National Vulnerability Database
PulseAugur coverage of National Vulnerability Database — every cluster mentioning National Vulnerability Database across labs, papers, and developer communities, ranked by signal.
4 day(s) with sentiment data
-
Critical macOS Screen Sharing flaw exploited for Monero cryptojacking
A critical vulnerability in macOS Screen Sharing, identified as CVE-2026-65400, is being actively exploited by attackers to gain remote root access on Macs. The flaw allows unauthorized authentication, leading to the in…
-
NIST plans AI-era overhaul of National Vulnerability Database amid funding concerns
The National Institute of Standards and Technology (NIST) is initiating a project to re-envision its National Vulnerability Database for the age of artificial intelligence. This overhaul aims to create a new blueprint f…
-
AI accelerates discovery rate, especially for cyber vulnerabilities · METR analysis
A new analysis from METR suggests that the rate of publicly disclosed discoveries has accelerated, particularly in the realm of cybersecurity vulnerabilities. While AI's contribution is evident in some areas, such as a …
-
NIST flags LLM threat to National Vulnerability Database processes · 2 sources tracked
The National Institute of Standards and Technology (NIST) has expressed concern regarding the evolving capabilities of large language models (LLMs) in discovering and exploiting software vulnerabilities. NIST believes t…
-
Generative AI tool AegisShield democratizes cyber threat modeling
Researchers have developed AegisShield, a generative AI tool designed to automate and simplify cyber threat modeling, particularly for organizations with limited resources. The tool integrates the STRIDE framework and M…
-
AI discovers vulnerabilities faster than humans can fix them
AI is discovering software vulnerabilities at a rate far exceeding human capacity for remediation. A recent analysis indicates that over 90% of AI-identified vulnerabilities are valid, yet only 6% are being patched. Thi…
-
China flags 'backdoor' vulnerabilities in Anthropic's Claude Code
China's National Vulnerability Database has issued a warning regarding Anthropic's Claude Code, alleging that certain versions contain security backdoor vulnerabilities. The government claims a monitoring mechanism with…
-
China flags 'backdoor' risks in Anthropic's Claude Code; AI firm responds
China's Ministry of Industry and Information Technology (MIIT) has issued a warning regarding security risks associated with Anthropic's Claude Code AI tool, citing a "backdoor" that could transmit sensitive user data. …
-
New knowledge graph links software vulnerabilities to attack behaviors
Researchers have developed a new knowledge graph, CVE-TTP KG, designed to link software vulnerabilities with attacker tactics and techniques. This system aims to improve threat interpretation by connecting information f…
-
Security expert warns against AI agents for alert overload
A security expert argues against deploying AI agents to manage the overwhelming volume of cybersecurity alerts, particularly in the wake of the National Vulnerability Database (NVD) pipeline collapse. The expert emphasi…
-
CyberGraph RAG uses TigerGraph to improve LLM cybersecurity analysis
Researchers developed CyberGraph RAG, a system designed to improve how large language models handle cybersecurity data by leveraging graph databases. Unlike traditional RAG which struggles with the relational nature of …
-
AI security tools may hallucinate vulnerabilities from training data
Large language models used for AI-assisted vulnerability discovery can falsely present information from their training data as novel findings. This occurs because LLMs cannot distinguish between recalling information ab…
-
CyberSecQwen-4B: Small, specialized model offers local defense for cybersecurity
A new, specialized language model named CyberSecQwen-4B has been developed for defensive cybersecurity tasks. This model is designed to be small, runnable locally, and handle sensitive data without needing external APIs…
-
New AI tool automates threat modeling for cyber-physical systems
Researchers have developed SMSI, a novel pipeline that automates threat modeling for cyber-physical systems. This system translates architectural models into actionable security control recommendations by mapping system…
-
FixV2W uses knowledge graph embeddings to improve CVE-CWE mapping accuracy
Researchers have developed FixV2W, a novel method to enhance the accuracy of mappings between Common Vulnerabilities and Exposures (CVE) and Common Weakness Enumeration (CWE) entries. This approach utilizes knowledge gr…