CISA updated ransomware intel on 59 bugs last year without telling defenders
ID: 12fa7347-39b7-51d4-8981-d4cf03a5684f
STIX ID: report--12fa7347-39b7-51d4-8981-d4cf03a5684f
Feed Name: The Register (Security)
Threat Score
**Executive summary:** In 2025 CISA silently flipped the "known ransomware use" status on 59 KEV catalog vulnerabilities without issuing alerts, potentially delaying defenders' ability to reprioritize patching; GreyNoise analyzed the flips (noting vendors such as Microsoft, Ivanti, Fortinet, Palo Alto Networks, and Zimbra) and published an RSS feed to notify when KEV entries change to 'Known' for ransomware use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
