Recent guidance establishes best practices for development of coordinated vulnerability disclosure (CVD) programs. This comes as both public and private organizations are grappling with the prospect of near-term "machine speed" discovery of vulnerabilities by attackers wielding AI tools, and looking at potential major overhauls to their remediation and reporting processes.
A bill establishing a new vulnerability disclosure program for federal contractors has passed the House, and will now move on to the Senate to be reviewed by the Committee on Homeland Security and Governmental Affairs.
Proposed EU Cyber Resilience Act includes a vulnerability disclosure requirement that would have all manufacturers report to the government within 24 hours of first discovered exploitation. In most cases, this would mean disclosing before the vulnerability has been mitigated.
Tenable CEO cites reports from several cybersecurity firms that indicate Microsoft is not being timely enough with its vulnerability disclosures and sometimes has a "dismissive" attitude.
New vulnerability disclosure rules announced by the Chinese government have raised the prospect of "zero-day hoarding," as anything discovered in the country must now be reported to the CCP and to no one else (in most cases).





