WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Security Awareness – Majority of Ransomware Attacks Last Year Exploited Old Vulnerabilities
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Security Awareness – Majority of Ransomware Attacks Last Year Exploited Old Vulnerabilities

Author: Alec Davison

Created: Tuesday, February 21, 2023 - 20:07

Categories: Cybersecurity, Security Preparedness

Many of the vulnerabilities successfully exploited by ransomware groups in 2022 were years old and permitted attackers to establish persistence and move laterally to compromise an organization, according to new research from the IT company Ivanti.

Ivanti’s latest report offers an in-depth look at vulnerabilities threat actors commonly exploited in ransomware attacks last year. These vulnerabilities were found in numerous products, such as Microsoft, Oracle, VMware, F5, and SonicWall. According to the report, ransomware gangs exploited a total of 344 unique vulnerabilities in attacks last year—an increase of 56 compared to 2021. Of this, 76 percent of the flaws were from 2019 or before. This report is notable as it emphasizes the importance of keeping IT systems patched. Indeed, a joint cybersecurity advisory issued last year highlighted the top vulnerabilities attackers were exploiting on systems and networks that remained unpatched.

Ivanti identified 57 vulnerabilities as presenting the greatest danger, since they offer threat actors with the capability to execute a complete attack. For instance, these vulnerabilities allow an attacker to gain initial access, maintain persistence, escalate privileges, evade defenses, access credentials, move laterally, collect sensitive data, and execute their final mission. Notably, 131 of the 344 flaws ransomware attackers exploited last year are not included in CISA’s Known Exploited Vulnerabilities (KEV) catalog. Lastly, the report found attackers tended to prefer flaws that exist across multiple products. Read more at DarkReading.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 18, 2026)

Jun 18, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness
Members Only

(TLP:AMBER) IOC Associated with Volt Typhoon Performed Network Enumeration on Utah Infrastructure

Jun 18, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Email Impersonation Remains a Persistent Risk for Water Utilities

Jun 18, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar