By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Online Tech Guru
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release
Reading: CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats
Best Deal
Font ResizerAa
Online Tech GuruOnline Tech Guru
  • News
  • Mobile
  • PC/Windows
  • Gaming
  • Apps
  • Gadgets
  • Accessories
Search
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release
Every Fire Emblem Game on the Nintendo Switch and Switch 2 in 2026

Every Fire Emblem Game on the Nintendo Switch and Switch 2 in 2026

News Room News Room 11 June 2026
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow
  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Online Tech Guru > News > CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats
News

CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats

News Room
Last updated: 10 June 2026 22:32
By News Room 5 Min Read
Share
CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats
SHARE

With new generations of AI models fueling both rapid software vulnerability discovery and the potential for faster exploitation by malicious hackers, the United States Cybersecurity and Infrastructure Security Agency released a new directive on Wednesday that requires more rapid and efficient software patching by federal civilian agencies. The “binding operational directive” (BOD) lays out a rubric for how quickly bugs must be fixed based on four assessments of urgency, with a turnaround time in critical cases of just three days.

Chris Butera, CISA’s acting executive assistant director for cybersecurity, told reporters on Wednesday that the goal of the directive is to help agencies prioritize, so they can address the most problematic vulnerabilities first while taking more time to remediate bugs that pose a less-pressing risk. The directive comes as private companies and governments have been scrambling to assess the extent of the cybersecurity reckoning that AI vulnerability and exploit development capabilities could unleash.

“Prioritizing IT and security operations attention on the most at-risk assets is particularly important now given advancements in artificial intelligence, which allow threat actors to find and exploit vulnerabilities in [federal] assets,” Butera said on Wednesday. “Defenders cannot afford to take weeks to patch systems that can be autonomously exploited en masse.”

The CISA directive’s criteria for evaluating patch urgency includes looking at whether a vulnerability is in a system that is publicly exposed, whether the bug is listed in CISA’s Known Exploited Vulnerabilities Catalog, whether an attacker could automate all of the steps to exploit the vulnerability, and how much access an attacker would get to the target if the bug were exploited. A vulnerability where all four points apply must be fixed within three days, according to the new directive, and the agency must also execute a “forensic triage” process to determine whether systems have already been compromised.

The directive supersedes two previous CISA orders related to patching timelines for urgent vulnerabilities—one from 2019 and one from 2021. Those established a framework in which the most critical bugs had to be patched within 15 days of detection and another class of high-urgency vulnerability had to be remediated within 30 days. And both encouraged faster patching for severe flaws when possible. Even before the AI era, in 2021, CISA wrote that “threat actors are extremely fast to exploit their vulnerabilities of choice: of those 4% of known exploited [vulnerabilities], 42% are being used on day 0 of disclosure; 50% within 2 days; and 75% within 28 days.”

US federal cybersecurity has improved significantly over the past decade, but it still often lags, thanks to funding shortfalls and competing priorities. CISA’s Butera said that the agency developed the new assessment rubric and the directive more broadly with these limitations in mind. He noted, for example, that the three-day deadline for the most urgent vulnerabilities isn’t, say, 24 hours, because such a short timeframe would not be feasible for most agencies.

New AI capabilities are already changing the landscape of vulnerability detection and bug hunting. And as this spurs new urgency in patching, many researchers have started to conclude, essentially, that no amount of patching will be enough—and that the software development community globally must work to adopt new, architectural or systemic approaches to invalidating whole classes of vulnerabilities at a time.

“CISA’s directive has its heart in the right place, but it only tackles half the challenge,” says Emily Long, CEO of the cloud security firm Edera. “If your architecture doesn’t limit what an attacker can reach after a breach, you’re just running faster on the same treadmill. Patching will always be important, but we should be talking more about containment by design.”

CISA’s Butera seemed to acknowledge this evolution on Wednesday. The new directive “is an initial step to counter the increased capabilities of emerging AI models,” he says. “Yet there is still more work to do.”

Share This Article
Facebook Twitter Copy Link
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Bluesky is getting ‘communities’ | The Verge

Bluesky is getting ‘communities’ | The Verge

News Room News Room 11 June 2026
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow

Trending

Yet more layoffs reported at Ubisoft, this time in San Francisco

On the same day as Ubisoft announced it was closing its studios in Winnipeg and…

11 June 2026

This World Cup, You Can Watch the Game From a Ref’s Point of View

When you tune in to the 2026 World Cup, you’ll get a peek at something…

11 June 2026

Framework delays its first Laptop 13 Pro shipments by a month

Delay in start of production for Framework Laptop 13 ProAs we were preparing Framework Laptop…

11 June 2026
News

The World Cup’s Trionda Ball Challenges Traditional Aerodynamics

The World Cup’s Trionda Ball Challenges Traditional Aerodynamics

The design of the official ball of the 2026 World Cup could become a determining factor in the scores of the 104 matches that will be played during the tournament.…

News Room 11 June 2026

Your may also like!

Trump Risks Key Surveillance Authority Over ‘Unqualified’ Spy-Chief Pick
News

Trump Risks Key Surveillance Authority Over ‘Unqualified’ Spy-Chief Pick

News Room 10 June 2026
Nearly a million passports and photo IDs were left unprotected on the public internet
News

Nearly a million passports and photo IDs were left unprotected on the public internet

News Room 10 June 2026
The LEGO Great Deku Tree Set Is Going Out of Stock Everywhere Ahead of Its Retirement
Gaming

The LEGO Great Deku Tree Set Is Going Out of Stock Everywhere Ahead of Its Retirement

News Room 10 June 2026
Kalshi adds required employment verification for some prediction market bets
News

Kalshi adds required employment verification for some prediction market bets

News Room 10 June 2026

Our website stores cookies on your computer. They allow us to remember you and help personalize your experience with our site.

Read our privacy policy for more information.

Quick Links

  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
Advertise with us

Socials

Follow US
Welcome Back!

Sign in to your account

Lost your password?