Artificial Intelligence & Machine Learning
,
Next-Generation Technologies & Secure Development
,
Security Operations
Initiative seeks to prevent duplicate vulnerability scanning and remediation efforts.

The U.S. government launched an clearinghouse on July 2 to coordinate artificial intelligence-assisted vulnerability discovery, the White House said Tuesday.
See Also: Edge Transformation: Top 5 SASE Predictions and Trends
The information sharing effort, called Gold Eagle, is built by the Departments of the Treasury, Defense and Homeland Security and will work with the Software Engineering Institute at Carnegie Mellon University to handle the findings and coordinate and disseminate vulnerabilities, National Cyber Director Sean Cairncross said in a press call.
The new clearinghouse was part of President Donald Trump’s June 2 executive order on AI, which directed Treasury to collaborate with industry and operators of critical infrastructure throughout the vulnerability discovery and remediation cycle.
“By concept and design, this clearinghouse enables unprecedented cybersecurity, AI-discovered vulnerability and patching coordination at a speed and scale never before,” Cairncross said.
The clearinghouse will involve cybersecurity leader in the government, industry professionals, open-source software providers and critical infrastructure operators, Cairncross said.
Open-source and proprietary AI models made in the United States are already being used to scan for vulnerabilities, a senior White House official said, which are coming in at an unprecedented scale (see: AI-Driven Bug Tsunami Prompts Exploitability Questions).
“A team of industry and government engineers are working to triage, prioritize and fix those vulnerabilities in a way that mitigates risk for industry absorbing them,” the official said.
An important responsibility of the clearinghouse is to “deconflict,” making sure resources are not wasted on fixing or scanning for the same vulnerabilities. A “Vulnerability Information and Coordination Environment,” developed by the CERT Coordination Center at CMU to coordinate vulnerability disclosure on a Python-based web platform, will be responsible for maintaining that distribution system.
“VINCE allows for processing and secure sharing, maintaining validation, prioritization, and disclosure vulnerabilities to ultimately patch and remediate defects in software that underpin essential services,” Cairncross said.
The open-source industry is “a necessary part” of the process, the official said without naming specific organizations, in maintaining the software, scanning for vulnerabilities and fixing flaws. The clearinghouse aims to bolster the U.S. open source ecosystem.
The effort is also made possible by the Cybersecurity Information Sharing Act of 2015, the official said, which will expire on Oct. 1. The White House is asking Congress for a long-term clean reauthorization of 10 years.
“That law provides liability and antitrust protection for industry to share information such as vulnerabilities to the USG,” the official said. “Without that reauthorization, this effort is fundamentally challenged, and I would expect that Congress will step up and do the right thing and act.”
