LIVE · cybersecurity feed
Live wire
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructureOpenAI locks down Astra over potential critical cyber capabilitiesCritical Flaws Discovered in Belgian eID Software Used by 2 Million PeopleSecurity Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITIONWebmail CSS Attacks Expose a New Risk for AI-Powered Email ToolsMetabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
vulnerability

NATO and an AI startup can now name and track software vulnerabilities

NATO’s cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws, the European Union Agency for Cybersecurity announced last week. The NATO Cyber Security Centre, part of the NATO Communications and Information Agency, and AISLE, a cybersecurity company […] The post NATO and an AI startup can now nam

zeroday.news ·

The NATO Cyber Security Centre and the AI-driven cybersecurity firm AISLE have been designated as CVE Numbering Authorities (CNAs) under the European Union Agency for Cybersecurity (ENISA) Root. This designation allows both entities to assign unique CVE (Common Vulnerabilities and Exposures) identifiers to newly discovered software vulnerabilities, streamlining the process of tracking and communicating security flaws.

The NATO Cyber Security Centre, which is part of the NATO Communications and Information Agency, will now be able to assign CVE IDs for eligible vulnerabilities found within the NATO enterprise. This capability is expected to enhance consistency in vulnerability tracking and facilitate faster information sharing with trusted partners across the alliance. The center's responsibilities include safeguarding NATO's networks, monitoring for threats, and coordinating incident responses.

AISLE, a cybersecurity company with offices in San Francisco and Prague, has a more specific authorization. Its CNA designation primarily covers vulnerabilities discovered in its own products. This allows the company to publish identifiers directly without needing to wait for a third-party authority to process a request. The company's co-founder noted that this step is foundational for coordinated disclosure, emphasizing the importance of applying the same security standards to one's own products as expected from others. Separately, AISLE researchers have reportedly disclosed hundreds of vulnerabilities in widely used open-source software, including OpenSSL, Linux, Apache, and OpenEMR, coordinating each through the relevant project's authority.

ENISA's chief cybersecurity and operations officer, Hans de Vries, highlighted that the expansion of CNAs, particularly with the addition of NATO and AISLE, reflects the evolving landscape of cybersecurity. He specifically cited the emergence of Frontier AI models and their impact on vulnerability discovery and exploitation as a key factor driving the need for robust vulnerability management infrastructure. ENISA's role, he stated, contributes to building a more globally representative, resilient, and scalable ecosystem for vulnerability identification.

With these additions, the ENISA Root now oversees twenty CNAs. Twelve of these were brought in directly by ENISA, while eight transitioned from the MITRE Root, which has managed the CVE program's daily operations for over two decades. The CVE program itself, run by CISA, faced potential disruption in April 2025 but was sustained by an 11-month contract extension. In the interim, several alternative vulnerability databases have emerged from European nonprofits and private entities, aiming to improve coordination in tracking, disclosing, and patching vulnerabilities. For example, The Computer Incident Response Center Luxembourg (CIRCL) recently launched the Global CVE Allocation System (GCVE) as an alternative to the existing CVE program.

vulnerabilityaicloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomwarecritical

FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure

The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.

vulnerability

OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users

OpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, incident response, and remediation. [...]

vulnerability

Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is keeping security from becoming the bottleneck, or worse, losing control of what gets shipped.

security

Everything we launched during Agents Week

Our latest Agents Week has come to a close. Here’s a recap of all the announcements we made, from Wallets to Radar.

ransomware

New StormEncryptor ransomware used by former Medusa affiliate

A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]

phishing

North Korean spies are running local LLMs to cause AI mischief

Kimsuky's phishing attacks get an AI boost