Many successful cyberattacks do not begin with a mysterious new zero-day. They begin with an internet-facing firewall, VPN, server or application that is running a vulnerability already known to be exploited in the real world.
CISA maintains a Known Exploited Vulnerabilities catalogue specifically to identify vulnerabilities with evidence of active exploitation.
Recommended response
- Know which systems are exposed to the internet.
- Maintain an accurate device and software inventory.
- Prioritise patches for actively exploited vulnerabilities.
- Replace or isolate products that are no longer supported.
- Monitor firewalls, VPNs and remote-access systems for suspicious activity.
For small businesses, good patch management is one of the highest-value security controls because it removes known paths attackers are already using.
Source: CISA Known Exploited Vulnerabilities Catalog and Cybersecurity Advisories.