Thursday, July 3, 2025
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions
marketibiza
  • Home
  • Auto insurance
  • Business insurance
  • Cyber insurance
  • Disability insurance
  • Health insurance
    • Life insurance
    • Insurance Law
    • Travel insurance
  • Contact Us
No Result
View All Result
marketibiza
  • Home
  • Auto insurance
  • Business insurance
  • Cyber insurance
  • Disability insurance
  • Health insurance
    • Life insurance
    • Insurance Law
    • Travel insurance
  • Contact Us
No Result
View All Result
marketibiza
No Result
View All Result
Home Cyber insurance

CISA’s 2024 KEV Catalog Replace: Vulnerabilities And Traits

admin by admin
2025年1月6日
in Cyber insurance
0
CISA’s 2024 KEV Catalog Replace: Vulnerabilities And Traits
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter


In 2024, the U.S. Cybersecurity and Infrastructure Safety Company (CISA) continued to construct on its important cybersecurity initiative by increasing its Identified Exploited Vulnerabilities (KEV) catalog.  

You might also like

U.S. DDoS Assaults Launched By Professional-Iran Hacktivists

Gefährliche Lücke in Brother-Druckern

Senator Chides FBI for Weak Recommendation on Cell Safety – Krebs on Safety

This database, which serves as a significant instrument for IT safety groups and organizations globally, added 185 new vulnerabilities this 12 months, bringing the whole variety of software program and {hardware} flaws at excessive threat of exploitation to 1,238. These vulnerabilities, that are actively being focused by cybercriminals, can pose extreme dangers to infrastructure, data security, and operations throughout numerous sectors. 

The regular progress of the KEV catalog, launched in November 2021, highlights the persistent menace posed by cyberattacks. This text explores the numerous traits within the KEV catalog for 2024, identifies the most typical vulnerabilities, and discusses the distributors that confronted the very best variety of software program flaws this 12 months. 

A Regular Development within the KEV Catalog 

CISA’s KEV catalog has seen a constant enhance within the variety of entries since its inception. In 2024, 185 vulnerabilities had been added, barely fewer than the 187 added in 2023. This secure price of latest entries follows a extra explosive growth within the early years of the catalog. In 2022, CISA added over 500 vulnerabilities within the first six months, and the preliminary launch noticed greater than 300 entries. 

Curiously, the catalog has not solely grown within the variety of new vulnerabilities but in addition within the age of vulnerabilities included. Whereas most of this 12 months’s entries had been latest (115 from 2024), a good portion (60 to 70) nonetheless consists of older vulnerabilities that stay actively exploited.  

Notably, among the earliest vulnerabilities, like CVE-2002-0367, courting again to 2002, proceed to pose a threat, being leveraged in ransomware assaults. The oldest addition to the 2024 KEV catalog was CVE-2012-4792, a Use-After-Free vulnerability present in Microsoft Web Explorer variations 6 by way of 8. 





Your browser does not support the video tag.

Prominent Software Weaknesses in the KEV Catalog 

Among the 185 new entries in 2024, several software weaknesses, known as Common Weakness Enumerations (CWEs), were particularly prevalent. These weaknesses expose critical vulnerabilities that cybercriminals can exploit to gain unauthorized access to systems, disrupt services, or steal sensitive data. 

The commonest vulnerability kind within the KEV catalog this 12 months was CWE-78 (OS Command Injection), present in 14 of the added vulnerabilities. OS command injection happens when an attacker is ready to inject malicious instructions right into a system that’s working an working system, probably resulting in unauthorized management. 

CWE-502 (Deserialization of Untrusted Information) was the second most typical vulnerability kind, showing in 11 of the brand new entries. This weak point permits attackers to exploit improperly dealt with or deserialized information, which might result in distant code execution or unauthorized entry. 

Different notable vulnerabilities included CWE-416 (Use After Free), which appeared in 10 vulnerabilities, and CWE-22 (Path Traversal) and CWE-287 (Improper Authentication), each of which accounted for 9 vulnerabilities every. 

Main Distributors with the Most Vulnerabilities in CISA KEV 

Microsoft continued to dominate the checklist of distributors with vulnerabilities added to the KEV catalog. In 2024, Microsoft had 36 vulnerabilities added to the checklist, up from 27 in 2023. The corporate’s widespread presence throughout enterprise methods, cloud platforms, and software program merchandise makes it a frequent goal for cyberattacks. 

Following Microsoft, Ivanti was the second most affected vendor, with 11 vulnerabilities added to the KEV catalog. This contains important flaws that had been exploited in a high-profile breach of CISA itself by way of an Ivanti vulnerability. Cyble’s honeypot sensor detected energetic assaults concentrating on Ivanti’s vulnerabilities as early as January 2024. 

Different main distributors that confronted a number of variety of vulnerabilities in 2024 included Google Chromium (9 vulnerabilities), Adobe (8 vulnerabilities), and Apple (7 vulnerabilities). Distributors like Cisco, D-Hyperlink, Palo Alto Networks, and Apache additionally had a number of vulnerabilities added to the checklist, highlighting the broad vary of industries and applied sciences impacted by these weaknesses. 

A notable instance of a vulnerability from 2024 is CVE-2024-39717, a 7.2-severity problem in Versa Director. Regardless of having simply 31 web-exposed cases, this vulnerability was exploited in provide chain assaults concentrating on Internet Service Suppliers (ISPs) and Managed Service Suppliers (MSPs). This highlights a important facet of the KEV catalog: the severity of a vulnerability doesn’t all the time align with its publicity or CVSS (Widespread Vulnerability Scoring System) rating. Even vulnerabilities with low publicity might be extremely damaging if leveraged in focused assaults. 

Associated

Share30Tweet19
admin

admin

Recommended For You

U.S. DDoS Assaults Launched By Professional-Iran Hacktivists

by admin
2025年7月3日
0
U.S. DDoS Assaults Launched By Professional-Iran Hacktivists

Iran-aligned hacktivists launched DDoS assaults in opposition to 15 U.S. organizations and 19 web sites within the first 24 hours after the U.S. bombed Iranian nuclear targets on...

Read more

Gefährliche Lücke in Brother-Druckern

by admin
2025年7月2日
1
Gefährliche Lücke in Brother-Druckern

srcset="https://b2b-contenthub.com/wp-content/uploads/2025/06/shutterstock_2628495169.jpg?high quality=50&strip=all 4032w, https://b2b-contenthub.com/wp-content/uploads/2025/06/shutterstock_2628495169.jpg?resize=300percent2C168&high quality=50&strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2025/06/shutterstock_2628495169.jpg?resize=768percent2C432&high quality=50&strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/06/shutterstock_2628495169.jpg?resize=1024percent2C576&high quality=50&strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2025/06/shutterstock_2628495169.jpg?resize=1536percent2C864&high quality=50&strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2025/06/shutterstock_2628495169.jpg?resize=2048percent2C1152&high quality=50&strip=all 2048w, https://b2b-contenthub.com/wp-content/uploads/2025/06/shutterstock_2628495169.jpg?resize=1240percent2C697&high quality=50&strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2025/06/shutterstock_2628495169.jpg?resize=150percent2C84&high quality=50&strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2025/06/shutterstock_2628495169.jpg?resize=854percent2C480&high quality=50&strip=all 854w, https://b2b-contenthub.com/wp-content/uploads/2025/06/shutterstock_2628495169.jpg?resize=640percent2C360&high...

Read more

Senator Chides FBI for Weak Recommendation on Cell Safety – Krebs on Safety

by admin
2025年7月2日
0
Senator Chides FBI for Weak Recommendation on Cell Safety – Krebs on Safety

Brokers with the Federal Bureau of Investigation (FBI) briefed Capitol Hill employees just lately on hardening the safety of their cell units, after a contacts checklist stolen from...

Read more

Bert Ransomware: What You Want To Know

by admin
2025年7月1日
1
Bert Ransomware: What You Want To Know

What's the Bert ransomware?Bert is a recently-discovered pressure of ransomware that encrypts victims' recordsdata and calls for a fee for the decryption key.Why is it known as Bert?I...

Read more

A Should-Have for Monetary Establishments

by admin
2025年7月1日
0
A Should-Have for Monetary Establishments

Within the very dynamic monetary world of 2025 which is reworking at a breakneck pace, safety of delicate data has come to be a base of operational integrity....

Read more
Next Post
How do family no-claim reductions work?

How do family no-claim reductions work?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Auto insurance
  • Business insurance
  • Cyber insurance
  • Disability insurance
  • Health insurance
  • Insurance Law
  • Life insurance
  • Travel insurance

Trending News

‘Considerably missing’: Organisations falling brief on AI insurance policies

‘Considerably missing’: Organisations falling brief on AI insurance policies

2025年7月3日
U.S. DDoS Assaults Launched By Professional-Iran Hacktivists

U.S. DDoS Assaults Launched By Professional-Iran Hacktivists

2025年7月3日

What Is A DP1 Coverage And How Does It Work?

2025年7月3日

Greatest Automotive Insurance coverage In Illinois For Your Auto!

2025年7月3日
Gefährliche Lücke in Brother-Druckern

Gefährliche Lücke in Brother-Druckern

2025年7月2日
Allstate to current at William Blair Development Inventory Convention on June 5

Allstate completes sale of Group Well being enterprise

2025年7月2日
Frequent Errors That Usually Lead To Denied Florida Social Safety Incapacity Claims

Frequent Errors That Usually Lead To Denied Florida Social Safety Incapacity Claims

2025年7月2日

Market Biz

Welcome to Marketi Biza The goal of Marketi Biza is to give you the absolute best news sources for any topic! Our topics are carefully curated and constantly updated as we know the web moves fast so we try to as well.

CATEGORIES

  • Auto insurance
  • Business insurance
  • Cyber insurance
  • Disability insurance
  • Health insurance
  • Insurance Law
  • Life insurance
  • Travel insurance

Recent News

‘Considerably missing’: Organisations falling brief on AI insurance policies

‘Considerably missing’: Organisations falling brief on AI insurance policies

2025年7月3日
U.S. DDoS Assaults Launched By Professional-Iran Hacktivists

U.S. DDoS Assaults Launched By Professional-Iran Hacktivists

2025年7月3日
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions

Copyright © 2023 Market Biz All Rights Reserved.

No Result
View All Result
  • Home
  • Auto insurance
  • Business insurance
  • Cyber insurance
  • Disability insurance
  • Health insurance
  • Insurance Law
  • Life insurance
  • Travel insurance
  • Contact Us

Copyright © 2023 Market Biz All Rights Reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?