Hello friends! 👋
Welcome back to Simplifying Cybersecurity, the weekly newsletter where I distill 25 years of vCISO experience into 5 ideas, tools, and career hacks. This was one of the biggest weeks in cybersecurity in 2026. TLet's go.
🧠 NIST Is Breaking Up With Your CVEs
On April 15, 2026, NIST announced it will stop automatically enriching most CVEs in the National Vulnerability Database (NVD). Going forward, NIST will only enrich CVEs that appear in CISA's KEV catalog or affect software used by the federal government (Source: The Hacker News).
The reason: CVE submissions increased 263% between 2020 and 2025, and NIST doesn't have the staff to keep up.
Why you should care (3 minute read): The NVD has been the default source for CVSS scores, CWE mappings, and CPE data for every vulnerability scanner, SIEM rule, and compliance report in the industry. If your organization depends on NVD enrichment to prioritize patches, you now have a gap. Vulnerabilities that don't hit the KEV catalog or affect federal software will still be listed, but without the metadata your tools depend on.
So What? For aspiring analysts, this is a conversation you want to be ready for in interviews. Vulnerability management is shifting from "scan and patch everything" to "prioritize what matters." The CISA KEV catalog (which I've been telling you to read weekly since Issue 15) is now officially the prioritization standard.
The Hack: If you haven't bookmarked the CISA KEV Catalog, do it today. It's free, it's updated weekly, and it's now the single most important vulnerability data source for defenders. Understanding why this matters puts you ahead of every candidate who memorized a CVSS scoring formula but doesn't know the NVD is changing.
🔍 Microsoft's Second-Biggest Patch Tuesday and a SharePoint Zero-Day
🔴 April 2026 Patch Tuesday: 165 CVEs, including CVE-2026-32201 (SharePoint Zero-Day)
Microsoft's April 2026 Patch Tuesday is the second-largest in history by CVE count: 165 vulnerabilities patched, including one actively exploited SharePoint zero-day and 19 flaws rated "exploitation more likely" (Source: SecurityWeek).
The exploited flaw, CVE-2026-32201, is a spoofing vulnerability in SharePoint Server caused by improper input validation. An attacker could use it to access and alter sensitive information over a network. CISA added it to the KEV catalog with a patch deadline of April 28 (Source: SecurityWeek).
Also in this batch: CVE-2026-33825, a Microsoft Defender privilege escalation flaw that was publicly disclosed before patches were released. This is believed to be the "BlueHammer" vulnerability a frustrated researcher made public on GitHub after disagreeing with Microsoft's response (Source: SecurityWeek).
Timeline:
April 14, 2026: Microsoft releases 165 patches, including the SharePoint zero-day
April 14, 2026: CISA adds CVE-2026-32201 to KEV catalog with April 28 deadline
April 14, 2026: BlueHammer (CVE-2026-33825) confirmed as publicly disclosed prior to patch
What aspiring analysts should take from this:
165 patches in one month means prioritization is the job. You're not patching all of them on day one. The skill is knowing which ones to patch first and explaining why.
The BlueHammer story shows what happens when a researcher and a vendor disagree on severity. This is the messy, human side of vulnerability management. Understanding the disclosure process matters.
SharePoint is everywhere in enterprise environments. If an interviewer asks you about a recent zero-day, this one is relevant, timely, and easy to explain.
🔐 SPONSORED: AI Is Coming for Tier 1 Triage Work. Here's What That Means for You.
If you're training for a SOC analyst role, you need to understand how AI agents are reshaping the work you're preparing to do. Scanner.dev published a hands-on guide to building autonomous SOC triage agents using the Claude Agent SDK and the Model Context Protocol (MCP). The article walks through the real-world problem (alert volumes growing faster than headcount, most alerts being false positives), the human-AI partnership model (read-only tools for investigation, staging tools for human review, no autonomous response actions), and two techniques that improve agent accuracy: hypothesis-driven investigation and self-critique loops. In their testing, an unguided LLM achieved 71% accuracy and missed a real insider threat. With their structured framework, accuracy rose to 78% with zero false "Malicious" calls. The key insight: AI agents don't replace analysts. They handle routine triage so analysts have bandwidth for detection engineering, threat hunting, and the strategic work that compounds.
Read the full guide: Building Your First AI SOC Agents: Foundations and Your First Agent (Part 1)
🤔 Know someone who would get value from this newsletter? Forward this issue to one person who's studying for a cybersecurity career. It takes 5 seconds, and it might be the thing that keeps them going this week.
📋 The AI Cyber Arms Race Is Creating New Job Titles. Learn Them Now.
Two pretty big things happened this week at the intersection of AI and cybersecurity.
OpenAI released GPT-5.4-Cyber, a specialized model fine-tuned for defensive cybersecurity tasks. Vetted security professionals get expanded access to capabilities like vulnerability research and analysis with fewer restrictions. OpenAI is rolling access out through its Trusted Access for Cyber program, starting with thousands of individuals and hundreds of security teams (Source: Axios).
Anthropic's Mythos continues to operate under a more restrictive model, with access limited to roughly 40 organizations (Source: Axios).
The arms race is real. OpenAI and Anthropic are building AI models that find zero-days. Defenders are building AI agents that triage alerts. And organizations are hiring people who understand both.
New job titles to watch in 2026:
AI Security Engineer
LLM Red Team Specialist
AI SOC Analyst
Prompt Security Researcher
The Hack: You don't need to become an AI engineer. But you need to be able to answer this interview question: "How do you see AI changing the role of a SOC analyst?" The right answer involves triage automation, human-AI partnership, and the shift from alert processing to hypothesis-driven investigation. The wrong answer is "AI will replace analysts." (It won't. It will change what analysts spend their time on.)
😂 Whatever Happened to Learning on the Job?
🛠️ The 5-Minute Habit: Document One Thing You Learned This Week
This is the simplest habit in the rotation. And the most underrated.
Open a note (Google Doc, Notion, plain text file, pen and paper).
Write one sentence: "This week I learned..."
Finish the sentence with something specific. A CVE you read. A concept that clicked. A tool you tried. An interview question you practiced.
Add the date.
Save it.
Do this every week. After 3 months, you'll have 12 documented learning moments. After 6 months, 24. After a year, 52.
Why this works: When an interviewer asks "What have you been learning recently?" most candidates freeze and say something vague. You'll open your log and say "Last Tuesday, I studied CVE-2026-32201, the SharePoint zero-day from Microsoft's April Patch Tuesday. It's a spoofing flaw caused by improper input validation. CISA added it to the KEV catalog with an April 28 deadline." That answer gets callbacks. The vague one doesn't.
🚨 The 30 Day Career Sprint: Becoming a Cybersecurity Analyst is now available on Amazon!
If you're ready to stop overthinking and start moving toward your first role in cybersecurity, this book is your roadmap. Grab your copy here ➡️ https://simplifyingcybersecurity.com/30DayCareerSprint
Have a great week!
Jerod Brennen
🔗 Connect with me on LinkedIn
👥 Follow Simplifying Cybersecurity
Did someone forward this to you? Subscribe so you don't miss next week's issue. Have a question or topic you'd like covered? Hit reply. I read every message. 💬



