KEVs Open the Door, Ransomware Kicks It In: The Lifecycle of a Known Exploited Vulnerability

kimb3r (Product Manager and Exploitation Researcher @ VulnCheck)

SAINTCON 2025 · Day 4 · Main Track 3

Overview

In this insightful SAINTCON presentation, Kimber, Director of Product at VulnCheck and President of 801 Labs, dissects the multifaceted lifecycle of a Known Exploited Vulnerability (KEV), illustrating how these critical security flaws rapidly escalate from initial discovery to widespread exploitation by ransomware gangs. The talk serves as a crucial guide for vulnerability management professionals, offering a pragmatic framework for understanding attacker motivations and the progression of threats. Kimber challenges the traditional reliance on static vulnerability scoring, advocating for a dynamic, context-rich approach to defense that leverages exploit intelligence.

Watch on YouTube

Visual summary for KEVs Open the Door, Ransomware Kicks It In: The Lifecycle of a Known Exploited Vulnerability by kimb3r
Visual summary for KEVs Open the Door, Ransomware Kicks It In: The Lifecycle of a Known Exploited Vulnerability by kimb3r

Key moments

  1. 0:00 Introduction and speaker background
  2. 2:00 Defining Known Exploited Vulnerabilities (KEVs) and CISA
  3. 3:40 The pyramid of vulnerability states: CVEs to KEVs
  4. 5:45 Stage 1: Initial exploitation and hacker choices
  5. 8:00 Identifying signals of initial exploitation in logs
  6. 8:50 Stage 1.5: Proof of Concept (PoC) roulette

KEVs Open the Door, Ransomware Kicks It In: The Lifecycle of a Known Exploited Vulnerability

Speakers: kimb3r, Director of Product and Exploitation Researcher @ VulnCheck

Conference: SAINTCON

YouTube: https://www.youtube.com/watch?v=Pl6wFU6cqUs

Overview

In this insightful SAINTCON presentation, Kimber, Director of Product at VulnCheck and President of 801 Labs, dissects the multifaceted lifecycle of a Known Exploited Vulnerability (KEV), illustrating how these critical security flaws rapidly escalate from initial discovery to widespread exploitation by ransomware gangs. The talk serves as a crucial guide for vulnerability management professionals, offering a pragmatic framework for understanding attacker motivations and the progression of threats. Kimber challenges the traditional reliance on static vulnerability scoring, advocating for a dynamic, context-rich approach to defense that leverages exploit intelligence.

The core premise of the presentation revolves around the idea that while KEV lists, such as those maintained by CISA, are valuable, they represent only a snapshot in time and lack the granular context needed for truly proactive defense. Kimber argues that by understanding the predictable, albeit "amorphous blob" nature of a vulnerability's journey through various stages of exploitation – from proof-of-concept development to botnet integration, phishing campaigns, and ultimately ransomware deployment – organizations can shift from reactive patching to a more strategic, intelligence-driven security posture.

This deep dive into the KEV lifecycle is particularly pertinent in today's threat landscape, where the speed of weaponization is accelerating, and the financial incentives for cybercriminals are immense. The talk emphasizes that recognizing the early signs of exploitation and understanding the full "exploit chain" can empower defenders to prioritize patches, enhance detection engineering, and build more resilient systems against the most impactful threats, including sophisticated ransomware campaigns that now affect not just enterprises but also individuals.

Background

▶ Watch: Introduction and speaker background (0:00)

The concept of a Known Exploited Vulnerability (KEV) has gained significant traction, largely due to the efforts of the Cybersecurity and Infrastructure Security Agency (CISA). CISA, a U.S. government entity responsible for federal cybersecurity, established Binding Operational Directive (BOD) 22-01. This directive mandates that all federal entities remediate vulnerabilities present on CISA's KEV catalog within two weeks of their listing. While this initiative aims to enhance the security posture of government systems, Kimber raises a critical question: is this list truly helping the broader security community, or does it merely scratch the surface of a much deeper problem?

To frame the problem, Kimber introduces a "pyramid of vulnerabilities," illustrating the progression of a security flaw from its initial identification to widespread exploitation. At the base of this pyramid are all CVEs (Common Vulnerabilities and Exposures) – a vast database of disclosed vulnerabilities. Historically, the belief was that tracking and patching all CVEs would secure systems. However, the reality is far more complex. Above CVEs, the pyramid ascends through proof-of-concept (PoC) code, which then evolves into weaponized exploits. At the apex of this pyramid are Known Exploited Vulnerabilities, signifying that these flaws are actively being leveraged in the wild, often by sophisticated threat actors or integrated into broader criminal campaigns. This prevalence implies that if a vulnerability reaches this stage, it is almost guaranteed to be targeted, driving a continuous cycle of exploitation fueled largely by financial gain.

The speaker's work at VulnCheck, an exploit intelligence data company, has provided an opportunity to delve deeply into the practical aspects of vulnerability management and the actual mechanics of the exploitation lifecycle. This experience has highlighted that while foundational vulnerability scoring systems like CVSS (Common Vulnerability Scoring System) provide a severity metric, and models like EPSS (Exploit Prediction Scoring System) offer a probability of exploitation within 30 days, they often lack the critical contextual evidence of how a vulnerability is being exploited and by whom. This gap in understanding is precisely what the detailed KEV lifecycle aims to address, moving beyond a simple "true or false" assessment of exploitation to a nuanced understanding of its real-world impact and progression.

Key Findings

▶ Watch: The pyramid of vulnerability states: CVEs to KEVs (3:40)

Kimber's presentation highlights several key findings regarding the lifecycle of known exploited vulnerabilities, emphasizing its dynamic and often non-linear nature. The central finding is that the KEV lifecycle is an "amorphous blob," not a rigid, predictable sequence of events, yet it exhibits discernible patterns that defenders can leverage. This understanding moves beyond traditional vulnerability metrics to incorporate crucial exploit intelligence and threat context.

Firstly, the talk underscores that initial exploitation is rapidly followed by the development and proliferation of proof-of-concept (PoC) code. This PoC phase, while characterized by uncertainty, is critical as it often dictates the speed at which a vulnerability transitions from theoretical to practical exploitation. The speaker notes that the existence of multiple PoCs is beneficial for defenders, as it aids in developing robust detection rules. However, it also introduces risks, such as the emergence of malicious PoCs designed to ensnare hurried researchers.

Secondly, a significant finding is the swift automation and integration of exploits into botnets. This stage marks a critical shift from targeted attacks to widespread scanning and compromise, particularly for network edge devices. The ability for script kiddies and crimeware groups to rent botnet access on the dark web further democratizes exploitation, making it accessible to a broader range of malicious actors and obscuring their identities.

Thirdly, the lifecycle often sees exploits being adopted into phishing kits, targeting a specific subset of vulnerabilities that can be weaponized through malicious documents or emails. This stage also introduces the concept of Initial Access Brokers (IABs), who exploit networks and then sell access to other, often more sophisticated, threat actors. This market for initial access significantly extends the dwell time of attackers and complicates attribution.

Finally, the talk positions ransomware deployment as the ultimate, high-value end goal for many exploitation campaigns. This stage rarely involves a single vulnerability but rather an "exploit chain" – a combination of multiple exploits to achieve deeper access, root privileges, or full environment ownership. The rise of Ransomware-as-a-Service (RaaS) groups further streamlines this process for criminals, making ransomware a pervasive threat with far-reaching real-world impacts on both enterprises and individuals. The speaker stresses that contextual evidence—such as threat actor discussions, the availability of kits, and public disclosures like 8K filings—provides invaluable insight into the severity and immediacy of a threat, far beyond what traditional scoring systems can convey.

Technical Deep Dive

▶ Watch: Stage 1: Initial exploitation and hacker choices (5:45)

The technical deep dive into the KEV lifecycle, as presented by Kimber, meticulously breaks down the journey of a vulnerability from its nascent discovery to full-blown criminal exploitation. This progression is not strictly linear but rather a dynamic interplay of various actors and technical developments, often driven by the pursuit of profit.

Stage 1: Initial Exploitation

The lifecycle begins with the initial exploitation of a vulnerability. Computers, by their very nature, are susceptible to flaws, and dedicated individuals are constantly seeking to manipulate these systems. Once a bug is found, the discoverer faces an ethical choice: responsible disclosure or criminal exploitation. Responsible disclosure typically involves reporting the bug to a CVE Naming Authority (CNA), leading to the birth of a CVE. This process is encouraged by bug bounty programs from platforms like HackerOne and Bugcrowd, which incentivize ethical hacking. Conversely, choosing the "crimey way" means developing the exploit for illicit gain, often involving cryptocurrency.

From a defensive perspective, signals of initial exploitation include in-the-wild scanning and notifications from various KEV lists. Many security vendors are now developing their own KEV lists to alert customers. CISA's KEV list is noted for its "highest fidelity evidence of exploitation," meaning the agency has strong proof of active exploitation. However, a significant limitation is that CISA often does not provide specific references, proof, or Indicators of Compromise (IoCs), making it a "true or false" assessment for defenders without deeper context.

Stage 1.5: Proof of Concept (PoC) Roulette

This stage is characterized by the most uncertainty regarding the precise nature of exploitation. When a CVE is disclosed, security researchers and malicious actors alike engage in patch diffing – comparing vulnerable and patched versions of software to identify changes and develop exploit code. The goal for ethical researchers is to prove viable exploitation paths to aid in defense development. For criminals, it's to be the first to develop a working exploit for high-value targets.

A crucial aspect here is the proliferation of PoC code, often on platforms like GitHub. While more PoCs can lead to better detection rules, this phase also presents a significant risk: malicious PoCs. The speaker warns that in the rush to understand a new CVE, security professionals might download and execute unvalidated PoC code, only to find it's a crypto miner or other malware. The advice is clear: always validate sources, scrutinize code, and use sandboxes. This highlights a cat-and-mouse game where attackers leverage the defender's urgency.

Stage 2: Automation and Botnets

Once PoC code becomes stable and reliable, it enters the realm of automation and botnets. This is where "script kiddies" and organized crimeware groups adopt the exploit. Exploits are integrated into botnets, which then autonomously scan the internet for vulnerable systems. This is particularly prevalent for network edge devices such as Palo Alto, Cisco, and F5 appliances, which are frequently exposed to the internet.

The scale of this stage is massive, with research groups deploying honeypots globally to detect these waves of scanning activity. This allows for predictive intelligence regarding emerging threats. A key technical aspect is the obfuscation of the attacker's identity; criminals can rent botnet services on the dark web to launch attacks, making attribution challenging. Defensive signals include a surge in telemetry reported by threat intelligence companies like Grey Noise and Shadow Server, as well as discussions on social media.

Stage 3: Adoption into Phishing Kits

A subset of CVEs, particularly those that can be weaponized through user interaction, progresses to adoption into phishing kits. This includes vulnerabilities that can be triggered by malicious PDFs, macro-enabled documents, or other crafted files sent via email. Exploit developers sell these ready-made exploits to groups specializing in creating and distributing phishing campaigns.

This stage also introduces Initial Access Brokers (IABs). These actors infiltrate networks, often through phishing or similar techniques, and then sell access to the compromised "boxes" to other threat actors. This explains some instances of longer dwell times in compromised networks, as the IAB maintains access while seeking a buyer. Monitoring this phase relies heavily on OSINT (Open-Source Intelligence), including tracking discussions in threat actor group chats on platforms like Telegram and monitoring exposed phishing panels.

Stage 4: Ransomware Deployment

The pinnacle of the KEV lifecycle, and often the ultimate financial goal for many attackers, is ransomware deployment. This is rarely a single-exploit event. Instead, it typically involves an exploit chain – a sequence of multiple vulnerabilities and techniques chained together to achieve deeper access, escalate privileges, and ultimately deploy ransomware across an environment. The objective is often to gain root access or full ownership of the target environment.

The rise of Ransomware-as-a-Service (RaaS) groups has professionalized this stage. These groups specialize in the deployment and negotiation aspects of ransomware, allowing other criminal entities to leverage their expertise without needing to develop the entire exploit chain themselves. The real-world impact of this stage is profound, extending beyond enterprises to affect individuals, including vulnerable populations, as highlighted by examples like AARP articles discussing ransomware targeting seniors. Defensive signals include data leaks, the availability of ransomware kits in underground markets, and, most tellingly, 8K filings by publicly traded companies disclosing ransomware incidents and financial losses. These filings often precede public notifications of data breaches.

Demo / Proof of Concept

▶ Watch: Identifying signals of initial exploitation in logs (8:00)

Kimber provided a compelling real-world example to illustrate the rapid progression through the KEV lifecycle, focusing on a Palo Alto Networks exploit, CVE-2024-3400. This vulnerability, described as prolific and subject to constant scanning, demonstrates the accelerated timeline from disclosure to weaponization and ransomware interest.

The timeline for CVE-2024-3400 was exceptionally condensed:

  • April 12th: The official NVD (National Vulnerability Database) published the CVE. Simultaneously, both VulnCheck and CISA added it to their respective known exploitation lists, indicating active exploitation in the wild. The first reported threat actor was also observed on this date, essentially making it a zero-day event for many.
  • April 13th: Just one day later, discussions among ransomware groups concerning CVE-2024-3400 began to emerge, signifying their immediate interest in leveraging the flaw for financial gain.
  • April 17th: The first weaponized exploit for CVE-2024-3400 was publicly published. This marked the point where reliable exploit code became widely available, transitioning the vulnerability from a theoretical threat to a readily exploitable one.

From a defender's perspective, this rapid sequence of events highlights the urgency required. Kimber explained that security teams, armed with knowledge of the CVE's high CVSS score, high EPSS predictability, and crucially, the immediate threat actor and ransomware group interest, would have compelling evidence to push for emergency patching. The speaker, drawing on experience at Grey Noise, described the internet traffic for CVE-2024-3400 as showing "exponential growth" after the weaponized exploit was released. Initially, traffic would consist of "attempts that won't work" or "attempts that are trying to work," but then it would spike dramatically, indicating widespread, successful exploitation attempts. This real-time observation underscored that once a weaponized exploit is available, the vulnerability enters the "ecosystem" of active threats, leading to tangible harm that could have been prevented with proactive measures.

Defensive Implications

▶ Watch: Stage 1.5: Proof of Concept (PoC) roulette (8:50)

Understanding the KEV lifecycle is paramount for defenders seeking to move beyond reactive vulnerability management to a proactive, intelligence-driven security posture. Kimber emphasizes that relying solely on traditional scoring systems like CVSS (severity), EPSS (30-day probability of exploitation), and even SSBC (a CISA-developed decision framework) is insufficient. What's missing is the contextual evidence of exploitation – the "how bad is it going to be?" factor. Defenders need to know whether the activity in the wild is merely "script kiddies throwing really bad proof of concept code" or if it's an "advanced ransomware group who is actively getting millions of dollars from this kind of exploit chain."

To operationalize this understanding, several strategic shifts are recommended:

  1. Prioritize Patches with Lifecycle Context: While basic prioritization based on severity is standard, understanding the current stage of a vulnerability within its exploitation lifecycle allows for more intelligent resource allocation. A CVE that has entered the botnet or ransomware deployment phase demands immediate attention, regardless of its raw CVSS score, due to its proven, active threat.
  1. Shift to Alerting and Threat Modeling: Beyond simply patching, organizations must develop repeatable processes for alerting and threat modeling. This involves asking critical questions:
  • Do network defenses exist and are they operationalized?
  • If a botnet compromises an entry point, what can it do, and how would we detect it?
  • For CVEs associated with ransomware or phishing, who in the organization frequently reads emails, who is most likely to click malicious links, and what are the potential lateral movement paths if those individuals are exploited?
  1. Enhance Detection Engineering: The lifecycle framework provides a continuous improvement program for detection engineering. Defenders should regularly verify that their existing detections catch variations on known exploitation. If a Microsoft Word vulnerability has been "mitigated" with a block rather than a full patch, it's crucial to confirm that the block is effective against active exploitation. Furthermore, understanding why a patch isn't being applied for a ransomware-associated vulnerability is critical, helping to assess whether the organization is accepting a continuous, high-level risk or if there's a strategic reason for deferring the optimal remediation.
  1. Recognize Early Signs for Proactive Defense: The most significant implication is the ability to recognize early signs of progression through the lifecycle. Knowing that a vulnerability is in the "unknown phase" of PoC development, or seeing an article referencing a threat actor, can signal that ransomware or phishing campaigns might be next. This allows for a proactive approach – deploying temporary mitigations, enhancing monitoring, and preparing for a potential incident – rather than a trailing, reactive one. The goal is to avoid overwhelming vulnerability management teams with endless lists and instead provide them with the right context to develop and mature their security programs.

Key Takeaways

  • The KEV lifecycle is dynamic and amorphous but predictable: While not strictly linear, vulnerabilities progress through discernible stages from initial exploitation to ransomware, driven by attacker motivations.
  • Contextual exploit intelligence is crucial: Beyond CVSS, EPSS, and SSBC scores, understanding how and by whom a vulnerability is being exploited provides essential context for effective prioritization and defense.
  • Proactive defense relies on recognizing early signs: Identifying a vulnerability's stage in the lifecycle (e.g., PoC roulette, botnet integration) enables defenders to anticipate threats and implement proactive measures before widespread impact.
  • Prioritize patching based on lifecycle stage: Vulnerabilities actively used by ransomware groups or integrated into botnets demand immediate attention, even if their raw severity score might seem moderate.
  • Threat modeling and detection engineering are key operational defenses: Organizations must develop repeatable processes to threat model entry points, identify high-risk users for phishing, and continuously verify that their detections and mitigations are effective against evolving exploitation techniques.
  • Beware of malicious Proof-of-Concept (PoC) code: In the rush to understand new vulnerabilities, security professionals must exercise caution, validate sources, and sandbox PoC code to avoid becoming victims of secondary attacks like crypto miners.

About the Speaker(s)

Kimber is a prominent figure in the cybersecurity community, serving as the Director of Product at VulnCheck, an exploit intelligence data company. In this role, Kimber specializes in exploitation research, contributing to a deeper understanding of vulnerability management and the actual lifecycle of exploited flaws. Beyond her corporate responsibilities, Kimber is also the President of 801 Labs, a hacker space located in Salt Lake City, demonstrating a strong commitment to fostering community and knowledge sharing within the cybersecurity domain.

Kimber's extensive career experience spans various critical areas of cybersecurity, including threat intelligence, detection engineering, threat hunting, and Managed Detection and Response (MDR). She has also delved into compliance, showcasing a broad expertise across the security spectrum. While humorously stating she would "never do pen testing," her passion for "running cables through buildings and weird signals" provides a unique perspective on the foundational elements that underpin secure systems. This diverse background and deep-seated interest in the intricacies of system vulnerabilities make her a highly credible and insightful voice on the subject of known exploited vulnerabilities.

All talks from SAINTCON 2025