Skip to main content
hamster.news

Loading...

Infosec NewsGoogle News Cybersec
Sep 2, 2026, 03:18 AM
Read Original

CISA vulnerability directive designed to ‘buy back time’ against hackers - Federal News Network

CISA vulnerability directive designed to ‘buy back time’ against hackers - Federal News Network
AI Summary

Summary

CISA’s June 10 binding operational directive mandates federal agencies to patch the most urgent vulnerabilities on its Known Exploited Vulnerabilities list within three days, a major shift from the previous two to three weeks average. Acting associate director Jay Gazlay stated the directive is a cultural change designed to give security teams time to focus on resilience against targeted attacks. The rules allow for more regular patch cycles for lower-risk vulnerabilities, particularly those on internal systems. The directive was driven by advancements in artificial intelligence models that can identify and exploit vulnerabilities. Gazlay said the new approach directs agencies to spend time patching the most critical internet-connected devices while reducing effort on less risky internal patches.

Key points

  • Agencies must patch the highest-risk vulnerabilities on the Known Exploited Vulnerabilities list within three days.
  • The directive allows for more regular patch cycles for lower-risk vulnerabilities, especially those on internal systems.
  • Jay Gazlay, acting associate director for vulnerability management at CISA, said the directive corrects mistakes from previous binding operational directives.
  • The policy shift aims to reduce the time security teams spend on patches that
  • don't matter
  • making their work easier.
  • CISA is helping agencies implement the approach through the Continuous Diagnostics and Mitigation dashboards and automated services.

Timeline

June 10

CISA issued the new binding operational directive on software patching.

Aug. 27

Gazlay discussed the directive during a LinkedIn event hosted by CISA.

So what we’re doing here is we’re articulating where they should spend their time patching, and more importantly, where they shouldn’t spend their time patching.

Jay Gazlay

Background

The directive is a response to the increasing ability of artificial intelligence models to identify and exploit cyber vulnerabilities.

Why it matters

The new rules aim to make security teams more efficient by reducing the time spent on low-risk patches, allowing them to focus on resilience and monitoring coverage.

ChatGLM
GLM AIFree
Summary · Sep 4, 2026, 06:12 PM
AI summaries
0 of 15 used
Original Description
CISA vulnerability directive designed to ‘buy back time’ against hackers  Federal News Network