CISA Makes Unpublicized Ransomware Updates to KEV Catalog
ID: 3a4af45b-c29e-5219-984e-15f397c847aa
STIX ID: report--3a4af45b-c29e-5219-984e-15f397c847aa
Feed Name: Dark Reading
GreyNoise found that CISA's Known Exploited Vulnerabilities (KEV) catalog had 59 CVEs in 2025 whose "Known To Be Used in Ransomware Campaigns?" flag was quietly flipped from "Unknown" to "Known"—in some cases days after catalog inclusion and in others months or years later. Many flipped CVEs are high-severity remote code execution or authentication-bypass flaws affecting vendors like Microsoft, Ivanti, Fortinet and expose edge devices; the silent updates impede timely prioritization, so GreyNoise published an RSS feed to notify defenders of ransomware-flag changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
