SendTech Times
News
SYSTEMS SHIFT:

NATO Cyber Centre Joins CVE Numbering Network

Newsroom brief

CyberScoop reported that NATO’s cyber defence arm and AISLE joined the ENISA Root as CVE numbering authorities, adding new channels for tracking software flaws as AI changes vulnerability discovery.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: CyberScoop
NATO Cyber Centre Joins CVE Numbering Network

NATO’s cyber defence arm and AI security startup AISLE have gained authority to issue CVE identifiers, CyberScoop reported, expanding Europe’s role in the system used to name and track publicly disclosed software flaws.

The change puts two very different organisations inside the ENISA Root for the Common Vulnerabilities and Exposures programme.

The NATO Cyber Security Centre can assign identifiers across the NATO enterprise, while AISLE’s mandate is limited to vulnerabilities discovered in its own products.

Vendors, researchers and government defenders gain a clearer label before flaws are shared, patched or discussed across separate organisations.

ENISA Root Adds NATO And AISLE

The European Union Agency for Cybersecurity announced the additions last week.

Twenty numbering authorities now sit under the ENISA Root: 12 brought in by ENISA itself and eight moved from the MITRE Root, the U.S. nonprofit-operated structure that has handled the programme’s daily work for more than 20 years.

The CVE system gives each public vulnerability a unique record.

That record becomes the common marker used by governments, suppliers and security teams when they refer to a specific flaw, reducing confusion when advisories, patches and incident reports cross organisational or national boundaries.

NATO’s new authority covers eligible flaws across alliance systems.

The NATO Cyber Security Centre guards NATO networks, monitors threats and coordinates responses when incidents occur, and the new role is designed to make tracking more consistent and allow information-sharing with trusted partners earlier in the process.

AI Discovery Raises The Numbering Burden

ENISA cybersecurity and operations chief Hans de Vries linked the expansion to shifts in the global threat landscape and to frontier AI models that can affect both flaw discovery and exploitation.

His statement framed ENISA’s role as part of a more globally representative and scalable identification ecosystem.

That AI context is central to the timing.

Automated discovery can increase the number of flaws that need triage, validation and public identifiers, while exploit-development capabilities shorten the window between discovery and operational risk.

A numbering authority does not itself fix a vulnerability, but it creates the shared reference point that lets defenders, vendors and coordinators move around the same record.

AISLE Gets A Narrower Mandate

AISLE’s authorisation is narrower than NATO’s.

The company, which has offices in San Francisco and Prague, said its CVE designation covers vulnerabilities found in its own products, so it can issue records directly instead of routing each request through an outside numbering authority.

Jaya Baloo, AISLE’s co-founder, called the step foundational and linked coordinated disclosure to holding the company’s products to the same standard it expects from others.

The company also credited its research team with hundreds of disclosures affecting widely used open-source projects including OpenSSL, Linux, Apache and OpenEMR, each handled through the relevant authority for that project.

CVE Governance Remains Unsettled

The expansion follows a period of pressure on vulnerability tracking.

The CVE programme narrowly avoided disruption in April 2025 when an 11-month contract extension prevented the shutdown of MITRE’s work.

Since then, European nonprofits and private entities have launched competing or complementary databases intended to coordinate how flaws are tracked, disclosed and patched.

One of those efforts is the Global CVE Allocation System, launched earlier this year by the Computer Incident Response Center Luxembourg.

A timetable for how ENISA-rooted assignments will operate alongside newer alternatives such as GCVE remains absent.

Share this article
inXf

Related articles

More
Liquid Network Hack Leaves $47 Million Loss After Bitcoin Return
Cybersecurity

Liquid Network Hack Leaves $47 Million Loss After Bitcoin Return

Attackers stole 4,000 bitcoin from the Liquid Network, returned most of the funds after a patch and kept 598 coins worth about $47 million as a claimed bounty.

UAE Cyber Summit Puts AI Risk Inside A National Resilience Plan
Cybersecurity

UAE Cyber Summit Puts AI Risk Inside A National Resilience Plan

The UAE’s 3rd Government Cybersecurity Summit in Abu Dhabi framed cyber defence as a national resilience issue, linking AI-enabled threats, telecom exposure, data compression and regional cooperation.

Check Point CEO Warns AI Is Compressing Cyber Defence Timelines
Cybersecurity

Check Point CEO Warns AI Is Compressing Cyber Defence Timelines

Frontier Enterprise interviewed Check Point CEO Nadav Zafrir on how AI is accelerating phishing, vulnerability exploitation and remediation demands while pushing security teams toward CTEM, AI firewalls and open-platform consolidation.

White House Private Cyber Program Tests Hackback Limits Against Foreign Crime Groups
Cybersecurity

White House Private Cyber Program Tests Hackback Limits Against Foreign Crime Groups

Ars Technica reported that a Trump memorandum directs federal officials to build a program allowing vetted private security firms to conduct authorized cyber operations against foreign criminal hacking groups under Justice and Homeland Security oversight.

Target-Locked Malware Narrows Central Asia Cyber Espionage Risk
Cybersecurity

Target-Locked Malware Narrows Central Asia Cyber Espionage Risk

Backend News reported, citing Kaspersky, that a campaign active since January 2025 used custom malware, OctLurk and SilkLurk backdoors, and PlugX to target public-sector, healthcare and research bodies in Central Asia and Syria.

Google, Microsoft And OpenAI Back AI Cyber Defence Push
Cybersecurity

Google, Microsoft And OpenAI Back AI Cyber Defence Push

Google, Microsoft, Anthropic, OpenAI and other firms backed an open letter calling for stronger AI-era cyber defences for critical infrastructure, hospitals and utilities.

EU Cyber Resilience Act Puts 24-Hour Clock On Software Supply Chains
Cybersecurity

EU Cyber Resilience Act Puts 24-Hour Clock On Software Supply Chains

The European Commission lists 11 September 2026 as the start of Cyber Resilience Act reporting duties and 11 December 2027 for its main product-security obligations. Manufacturers face distinct reporting and engineering deadlines.

OpenAI Widens Cyber AI Access Through Vetted Security Partners
Cybersecurity

OpenAI Widens Cyber AI Access Through Vetted Security Partners

OpenAI is giving approved security vendors and services firms access to cyber AI models while keeping Astra under tighter review for potential misuse risk.

Keep Reading

More Stories

Latest
Ethereum Testnet Update Targets 200 Million-Gas BlocksCrypto/Web3Oct 6, 2026Ethereum Testnet Update Targets 200 Million-Gas BlocksEthereum developers released Prysm 7.2.1 so the Sepolia trial of Glamsterdam can test 200 million-gas blocks, more than three times the prior 60 million setting, before any main-network change.Kepler Targets 2027 Production for HBM Replacement MemoryCloud & Data CentersOct 6, 2026Kepler Targets 2027 Production for HBM Replacement MemoryEE Times reports that Kepler Computing is preparing 3D ferroelectric memory for 2027 production, promising higher capacity and bandwidth per watt while limiting reliance on advanced-node lithography.Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceCapital & PolicyOct 6, 2026Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceYokogawa Engineering Asia has launched a Singapore center focused on OT cyber resilience, training, response planning and recovery coordination for Southeast Asia, Oceania and Taiwan.ClickFix Attack Uses Browser Cache To Hide Malware PayloadCybersecurityOct 6, 2026ClickFix Attack Uses Browser Cache To Hide Malware PayloadMicrosoft Threat Intelligence traced a ClickFix cache-smuggling method that preloads malware into browser caches, then uses file size checks and a pasted Run command to launch later credential-theft stages.VOA Tests Six-Month Startup Buildout Before Funding DecisionsFintech & Digital PaymentsOct 6, 2026VOA Tests Six-Month Startup Buildout Before Funding DecisionsTechCabal’s interview with VOA Venture Partners founder Victoria Olayide Adesanya describes a six-month build programme that lets the firm work inside African financial-infrastructure startups before deciding whether to invest.Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCrypto/Web3Oct 6, 2026Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCoinDesk reported that bitcoin stayed near $86,000 while the U.S. Dollar Index reached about 102.5, with U.S. rate expectations and European political risks strengthening the dollar backdrop.Google Freezes OSS Bug Bounty Reports After AI Submission FloodCybersecurityOct 6, 2026Google Freezes OSS Bug Bounty Reports After AI Submission FloodGoogle has stopped accepting new product vulnerability reports in its OSS VRP after invalid automated submissions swamped reviewers, while older reports and some Cloud VRP routes remain open.Fleuret AI Raises €4M For Continuous AI Pentesting PlatformCybersecurityOct 6, 2026Fleuret AI Raises €4M For Continuous AI Pentesting PlatformTech.eu reported that French startup Fleuret AI raised €4 million in pre-seed funding to develop an agentic-AI platform that turns penetration testing into a continuous security process.GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%Fintech & Digital PaymentsOct 6, 2026GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%A GFT Technologies analysis says AI-linked software documentation can cut maintenance effort and speed developer onboarding when knowledge assets stay synchronized with code changes.Schneider Electric Lines Up $22.6 Billion PTC DealAIOct 5, 2026Schneider Electric Lines Up $22.6 Billion PTC DealSchneider Electric plans to buy PTC in a cash transaction valuing the US engineering software provider’s equity at about $22.6 billion, adding product-lifecycle software to its industrial AI push.Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueCapital & PolicyOct 5, 2026Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueOla Electric founder Bhavish Aggarwal pledged 20 Cr shares to finance his participation in a rights issue that forms part of a larger ₹1,500 Cr fundraising plan.Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseAIOct 5, 2026Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseNatrona County trustees questioned whether teacher AI tools expose student data, even as existing district rules already ban unauthorized generative AI use by students.