#Nist

Every story tagged Nist, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

3 stories · open in the command center

  • Security & PrivacyArs TechnicaDan Goodin2m

    Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission

    Anthropic's AI security model discovered a critical flaw in HAWK, a post-quantum cryptography algorithm under NIST consideration, effectively halving its key strength and forcing its withdrawal from standardization—demonstrating that AI can discover novel cryptographic weaknesses by recombining existing mathematical techniques in unexpected ways. While current production cryptosystems remain secure and the findings use weakened test versions, this breakthrough signals that organizations must accelerate quantum-resistant cryptography adoption and reassess their cryptographic roadmaps before AI-assisted attacks become more sophisticated. For IT leaders, this underscores the urgency of transitioning to NIST-approved post-quantum algorithms (like ML-DSA and FN-DSA) rather than waiting for additional standardization cycles, as AI-driven cryptanalysis is becoming a viable threat vector.

  • AI & MLTechMemeMaria Curi2m

    CAISI Director Chris Fall is resigning after taking over the federal AI testing institute in April; NIST Director Arvind Raman will serve as acting director (Maria Curi/Axios)

    The director of NIST's Center for AI Standards and Innovation (CAISI) is resigning after only three months, creating leadership instability at a critical federal agency responsible for AI governance and testing standards. This leadership disruption could delay the development of AI safety frameworks and standards that organizations rely on for compliance and responsible AI deployment. IT leaders should monitor CAISI's strategic direction closely, as any gaps in federal AI standard-setting may create uncertainty around future regulatory requirements and industry best practices.

  • Security & PrivacyHacker News3m

    NIST gives up enriching most CVEs

    NIST has announced it will no longer enrich most CVE entries in the National Vulnerability Database due to budget constraints and overwhelming volume, instead focusing only on actively exploited vulnerabilities (CISA KEV), bugs in federal agency software, and critical infrastructure software. This policy shift eliminates a centralized source of truth for vulnerability data, forcing organizations to aggregate intelligence from multiple sources and potentially rely on vendor-assigned severity scores that may underestimate risk. The change comes as AI-powered vulnerability discovery tools are expected to exponentially increase CVE volume, fundamentally disrupting vulnerability management programs that depend on comprehensive NVD data.

Browse all tags