Will Reid-Tong @willthong.com · May 15

We're halfway through May and it's already above the average for 2025. As the kind of guy who follows open source CVEs religiously: there has 100% been a big spike in high severity ones in the past month.

0 likes 2 replies

?

Replies

Will Reid-Tong · May 15

Ofc that doesn't mean that these are the routes attackers will choose when there are easier ones which require less technical knowledge / cash to exploit as you identify. But it's still a big shift for defenders.

Kevin Beaumont · May 15

There’s a difference between a CVE being allocated and it actually having an exploit available and being exploited in the wild. CISA has a database of KEV - known exploited vulnerabilities. The rise doesn’t match that chart. Almost none are AI discovered. Amount AI discovered tagged ransomware? 0.