DARKSIGNALS / PUBLIC PAGE

CISA KEV evidence model

Known exploited is not every kind of cyber risk.

Public scope

How to distinguish KEV inclusion, severity, exploit code, ransomware use and current exploitation.

Known exploited is not every kind of cyber risk.

  • KEV inclusion establishes a catalogue status, not a complete severity assessment.
  • Exploit code, ransomware use and current exploitation are separate propositions.
  • The public evidence model preserves the difference between a known exploited vulnerability and broader cyber risk.

Public sources

Reviewed public-source links used for this page are listed below.

Related public pages