WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Ransomware Trend Awareness – New Vulnerabilities Utilized in Q1 2023 Ransomware Attacks
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Ransomware Trend Awareness – New Vulnerabilities Utilized in Q1 2023 Ransomware Attacks

Author: April Zupan

Created: Thursday, May 25, 2023 - 17:07

Categories: Cybersecurity

HelpNetSecurity provided a summary on a recent report produced by researchers at Ivanti, Securin, and Cyware discussing ransomware-related vulnerabilities for Q1 2023. Twelve new vulnerabilities have become associated with ransomware over this period, 73 percent of which are trending on the deep and dark web. Eighteen ransomware-associated vulnerabilities are currently not being detected by popular scanners, and 119 are present in open-source code that multiple vendors and products utilize.

In addition to vulnerabilities, the document also tracks weakness categories that make products and organizations more at risk of being successfully targeted by ransomware and an analysis of how these vulnerabilities interact with the MITRE ATT&CK® Framework. Read more at HelpNetSecurity.

Analyst note (Jennifer Lyn Walker): This report references the MITRE ATT&CK® Framework as a “kill chain.” This is a misnomer and appears to be confounded with the well-known Lockheed Martin Cyber Kill Chain®. ATT&CK® is a knowledge base of adversary tactics and techniques based on real-world observations. While ATT&CK® does have tools to build out an attack model/path, to the best of my knowledge MITRE intentionally does not refer to “kill chain” so as not to cause confusion.

Despite this confusion, at first blush, this comprehensive report has practical information on currently observed ransomware attack trends that should be useful in updating and prioritizing cyber defenses.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar