Cybersecurity and Infrastructure Security Agency
The United States Cybersecurity and Infrastructure Security Agency. Continuously publishes vulnerability advisories, active-threat alerts, industrial control system advisories and the Known Exploited Vulnerabilities catalogue. A reference operational feed on actively exploited vulnerabilities.
Dissemination based on agency intelligence, vendor reporting and partner coordination. The Known Exploited Vulnerabilities catalogue rests on evidence of actual exploitation, making it a prioritisation signal rather than an exhaustive inventory.
Use to track actively exploited vulnerabilities and support a technical exposure assessment. Relevant for cyber underwriting and software-accumulation analysis.