CISA’s vulnerability review of fiscal years 2024–2025 found that damaging compromises predominantly resulted from opportunistic exploitation of known, internet-exposed vulnerabilities and fundamental security failures—not zero-days or highly sophisticated campaigns. The affected weaknesses frequently involved memory safety, injection, and improper input validation; 41.5% of known exploited vulnerabilities mapped to persistent MITRE CWE Top 25 weakness classes.
CISA reported widespread risk from vulnerable exposed services, unsupported software, and deprecated SSL/TLS, and warned that CVSS scores alone are insufficient for remediation decisions. Its Binding Operational Directive 26-04 prioritization framework weighs internet exposure, Known Exploited Vulnerabilities Catalog status, likelihood of automated exploitation, and technical impact; recommended actions include rapidly remediating exposed KEVs, retiring end-of-support systems, strengthening input validation, and adopting Secure by Design practices such as memory-safe languages and SBOMs.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
CISA published its Vulnerability Review based on CISA and open-source data from fiscal years 2024 and 2025. The review found that many compromises stem from exploitation of exposed, well-known vulnerabilities and fundamental security failures, and promoted risk-based prioritization and Secure by Design practices.
CISA's review states that the Chinese state-sponsored Salt Typhoon group has exploited widely known, unpatched CVEs since at least 2021, targeting telecommunications, transportation, and military infrastructure worldwide.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetheregister.com
Open sourcesecurityonline.info
Open sourcecisa.gov
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.