The US National Institute for Standards and Technology wants to modernize its National Vulnerability Database to embrace AI-powered vulnerability research

The U.S. National Institute of Standards and Technology (NIST) has initiated a public consultation to modernize its National Vulnerability Database (NVD), aiming to integrate artificial intelligence (AI) and automation workflows. This effort, announced in a Request for Information (RFI) published in the Federal Register on August 12, seeks to adapt the NVD to a cybersecurity landscape increasingly influenced by AI and the demand for machine-consumable security data.
NIST is soliciting "forward-looking perspectives, practical recommendations, and innovative models" to enhance the NVD's scalability, automation, interoperability, transparency, and overall utility. The agency acknowledges that traditional vulnerability management approaches, which rely on periodic scanning, static prioritization, and manual remediation, are becoming insufficient given the rapid pace of technological change, the proliferation of AI-enabled tools, and the growing volume of vulnerabilities.
Currently, the NVD automatically ingests Common Vulnerabilities and Exposures (CVE) records within approximately an hour. Following this, human analysts enrich these records by adding critical information such as severity scores and details about affected product versions. These enriched records are then made accessible via the NVD website and various automated tools.
The RFI highlights both the opportunities and risks presented by AI in vulnerability management. While AI offers potential for modernizing the process, NIST also recognizes the threat of AI-assisted vulnerability discovery and exploitation. The goal is to evolve the NVD into a system that is "continuous, contextual, and automated," enabling it to effectively respond to emerging threats and organizational priorities.
The RFI includes 30 specific questions designed to gather stakeholder input on necessary changes to the NVD and how AI tools and automation workflows should be integrated. Stakeholders have until October 13 to submit their responses.
Industry experts recognize the potential of AI in vulnerability discovery, particularly for analyzing source code to identify obscure vulnerabilities that human researchers might miss. However, there is also caution regarding the use of AI for remediation, especially in critical or production systems. While AI-driven remediation might be suitable for test environments, the consensus emphasizes the continued necessity of human oversight in production systems.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.