We’ve launched a new questionnaire designed to evaluate an organization's compliance with the NIST AI RMF. This security questionnaire offers a structured framework for effectively assessing the risks associated with AI systems. It covers the core functions of the NIST AI RMF—governing, mapping, measuring, and managing AI systems—ensuring that vendors uphold best practices in AI governance and operational management.
Expanded news and incident coverage
We’ve greatly enhanced our news and incident scanning capabilities, now delivering five times broader coverage to provide faster, high-impact insights. This empowers your security teams and SOC analysts to detect incidents affecting your organization or supply chain sooner, enabling proactive responses to mitigate risks early. With an expanded range of advanced data collectors, including official reports and government databases, we now offer a more comprehensive view of emerging threats to fortify your security posture.
Other improvements
- This release includes small improvements to Trust Exchange, including a new home page for free users, and improvements to notifications.
- We’ve added product and version detection for the Roundcube email client to detect the following vulnerabilities:some text
- CVE-2024-42008 - A cross-site scripting flaw via a malicious email attachment served with a dangerous Content-Type header
- CVE-2024-42009 - A cross-site scripting flaw that arises from post-processing of sanitized HTML content
- CVE-2024-42010 - An information disclosure flaw that stems from insufficient CSS filtering
- This release includes a number of bug fixes.