GREPWISE

Nine, out of everything

The Known Exploited Vulnerabilities catalog is a public JSON file listing flaws confirmed to be under active attack rather than merely severe. It holds 1,665 entries, and only nine were added in the first eleven days of August. That is a queue you can actually work through, unlike the thousands of advisories published in the same period.

One thousand six hundred and sixty-five flaws confirmed under attack. Nine of them arrived this month.

Thousands of vulnerabilities are published every month. Patching by severity means a queue that never empties.

There is a much shorter list, and it is a public file you can query.

It records what is confirmed under active attack, not what might be. The catalog carries one thousand six hundred and sixty-five entries.

Filter to the ones added since the first of August, and there are nine. Nine, out of everything published in that time. One is a self-hosted analytics tool that scored the maximum and was used to reach a company’s entire customer list.

That is a queue you can finish. Severity tells you how bad something would be. This tells you what somebody is already doing.

Work this list first. It is a file, so you can automate it.

#linux#security#patching#infosec#sysadmin

❯ Work this list first. It is a file, so you can automate it.

cd ..