Every story tagged Nist, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
3 stories · open in the command center
Anthropic's AI security model discovered a critical flaw in HAWK, a post-quantum cryptography algorithm under NIST consideration, effectively halving its key strength and forcing its withdrawal from standardization—demonstrating that AI can discover novel cryptographic weaknesses by recombining existing mathematical techniques in unexpected ways. While current production cryptosystems remain secure and the findings use weakened test versions, this breakthrough signals that organizations must accelerate quantum-resistant cryptography adoption and reassess their cryptographic roadmaps before AI-assisted attacks become more sophisticated. For IT leaders, this underscores the urgency of transitioning to NIST-approved post-quantum algorithms (like ML-DSA and FN-DSA) rather than waiting for additional standardization cycles, as AI-driven cryptanalysis is becoming a viable threat vector.
The director of NIST's Center for AI Standards and Innovation (CAISI) is resigning after only three months, creating leadership instability at a critical federal agency responsible for AI governance and testing standards. This leadership disruption could delay the development of AI safety frameworks and standards that organizations rely on for compliance and responsible AI deployment. IT leaders should monitor CAISI's strategic direction closely, as any gaps in federal AI standard-setting may create uncertainty around future regulatory requirements and industry best practices.
NIST has announced it will no longer enrich most CVE entries in the National Vulnerability Database due to budget constraints and overwhelming volume, instead focusing only on actively exploited vulnerabilities (CISA KEV), bugs in federal agency software, and critical infrastructure software. This policy shift eliminates a centralized source of truth for vulnerability data, forcing organizations to aggregate intelligence from multiple sources and potentially rely on vendor-assigned severity scores that may underestimate risk. The change comes as AI-powered vulnerability discovery tools are expected to exponentially increase CVE volume, fundamentally disrupting vulnerability management programs that depend on comprehensive NVD data.