Risky Bulletin Newsletter
June 12, 2026
Risky Bulletin: In the age of AI, CISA changes federal patching rules
Presented by
News Editor
The US Cybersecurity and Infrastructure Security Agency (CISA) issued a new binding operational directive (BOD) this week that updates the patching rules for federal civilian agencies.
The new order cites the rise of AI-automated attacks as the main reason to prioritize bugs based on the risk they pose to federal networks and shorten patching deadlines.
The order introduces a new decision tree (pictured below) that will prioritize vulnerabilities that are exploited in the wild, are easy to exploit and automate, and grant broad access to a system if they have been exploited.