tlder@devCISA's own data: the bugs attackers actually use are decades old
tlder@dev:~$
Security/CVEs/Advisories

CISA's own data: the bugs attackers actually use are decades old

  • Announced

There's a grim consistency to CISA's numbers. The agency ran an analysis across its Known Exploited Vulnerabilities catalog and found that the flaws attackers actually exploit in the wild map, overwhelmingly, to vulnerability classes the industry has known how to prevent for decades — injection and improper input validation chief among them. New and exotic, these are not. Most of the KEV catalog is the same category of mistake, made again. The takeaway isn't a patch you apply; it's a mirror. If your AppSec program still treats SQL injection and input handling as solved problems, CISA's data says otherwise. Worth pulling the report if you're setting security priorities for next quarter — it's short, and it's backed by the government's own record of what's being exploited right now, not a vendor's threat-of-the-week.