CISA Silently Updates Vulnerabilities Exploited by Ransomware Groups
ID: 8658bf8b-2234-55eb-97ae-740776586f12
STIX ID: report--8658bf8b-2234-55eb-97ae-740776586f12
Feed Name: The Cyber Express
Threat Score
The article reports that CISA quietly flipped 59 CVEs in 2025 from 'unknown' to 'known' exploitation by ransomware groups—many affecting Microsoft and edge/network devices (Fortinet, Ivanti, Palo Alto)—highlighting common exploitation types (authentication bypass, RCE), rapid adoption by ransomware operators, and a lack of public advisories when the KEV status changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
