US shortens cyber fix window to three days as AI threats rise

WASHINGTON, June 10 : The U.S. cyber defense agency said on Wednesday that government officials now have three days to deal with the most serious categories of digital vulnerabilities in their networks, a compressed timeline that is due in part to hackers’ use of artificial intelligence.The deadline, which wa


Business

US shortens cyber fix window to three days as AI threats rise

US shortens cyber fix window to three days as AI threats rise

FILE PHOTO: Figurines with computers and smartphones are seen in front of the words “Artificial Intelligence AI” in this illustration taken, February 19, 2024. REUTERS/Dado Ruvic/Illustration/File Photo

Read a summary of this article on FAST.

Get bite-sized news via a new
cards interface. Give it a try.

Click here to return to FAST
Tap here to return to FAST

FAST

WASHINGTON, June 10 : The U.S. cyber defense agency said on Wednesday that government officials now have three days to deal with the most serious categories of digital vulnerabilities in their networks, a compressed timeline that is due in part to hackers’ use of artificial intelligence.

The deadline, which was set in a new directive issued by the Cybersecurity and Infrastructure Security Agency, obligates civilian federal agencies with vulnerable software or equipment to fix, disable, or remove it from the internet within three calendar days, depending on the severity of the threat.

Many cyber experts worry that new, more capable AI models along the lines of Anthropic’s Mythos are supercharging hackers’ abilities to take advantage of digital vulnerabilities across the internet, forcing defenders to plug security holes almost as soon as they are discovered. The directive said that because the window to respond to hacks was potentially narrowing, “we must take immediate action to harden American networks” and make sure government policies for applying fixes are up to the task.

Reuters first reported last month that U.S. officials were considering the adoption of a three-day deadline to deal with potentially dangerous flaws.

Guess Word

Guess Word
Crack the word, one row at a time


Buzzword

Buzzword
Create words using the given letters


Mini Sudoku

Mini Sudoku
Tiny puzzle, mighty brain teaser


Mini Crossword

Mini Crossword
Small grid, big challenge


Word Search

Word Search
Spot as many words as you can


Show More


Show Less

Even under the new directive, there is still more time to deal with less severe weaknesses, such as ones that are not easy for hackers and cybercriminals to automate, or do not  concern publicly exposed digital infrastructure. An appendix to the order leaves two weeks to deal with many vulnerabilities and as long as two months for the least serious category of flaw.

CISA did not immediately return a message seeking comment.

Source: Reuters

Sign up for our newsletters

Get our pick of top stories and thought-provoking articles in your inbox

Inbox

Get the CNA app

Stay updated with notifications for breaking news and our best stories

Get WhatsApp alerts

Join our channel for the top reads for the day on your preferred chat app

Whatsapp

Get bite-sized news via a new
cards interface. Give it a try.

Click here to return to FAST
Tap here to return to FAST

FAST

About The Author

Leave a Reply

Your email address will not be published. Required fields are marked *