logo

CISA updated ransomware intel on 59 bugs last year without telling defenders

ID: 12fa7347-39b7-51d4-8981-d4cf03a5684f

STIX ID: report--12fa7347-39b7-51d4-8981-d4cf03a5684f

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2026-02-03

Date Updated: 2026-04-26

Author: Connor Jones

...
...

**Executive summary:** In 2025 CISA silently flipped the "known ransomware use" status on 59 KEV catalog vulnerabilities without issuing alerts, potentially delaying defenders' ability to reprioritize patching; GreyNoise analyzed the flips (noting vendors such as Microsoft, Ivanti, Fortinet, Palo Alto Networks, and Zimbra) and published an RSS feed to notify when KEV entries change to 'Known' for ransomware use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.