinical services continue uninterrupted, and based on the investigation conducted to date, there is no indication that patients have been affected,” the statement, provided to CBC News by spokesperson Tara Seel, says.

Shared Health said it has launched an investigation to determine the nature and scope of the attack and is reviewing the systems affected by it. No other systems appear to be affected, the statement said.

Shared Health also said it has notified the provincial government and has sought expert advice to try to resolve the problem.

Health Sciences Centre said in an internal memo to staff that it has increased the presence of security and institutional safety officers at hospital entrances while doors are still affected by the attack.

The attack has affected doors, elevators, ventilation and air conditioning.

Kevin Surace, CEO, Token (https://www.linkedin.com/in/ksurace)

“This incident is a vivid demonstration that the boundary between IT and physical infrastructure has disappeared. Doors, elevators, ventilation, access controls and other building systems are now computers with physical consequences. Whether ransomware deliberately manipulates equipment or merely disables the systems used to manage it, an identity compromise can quickly become a safety and operational continuity event.

“We do not yet know how the attackers entered this hospital. But organizations should assume that facilities employees, contractors and vendors with privileged access will be targeted through convincing AI generated phishing and spoofed login sites. Training unfortunately cannot make people resilient against AI generated attacks, and should not carry the burden of protecting critical infrastructure. For identities capable of affecting the physical environment, organizations should require dedicated, hardware bound, phishing resistant authentication with biometric user verification as MFA and even passkeys are regularly compromised. They should also eliminate weaker fallback methods, strictly limit privileges and isolate operational systems from ordinary corporate networks.

“Resilience must mean much more than restoring servers and data. Organizations need to test whether they can place a facility into a safe state, operate critical systems manually, maintain operations while networks are isolated and recover trusted configurations. Those exercises must include IT, facilities, physical security, safety teams and outside service providers. If a ransomware drill ends when the backup is restored, it has not tested the consequence that matters most: whether the physical environment remains safe.”

Seemant Sehgal, Founder & CEO, BreachLock (https://www.linkedin.com/in/s-sehgal)

“Hospital building systems running on the same network fabric as clinical IT systems is a configuration that has existed for years, and the risk has been understood long before this attack made it visible. The path to disrupting doors and elevators is the same path that leads to patient records, just with a different endpoint on the other side of an unenforced segmentation boundary.

“Organizations that have actually mapped how their OT connects to their enterprise network already know exactly which physical systems are reachable from a compromised workstation, and that knowledge is what determines whether an incident like this stays contained or becomes a headline.”

John Strand, Owner, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)

“The IT and physical infrastructure have always been very much connected. Very few organizations have a true separation between those two domains. You do run into organizations that have them on separate VLANs, but having them truly segmented and truly separated is incredibly rare. And that’s often done for the purposes of making life easier for day-to-day operations. It’s very hard to operate if you have a full air gap that you have to jump across every time you need to access those physical infrastructure components.

“It always did [impact the physical environment]. And this is one of the problems that you see in a lot of organizations whenever they’re doing their compliance documentation or security assessments. They like to create exceptions.

“Whenever they’re being rated against whatever framework they’re using, whether we’re dealing with HIPAA, NERC CIP, PCI, or something else, organizations love putting up exclusions and saying, ‘The only thing that’s in scope is this specific network segment,’ which just so happens to be the network segment where they have good security. Then they can ignore a lot of the operational and physical technologies that exist elsewhere in their organizations.

“And there’s a reason why they want to ignore it. Many times, patches and standard security technologies like EDR simply aren’t available for those systems. But excluding those systems from an assessment doesn’t make the risk disappear.

“Very, very few [organizations are testing resilience beyond simply restoring systems and data]. Once again, a lot of organizations like to create exceptions and exclusions whenever they’re being tested, evaluated, or going through compliance because they know that a lot of the legacy operational technology implemented in the physical world, things like HVAC systems and door controls, is often very old. Many of these systems have a lot of vulnerabilities. More importantly, they’re very, very expensive to upgrade and replace with up-to-date technology.

This gets into a question that I’m constantly asking our customers whenever we’re doing assessments with them. They’ll say, ‘Well, we don’t worry about this because it’s legacy technology.’ Okay. Having legacy technology is acceptable. Using the fact that it’s legacy technology as a shield to prevent it from ever being tested or ever being updated is not acceptable.

“If organizations know they have legacy technology, especially technology that directly interacts with the physical world, simply deciding that they don’t want to patch or update it is not acceptable. There needs to be a roadmap for when those technologies will be replaced and how the organization is going to replace them.

“But there’s this mentality that exists in a lot of organizations. ‘It’s physical. It makes the doors work.’ Or, ‘It’s physical. It makes the HVAC work.’ Basically, if it ain’t broke, don’t fix it.

“If you’re looking at what’s happening with security right now and how attackers are targeting these systems, it is very much broken.”

I hope that they not only address the means that these threat actors got in and deployed ransomware, but they tell everyone about it so that we learn from their mistakes.

LG Launches Life’s Good 2026

Posted in Commentary with tags on August 12, 2026 by itnerd

LG Electronics launched its 2026 Life’s Good campaign under the key message “Free up your mind.” The campaign explores how LG AI can help reduce the mental load of everyday life by quietly taking care of routine demands, creating more room for people to focus on what truly matters.

The campaign arrives at a time when people work harder than ever to keep everyday life running, yet increasingly struggle to switch off from its demands. According to LG survey findings, people spend nearly a quarter of the year burdened by mental load – the equivalent of 87 days a year. Mental load is the invisible burden of constant information, countless micro-decisions and everyday demands. For many people, mental load follows them home, occupying their minds even during moments of rest and recharge.

Building on previous campaign films such as We don’t make life good, you do (2024) and Less artificial. More human (2025), this year’s campaign centers on the growing mental load of modern life and making room for what makes life good.

Bringing the Campaign to Life

The campaign’s hero film follows a family stepping away from the mental load of everyday life for one evening. The film captures small but meaningful moments crowded out by everyday demands, from spontaneous conversations and shared meals to the simple pleasure of being fully present.

With this story, LG invites people to consider a simple question: what might you make room for if you could set your mental load down, even for just one evening?

The campaign’s message comes to life through product-focused films featuring LG WashTower, LG Styler, LG OLED and LG DUALCOOL. The films show how LG products can help reduce everyday mental load by quietly taking care of routine demands, freeing up people’s minds to enjoy life’s meaningful moments.

As part of the campaign, LG also offers an interactive experience designed to help people better understand their own mental load. By answering a set of questions, people can reflect on how much mental load they carry and what contributes to it. By making an invisible burden more visible, LG hopes people will free up their minds to experience Life’s Good.

The campaign is grounded in research that reveals just how deeply mental load has become embedded in everyday life.

The Scale of the Problem

Survey findings show that, on average, people experience 27 mental load interruptions during their waking hours.

The Human Cost

More than half (51%) of respondents said mental load stops them from sleeping well, while nearly half (49%) said it impacts their physical health.

The findings also revealed a key human truth: people work hard to stay organized, yet what they miss most is the freedom to be spontaneous. When asked what they would do if that weight were lifted, people did not reach for greater productivity or achievement. Instead, they spoke about getting lost in a book, spending unplanned time with loved ones and enjoying moments free from everyday responsibilities. 

The Role of Technology

The study found that unpaid responsibilities at home contribute more to mental load than paid work, highlighting the opportunity for household technology to make a meaningful difference.

Nearly three in four (73%) of respondents believe the right household technology could help reduce their mental load, with the strongest demand for solutions that proactively handle routine tasks without requiring constant attention.

The findings suggest a clear direction for technology: not simply to help people do more, but to quietly take care of everyday demands so they can spend less time managing life and more time living it. This insight aligns with LG’s Affectionate Intelligence vision and the campaign message: Free up your mind. Life’s Good.

To learn more about the campaign, visit www.lg.com/lifesgood.

Survey Methodology
Fieldwork: Conducted April 24–28, 2026 via Focaldata
Countries: US, UK and Australia
Age: 18–64
Sample size: 3,165 respondents (a minimum of 1,000 per market), nationally representative by age, gender and region

Note: Survey results reflect respondents’ perceptions and do not constitute clinical or scientific evidence of health benefits.

TELUS commits $2 million to support emergency wildfire relief across British Columbia

Posted in Commentary with tags on August 12, 2026 by itnerd

As devastating wildfires sweep across British Columbia, TELUS is responding with a $2 million commitment in network connectivity, data top-ups and bill credits for affected customers, and donations and support to charities. TELUS is directing resources toward affected First Nations and non profit organizations on the ground – including the Salvation Army BC and community food banks – while ensuring residents and first responders have access to the critical communications services they need to stay connected.

Maintaining connectivity and critical network operations

TELUS technicians are working tirelessly to keep network infrastructure operational under extreme conditions, including bringing in additional equipment like generators to keep cell sites running despite a lack of commercial power, and restoring damaged infrastructure as soon as it is safe to do so. This critical work ensures firefighters and other emergency personnel working on the frontlines of the fire remain connected, that residents facing possible evacuation orders have access to the latest information, and keeps families in touch during this difficult time. Our teams are coordinating with government agencies and relief organizations to provide connectivity at evacuation centres, command centres, and other critical locations, while deploying mobile connectivity solutions to fill gaps where fixed infrastructure has been damaged.

How TELUS is further supporting our customers and communities: 

  • Keeping families connected – Affected customers should not be worried about their bills. We’re automatically giving 50 GB of free wireless data to evacuated TELUS and Koodo postpaid mobility customers to keep them connected, and are crediting TELUS Internet, TV, home phone, and SmartHome Security bills for all evacuated households. We will continue to pause all home services billing for any customers who face an extended evacuation or displacement. Evacuated customers can call the dedicated line 1-855-889-7233 beginning Wednesday, August 12 for help with their TELUS services and re-entry plans. 
  • Delivering emergency support on the ground – TELUS team members and volunteers are delivering emergency kits with essential supplies, extra cell phones, and power bricks and charging cables to evacuation centres. We’re also working closely with evacuated First Nations communities to address their specific connectivity needs and offer our support including through emergency kits.
  • Supporting communities with direct funding – TELUS and the TELUS Friendly Future Foundation are committing $100,000 to affected First Nations including Okanagan Indian Band and Westbank First Nation and local charities providing immediate aid on the ground. This funding goes directly to trusted partners including Animal Lifeline Emergency Response Team Society, Canadian Disaster Animal Response Team Southwest BC Society, Central Okanagan Food Bank, Clinton Food Bank Society, Mamas for Mamas, Nicola Valley and District Food Bank Society, North Okanagan Friendship Centre Society, and Salvation Army British Columbia Division. 
  • How customers can help – TELUS customers can text DONATE to 41010 to donate $20, or redeem their TELUS Rewards points to support wildfire relief through the TELUS Friendly Future Foundation.
  • Providing wellbeing support – The TELUS Health Community Crisis Support line (1-844-751-2133) offers free, professional emotional support and/or resource referrals to anyone in Canada and is operational 24/7. 

A longstanding commitment to disaster response and recovery

For more than two decades, TELUS has invested over $300 million in emergency response and community recovery globally, including more than $125 million toward wildfire and flood relief across Canada in recent years. British Columbia is TELUS’ home, and when things are at their worst, British Columbians know they can count on the TELUS team to step-up and be at their best. TELUS is leveraging its technology, health capabilities, and remarkable team to help British Columbians stay safe, connected and supported throughout this wildfire emergency. 

11GB Of Data Exposed Says Cybernews

Posted in Commentary with tags on August 12, 2026 by itnerd

Cybernews researchers discovered an unprotected Talentsconnect database with nearly 11GB of live recruitment data, referencing 843 companies, including references associated with Siemens, Deutsche Bank, Vodafone, BASF, and EY. Talentsconnect is a company that specializes in direct-to-talent (D2T) matching platforms, which connect job seekers and employers. 

Here are the key findings:

  • The exposed database with over 5 million job listings included applicants’ names, emails, phone numbers, salary expectations, Base64-encoded CVs, or cover letters.
  • The database showed 335 plaintext credentials across 56 client integrations. One belonged to the waste management company Remondis, with username and password information potentially providing access to their recruitment portal.
  • Researchers found 80 plaintext credentials for FFG Prescreen, a background-check tool used in hiring. These are intended to allow candidates to modify submissions, but malicious actors could exploit them to post fake jobs, alter details, or delete data. 
  • Exposed data contained AWS Secrets Manager references for such companies as Siemens, Vantage Towers (Vodafone), Hornbach, ARAG, Computacenter, Peek & Cloppenburg, and UniCredit.

“This is a single point of failure sitting behind the hiring pipelines of hundreds of major European employers. Anyone on the internet could have read the entire client roster, harvested candidate personal data, or, because access was read/write, altered or injected data. For example, posting fake job ads under real company names, submitting fraudulent applications with malicious attachments, or deleting listings,” our researchers explained.

Talentsconnect closed the database after researchers disclosed the issue to the company, and the information is no longer publicly accessible. Cybernews researchers found no evidence that unauthorized users accessed the data while it was still leaking. 

For more information, here’s the full report:

https://cybernews.com/security/talentsconnect-hr-database-data-leak

Park Place Technologies Achieves Additional “Powered by Nutanix: Verified Solutions” Badge

Posted in Commentary with tags on August 12, 2026 by itnerd

Park Place Technologies today announced it has achieved its fourth “Powered by Nutanix: Verified Solutions” badge. The badge reflects the company’s commitment to designing and delivering services aligned with Nutanix prescribed best practices and architectural standards.  

Through the “Powered by Nutanix: Verified Solutions” program, Park Place Technologies’ Sovereign Cloud offering has been reviewed against Nutanix-defined technical and operational criteria for alignment with platform best practices. As data sovereignty moves up the boardroom agenda, this offering responds to a clear market need: cloud models that give organizations the freedom to innovate while maintaining greater control over data location, governance, and operational risk. 

It follows the successful achievement of our previous “Powered by Nutanix: Verified Solutions” badges for Dedicated Private Cloud, Multi-Tenant Private Cloud, and Disaster Recovery as a Service solutions, reflecting a sustained, scalable commitment to delivering secure, resilient, and enterprise-grade cloud and IaaS services to customers. 

These recognitions are designed to provide customers with confidence that their cloud services are built on Nutanix technology and aligned with defined design and operational guidelines.  

The “Powered by Nutanix: Verified Solutions” program empowers service providers to deliver comprehensive, market-ready cloud offerings built on the Nutanix Cloud Platform. These solutions provide a modern architecture that is designed to support performance, security, and scalability requirements and the flexibility to support virtual machines, containers, and AI workloads, all managed via a single, unified control plane. 

With four “Powered by Nutanix: Verified Solutions” badges, Park Place Technologies has achieved a key milestone that underscores its commitment to delivering validated, enterprise-grade cloud solutions. 

The announcement comes at a time when many organizations are reassessing their virtualization and cloud strategies. As enterprises evaluate options for hybrid cloud, sovereign cloud requirements, and alternative virtualization platforms, Park Place Technologies provides customers with a range of deployment models supported by independently verified solutions. This enables businesses to align infrastructure decisions with operational, regulatory, and commercial objectives while reducing transformation risk.

The Park Place xCloud platform, powered by Nutanix technology, offers customers flexible deployment options spanning dedicated private cloud, multi-tenant cloud, Disaster Recovery as a Service, and sovereign cloud. This approach allows organizations to place workloads where they make the most sense from a performance, security, compliance, and cost perspective. 

The latest validation further strengthens the longstanding relationship between Park Place Technologies and Nutanix and highlights the organizations’ shared commitment to helping customers modernize infrastructure while maintaining operational resilience and business agility. 

The “Powered by Nutanix: Verified Solutions” badge reflects evaluation against Nutanix program criteria and does not constitute a warranty, endorsement, or guarantee of performance, security, or regulatory compliance by Nutanix.  

MCP Servers Are the New Software Supply Chain Risk

Posted in Commentary with tags on August 12, 2026 by itnerd

New research from ASSET Research Group shows malicious MCP servers can split data-exfiltration instructions across multiple tool calls, letting AI coding agents piece together and leak SSH keys, source code, and customer data even when a single blunt request would get refused. No CVE yet, but the technique worked against nearly every major model tested once the request was fragmented.

The Hacker News has a good writeup about this here: Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

Justin Beals, CEO and Founder of Strike Graph, sees this as a governance failure, not a model failure, and has a sharp take on why treating MCP servers as trusted extensions rather than unverified third parties amounts to repeating a twenty-year-old mistake with software dependencies:

“This is the AI supply chain problem in miniature. Everyone is watching for one bad instruction. Nobody is watching for four good ones that add up to a bad outcome.

The real failure here is trust. Once a developer connects an MCP server, that server is treated like a trusted extension of the agent instead of an unverified third party. That is the same mistake we made with software dependencies for twenty years, just moved one layer up the stack.

Organizations need to start governing AI agents the way they govern any other identity with access to sensitive systems. That means verifying MCP servers before connecting them, not after something goes missing. Treat every tool result as untrusted data until proven otherwise. The agents are only going to get more capable and more connected. The organizations that survive this next phase will be the ones who assumed the server on the other end was hostile from day one.”

If you think you are exposed, then this is your wake up call to take action. Because if you don’t take action, pwnage is inevitable.

Guest Post: By Is the National Vulnerability Database still meeting the needs of defenders, or has the volume and complexity of modern vulnerabilities outgrown the current model?

Posted in Commentary with tags on August 12, 2026 by itnerd

By Tyler Reguly, Associate Director of Security R&D at Fortra

Is the National Vulnerability Database still meeting the needs of defenders, or has the volume and complexity of modern vulnerabilities outgrown the current model?

A more interesting question might be “has the National Vulnerability Database ever actually met the needs of defenders?” The only valuable information provided by NVD in the past has been CVSS information, and I’ll leave it up to the individual to decide if CVSS has ever been “valuable.” The other information provided by NVD was CPE data, and it has long been known that if you were using NVD CPE data for vulnerability detection, you were not getting accurate or reliable vulnerability detection.

What role should AI play in vulnerability discovery, prioritization, and remediation, and where is human oversight still necessary?

AI is playing a pretty strong role in vulnerability discovery with source code. That is the perfect application in my mind. We’re seeing the results with the size of the patch drops from companies like Microsoft and Oracle. When you let AI explore your source code, you fix all sorts of obscure vulnerabilities.

At the same time, we’re climbing a hill right now, discovering all the obscure issues that were either too buried, too complex, or too restrictive to be sought out by human researchers. Once these issues are all discovered and AI tools are run on new code bases, problems will be fixed before they are shipped, and those aren’t vulnerabilities and don’t require CVEs, so we’ll start to go back down the hill, and everything will normalize once again.

When it comes to prioritization, anything I’ve seen out of AI so far has been “good enough.” I’d call it on par with a junior analyst. I haven’t seen it perform prioritization as well as a VM expert.

Finally, remediation… I would not trust the remediation of vulnerabilities in critical systems to AI just yet. There’s no coming back from that. There’s a reason human-in-the-loop is still so critical, and as soon as AI starts remediating vulnerabilities, you lose the human oversight. In test environments, sure. In labs, definitely. In production systems… not yet.

What risks could organizations face if they rely too heavily on AI-generated vulnerability analysis and prioritization?

The risk is overlooking real risk. AI prioritization tends to rely on knowns and treats prioritization like a science. CVSS was used for years as a prioritization metric (they finally updated their documentation to advise against this, but people still use it that way). Prioritization is still, in my mind, an art. There’s a gut feeling that goes along with all the variables. You can get close (and some companies have interesting algorithms in the space), but you still have the art of it all that plays a major role in my mind.

How should security teams adapt their vulnerability management programs as attackers increasingly use AI to identify and exploit vulnerabilities faster?

Remember that vulnerability management is just one of the pillars of good cybersecurity hygiene. If you are layering it with FIM, EDR, and proper system hardening, then you’ve got a solid foundation. Yes, you have to make adjustments in some places, but remember that patches fix multiple vulnerabilities, that few vulnerabilities are ever actually exploited, and that known active exploitation increases risk. From there, a few simple choices will keep your VM program running smoothly.

If NIST successfully modernizes the NVD, what capabilities or improvements would have the biggest impact on organizations over the next five years?

First, we should talk about what modernization looks like. It’s better application of CPEs and CWEs. It’s inclusion of EPSS data alongside CVSS data. It’s providing better remediation guidance and a more structured list of external resources. My biggest fear is that OVAL will be seen as a useful standard and further adopted or that CPE data will continue to be less than complete. I’m not saying that everything needs better enrichment, but critical vulnerabilities need to be completely enriched and pulled out and better accessed. We need to deprioritize CVSS data. If we can start to make changes and improvements, then we may see a place where organizations can actually start to look for guidance. Right now, I would say that CISA Kev and CVE.org are a better combination of data than NVD, and I’m not sure anyone really needs to go to NVD. 10 years ago, NVD was at the top of the pecking order, and it would be interesting to see them return to that status.