CISA Updates Ransomware Vulnerability Notices Without Alerting Defenders
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The US Cybersecurity and Infrastructure Security Agency (CISA) made updates to its Known Exploited Vulnerability (KEV) catalog in 2025, reflecting the use of 59 vulnerabilities by ransomware operators. Experts, including Glenn Thorpe from GreyNoise, expressed concern over CISA’s failure to notify defenders when the status of these vulnerabilities changed from ‘unknown’ to ‘known’ regarding ransomware exploitation. This oversight means that defenders may miss crucial opportunities to mitigate risks associated with these vulnerabilities.
Among the vulnerabilities updated, the largest share (16) were Microsoft CVEs, while other affected vendors included Ivanti, Fortinet, PANW, and Zimbra. Thorpe’s analysis revealed that 39 percent of the vulnerabilities confirmed to be used in ransomware campaigns were added to the KEV catalog before 2023, with the oldest vulnerability flipping status 1,353 days after its initial addition.
The rapid pace at which CISA updates the KEV catalog often outstrips defenders’ ability to respond. The vulnerabilities are only confirmed to be exploited by ransomware after they are added to the catalog, and CISA does not provide alerts for changes in their status. This lack of communication can lead to a significant shift in an organization’s risk posture, as the vulnerabilities that ransomware operators exploit are often the most damaging.
Implications for Cybersecurity Professionals
Organizations must be aware of the vulnerabilities listed in the KEV catalog and monitor their statuses closely. The failure to communicate changes in exploitation status can leave organizations vulnerable to attacks. Authentication bypasses and remote code execution flaws were identified as the most likely vulnerabilities to flip status after being added to the catalog, indicating areas where organizations should focus their security efforts.
To assist defenders, GreyNoise has launched an RSS feed that updates hourly, allowing cybersecurity professionals to track changes in the KEV catalog’s ransomware statuses. This tool can help organizations stay informed and adjust their security measures accordingly.
The analysis of these vulnerabilities underscores the need for improved communication between agencies like CISA and the cybersecurity community. As ransomware threats continue to evolve, timely information sharing will be critical in defending against potential attacks.
Key Takeaways
- Subscribe to the GreyNoise RSS feed to receive updates on changes in the KEV catalog’s ransomware statuses.
- Regularly review the KEV catalog for vulnerabilities that may impact your organization.
- Prioritize patching vulnerabilities that have been confirmed to be exploited by ransomware operators.
- Implement monitoring systems to detect changes in vulnerability statuses and adjust your risk management strategies accordingly.
- Engage with cybersecurity communities to share insights and stay informed about emerging threats.
Key Terms & Concepts
- CISA: In this article, CISA refers to the US Cybersecurity and Infrastructure Security Agency, responsible for managing cybersecurity risks.
- KEV catalog: The KEV catalog is a list maintained by CISA that identifies vulnerabilities known to be exploited by attackers.
- CVE: CVE stands for Common Vulnerabilities and Exposures, a system for identifying and cataloging vulnerabilities in software.
- ransomware: Ransomware is a type of malicious software that encrypts files and demands payment for their release.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.