You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<figcaption>Population Sizes associated with the Risk Remediation Taxonomy - Likelihood of Exploit branch. <br>Representative sizes and overlaps shown as there isn't authoritative exact data.</figcaption>
2615
2615
</figure>
2616
-
<p>TODO update venn with latest data - and add weaponized exploits</p>
2617
2616
<ol>
2618
-
<li>~~50% (~~100K) of all CVEs (~200K) have known exploits available (based on a commercial <abbrtitle="CTI Cyber Threat Intelligence.">CTI</abbr> product used by the author)</li>
2617
+
<li>~~50% (~~100K) of all CVEs (~200K) have known exploits Proof Of Concepts available (based on a commercial <abbrtitle="CTI Cyber Threat Intelligence.">CTI</abbr> product used by the author)</li>
2619
2618
<li>~~5% (~10K) of all CVEs are actively exploited <ol>
2620
2619
<li><strong>There isn't a single complete authoritative source for these CVEs</strong></li>
2621
2620
</ol>
2622
2621
</li>
2623
-
<li>~~10% of CVEs with Known Exploits Available (KEA) are known exploited</li>
2624
2622
<li>~~0.5% (~1K) of all CVEs (~200K) are in <abbrtitle="Cybersecurity & Infrastructure Security Agency">CISA</abbr> Known Exploited Vulnerability </li>
2625
-
<li>~~5% (50) of all <abbrtitle="Cybersecurity & Infrastructure Security Agency">CISA</abbr><abbrtitle="Known Exploited Vulnerability">KEV</abbr> CVEs (~1K) are not listed in Vendor DBs</li>
2626
2623
</ol>
2627
2624
<divclass="admonition note">
2628
2625
<pclass="admonition-title">CVEs represent a subset of all vulnerabilities. Your organization will have a subset of these CVEs</p>
<figcaption>Population Sizes associated with the Risk Remediation Taxonomy - Likelihood of Exploit branch. <br>Representative sizes and overlaps shown as there isn't authoritative exact data.</figcaption>
1510
1510
</figure>
1511
-
<p>TODO update venn with latest data - and add weaponized exploits</p>
1512
1511
<ol>
1513
-
<li>~~50% (~~100K) of all CVEs (~200K) have known exploits available (based on a commercial <abbrtitle="CTI Cyber Threat Intelligence.">CTI</abbr> product used by the author)</li>
1512
+
<li>~~50% (~~100K) of all CVEs (~200K) have known exploits Proof Of Concepts available (based on a commercial <abbrtitle="CTI Cyber Threat Intelligence.">CTI</abbr> product used by the author)</li>
1514
1513
<li>~~5% (~10K) of all CVEs are actively exploited <ol>
1515
1514
<li><strong>There isn't a single complete authoritative source for these CVEs</strong></li>
1516
1515
</ol>
1517
1516
</li>
1518
-
<li>~~10% of CVEs with Known Exploits Available (KEA) are known exploited</li>
1519
1517
<li>~~0.5% (~1K) of all CVEs (~200K) are in <abbrtitle="Cybersecurity & Infrastructure Security Agency">CISA</abbr> Known Exploited Vulnerability </li>
1520
-
<li>~~5% (50) of all <abbrtitle="Cybersecurity & Infrastructure Security Agency">CISA</abbr><abbrtitle="Known Exploited Vulnerability">KEV</abbr> CVEs (~1K) are not listed in Vendor DBs</li>
1521
1518
</ol>
1522
1519
<divclass="admonition note">
1523
1520
<pclass="admonition-title">CVEs represent a subset of all vulnerabilities. Your organization will have a subset of these CVEs</p>
0 commit comments