:

NIST STOPS RATING LOW-PRIORITY SECURITY FLAWS

INDUSTRY DESK1 MIN READ
SUN, APR 19, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

The National Institute of Standards and Technology will cease assigning severity scores to lower-priority vulnerabilities, citing mounting workload pressures from surging submission volumes.

NIST's decision reflects the agency's resource constraints as the vulnerability landscape expands. The organization will focus its rating efforts on higher-priority flaws while deprioritizing less critical issues. The move addresses a practical bottleneck: security researchers and vendors have increasingly submitted vulnerabilities for official severity assessment, outpacing NIST's capacity to evaluate them. By narrowing its scope, the agency aims to maintain quality and timeliness for critical vulnerability ratings. Organizations relying on NIST severity scores for lower-tier vulnerabilities may need alternative assessment methods or rely on vendor guidance. This shift could accelerate adoption of other vulnerability rating systems or internal assessment frameworks. The decision highlights ongoing challenges in vulnerability management infrastructure as cyber threats proliferate and disclosure practices evolve.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The ShinyHunters extortion group has published sensitive data from nearly 13 million Carhartt customer accounts stolen earlier this month, according to data breach notification service Have I Been Pwned.

8H AGOSecurity Desk

A Russian-speaking ransomware gang called Aur0ra exploited SpaceX's Cursor AI coding assistant to breach at least seven companies between mid-April and late May, according to security firm Gambit Security.

8H AGOAI Desk

Americans are systematically targeting and disabling Flock Safety cameras across the country in a decentralized protest movement. The surveillance devices face everything from vandalism to theft as public opposition intensifies.

16H AGOIndustry Desk

The US Justice Department has dismantled online infrastructure used by Chinese state-sponsored hackers targeting NASA, the Federal Reserve, and the Senate. The action represents a coordinated effort to disrupt cyber operations against American government agencies and critical infrastructure.

16H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.