• About Us
  • Disclaimer
  • Contact Us
  • Privacy Policy
Sunday, July 26, 2026
mGrowTech
No Result
View All Result
  • Technology And Software
    • Account Based Marketing
    • Channel Marketing
    • Marketing Automation
      • Al, Analytics and Automation
      • Ad Management
  • Digital Marketing
    • Social Media Management
    • Google Marketing
  • Direct Marketing
    • Brand Management
    • Marketing Attribution and Consulting
  • Mobile Marketing
  • Event Management
  • PR Solutions
  • Technology And Software
    • Account Based Marketing
    • Channel Marketing
    • Marketing Automation
      • Al, Analytics and Automation
      • Ad Management
  • Digital Marketing
    • Social Media Management
    • Google Marketing
  • Direct Marketing
    • Brand Management
    • Marketing Attribution and Consulting
  • Mobile Marketing
  • Event Management
  • PR Solutions
No Result
View All Result
mGrowTech
No Result
View All Result
Home Technology And Software

CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats

Josh by Josh
June 10, 2026
in Technology And Software
0
CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats


With new generations of AI models fueling both rapid software vulnerability discovery and the potential for faster exploitation by malicious hackers, the United States Cybersecurity and Infrastructure Security Agency released a new directive on Wednesday that requires more rapid and efficient software patching by federal civilian agencies. The “binding operational directive” (BOD) lays out a rubric for how quickly bugs must be fixed based on four assessments of urgency, with a turnaround time in critical cases of just three days.

Chris Butera, CISA’s acting executive assistant director for cybersecurity, told reporters on Wednesday that the goal of the directive is to help agencies prioritize, so they can address the most problematic vulnerabilities first while taking more time to remediate bugs that pose a less-pressing risk. The directive comes as private companies and governments have been scrambling to assess the extent of the cybersecurity reckoning that AI vulnerability and exploit development capabilities could unleash.

“Prioritizing IT and security operations attention on the most at-risk assets is particularly important now given advancements in artificial intelligence, which allow threat actors to find and exploit vulnerabilities in [federal] assets,” Butera said on Wednesday. “Defenders cannot afford to take weeks to patch systems that can be autonomously exploited en masse.”

The CISA directive’s criteria for evaluating patch urgency includes looking at whether a vulnerability is in a system that is publicly exposed, whether the bug is listed in CISA’s Known Exploited Vulnerabilities Catalog, whether an attacker could automate all of the steps to exploit the vulnerability, and how much access an attacker would get to the target if the bug were exploited. A vulnerability where all four points apply must be fixed within three days, according to the new directive, and the agency must also execute a “forensic triage” process to determine whether systems have already been compromised.

The directive supersedes two previous CISA orders related to patching timelines for urgent vulnerabilities—one from 2019 and one from 2021. Those established a framework in which the most critical bugs had to be patched within 15 days of detection and another class of high-urgency vulnerability had to be remediated within 30 days. And both encouraged faster patching for severe flaws when possible. Even before the AI era, in 2021, CISA wrote that “threat actors are extremely fast to exploit their vulnerabilities of choice: of those 4% of known exploited [vulnerabilities], 42% are being used on day 0 of disclosure; 50% within 2 days; and 75% within 28 days.”

US federal cybersecurity has improved significantly over the past decade, but it still often lags, thanks to funding shortfalls and competing priorities. CISA’s Butera said that the agency developed the new assessment rubric and the directive more broadly with these limitations in mind. He noted, for example, that the three-day deadline for the most urgent vulnerabilities isn’t, say, 24 hours, because such a short timeframe would not be feasible for most agencies.

New AI capabilities are already changing the landscape of vulnerability detection and bug hunting. And as this spurs new urgency in patching, many researchers have started to conclude, essentially, that no amount of patching will be enough—and that the software development community globally must work to adopt new, architectural or systemic approaches to invalidating whole classes of vulnerabilities at a time.

“CISA’s directive has its heart in the right place, but it only tackles half the challenge,” says Emily Long, CEO of the cloud security firm Edera. “If your architecture doesn’t limit what an attacker can reach after a breach, you’re just running faster on the same treadmill. Patching will always be important, but we should be talking more about containment by design.”

CISA’s Butera seemed to acknowledge this evolution on Wednesday. The new directive “is an initial step to counter the increased capabilities of emerging AI models,” he says. “Yet there is still more work to do.”



Source_link

READ ALSO

The Best Backpacking Sleeping Pads, Tested on the Trail (2026)

Monday.com is the latest tech company to blame AI for layoffs — here are 20 others

Related Posts

The Best Backpacking Sleeping Pads, Tested on the Trail (2026)
Technology And Software

The Best Backpacking Sleeping Pads, Tested on the Trail (2026)

July 26, 2026
Monday.com is the latest tech company to blame AI for layoffs — here are 20 others
Technology And Software

Monday.com is the latest tech company to blame AI for layoffs — here are 20 others

July 26, 2026
Anthropic launches Claude Opus 5, a cheaper AI model for coding, agents and enterprise workflows
Technology And Software

Anthropic launches Claude Opus 5, a cheaper AI model for coding, agents and enterprise workflows

July 25, 2026
EU Says TikTok Hasn’t Done Enough To Ensure Minors’ Safety
Technology And Software

EU Says TikTok Hasn’t Done Enough To Ensure Minors’ Safety

July 25, 2026
Cricut Explore 5 vs. Siser Romeo: Choosing the Right Smart Cutting Machine (2026)
Technology And Software

Cricut Explore 5 vs. Siser Romeo: Choosing the Right Smart Cutting Machine (2026)

July 25, 2026
I tried out OpenAI’s new AI keypad — which will be fun for some coders and slightly mystifying to everyone else
Technology And Software

I tried out OpenAI’s new AI keypad — which will be fun for some coders and slightly mystifying to everyone else

July 25, 2026
Next Post
Top 10 SEO Reseller Packages for Agencies

Top 10 SEO Reseller Packages for Agencies

POPULAR NEWS

Trump ends trade talks with Canada over a digital services tax

Trump ends trade talks with Canada over a digital services tax

June 28, 2025
15 Trending Songs on TikTok in 2025 (+ How to Use Them)

15 Trending Songs on TikTok in 2025 (+ How to Use Them)

June 18, 2025
Communication Effectiveness Skills For Business Leaders

Communication Effectiveness Skills For Business Leaders

June 10, 2025
App Development Cost in Singapore: Pricing Breakdown & Insights

App Development Cost in Singapore: Pricing Breakdown & Insights

June 22, 2025
Comparing the Top 7 Large Language Models LLMs/Systems for Coding in 2025

Comparing the Top 7 Large Language Models LLMs/Systems for Coding in 2025

November 4, 2025

EDITOR'S PICK

GM isn’t ready to rip off the CarPlay/Android Auto band-aid quite yet

GM isn’t ready to rip off the CarPlay/Android Auto band-aid quite yet

October 28, 2025
Ex-Google X trio wants their AI to be your second brain — and they just raised $6M to make it happen

Ex-Google X trio wants their AI to be your second brain — and they just raised $6M to make it happen

September 10, 2025
Is Silicon Valley Losing Its Influence on DC?

Is Silicon Valley Losing Its Influence on DC?

July 29, 2025
We Found 265 of the Best Prime Day Deals Still on for 2025: Up To 55% Off

We Found 265 of the Best Prime Day Deals Still on for 2025: Up To 55% Off

October 9, 2025

About

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

Follow us

Categories

  • Account Based Marketing
  • Ad Management
  • Al, Analytics and Automation
  • Brand Management
  • Channel Marketing
  • Digital Marketing
  • Direct Marketing
  • Event Management
  • Google Marketing
  • Marketing Attribution and Consulting
  • Marketing Automation
  • Mobile Marketing
  • PR Solutions
  • Social Media Management
  • Technology And Software
  • Uncategorized

Recent Posts

  • From influencer feeds to pop-up cafes: Tips for expanding comms beyond the screen
  • The Best Backpacking Sleeping Pads, Tested on the Trail (2026)
  • 3 Things We Loved from Laneige’s Wonder Lab Pop-up in Orlando
  • Monday.com is the latest tech company to blame AI for layoffs — here are 20 others
  • About Us
  • Disclaimer
  • Contact Us
  • Privacy Policy
No Result
View All Result
  • Technology And Software
    • Account Based Marketing
    • Channel Marketing
    • Marketing Automation
      • Al, Analytics and Automation
      • Ad Management
  • Digital Marketing
    • Social Media Management
    • Google Marketing
  • Direct Marketing
    • Brand Management
    • Marketing Attribution and Consulting
  • Mobile Marketing
  • Event Management
  • PR Solutions