- Cybersecurity Docket
- Posts
- NIST Narrows the Priorities of its National Vulnerability Database
NIST Narrows the Priorities of its National Vulnerability Database
Plus, new guidebook for corporate boards addresses cyber-risk oversight

SPONSORED BY

Good morning! Here’s what’s up.

People
Caroline Bellamy, former Chief Data and AI Officer at the U.K. Ministry of Defense, has joined Strider Technologies as executive director.

Clips ✂️
NIST narrows scope of CVE analysis to keep up with rising tide of vulnerabilities
The federal agency tasked with analyzing security vulnerabilities is overwhelmed as it and other authorities struggle to keep pace with a flood of defects that grows every year. The National Institute of Standards and Technology announced Wednesday that it has capitulated to that deluge and narrowed the priorities for its National Vulnerability Database.
NIST said it will only prioritize analysis for CVEs that appear in the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerabilities catalog, software used in the federal government and critical software defined under Executive Order 14028.
The federal agency’s goal with the change is to achieve long-term sustainability and stabilize the NVD program, which has encountered previous challenges, notably a funding lapse in early 2024 that forced NIST to temporarily stop providing key metadata for many vulnerabilities in the database.
The agency still hasn’t cleared a backlog of unenriched CVEs that built up during that pause and grew since then.
New Guide for Corporate Boards Addresses the Rising Stakes for Cyber-Risk Oversight
Cyber risk is a defining test of board oversight. Yet many directors are still working to keep pace with a threat landscape that is accelerating in scale, sophistication, and consequence.
More than 600 million cyberattacks are tracked each day, and cybercrime losses are projected to approach $20 trillion annually in the coming years, according to research cited in the fifth edition of the Director's Handbook on Cyber-Risk Oversight, which was released [April 16]. At the same time, regulators, investors, and stakeholders are raising expectations for how boards oversee cybersecurity strategy, disclosure, and resilience.
The latest edition of the Handbook sets out six core principles to guide board oversight of cyber risk, along with practical tools to help directors engage with management, assess organizational preparedness and oversee incident response. Developed by National Association of Corporate Directors® (NACD®) and the Internet Security Alliance (ISA), the resource helps corporate boards strengthen their governance and oversight of cybersecurity risk.
Ghost breaches: How AI-mediated narratives have become a new threat vector
A company wakes up to a news story claiming it has suffered a major data breach. The details are specific, technical and convincing. But the breach didn’t happen. No systems were compromised. No data was taken. A language model generated the entire story, filling in plausible details from scratch. And before the company can figure out what’s going on, a reporter at a reputable outlet picks up the story and requests comment. Within hours, the company is drafting statements and mobilizing its communications team to address a fictional event.
A second incident begins with something real. Years earlier, a company had suffered a genuine breach that received wide media coverage. The incident was investigated, resolved and closed. Then one of the outlets that originally reported on it redesigned its website. Old articles received new URLs and updated timestamps, and search engines re-indexed them as fresh content. AI-powered news aggregators picked up the signal and flagged it as a developing story. The company found itself fielding inquiries about an incident that had been resolved years before.
Rethinking Cybersecurity for AI Speed in the Mythos Era
Cybersecurity teams must adapt to machine-speed threats in the age of Anthropic's Claude Mythos - a new artificial intelligence model that uncovers vulnerabilities but could lead to a flood of rapid exploits. While AI tools supercharge attackers, they don't dramatically increase vulnerability discovery and patching processes, said Equifax CTO Jamil Farshchi.
Legacy approaches to IT services fail under these conditions, with some companies typically taking at least two months to patch vulnerabilities, while attackers can exploit flaws within hours. Farshchi, who previously served as CISO at Equifax, said teams need to move beyond patch reliance and adopt prioritized risk models that anticipate real controls, attack paths and business impact - rather than static scoring systems.
"That old model just doesn't work anymore. It just doesn't, and so I think the organizations that are relying on it are already on their heels, and I think it's just going to continually get worse as these new models arrive," Farshchi said.
Shiny Hunters hits Alert 360, leaks 2.5M records
Alert 360, the fifth-largest home and business security systems provider in the US, has been claimed by ShinyHunters, along with 2.5 million records allegedly dumped on the dark web after the company refused to pay a ransom demand.
ShinyHunters listed the Oklahoma-based 24/7 monitoring and surveillance firm on its victim blog Thursday, and provided a download link to the purported 10GB of compressed data.
“Over 2.5M records containing PII and other internal corporate data have been compromised,” the cybercriminals wrote in the entry.
ShinyHunters also claimed that it dumped the stolen files after communications between the two parties broke down.
…
The group claims that by the time an organization is listed on the site, it is too late – except in rare cases – meaning unless the company reverses course and agrees to fork over the ransom demand.
Ransomware Hits Automotive Data Expert Autovista
Automotive analysis and data company Autovista is scrambling to restore its services across Europe and Australia after falling victim to a ransomware attack.
Autovista has engaged external experts and is currently working to contain the attack, the company said in a Thursday morning incident notice.
“We are responding to a ransomware incident affecting certain Autovista systems in Europe and Australia. We appreciate our customers’ patience as we work to respond to this incident in a disciplined manner,” Autovista said.
The company also emphasized its focus on securely restoring its applications as soon as possible but could not provide a firm timeline.
“We are currently working with third-party cybersecurity experts to investigate the incident. This investigation process is ongoing and will take time to complete,” Autovista said.
The company promised additional details on the incident and on when services will be restored as its investigation advances.

SPONSORED BY

Incident Response Forum D.C. 2026 is set for Wednesday, April 22, 2026 at the historic Mayflower Hotel in Washington, D.C.!
Incident Response Forum is the only conference of its kind, bringing together hundreds of cybersecurity and incident response attorneys, in-house counsel and compliance executives, and other top professionals in the field. It is focused solely on the field of Incident Response – the work that begins after a data breach that has quickly become the fastest growing practice area at law firms and consulting firms – and is geared specifically for the legal and compliance professionals who have emerged as critical players during the aftermath of a data security incident.
Join us in person or tune in virtually to hear from nearly 50 luminaries in the incident response field—including senior officials from the DOJ and FBI, and lawyers and consultants from the best firms and in the world.
👉 Please register here.
