What CISA’s own ransomware advisories name
CISA publishes 25 advisories under its own '#StopRansomware:' banner. We read every one of them and counted what is written in it: the vulnerability identifiers it names, the techniques it lists, and whether CISA's own index links to it. This is a count of documents, not a description of how ransomware works.
Updated 29 September 2026 · all 25 advisories in the series, read from cisa.gov on 29 September 2026 · method and dataset below
What this counts, and what it does not
Every figure on this page is a statement about CISA’s documents. How any ransomware family actually gains access, how often vulnerabilities are exploited, and anything about victims. None of those is in this dataset.
- This is a count of what CISA's documents name. An advisory that names no CVE is not evidence that the ransomware family exploits no vulnerability. AA23-075A (LockBit 3.0) names no CVE while telling readers to 'prioritize remediating known exploited vulnerabilities'.
- AA23-325A is the clearest warning against misreading this dataset. It lists no Initial Access technique at all, yet it is specifically about exploitation of Citrix Bleed (CVE-2023-4966), which is named in its own title.
- AA24-242A's T1110.003 row reads 'RansomHub affiliates may use password spraying to obtain initial access' - CISA's own words - yet the row is printed under Credential Access. The prose and the coding disagree inside one cell of one advisory.
- n = 25. This is a census of a named series, not a sample, so there is no sampling error; but it is a small corpus, one advisory is four percentage points, and every cell has to be right. Each row carries its source URL, retrieval timestamp and the sha256 of the exact page parsed so any cell can be checked.
- Percentages on the per-year cuts are suppressed. No year has more than eleven advisories (2022: 6, 2023: 11, 2024: 4, 2025: 3, 2026: 1 to date), so those cuts are reported as counts and no percentage is given on them.
- These are living documents. Advisories carry version histories, and revisions are made inside table cells as well. Everything here is the versions retrieved on 2026-09-29; the counts can move when CISA revises an advisory.
- AA22-249A (Vice Society) is published at two URLs, /aa22-249a and /aa22-249a-0, with the same title, the same date, the same two CVEs and the same technique IDs. Counted once. A naive title match over every advisory URL returns 26 URLs for 25 advisories.
- The prefix test is applied case-insensitively as a defensive measure, because CISA's hashtag casing is not guaranteed across a series published over four years. It makes no difference to this population: all 26 strict-prefix pages carry the exact string '#StopRansomware:', so a case-sensitive test returns the same 26 URLs and the same 25 advisories.
- AA23-325A writes 'CVE 2023-4966' with a space in its own title, and AA23-040A writes 'CVE 2021-44228'. The extraction is hyphen-tolerant. Across all 178 advisory pages fetched, 11 contain an unhyphenated rendering; in none of them does it change the CVE set, because the same identifier also appears hyphenated elsewhere on the page. The tolerant pattern is correct practice but it rescued nothing here.
- CVEs are counted from the visible text, not from the markup. AA23-325A links to Citrix's own security bulletin, and that link's URL and title both carry CVE-2023-4967 - an identifier that appears nowhere in CISA's visible prose. A scan of the raw HTML would credit CISA with naming it. This is the only advisory in the series where the two rules differ, and it does not change the headline either way.
- Six advisories publish no version-history block at all. Their revision count is NULL, not zero: the series does not say whether they were never revised or whether the block is simply absent. Fifteen advisories show a 'Last Revised' date in the page header, and one of those - AA23-352A - carries no block, so revision counts are a floor.
- AA23-040A is in the series by the title rule but is not a per-family advisory: it describes state-sponsored activity funded by ransomware. 'Ransomware families' therefore describes 24 of the 25; the correct noun for the population is 'advisories'.
- Advisories cite five different MITRE ATT&CK framework versions (v12, v15, v16, v17, v19). Technique IDs and tactic placement can move between versions, so a technique coded under Initial Access in one advisory is not automatically the same coding as in another.
- Two advisories print, in their Initial Access tables, techniques ATT&CK assigns elsewhere: AA23-061A lists T1021.001 (Lateral Movement in ATT&CK) and AA23-352A lists T1059.001 (Execution). They are counted exactly as CISA printed them and listed separately, not silently corrected or dropped.
- AA25-071A puts the TACTIC id TA0001 in the ID column of its Initial Access table. It is not a technique id and is not counted as one.
- All 48 distinct CVEs named by the series are in CISA's KEV catalogue and all 48 are flagged knownRansomwareCampaignUse 'Known', against a catalogue base rate of 361 of 1,728 (20.9%). CISA maintains both the advisories and the flag, so this is internal consistency, not independent corroboration.
- CISA runs three StopRansomware listings and no two of them hold the same set. The maintained index at /stopransomware/official-alerts-statements-cisa links 38 advisories, 18 of them in the series. A second listing at /stopransomware/stopransomware runs newest first, and its newest entry is the Black Basta advisory of 10 May 2024 (AA24-131A), whose headline it prints as '#STOPRANSOMARE: BLACK BASTA'. A third sits at /stopransomware/alerts. None of them claims to cover the whole series, which is why the population was built from the sitemap and each advisory's own title, never from an index label.
- The reported ATT&CK coding is one machine-structural pass reconciled against one hand-coded pass, plus a third-method re-derivation and a cross-check against a separately written implementation that agreed on 24 of 25. It is not two blind human passes, and is not described as one.
- We found no prior published count of this series, and no machine-readable publication of CISA's AA-numbered advisories: CISA publishes CSAF for its ICS series only. That is a negative search result, not proof that no such count exists, and no claim of being first is made anywhere in this study.
- Three advisories - AA23-319A, AA23-352A and AA24-131A - link a superseded PDF revision alongside the current one. The companion PDF is taken to be the newest advisory-specific PDF the page links, dated by the /YYYY-MM/ segment of its own URL, which on all three is also the file CISA lists first. Read that way the HTML and companion-PDF bases give the same count. Read the superseded revisions as well and one advisory moves: AA23-319A's withdrawn November 2023 file names CVE-2020-1472, which neither its current PDF nor its HTML does.
- No individual is named in the dataset, in any finding or in any figure. Prior work cited on this page is credited to the organisation or project that published it, which is what the ODbL and CC BY licences on that work require.
- No leak-site data, no dark-web source, no victim organisation and no personal data was used or is published. Every fact comes from CISA's own published documents.
Census of the 25 advisories in CISA's #StopRansomware series, read from cisa.gov on 2026-09-29. Counts describe those documents on that date.
What was counted
Every cybersecurity advisory CISA publishes whose own title begins '#StopRansomware:' - 25 advisories, from AA22-181A (MedusaLocker, first published 30 June 2022) to AA26-222A (Gunra, 10 August 2026). For each one: the CVEs it names, the ATT&CK Initial Access techniques it lists, whether it publishes a version history, and whether CISA's own curated StopRansomware index links it.
15,172 sitemap entries, of which 178 are cybersecurity advisory URLs — 175 on the regular aaNN‑NNNx pattern and 3 irregular slugs (aa21-0000a, aa22-249a-0, aa23-108), all of them fetched. 26 of the 178 carry a title beginning “#StopRansomware:”. 26 URLs, 25 advisories: AA22-249A is served at two URLs, one of them the irregular slug /aa22-249a-0, which is why the denominator here is every advisory URL in the sitemap and not only the regular aaNN-NNNx ones.
Scroll the chart sideways to see all of it →
46 distinct advisories over 10 pages of results. A strict subset of frame A; produces the same 25 codes.
Scroll the chart sideways to see all of it →
38 advisory links, 18 of them in the series. A subset frame and the reconciliation, not an independent count of the series.
Scroll the chart sideways to see all of it →
| Excluded from the population | Why |
|---|---|
| Six /news-events/alerts/ pages carrying '#StopRansomware:' titles | they are announcement pages pointing at the advisories, not advisories |
| AA22-249A's second URL, /aa22-249a-0 | same advisory, same title, same date, same CVEs; counted once |
| aa21-0000a and aa23-108 | irregular sitemap slugs that are not in the series (an ATT&CK table fragment and an APT28 advisory); both fetched and tested, not assumed |
Scroll the table sideways to see every column →
Every cybersecurity advisory published by CISA whose own title begins '#StopRansomware:', case-insensitively - CISA's branded ransomware advisory series, co-sealed with the FBI and usually others, and per-family in 24 of its 25 advisories. Judged on the advisory's own <h1> and <title>, never on an index label.
Eleven of the twenty-five name no CVE on the page as served
11 of the 25 #StopRansomware advisory pages, as published on cisa.gov on 2026-09-29, name no CVE identifier anywhere in the body text - 44.0% of the series. Reading each advisory's current companion PDF as well does not change that: the same 11 name none there either. The remaining 14 name 64 CVE mentions between them, 48 distinct identifiers, from none to eleven per advisory.
This is a count of what CISA's documents name. An advisory that names no CVE is not evidence that the ransomware family exploits no vulnerability.
Scroll the chart sideways to see all of it →
Source: the 25 advisory pages on cisa.gov, read 29 September 2026. Basis: the HTML page as served.
On the HTML page as served, 11 of 25 advisories (44%) name no CVE. Reading each advisory’s current companion PDF as well returns 11 of 25 (44%) — the same advisories, and none of the 23 advisories that attach a PDF has a companion PDF whose CVE set differs from its page.
The count only moves if superseded PDF revisions are read too. 3 advisories (AA23-319A, AA23-352A, AA24-131A) still link an older file beside the current one, and on that third basis 10 of 25 name no CVE (40%), because of AA23-319A: Rhysida. The HTML page names no CVE, and neither does the current companion PDF (April 2025 revision). The advisory also still links the superseded November 2023 PDF, and that file does name one, in the sentence 'actors have been observed exploiting Zerologon (CVE-2020-1472)—a critical elevation of privileges vulnerability in Microsoft's Netlogon Remote Protocol [T1190]'. The April 2025 revision rewrote that section. This is the only advisory in the series where reading the superseded PDF as well as the current one changes the count.
The HTML page is the unit of measurement because 2 advisories (AA22-249A and AA23-040A) attach no PDF at all, so a PDF-based census cannot be run across the series. 23 of 25 carry one. The companion PDF is the newest advisory-specific PDF the advisory page links, dated by the /sites/default/files/YYYY-MM/ segment of its own URL. Where an advisory links more than one, CISA also lists the newest first in its attachment block, so the two rules agree on every advisory in the series.
Scroll the chart sideways to see all of it →
Scroll the chart sideways to see all of it →
Vertical axis: how many CVE identifiers the advisory names in its own body text. Horizontal axis: how many advisories name that many. Median 2, mean 2.56, maximum 11 (AA25-050A). Source: the advisory pages on cisa.gov, read 29 September 2026.
Both published bases give the same figure. Eleven of the twenty-five advisories name no CVE on the page CISA serves, and the same eleven name none in their current companion PDF either. The figure only moves if superseded PDF revisions are read as well, which is a third and differently labelled basis: on that reading it is ten of twenty-five, because AA23-319A's withdrawn November 2023 file names CVE-2020-1472. Any figure taken from this study should name the artefact it was counted from.
Every CVE the series names is in CISA's KEV catalogue
All 48 distinct CVEs named across the series appear in CISA's Known Exploited Vulnerabilities catalogue (catalogVersion 2026.09.27, 1,728 entries), and all 48 carry knownRansomwareCampaignUse = 'Known'. The catalogue-wide rate for that flag is 361 of 1,728, 20.9%.
CISA maintains both the advisories and the KEV flag. Read this as internal consistency between two CISA products, not as independent corroboration.
| Measure | Count | Of | Share |
|---|---|---|---|
| Distinct CVEs named by the series that appear in KEV | 48 | the 48 distinct CVEs named by the series | 100% |
| Of those, flagged for known ransomware campaign use | 48 | the 48 distinct CVEs named by the series | 100% |
| KEV entries carrying that flag, catalogue-wide | 361 | the whole KEV catalogue (1,728 entries) | 20.9% |
Scroll the table sideways to see every column →
KEV catalogVersion 2026.09.27, 1,728 entries, published under a CC0 1.0 dedication. This is one catalogue version read on one day, not a measure of how the flag changes over time. The catalogue’s declared count matched its array length, and the join asserted that the number of matched identifiers equalled the number of distinct identifiers named.
What the advisories list under Initial Access
On the whole-document rule, the 25 advisories print 62 advisory-technique pairs under Initial Access, with 2 of 25 listing none. On the tables-only rule the totals are 59 pairs and 3 of 25 listing none. The two rules differ on exactly one advisory, AA23-040A, and no figure here should be quoted without naming its rule. T1190 Exploit Public-Facing Application is the identifier most advisories list under Initial Access: 17 of 25 on the whole-document rule, 16 of 25 on the tables-only rule. T1133 External Remote Services follows at 13 and 12 of 25, and the T1566 Phishing family stands at 13 of 25 on both rules.
These are counts of what each advisory's ATT&CK section prints. They are not a measure of how any ransomware family gains access.
Scroll the chart sideways to see all of it →
Vertical axis: the technique identifier as the advisory prints it. Horizontal axis: how many of the 25 advisories list it. Two counting rules are shown and never merged. Source: the ATT&CK sections of the advisory pages, read 29 September 2026.
| Technique | Identifier | Advisories, tables only (of 25) | Advisories, whole document (of 25) |
|---|---|---|---|
| Exploit Public-Facing Application | T1190 | 16 | 17 |
| External Remote Services | T1133 | 12 | 13 |
| Phishing | T1566 | 10 | 10 |
| Valid Accounts | T1078 | 10 | 10 |
| Spearphishing Attachment | T1566.001 | 4 | 4 |
| Spearphishing Link | T1566.002 | 2 | 2 |
| Drive-by Compromise | T1189 | 2 | 2 |
| Supply Chain Compromise | T1195 | 0 | 1 |
| Remote Desktop Protocol | T1021.001 | 1 | 1 |
| PowerShell | T1059.001 | 1 | 1 |
| Spearphishing Voice | T1566.004 | 1 | 1 |
Scroll the table sideways to see every column →
The tables-only rule counts technique identifiers printed in a table scoped to the Initial Access tactic: 59 advisory-technique pairs, with 3 of 25 advisories listing none (AA23-040A, AA23-325A, AA23-353A). The whole-document rule also counts identifiers named in prose under a heading the advisory has itself tagged as Initial Access: 62 pairs, 2 of 25 listing none (AA23-325A, AA23-353A). The rules differ on AA23-040A and on nothing else. Any figure taken from here should name the rule it uses.
Scroll the chart sideways to see all of it →
4 of the 25 advisories cite T1110 Brute Force or one of its sub-techniques (AA23-263A, AA24-060A, AA24-109A, AA24-242A). In all 4, CISA prints the row under Credential Access. Zero advisories in the series print it under Initial Access, which is why no framing of this study uses the phrase — even though AA24-242A’s own row text says password spraying is used “to obtain initial access”. The coding follows the tactic each advisory prints.
Scroll the chart sideways to see all of it →
AA23-061A lists T1021.001, which ATT&CK places under Lateral Movement; AA23-352A lists T1059.001, which ATT&CK places under Execution. Both are counted exactly as CISA printed them and listed separately, not silently corrected and not dropped.
Scroll the chart sideways to see all of it →
The coding is one machine-structural pass reconciled against one hand-coded pass, re-derived a third way and cross-checked against a separately written implementation, which agreed on 24 of 25 advisories (96%); two separately written implementations; the single difference is the AA23-040A coding rule, not an error on either side. It is not two blind human passes and is not described as one. The advisories also cite five different ATT&CK framework versions (v12, v15, v16, v17, v19), so a technique coded under Initial Access in one advisory is not automatically the same coding as in another.
The ATT&CK tables do not use one layout across the series
Across the series the advisories use 3 different table conventions (L1, L2, L4), 2 advisories use two of them in one document, and 1 advisory (AA23-040A) publishes no ATT&CK table at all. A pattern written for one convention does not find the others, which is why the technique coding was reconciled between a machine-structural pass and a hand-coded pass rather than taken from a single scrape.
| Code | How the tactic is carried | Advisories |
|---|---|---|
| L1 | one table per tactic, tactic named in the caption | 15 |
| L2 | combined table, tactic carried by a full-width row-group header | 6 |
| L1|L4 | one table per tactic, tactic named in the caption; also combined table, tactic in column 1 of a row whose other cells are empty | 2 |
| L0 | no ATT&CK table; technique IDs cited inline in prose | 1 |
| L4 | combined table, tactic in column 1 of a row whose other cells are empty | 1 |
Scroll the table sideways to see every column →
L0 is not a table convention: it is the one advisory that prints no ATT&CK table and cites technique identifiers inline in prose. L3 is a convention the coding scheme defines but no advisory in this series uses.
Nineteen of the twenty-five publish a version-history block; six publish none
19 of the 25 advisories publish a version-history or revisions block; 6 publish none and are recorded NULL, not zero - the series does not say whether they were never revised or whether the block is simply absent. Among the 19 that publish one, the entry count runs from 1 to 6 (AA23-061A, BlackSuit/Royal). The heading is written 'Revisions' on 2022 advisories and 'Version History', in mixed or upper case, from 2023 onwards, and entries appear in both orders.
| Measure | Count | Of | Share |
|---|---|---|---|
| Advisories publishing a version-history block | 19 | all 25 advisories in the series | 76% |
| Advisories publishing none (recorded null, never zero) | 6 | all 25 advisories in the series | 24% |
Scroll the table sideways to see every column →
The 6 publishing no block are AA23-040A, AA23-075A, AA23-158A, AA23-284A, AA23-352A, AA24-242A. Among the 19 that publish one, entries run from 1 to 6, median 1. The heading changes wording across the series: Revisions (2022 advisories, 6), then Version History (2023 onwards, 9), then VERSION HISTORY in block capitals (2023 onwards, 4).
Seven of the twenty-five are not linked from CISA's curated StopRansomware index
18 of the 25 advisories in the series appear in CISA's curated StopRansomware index; 7 do not - every 2022 advisory in the series plus AA23-040A. The index carries 38 advisory links in total, 20 of which are not part of the branded series at all, reaching back to AA18-337A (SamSam) and AA19-339A (Dridex).
| Advisory | Title as served | First published | In CISA’s curated index |
|---|---|---|---|
| AA22-181A | MedusaLocker | 30 Jun 2022 | No |
| AA22-223A | Zeppelin Ransomware | 11 Aug 2022 | No |
| AA22-249A | Vice Society | 6 Sept 2022 | No |
| AA22-294A | Daixin Team | 21 Oct 2022 | No |
| AA22-321A | Hive Ransomware | 17 Nov 2022 | No |
| AA22-335A | Cuba Ransomware | 1 Dec 2022 | No |
| AA23-040A | Ransomware Attacks on Critical Infrastructure Fund DPRK Malicious Cyber Activities | 9 Feb 2023 | No |
Scroll the table sideways to see every column →
The index does not claim to cover the series - it describes itself as 'official CISA updates' - and it cannot be used as the population frame. CISA runs three StopRansomware listings and no two of them hold the same set: this one, a second at /stopransomware/stopransomware whose newest entry is the Black Basta advisory of 10 May 2024 and which prints that headline as '#STOPRANSOMARE: BLACK BASTA', and a third at /stopransomware/alerts.
Advisories by year of first publication
The series starts on 30 June 2022 and the annual counts are small and vary: six advisories in 2022, eleven in 2023, four in 2024, three in 2025 and one so far in 2026. No annual cut has a denominator above eleven, so they are reported as counts and no percentage is given on them.
| Year first published | Advisories | Of which name no CVE (HTML as served) |
|---|---|---|
| 2022 | 6 | 3 of 6 |
| 2023 | 11 | 6 of 11 |
| 2024 | 4 | 1 of 4 |
| 2025 | 3 | 1 of 3 |
| 2026 | 1 | 0 of 1 |
Scroll the table sideways to see every column →
Counts only. The largest annual denominator is 11, so no percentage is given on these cuts. The year is the date the advisory was first published, not the date of any later revision.
All 25 advisories, one row each
| Advisory | Title as served | First published | CVEs named | Initial Access (whole document) | Revision entries | In CISA’s index |
|---|---|---|---|---|---|---|
| AA22-181A | MedusaLocker | 30 Jun 2022 | none | T1133, T1566 | 1 | No |
| AA22-223A | Zeppelin Ransomware | 11 Aug 2022 | none | T1133, T1190, T1566 | 1 | No |
| AA22-249A | Vice Society | 6 Sept 2022 | 2: CVE-2021-1675, CVE-2021-34527 | T1078, T1190 | 1 | No |
| AA22-294A | Daixin Team | 21 Oct 2022 | none | T1078, T1190 | 1 | No |
| AA22-321A | Hive Ransomware | 17 Nov 2022 | 5: CVE-2020-12812, CVE-2021-31207, CVE-2021-34473, CVE-2021-34523, CVE-2021-42321 | T1133, T1190, T1566.001 | 1 | No |
| AA22-335A | Cuba Ransomware | 1 Dec 2022 | 2: CVE-2020-1472, CVE-2022-24521 | T1078, T1133, T1190, T1566 | 2 | No |
| AA23-040A | Ransomware Attacks on Critical Infrastructure Fund DPRK Malicious Cyber Activities | 9 Feb 2023 | 3: CVE-2021-20038, CVE-2021-44228, CVE-2022-24990 | T1133, T1190, T1195 | — | No |
| AA23-061A | Blacksuit (Royal) Ransomware | 2 Mar 2023 | none | T1021.001, T1133, T1190, T1566, T1566.001, T1566.002 | 6 | Yes |
| AA23-075A | LockBit 3.0 | 16 Mar 2023 | none | T1078, T1133, T1189, T1190, T1566 | — | Yes |
| AA23-136A | BianLian Ransomware Group | 16 May 2023 | 5: CVE-2020-1472, CVE-2021-31207, CVE-2021-34473, CVE-2021-34523, CVE-2022-37969 | T1078, T1133, T1190, T1566 | 2 | Yes |
| AA23-158A | CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability | 7 Jun 2023 | 2: CVE-2023-0669, CVE-2023-34362 | T1190, T1566 | — | Yes |
| AA23-263A | Snatch Ransomware | 20 Sept 2023 | none | T1078, T1133 | 1 | Yes |
| AA23-284A | AvosLocker Ransomware (Update) | 11 Oct 2023 | none | T1133 | — | Yes |
| AA23-319A | Rhysida Ransomware | 15 Nov 2023 | none | T1078 | 2 | Yes |
| AA23-325A | LockBit 3.0 Ransomware Affiliates Exploit CVE 2023-4966 Citrix Bleed Vulnerability | 21 Nov 2023 | 1: CVE-2023-4966 | none listed | 1 | Yes |
| AA23-352A | Play Ransomware | 18 Dec 2023 | 5: CVE-2018-13379, CVE-2020-12812, CVE-2022-41040, CVE-2022-41082, CVE-2024-57727 | T1059.001, T1078, T1133, T1190 | — | Yes |
| AA23-353A | ALPHV Blackcat | 19 Dec 2023 | none | none listed | 2 | Yes |
| AA24-060A | Phobos Ransomware | 29 Feb 2024 | none | T1078, T1133, T1566.001 | 1 | Yes |
| AA24-109A | Akira Ransomware | 18 Apr 2024 | 8: CVE-2020-3259, CVE-2020-3580, CVE-2023-20269, CVE-2023-27532, CVE-2023-28252, CVE-2024-37085, CVE-2024-40711, CVE-2024-40766 | T1078, T1133, T1190, T1566.001, T1566.002 | 2 | Yes |
| AA24-131A | Black Basta | 10 May 2024 | 5: CVE-2020-1472, CVE-2021-34527, CVE-2021-42278, CVE-2021-42287, CVE-2024-1709 | T1190, T1566, T1566.004 | 2 | Yes |
| AA24-242A | RansomHub Ransomware | 29 Aug 2024 | 9: CVE-2017-0144, CVE-2020-0787, CVE-2020-1472, CVE-2023-3519, CVE-2023-22515, CVE-2023-27997, CVE-2023-46604, CVE-2023-46747, CVE-2023-48788 | T1190, T1566 | — | Yes |
| AA25-050A | Ghost (Cring) Ransomware | 19 Feb 2025 | 11: CVE-2009-3960, CVE-2010-2861, CVE-2014-1812, CVE-2017-0143, CVE-2017-0144, CVE-2018-13379, CVE-2019-0604, CVE-2020-1472, CVE-2021-31207, CVE-2021-34473, CVE-2021-34523 | T1190 | 1 | Yes |
| AA25-071A | Medusa Ransomware | 12 Mar 2025 | 4: CVE-2023-48788, CVE-2024-1709, CVE-2025-10035, CVE-2026-1731 | T1190, T1566 | 2 | Yes |
| AA25-203A | Interlock | 22 Jul 2025 | none | T1189 | 1 | Yes |
| AA26-222A | Gunra Ransomware | 10 Aug 2026 | 2: CVE-2024-55591, CVE-2025-24472 | T1190 | 1 | Yes |
Scroll the table sideways to see every column →
CVE counts are taken from the visible text of the HTML page as served on 29 September 2026, with markup stripped first, so an identifier carried only inside a link’s address is not credited to CISA. Downloads: CSV · README and attribution · JSON.
How the census was built
How these figures were produced
- For each advisory in CISA's #StopRansomware series: the CVE identifiers its page names, the ATT&CK Initial Access techniques it lists, whether it publishes a version history and how many entries that history has, whether CISA's own curated StopRansomware index links it, and whether its companion PDF agrees with its HTML on the CVE set.
- Established three ways rather than inherited: the sitemap frame, the faceted fulltext listing and CISA's curated index. The first two agree exactly; the third is a subset and supplies the reconciliation. All three are CISA's own indexes, and two of them are subsets of the sitemap, so an advisory missing from CISA's sitemap would be missed by all three. Completeness is asserted against CISA's published indexes, not independently of them.
- robots.txt was fetched first and stored as evidence. It disallows /core/, /profiles/, /admin/, /search/, /media/oembed and four specific /user/ paths (register, password, login, logout), and gives PetalBot Disallow: /. It sets no Crawl-delay and excludes none of the paths used here.
- The sitemap was walked and every /news-events/cybersecurity-advisories/ URL fetched - 178 pages, of which 175 match the regular aaNN-NNNx slug and 3 do not - so that no advisory could be excluded by an assumption about URL shape. One of the irregular slugs, /aa22-249a-0, turns out to be in the series.
- Membership of the series was decided on each advisory's own served title, case-insensitively, never on an index label or a URL pattern.
- CVEs were extracted with a hyphen-tolerant pattern over the page's visible text - tags stripped first, so that an identifier carried only in a link's URL or title attribute is not credited to CISA - then re-extracted with a second, differently written pattern as a check.
- Version history was read from the block headed 'Revisions' or 'Version History'. Advisories publishing no block are NULL, not zero.
- ATT&CK Initial Access was coded twice by different methods and reconciled, then re-derived a third way, then cross-checked against a separately written implementation. Both counting rules are published.
- The CVEs were joined to CISA's KEV catalogue with count-equals-length assertions on both sides.
- Fetching ran one request in flight at 1.2-second spacing with an identifying User-Agent. The stored manifests record 625 snapshot requests across 238 distinct URLs and a 178-page sweep of every advisory URL in the sitemap, every one of them HTTP 200, with no 429 and no 5xx. A further 22 requests were made for licence, policy and prior-art context: 18 returned 200, 3 returned 404 and 1 failed to connect. The failures are reported rather than hidden; none of those pages carries a figure in this study.
- The HTML page CISA serves. Two advisories attach no PDF at all, so a PDF-based census cannot be run across the series. The PDF basis is published alongside as an alternative.
- Counting rules — CVEs: A CVE is counted where its identifier appears in the advisory's body text, including in the title. Duplicates within one advisory count once. Initial Access: Both rules are published. Rule A counts technique IDs printed in a table scoped to the Initial Access tactic. Rule B counts technique IDs the document names under Initial Access anywhere, including in prose under a sub-heading the advisory has itself tagged TA0001. Revisions: NULL where no block is published. Never zero. Duplicates: An advisory served at more than one URL counts once.
- Collected 2026-09-29 UTC. Analysis stage makes no network request and runs from the stored snapshot. This analysis makes no network request. Re-running scripts/research/stopransomware-advisory-census-2026/analyse.py against the stored snapshot reproduces the CSV byte for byte.
- None was collected or published. The advisories carry a CISA reporting mailbox, which is an organisational address and is not reproduced in the dataset. No individual is named in the dataset, in any finding or in any figure. Prior work cited on this page is credited to the organisation or project that published it, as its licence requires.
| Source | What it gave | Licence | Retrieved |
|---|---|---|---|
| CISA sitemap (population frame A) | 15,172 <loc> entries, 178 cybersecurity advisory URLs - 175 on the regular aaNN-NNNx pattern and 3 irregular slugs (aa21-0000a, aa22-249a-0, aa23-108), all of them fetched | US federal government work, not subject to US copyright under 17 U.S.C. 105(a) | 2026-09-29 |
| CISA cybersecurity advisories, faceted fulltext listing (frame B) | 46 distinct advisories over 10 pages | US federal government work, 17 U.S.C. 105(a) | 2026-09-29 |
| CISA StopRansomware curated index (frame C, and the reconciliation) | 38 distinct advisories | US federal government work, 17 U.S.C. 105(a) | 2026-09-29 |
| CISA Known Exploited Vulnerabilities catalogue | catalogVersion 2026.09.27, 1,728 entries | CC0 1.0 Universal (public domain dedication) | 2026-09-29 |
| The 25 advisory pages themselves | every figure in this study. Each of the 25 advisories is linked individually from the census table, and each row of the dataset carries its own source URL, retrieval timestamp and page sha256 | US federal government work, 17 U.S.C. 105(a) | 2026-09-29 |
| MITRE ATT&CK® | the plain-language names printed beside the technique identifiers (T1190 Exploit Public-Facing Application and the rest) and the Initial Access tactic those identifiers are grouped under. The technique identifiers themselves, and which of them each advisory lists, are read from the advisories | MITRE ATT&CK® Terms of Use: a non-exclusive, royalty-free licence to use ATT&CK for research, development and commercial purposes, on condition that MITRE's copyright notice and licence terms are reproduced. | 2026-09-29 |
Scroll the table sideways to see every column →
CISA publishes no explicit public-domain notice. The position rests on the statute and on CISA's TLP:CLEAR default, so this study does not say that CISA declares its own content public domain. CISA's own rules prohibit use of the DHS seal or CISA logo in any way implying endorsement. Neither is reproduced. Each advisory's own non-endorsement wording is stored per advisory and travels with any quotation from it. 23 of the 25 advisories publish a non-endorsement clause of their own, in 19 distinct wordings, and each is stored against its advisory in the dataset.
Four disagreements, three resolved and one left open
Two collection streams built this census, and the record of where they disagreed — and where the study's own brief disagreed with its retrieval timestamps — is published rather than dropped. Rather than publish the winner and drop the rest, each disagreement is recorded with its cause and its outcome.
| About | Outcome | Published value |
|---|---|---|
| How many advisories publish a version-history block | Resolved | 6 of 25 publish no block |
| How to code ATT&CK Initial Access for AA23-040A | Left open on purpose | both rules, side by side |
| Which PDF counts as an advisory's companion PDF | Resolved | 11 of 25 on the HTML basis and the same 11 of 25 on the companion-PDF basis; 10 of 25 if superseded PDF revisions are read as well |
| The collection date | Resolved | 2026-09-29 |
Scroll the table sideways to see every column →
- How many advisories publish a version-history block: Re-derived here from the stored HTML. The heading is written <h2><strong>Version History</strong></h2>, so a pattern that matches the heading tag's inner HTML rather than its stripped text misses it. AA22-181A, for example, publishes 'June 30, 2022: Initial Version' under an h3 'Revisions'. The published figure is 19 publishing a block and 6 not.
- How to code ATT&CK Initial Access for AA23-040A: Not resolved, and deliberately so. AA23-040A publishes no ATT&CK table but names T1190, T1133 and T1195 in prose under a sub-heading it has itself tagged TA0001 (Initial Access). Rule A counts tables only; rule B counts what the document names anywhere. The two coding streams chose differently and agree on the other 24 of 25. Both are published, in the JSON and as separate CSV columns. Any prose must name the rule it uses and must not mix them.
- Which PDF counts as an advisory's companion PDF: Three advisories - AA23-319A, AA23-352A and AA24-131A - link a superseded PDF revision alongside the current one, and an earlier draft of this analysis read whichever file it had stored first. On AA23-319A that was the November 2023 file, which names CVE-2020-1472; the April 2025 revision CISA now serves names no CVE at all. The rule is now stated and applied: the companion PDF is the newest advisory-specific PDF the page links, dated by the /YYYY-MM/ segment of its own URL, which on all three advisories is also the file CISA lists first. On that rule the HTML and companion-PDF bases agree exactly, at 11 of 25. The superseded-PDF reading is kept as a third, separately labelled basis rather than dropped.
- The collection date: Every retrieval timestamp in every manifest records 29 September 2026. The study dates its collection from those timestamps.
What already exists, and what this adds
We found no prior published count of what CISA's own #StopRansomware advisory series names. CISA publishes CSAF machine-readable output for its ICS advisory series only. The AA-numbered advisories are prose - HTML and PDF and we found no equivalent machine-readable publication of them. Four search framings found no existing count of the series. That is a negative search result. A negative search result is not proof that no such count exists, and no claim to be first is made here or anywhere else in this study.
| Work | Publisher | What it measured | How this study differs | How we checked it |
|---|---|---|---|---|
| ENISA Threat Landscape for Ransomware Attacks | European Union Agency for Cybersecurity (ENISA), July 2022 | 623 ransomware incidents in the EU, UK and US, May 2021 to June 2022, coded against MITRE ATT&CK. | ENISA counted incident reports from many publishers about incidents. We count one publisher's own advisory series, document by document, and report per-document what each one names. Our denominator is a closed, nameable set of CISA documents that anyone can re-derive; ENISA's was an open collection of third-party reports. | primary PDF downloaded and text-searched locally |
| ENISA Threat Landscape 2026 | ENISA, September 2026 | 8,257 incidents recorded 1 January 2025 to 31 December 2025. | Same distinction as above. Also a caution: several secondary summaries attribute '4,875 incidents, July 2024 to June 2025' to the 2026 edition; that is the 2025 edition. We checked the PDF. | primary PDF downloaded and text-searched locally |
| ICS Advisory Project | ICS Advisory Project (community project), ongoing since 2022 | CISA's ICS advisories converted to CSV and dashboards, enriched with vendor location, product and critical-infrastructure sector. | It covers the ICS advisory series (ICSA/ICSMA), not the #StopRansomware series, and it republishes those advisories as structured CSV. The #StopRansomware advisories are prose - HTML and PDF - with no structured publication behind them, so the same approach does not reach them. | README fetched and read |
| Open ICS Advisory Dataset (OICSAD) v0.1.0 | Open ICS Advisory Dataset project, 26 September 2026 | 3,937 CISA advisories (3,749 ICSA, 188 ICSMA) from 27 February 2010 to 24 September 2026 in CSAF form, parsed into three tables, 14,487 advisory-CVE links, 12,346 unique CVEs, 848 vendors, joined to CISA KEV. | Different corpus and a harder extraction problem. OICSAD reads structured CSAF, where the CVE list is a field. No CSAF exists for the #StopRansomware advisories, so every CVE in our census is read out of prose and every ATT&CK technique is hand-coded from tables whose layout changes between advisories. | repository page fetched and read |
| The State of Ransomware 2026 | Sophos, July 2026 | Vendor survey: 2,158 IT and cybersecurity leaders in 17 countries, fieldwork January to March 2026, recalling the previous 12 months. | Sophos asks victims what happened to them, in a survey, under one vendor's methodology. We count what is written in a fixed set of public documents. The two answer different questions and neither substitutes for the other. | Survey size, country count and fieldwork window checked against sophos.com. Individual root-cause percentages were not checkable against a Sophos primary document and are not carried. |
| Top Routinely Exploited Vulnerabilities (annual joint advisory series) | CISA with international partners, annual, e.g. AA24-317A for 2023 | CISA's own ranked list of the CVEs most routinely exploited in a year. | We count the #StopRansomware series only, and we count per advisory, not per vulnerability. | Page is in the study's own snapshot (raw/snapshot-2026-09-29/advisories/aa24-317a.html, retrieved 2026-09-29T07:03:16Z, one of the 178 advisory pages fetched); title, publication date and the 50 distinct CVE identifiers re-read from those stored bytes. |
| The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates | GreyNoise, 2 February 2026 | Changes to the knownRansomwareCampaignUse field in CISA's KEV catalogue during 2025: 59 entries moved from 'Unknown' to 'Known' with no announcement, with breakdowns by vendor, device class and month. | GreyNoise tracks how the flag changes over time across the whole catalogue. We take one catalogue version as a fixed reference point and use it only as context for a document census; we do not track change and make no claim about when any flag was set. | Post fetched and read 2026-09-29: publication date, the headline count of 59 flips during 2025 and the vendor and device-class breakdowns are as described. |
| Ransomware and Data Extortion Landscape TTP matrix | Tidal Cyber, 28 February 2023 (post); matrix ongoing | ATT&CK technique collections for 29 recently active ransomware groups and families, assembled from public reporting. | Tidal pools sources to describe a family. We deliberately do not pool: we record what one named document says, so the count is checkable against that document. Tidal's post does not claim to catalogue the #StopRansomware series. | post fetched and read; it does not mention cataloguing the #StopRansomware series |
Scroll the table sideways to see every column →
The closest prior work in shape: ENISA's Threat Landscape for Ransomware Attacks (2022), which could not establish an initial-access route for 594 of the 623 incidents it studied - 95.3%. That is the closest work in shape: a public body counting what the record does not say. It counted third-party incident reports; we count one publisher's own document series, document by document.
How this differs from our ransomware and backup page
We also keep a page on ransomware and backup targeting. That page collects figures other organisations have published about ransomware incidents: victim surveys, vendor telemetry and recovery rates. This page counts something much narrower — the contents of a fixed set of documents. It reports which CVEs CISA’s own #StopRansomware advisories name. It does not report how often ransomware exploits a vulnerability, and no figure here should be read that way.
Building this census also made us re-check that page. Three figures it carried have been deleted rather than restated: two 2024 backup-targeting percentages that had reached it through a third-party summary of a vendor report instead of the report itself, and a root-cause percentage from an earlier edition of a vendor survey, presented alongside a conditional compromise rate quoted without its condition. None could be checked against the publisher’s own document. The census figure now sits on that page in their place, with its basis attached.
Questions
How many of CISA's #StopRansomware advisories name no CVE?
11 of 25 — 44% — of the advisories CISA publishes under its own '#StopRansomware:' title prefix name no CVE identifier anywhere in the page as served on 29 September 2026. Reading each advisory's current companion PDF as well gives the same answer: 11 of 25 (44%), the same advisories. The denominator is the whole series, a census of 25 advisories rather than a sample. This counts what the documents name; it is not a measure of whether those ransomware families exploit vulnerabilities.
Does an advisory naming no CVE mean that ransomware family exploits no vulnerability?
No, and nothing in this study supports that reading. Of the 25 advisories in CISA's #StopRansomware series, 11 name no CVE on the page as served, but the count describes the document, not the threat. This is a count of what CISA's documents name. An advisory that names no CVE is not evidence that the ransomware family exploits no vulnerability. Two advisories make the point on their own: AA23-075A (LockBit 3.0) names no CVE while telling readers to prioritise remediating known exploited vulnerabilities, and AA23-325A lists no Initial Access technique at all although it is specifically about exploitation of a vulnerability named in its own title.
How many advisories are in CISA's #StopRansomware series?
25, served at 26 URLs, counted on 29 September 2026. Membership is decided by each advisory's own served title beginning '#StopRansomware:', tested case-insensitively, not by any index label. The population was established three ways: CISA's sitemap (15,172 entries, 178 cybersecurity advisory URLs, all fetched), CISA's faceted advisory listing, and CISA's curated StopRansomware index. One advisory, AA22-249A, is published at two URLs and is counted once. All three frames are CISA's own indexes, and two of them are subsets of the sitemap, so an advisory missing from CISA's sitemap would be missed by all three: completeness is asserted against CISA's published indexes, not independently of them.
How many distinct CVEs do the advisories name, and are they in CISA's KEV catalogue?
Read on 29 September 2026, the 25 advisories in CISA's #StopRansomware series name 64 CVE mentions between them, 48 distinct identifiers, ranging from none to 11 per advisory. All 48 of those distinct identifiers are in CISA's Known Exploited Vulnerabilities catalogue (catalogVersion 2026.09.27, 1,728 entries), and all 48 carry the flag for known ransomware campaign use, against a catalogue-wide rate of 361 of 1,728 (20.9%). CISA maintains both the advisories and that flag, so this is consistency between two CISA products rather than independent corroboration.
Which ATT&CK Initial Access techniques do CISA's #StopRansomware advisories list most often?
Across the 25 advisories in CISA's #StopRansomware series, read on 29 September 2026: on the whole-document counting rule, T1190 (Exploit Public-Facing Application) is listed under Initial Access by 17 of the 25 advisories, ahead of T1133 (External Remote Services) at 13 of 25. The same rule gives 62 advisory-technique pairs in total, with 2 of 25 advisories listing none. A stricter rule that counts only ATT&CK tables gives 59 pairs and 3 of 25 listing none; the two rules differ on one advisory, AA23-040A. These are counts of what each advisory prints, not measurements of how any family gains access.
Do CISA's #StopRansomware advisories list brute force as an initial access technique?
No. Across all 25 advisories in CISA's #StopRansomware series, read on 29 September 2026, 4 cite T1110 Brute Force or one of its sub-techniques, and in every one of those 4 the row is printed under Credential Access, not under Initial Access. Zero of the 25 advisories code T1110 under Initial Access. In one advisory the row text and the tactic column say different things: AA24-242A's T1110.003 row reads 'RansomHub affiliates may use password spraying to obtain initial access', and CISA still prints that row under Credential Access. The coding here follows the tactic each advisory prints.
How many of CISA's #StopRansomware advisories publish a version history?
19 of 25 — 76% — of the advisories in CISA's #StopRansomware series, read on 29 September 2026, publish a version-history or revisions block; 6 of 25 publish none. An advisory with no block is recorded as null rather than zero, because the series does not say whether it was never revised or whether the block is simply absent. Among the 19 that do publish one, the entry count runs from 1 to 6. The heading itself changes wording and case across the series: Revisions (2022 advisories, 6); Version History (2023 onwards, 9); VERSION HISTORY in block capitals (2023 onwards, 4).
Does CISA's own StopRansomware index list the whole series?
No. Read on 29 September 2026, 18 of 25 advisories in CISA's #StopRansomware series appear in CISA's curated StopRansomware index; 7 of 25 (28%) do not. The index carries 38 advisory links in total, 20 of which are not part of the '#StopRansomware:' titled series at all. That is why the index cannot serve as the population frame for the series, and why this census was built from CISA's sitemap and each advisory's own title instead.
Can I reuse the dataset?
Yes. The 25-row dataset behind this census of CISA's #StopRansomware advisory series, read on 29 September 2026, is published as CSV with a README, one row per advisory, each carrying its source URL, retrieval timestamp and the sha256 of the exact page parsed. Servnet's derived dataset and analysis are free to reuse under Creative Commons Attribution 4.0 International (CC BY 4.0), crediting Servnet with a link to this page. The underlying advisories and the KEV catalogue are works of the US federal government, not subject to US copyright under 17 U.S.C. 105(a); the KEV catalogue additionally carries a CC0 1.0 dedication. Nothing here is published with any CISA logo or DHS seal, and nothing implies CISA endorsement.
Related pages on Servnet
Servnet Research publishes dated observations from public sources for information only. It is not legal, security, financial or investment advice, and data are provided without warranty. Spotted an error, or want something re-measured or reviewed? See our corrections and takedown policy.
Background reading: what patch management involves and ransomware protection. The nearest study of ours in shape, counting CVEs rather than advisories, is our count of the security fixes Windows 10 machines stop receiving. · For reported incidents rather than advisories, see our count of personal data breach reports to the ICO. · More Servnet research
About this study
- What it is: a census of the 25 cybersecurity advisories whose own title begins “#StopRansomware:”, published by the United States Cybersecurity and Infrastructure Security Agency and read from cisa.gov on 29 September 2026. It counts what those documents name — CVE identifiers, ATT&CK Initial Access techniques, version-history entries and membership of CISA’s curated index. It does not measure how any ransomware family gains access, and an advisory naming no CVE is not evidence that the family exploits none. These are living documents and the counts can move when CISA revises one.
- Licence and attribution: the advisories and the Known Exploited Vulnerabilities catalogue are works of the United States federal government and are not subject to US copyright under 17 U.S.C. 105(a); the KEV catalogue additionally carries a CC0 1.0 dedication. The plain-language technique names printed beside the ATT&CK identifiers, and the Initial Access tactic they are grouped under, are reproduced from MITRE ATT&CK® under its Terms of Use: © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. ATT&CK® is a registered trade mark of The MITRE Corporation, and no endorsement by MITRE is implied. Servnet’s derived dataset and analysis are free to reuse under CC BY 4.0, crediting “Servnet: what CISA’s own ransomware advisories actually name” with a link to this page. No CISA logo or DHS seal is reproduced and nothing here implies CISA endorsement.
- Third-party names: CISA, the FBI, MITRE, ATT&CK, Citrix, Fortinet and other organisation and product names are trade marks of their respective owners, used only to identify products and organisations. Servnet is not affiliated with, endorsed by or acting for them.
- Our interest: Servnet sells and maintains IT hardware and services, including backup, patching and security services related to the subject of this study. The study counts what public documents say; it is not a recommendation to buy anything, and no organisation paid for, sponsored or approved it.
- Errors and takedown: tell us at webmaster@servnetuk.com and we will check it; see the corrections and takedown policy.
Talk to a UK specialist
Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.