This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Exploited CVEs of 2025: Lessons for Vendors and Defenders

Download resources

About this session

Patrick Garrity, a security researcher at VulnCheck, walks through what his team learned curating a free catalog of vulnerabilities confirmed exploited in the wild during the first half of 2025. He challenges the narrative of runaway CVE growth, showing most of the increase comes from WordPress plugins, open-source projects, and automated Linux disclosures rather than core enterprise software. Of 432 catalogued exploited vulnerabilities, roughly a third already had exploitation evidence on or before the day a CVE was even issued, and ransomware attribution consistently lags disclosure, so waiting for attribution before patching is too slow. He ranks threat by tier, known exploited, weaponized, and proof-of-concept, and shows CVSS severity barely shifts even when enriched with threat data, while EPSS scores for known exploited vulnerabilities climb only slowly over weeks. Network edge devices, content management systems, server software, and backup and virtualization stacks dominate real exploitation, alongside a handful of repeat nation-state actors. He closes on the EU Cyber Resilience Act, which requires 24-hour exploitation disclosure and 72-hour customer notification, and recommends prioritizing confirmed exploitation evidence over any single scoring system.

In 2025, It's estimated that over 500 vulnerabilities will be exploited in the wild for the first time. This talk will focus on the trends and patterns observed in these known exploited vulnerabilities year-to-date, offering comprehensive analysis to empower both vendors and defenders. Key Takeaways: Insights into 2025 exploited vulnerability trends and patterns. A look at how known exploitation maps to common vulnerability data. A deep dive into examples of this year's exploited vulnerabilities and how to identify risks before exploitation occurs. Recommendations on how vendors and defenders can get early indicators that a threat actor might exploit a vulnerability.

Key takeaways

  • Don't wait for threat-actor attribution before patching a known exploited vulnerability; attribution is consistently delayed well behind exploitation evidence, including for ransomware.
  • Treat network edge devices, content management systems, server software, and backup/virtualization stacks as your highest-exploitation categories and prioritize patching and mitigating controls there first.
  • Don't rely on CVSS severity alone to prioritize; base severity barely changes even when enriched with threat intelligence, so it can bury an actively exploited vulnerability under lower-priority items.
  • Treat EPSS as a slow-moving signal, not a real-time one; many confirmed exploited vulnerabilities still score in the lowest probability bucket weeks after exploitation was reported.
  • If you sell software into the EU, build a process now for 24-hour exploitation disclosure to authorities and 72-hour customer notification under the Cyber Resilience Act; fines scale with revenue.

Speakers

Patrick Garrity
Patrick Garrity
Security Researcher · Vulncheck
Patrick Garrity is a security researcher at VulnCheck where he focuses on vulnerabilities, vulnerability exploitation and threat actors. Patrick has spent the last decade helping building Cybersecurity companies including Duo Security, Censys… Read moreRead less

Patrick Garrity is a security researcher at VulnCheck where he focuses on vulnerabilities, vulnerability exploitation and threat actors. Patrick has spent the last decade helping building Cybersecurity companies including Duo Security, Censys, Blumira, Nucleus Security and VulnCheck.

Resources

Tags

More from GoSec 2025

Also from Patrick Garrity

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.