CISA KEV added a “used in ransomware" field a short while ago. It's a big help to defenders (or, should be, if you're defending the way you should be).
We've got a short blog post out this week —
https://www.greynoise.io/blog/getting-a-leg-up-on-initial-access-ransomware-with-cisa-kev-and-greynoise-tags — highlighting our ~75 🏷️ that align with KEV ransomware tags.
All are Initial Access-related.
The attached chart is Good News™ for a change, in that it shows both CISA & @greynoise increasingly have your back the day one of these super nefarious CVEs is released.
Getting A Leg Up On Initial Access Ransomware With CISA KEV and GreyNoise Tags | GreyNoise Blog
Discover the latest enhancement in CISA's KEV catalog! This blog post explores the newly added field indicating ransomware involvement in KEV CVEs. Coupled with GreyNoise Tags, this update proves invaluable for defenders.
