#patch-prioritization

[ follow ]
fromSecurityWeek
7 hours ago

New Paper and Tool Help Security Teams Move Beyond Blind Reliance on CISA's KEV Catalog

The KEV list is useful but largely misunderstood. KEVology explains what it is, and how best to use it. CISA's KEV Catalog, more commonly known as the KEV list, emerged with the issue of BOD 22-01 in November 2021. This catalog, currently a list of just over 1,500 vulnerabilities known to have been exploited in the wild, suggests a high value prioritization source for vulnerability remediation within industry.
Information security
Information security
fromSecurityWeek
3 days ago

Questions Raised Over CISA's Silent Ransomware Updates in KEV Catalog

CISA quietly changes KEV entries to mark vulnerabilities as observed in ransomware, creating material shifts in organizational risk and patch prioritization without public alerts.
[ Load more ]