Send us Fan Mail
CISA adding a vulnerability to its Known Exploited Vulnerabilities catalog isn't a patch reminder anymore. It's the moment your insurer and your counterparty's diligence team start treating you as someone who was on notice, and if you didn't patch, that's on you.
In this episode, David Shaw walks through how the KEV catalog moved from a federal compliance tool to a market-facing liability standard, the exploited vulnerabilities in Oracle, SonicWall, VMware, Microsoft, and Citrix systems that drove that shift across July, August, and early September, what insurers and diligence teams now read into a KEV listing, and the three conversations every executive needs to have this week.
In this episode:
What the KEV catalog is, and why it moved from government plumbing to a market liability standard
The exploited flaws behind that shift: Oracle E-Business Suite Payments, SonicWall SMA1000, VMware vCenter, Microsoft AD FS and SharePoint, and Citrix NetScaler
How insurers and incident response firms cite KEV entries to build a documented record of notice
What KEV exposure means in M&A diligence, rep and warranty coverage, and escrow
The vendor-risk lesson from the Suno breach
The three conversations to have this week: with your IT lead or MSP, your insurer or broker, and your diligence team
Resources mentioned:
CISA Known Exploited Vulnerabilities (KEV) Catalog
CISA Binding Operational Directives 22-01 and 26-04
Beazley Security and eSentire advisories
Connect with David Shaw:
Website: corvus-cyber.com
LinkedIn: linkedin.com/in/djshaw
Email: [email protected]
The Rook · Corvus Cybersecurity · corvus-cyber.com · David Shaw, CISSP, GLEG