Network: Wedgetail Astrostrategy Cyberstrategy Geofinance Geopolitics Geostrategy Global Energy

Charts

Every chart names its source, the date it was retrieved and its licence, and ships with the underlying numbers as a table and a CSV.

3 charts on Cyberstrategy · Across the network

How fast CISA is adding known-exploited vulnerabilities

Additions to the CISA KEV catalog per month. Listing means confirmed exploitation, not merely a severe score.

0100200300vulnerabilities1 Nov 211 Jun 221 Jan 231 Aug 231 Mar 241 Oct 241 May 251 Dec 251 Jul 26
View as table
PeriodKEV additions (vulnerabilities)
2021-11-01291.0
2021-12-0120.0
2022-01-0140.0
2022-02-0132.0
2022-03-01226.0
2022-04-0145.0
2022-05-0183.0
2022-06-0148.0
2022-07-013
2022-08-0123.0
2022-09-0124.0
2022-10-0112.0
2022-11-0110.0
2022-12-019
2023-01-015
2023-02-0114.0
2023-03-0118.0
2023-04-0117.0
2023-05-0119.0
2023-06-0124.0
2023-07-0116.0
2023-08-018
2023-09-0119.0
2023-10-0118.0
2023-11-0118.0
2023-12-0111.0
2024-01-0121.0
2024-02-019
2024-03-0110.0
2024-04-0110.0
2024-05-0114.0
2024-06-019
2024-07-0114.0
2024-08-0119.0
2024-09-0125.0
2024-10-0117.0
2024-11-0122.0
2024-12-0116.0
2025-01-0114.0
2025-02-0127.0
2025-03-0132.0
2025-04-0115.0
2025-05-0124.0
2025-06-0120.0
2025-07-0120.0
2025-08-0115.0
2025-09-0116.0
2025-10-0131.0
2025-11-0111.0
2025-12-0120.0
2026-01-0117.0
2026-02-0128.0
2026-03-0126.0
2026-04-0131.0
2026-05-0121.0
2026-06-0123.0
2026-07-0126.0
2026-08-0131.0
2026-09-0124.0

Source: CISA · retrieved 17 Sep 2026 · Public domain (US Government)

Download CSV · Embed this chart

Read the interpretation →

The gap between a CVE being published and being known-exploited

How long vulnerabilities take to reach the KEV catalog after publication — a distribution, not an average.

0100200300days0–282846–1,1281,692–1,9742,538–2,8203,384–3,6664,230–4,5125,076–5,3585,922–6,204

Source: CISA / NVD · retrieved 17 Sep 2026 · Public domain (US Government)

Download CSV · Embed this chart

Read the interpretation →

Ransomware leak-site postings by sector

Victims claimed on extortion leak sites, by sector and month. These are claims made by the groups, not confirmed incidents.

  • Manufacturing
  • Not Found
  • Healthcare
  • Other sectors
  • Professional Services
  • Technology
  • Transportation
  • Agriculture and Food Production
  • Financial Services
  • Retail & E-Commerce
  • qilin
  • krybit
  • safepay
  • thegentlemen
  • akira
  • BrainCipher
  • Storm
  • incransom
  • lockbit5
  • metaencryptor
  • play
  • shinyhunters
  • Falcon
  • direwolf
  • SilentRansomGroup
  • AuditTeam
  • chaos
  • insomnia
  • Orova
  • spacebears
  • Wallstreet
  • emperador
  • everest
  • medusalocker
  • DYSPHOR1A
  • Eclipse
  • gunra
  • majinahanashi
  • anubis
  • aurora
  • Dark Project
  • iah6477
  • Panzer
  • Vexy Ransomware
  • Booba Project
  • dragonforce
  • Global Secret Group
  • rhysida
  • ShadowByt3$
  • unsafe
050100150200250postings1 Aug 261 Sep 263 Sep 265 Sep 267 Sep 2610 Sep 2612 Sep 2614 Sep 2616 Sep 26
View as table
PeriodManufacturing (postings)Not Found (postings)Healthcare (postings)Other sectors (postings)Professional Services (postings)Technology (postings)Transportation (postings)Agriculture and Food Production (postings)Financial Services (postings)Retail & E-Commerce (postings)qilin (postings)krybit (postings)safepay (postings)thegentlemen (postings)akira (postings)BrainCipher (postings)Storm (postings)incransom (postings)lockbit5 (postings)metaencryptor (postings)play (postings)shinyhunters (postings)Falcon (postings)direwolf (postings)SilentRansomGroup (postings)AuditTeam (postings)chaos (postings)insomnia (postings)Orova (postings)spacebears (postings)Wallstreet (postings)emperador (postings)everest (postings)medusalocker (postings)DYSPHOR1A (postings)Eclipse (postings)gunra (postings)majinahanashi (postings)anubis (postings)aurora (postings)Dark Project (postings)iah6477 (postings)Panzer (postings)Vexy Ransomware (postings)Booba Project (postings)dragonforce (postings)Global Secret Group (postings)rhysida (postings)ShadowByt3$ (postings)unsafe (postings)
2026-08-0163123325
2026-08-3119.018.07754433322222
2026-09-0121.09635.011.012.0664915.014.04787642643332
2026-09-02614.0510.0812.0647432222
2026-09-03415.0578811.034544322
2026-09-04715.08888673332225
2026-09-0512.015.05684368432226
2026-09-0612.065683984332472
2026-09-0713.045323410.07433249
2026-09-0810.010.021.043410.032333342
2026-09-10510.018.0543448733423
2026-09-11410.013.0845459334434
2026-09-12511.07846469334444
2026-09-13412.011.0754483354434
2026-09-14513.011.0534473364533
2026-09-1510.013.04664364243322
2026-09-1615.06830.043324222222

Source: ransomware.live · retrieved 16 Sep 2026 · Commercial use prohibited without publisher permission
Leak-site postings are claims made by ransomware groups, not confirmed or verified incidents.

Download CSV · Embed this chart

Read the interpretation →