CISA asks US agencies to fix security bugs in less than 3 days thanks to AI threats


With new generations to Artificial intelligence models Fueling both Rapid detection of software vulnerabilities And the potential for Faster exploitation By malicious hackers, the US Cybersecurity and Infrastructure Security Agency issued a New directive On Wednesday, this requires more rapid and efficient software patching by federal civilian agencies. The Binding Operational Directive (BOD) sets a model for how quickly bugs should be fixed based on four urgency ratings, with a response time period in critical cases of just three days.

Chris Butera, acting associate executive director for cybersecurity at CISA, told reporters Wednesday that the goal of the guidance is to help agencies prioritize, so they can address the most problematic vulnerabilities first while taking more time to address bugs that pose a less urgent risk. This guidance comes as private companies and governments scramble to assess the extent to which cybersecurity exploits could unleash artificial intelligence vulnerabilities and exploit development capabilities.

“Prioritizing IT and security operations’ attention to the most vulnerable assets is especially important now given advances in artificial intelligence, which allows threat actors to find and exploit vulnerabilities in (federal) assets,” Butera said Wednesday. “Defenders cannot take weeks to collectively patch systems that could be independently exploited.”

CISA guidance’s criteria for assessing the urgency of a patch include considering whether the vulnerability exists in a publicly exposed system, and whether the bug is listed in the CISA manual Catalog of known exploited vulnerabilitiesWhether the attacker can automate all the steps to exploit the vulnerability, and the extent of access that the attacker can have to the target if the vulnerability is exploited. A vulnerability that applies to the four points must be fixed within three days, according to the new guidance, and the agency must also implement “Forensic triageA process to determine whether systems have already been compromised.

This guidance replaces two previous CISA orders relating to patching timelines for urgent vulnerabilities – one of which… 2019 And one of 2021. They created a framework within which the most critical bugs must be patched within 15 days of their discovery, and another category of highly urgent vulnerabilities must be addressed within 30 days. They both encouraged rapid patching of severe defects when possible. Even before the era of artificial intelligence, in 2021, CISA books “Threat actors are very quick to exploit vulnerabilities of their choice: of the 4% of known exploits, 42% are used on the first day of detection; 50% within 2 days; and 75% within 28 days.”

Federal cybersecurity in the United States has improved dramatically over the past decade, but it still often lags behind, thanks to lack of funding and competing priorities. CISA’s Butera said the agency developed the new assessment model and broader guidance with these limitations in mind. He noted, for example, that the three-day deadline for the most urgent vulnerabilities is not, say, 24 hours, because such a short time frame would not be possible for most agencies.

New AI capabilities already exist Change of scenery Discovering security vulnerabilities and catching errors. As this stimulates a new urgency for patching, many researchers are beginning to conclude, essentially, that no amount of patching will be enough — and that the software development community globally must work to adopt new architectural or systemic approaches to invalidate entire classes of vulnerabilities at once.

“The CISA guidance has the heart in the right place, but it only addresses half the challenge,” says Emily Long, CEO of cloud security company Edera. “If your architecture doesn’t limit what an attacker can access after a breach, you run faster on the same treadmill. Patching will always be important, but we should talk more about containment by design.”

CISA’s Butera appeared to acknowledge the development on Wednesday. He says the new guidance “is an initial step to address the growing capabilities of emerging AI models.” “However, there is still more work to be done.”

Leave a Reply

Your email address will not be published. Required fields are marked *