Fresh research suggests attackers are actively monitoring databases of vulnerabilities that are known to be useful in carrying out ransomware attacks. GreyNoise's annual Mass Internet Exploitation Report revealed this week that 28 percent of the bugs logged in CISA's Known Exploited Vulnerability (KEV) catalog were also used by ransomware criminals in 2024. It's a logical assumption to make that attackers would see the KEV list as a useful tool to help them plan their attacks. It notes the vulnerabilities that others have seen success in exploiting, shows whether they were used in ransomware attacks, and usually provides links to all the relevant documentation explaining how the exploits work. The KEV program is aimed at improving patching in the US public sector, but evidence suggests it's also having an unintended yet welcome effect on the private sector. GreyNoise's data showed not all KEV catalog listings were inspirational for ransomware slingers. Some bugs were exploited by extortionists just before CISA added them to the KEV catalog. Some examples here include the remote code execution (RCE) issue in Cleo Harmony (CVE-2024-50623), which, according to GreyNoise, was exploited in early 2024 but only made it to the KEV list in December after a mass exploitation campaign began. Then there's the perfect 10 critical command execution vulnerability in Progress's Kemp LoadMaster (CVE-2024-1212), which was disclosed to the National Vulnerability Database in February 2024 but no...
CISA's KEV list informs ransomware attacks, paper suggests
The Register
·Connor Jones
·Published Feb 28, 2025
·Updated
Affected Software
7 affected components
Cleo Harmony
Progress Kemp LoadMaster
Dasan GPON home routers
Realtek SDK
Ivanti VPN
VMware ESXi
VMware vCenter
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how CISA's KEV list informs ransomware attacks and highlights research indicating that attackers monitor databases of vulnerabilities.
2
What security implications are discussed in the article?
The article outlines how the knowledge of known vulnerabilities can lead to increased ransomware attacks targeting specific software solutions.
3
What products or software are affected by the vulnerabilities mentioned?
Affected software includes Cleo Harmony, Progress Kemp LoadMaster, Dasan GPON home routers, Realtek SDK, Ivanti VPN, VMware ESXi, and VMware vCenter.
4
How significant is the monitoring of vulnerabilities by attackers?
According to the report, 28 percent of internet exploitation is linked to attackers actively monitoring these vulnerabilities.
5
What organization is responsible for the KEV list discussed in the article?
The KEV list is maintained by the Cybersecurity and Infrastructure Security Agency (CISA).