logo

Ransomware criminals love CISA's KEV list – and that's a bug, not a feature

ID: ea5d0f70-6e0a-537a-9d5c-22bff375a3ac

STIX ID: report--ea5d0f70-6e0a-537a-9d5c-22bff375a3ac

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-02-28

Date Updated: 2026-04-26

Author: Connor Jones

...
...

GreyNoise's Mass Internet Exploitation Report finds active and widespread exploitation of known and legacy vulnerabilities in 2024—many used for ransomware and botnet activity—with a notable portion of CVEs listed in CISA's KEV catalog being leveraged by attackers. The report calls out critical, high-impact flaws (including multiple 9.8-rated RCEs), documents vendor patching and disclosure failures (Ivanti, D-Link, VMware/Broadcom), and warns organizations to strengthen patching, monitoring, and consider vendor/product risk given automation-driven exploitation at scale.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.