CISA Releases New KEV Nomination Form for Vendors and Researchers

www.news4hackers.com-cisa-releases-new-kev-nomination-form-for-vendors-and-researchers-cisa-releases-new-kev-nomination-form-for-vendors-and-researchers

The New KEV Catalog Submission Process

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has introduced a new web-based form for submitting knowledge gaps in externally validated (KEV) vulnerabilities.

What is the KEV Catalog?

The KEV catalog lists vulnerabilities that have been confirmed as exploited in the wild, providing valuable information for organizations seeking to protect themselves against these threats.

“The KEV catalog was established in November 2021, with CISA having since gradually expanded it.”

New Submission Process

CISA has opened up the submission process, allowing external stakeholders to contribute to the catalog’s growth by submitting vulnerabilities that meet specific criteria, including assignment of a Common Vulnerabilities and Exposures (CVE) identifier, confirmation of exploitation in the wild, and provision of remediation guidance.

Organizations and individuals can also continue to submit vulnerabilities via email at vulnerability@cisa.dhs.gov if they prefer.

“This new submission mechanism is expected to enhance the effectiveness of the KEV catalog, ultimately contributing to the security and resilience of the nation’s critical infrastructure,” said CISA’s Acting Executive Assistant Director for Cybersecurity, Chris Butera.

Collaboration and Growth

CISA has collaborated with various stakeholders to grow the KEV catalog and address concerns surrounding the speed of additions, and this new submission mechanism is expected to further enhance the agency’s ability to identify, validate, and disseminate critical threat information efficiently.



About Author

en_USEnglish