Cyber Security Works (CSW) reported 22 new vulnerabilities associated with ransomware in the first quarter, a 7.6% spike since January, and the time window to patch before vulnerabilities are exploited is getting shorter. 

CSW is a U.S. Department of Homeland Security-sponsored common vulnerabilities and exposures (CVEs) Numbering Authority, and it also offers attack surface management services. Its threat intelligence researchers found almost all the new vulnerabilities (21) are considered of critical or high-risk severity, and 19 are associated with the Conti ransomware gang.

Plus, 141 of Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEVs) are being used by ransomware operators including 18 new additions this quarter, according to the research

“If you look at ransomware, it's a business, it's financially motivated,” CSW CEO and co-founder Aaron Sandeen told SDxCentral. “That's the key here, and being able to understand what the association is between these bad acting groups and specific vulnerabilities and how they can be used as ransomware tools for them is absolutely critical.”

That’s why in addition to the CVE criticality scores, CSW also scans and identifies new vulnerabilities, and then offers extra intelligence on new ransomware capabilities to help customers prioritize their remediation efforts, he added.

“Today, on average, vulnerabilities are being weaponized within eight days of being published by the vendor,” Sandeen noted. “Latencies are dangerous windows of opportunities that are afforded to the attackers, and they spare no time in exploiting them.”

Meanwhile, vulnerability detection and reporting technologies are getting better as well, and “automation is key … quantum computing is starting to become a factor,” he said.

Additionally, the report revealed that 11 out of 22 new vulnerabilities remain undetected by popular scanners, and researchers noticed attackers are going after weaknesses associated with key products.

“Organizations will need to utilize attack surface management and perform additional application scanning to understand and prioritize vulnerabilities associated with ransomware,” Sandeen said.  

Patching Can be Overwhelming

For organizations short on talents and resources, even some large enterprises, patching vulnerabilities in a timely manner can be challenging. 

“I definitely think that risk-based vulnerability management goes a long way to helping organizations … because if you try to fix everything, you're gonna get overwhelmed,” Sandeen said. “So this intelligence and being able to pinpoint and prioritize is absolutely critical.”

Secondly, security teams should be able to develop concise communication about the risks, issues, and the impact of the vulnerabilities, along with solving options to the business side of the company, he added.

On top of the right resources, intelligence, and modern technologies, if the teams can shift the security left in DevSecOps and automate the process, “it gets away from having to patch, you're actually fixing from a remediation perspective,” Sandeen pointed out.

And basic security hygienes like backups can help too. “You have to have solid backup strategies so that if you do have something bad happen, you can revert to backups,” he said. "That's a fantastic remedy to ransomware.”