{"name":"CISA #StopRansomware advisory census 2026: what the advisories name","url":"https://www.servnetuk.com/research/stopransomware-advisory-census-2026","licence":"Servnet’s derived dataset and analysis: CC BY 4.0 (attribute \"Servnet: what CISA’s own ransomware advisories actually name\", with a link to the study page). The underlying CISA advisories and the Known Exploited Vulnerabilities catalogue are works of the US federal government and are not subject to US copyright under 17 U.S.C. 105(a); the KEV catalogue additionally carries a CC0 1.0 dedication.","note":"Every figure is a count of what CISA’s own documents name. An advisory that names no CVE is not evidence that the ransomware family exploits no vulnerability.","slug":"stopransomware-advisory-census-2026","study":"What CISA's own ransomware advisories actually name","question":"Across the advisories CISA has published under its own '#StopRansomware:' title prefix, how many name a specific vulnerability, and how many describe the family without naming a single CVE?","publisher":"Servnet","built":"2026-09-29T08:20:26Z","snapshot_as_at":"2026-09-29","as_at_line":"Census of the 25 advisories in CISA's #StopRansomware series, read from cisa.gov on 2026-09-29. Counts describe those documents on that date.","unit_of_analysis":"one advisory","dataset":{"csv":"/research/stopransomware-advisory-census-2026.csv","readme":"/research/stopransomware-advisory-census-2026-README.txt","rows":25,"unit":"one row per advisory in the series","licence":"Source material: US federal government work, not subject to US copyright under 17 U.S.C. 105(a). KEV fields: CC0 1.0 Universal.","derived_licence":"Creative Commons Attribution 4.0 International (CC BY 4.0)","derived_licence_url":"https://creativecommons.org/licenses/by/4.0/","derived_attribution":"Servnet, 'What CISA's own ransomware advisories actually name', https://www.servnetuk.com/research/stopransomware-advisory-census-2026","excludes":"no personal data; no named individuals; no victim organisations","csv_sha256":"8102816f6af292feecdd07529a13a5e69cf48b92b6f70ce3089a2107ca815317","readme_sha256":"edbc82c93fe08d7b57efc7892d2e55666d65c638852fc09d63af1db2b93f8404"},"population":{"n":25,"definition":"Every cybersecurity advisory published by CISA whose own title begins '#StopRansomware:', case-insensitively - CISA's branded ransomware advisory series, co-sealed with the FBI and usually others, and per-family in 24 of its 25 advisories. Judged on the advisory's own <h1> and <title>, never on an index label.","established_how":"three frames, none of them inherited from the brief","frames":{"a_sitemap":{"advisory_urls":178,"regular_pattern_urls":175,"irregular_slugs":["aa21-0000a","aa22-249a-0","aa23-108"],"sitemap_entries":15172,"strict_prefix_urls":26,"note":"26 URLs, 25 advisories: AA22-249A is served at two URLs, one of them the irregular slug /aa22-249a-0, which is why the denominator here is every advisory URL in the sitemap and not only the regular aaNN-NNNx ones."},"b_faceted_listing":{"distinct_advisories":46,"pages":10,"note":"a strict subset of frame A; produces the same 25 codes"},"b2_faceted_listing_ransomware":{"distinct_advisories":67,"pages":17},"c_curated_index":{"advisory_links":38,"of_which_in_the_series":18,"note":"a subset frame and the reconciliation, not an independent count of the series"},"union":175},"excluded":[{"what":"Six /news-events/alerts/ pages carrying '#StopRansomware:' titles","why":"they are announcement pages pointing at the advisories, not advisories"},{"what":"AA22-249A's second URL, /aa22-249a-0","why":"same advisory, same title, same date, same CVEs; counted once"},{"what":"aa21-0000a and aa23-108","why":"irregular sitemap slugs that are not in the series (an ATT&CK table fragment and an APT28 advisory); both fetched and tested, not assumed"}],"oddball_sitemap_urls":[{"slug":"aa21-0000a","title":"ATT&CK Table for Sophisticated Spearphishing Campaign CSA","is_stopransomware_prefixed":false,"body_chars":400,"cve_count":0,"source_url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-0000a"},{"slug":"aa22-249a-0","title":"#StopRansomware: Vice Society","is_stopransomware_prefixed":true,"body_chars":17734,"cve_count":2,"source_url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-249a-0"},{"slug":"aa23-108","title":"APT28 Exploits Known Vulnerability to Carry Out Reconnaissance and Deploy Malware on Cisco Routers","is_stopransomware_prefixed":false,"body_chars":7930,"cve_count":1,"source_url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-108"}]},"preRegisteredMetrics":[{"id":"zero_cve_html","statement":"#StopRansomware advisories whose HTML page, as served on 2026-09-29, names no CVE identifier anywhere in the body text.","n":11,"denominator":25,"denominator_label":"all 25 advisories whose own title begins '#StopRansomware:' (case-insensitive), counted once each","pct":44,"advisory_ids":["AA22-181A","AA22-223A","AA22-294A","AA23-061A","AA23-075A","AA23-263A","AA23-284A","AA23-319A","AA23-353A","AA24-060A","AA25-203A"],"basis":"HTML page as served","how_to_recompute":"CSV: count rows where names_any_cve_html == 'no', divide by 25. From source: fetch each source_url, search the body text with a hyphen-tolerant CVE pattern.","guard":"This is a count of what CISA's documents name. An advisory that names no CVE is not evidence that the ransomware family exploits no vulnerability."},{"id":"zero_cve_html_or_companion_pdf","statement":"The same count on the second basis: names no CVE in EITHER the HTML page or the advisory's current companion PDF - the newest advisory-specific PDF the page links. It returns the same set of advisories.","n":11,"denominator":25,"denominator_label":"the same 25 advisories","pct":44,"advisory_ids":["AA22-181A","AA22-223A","AA22-294A","AA23-061A","AA23-075A","AA23-263A","AA23-284A","AA23-319A","AA23-353A","AA24-060A","AA25-203A"],"basis":"HTML page or current companion PDF","moves_on":[],"how_to_recompute":"CSV: count rows where names_any_cve_html_or_companion_pdf == 'no'. It must equal the HTML count and name the same advisories.","guard":"This is a count of what CISA's documents name. An advisory that names no CVE is not evidence that the ransomware family exploits no vulnerability."},{"id":"zero_cve_html_or_any_attached_pdf","statement":"A third and differently labelled basis: names no CVE in the HTML page or in ANY PDF the page links, including superseded revisions CISA leaves attached beside the current file.","n":10,"denominator":25,"denominator_label":"the same 25 advisories","pct":40,"advisory_ids":["AA22-181A","AA22-223A","AA22-294A","AA23-061A","AA23-075A","AA23-263A","AA23-284A","AA23-353A","AA24-060A","AA25-203A"],"basis":"HTML page or any attached PDF, current or superseded","moves_on":["AA23-319A"],"how_to_recompute":"CSV: count rows where names_any_cve_html_or_any_attached_pdf == 'no'. The one difference from the other two bases must be AA23-319A and nothing else.","guard":"This is a count of what CISA's documents name. An advisory that names no CVE is not evidence that the ransomware family exploits no vulnerability."},{"id":"population","statement":"Advisories in CISA's #StopRansomware branded series.","n":25,"denominator":25,"denominator_label":"itself - this is a census, not a sample","pct":100,"how_to_recompute":"Walk https://www.cisa.gov/default/sitemap.xml, take every /news-events/cybersecurity-advisories/ URL, fetch each page and keep those whose own <h1> or <title> begins '#StopRansomware:' case-insensitively. Collapse AA22-249A's two URLs to one advisory."},{"id":"distinct_cves","statement":"Distinct CVE identifiers named anywhere in the series.","n":48,"denominator":64,"denominator_label":"64 advisory-CVE mentions across the 25 advisories","pct":null,"how_to_recompute":"CSV: split cves_named_html on ';', take the distinct set."},{"id":"kev_coverage","statement":"Distinct CVEs named by the series that appear in CISA's Known Exploited Vulnerabilities catalogue.","n":48,"denominator":48,"denominator_label":"the 48 distinct CVEs named by the series","pct":100,"how_to_recompute":"Join the distinct CVE list to the KEV catalogue (catalogVersion 2026.09.27) on cveID.","caution":"CISA maintains both the advisories and the KEV flag, so this is a consistency check, not independent corroboration."},{"id":"absent_from_cisa_curated_index","statement":"Advisories in the series that CISA's own curated StopRansomware index does not link.","n":7,"denominator":25,"denominator_label":"all 25 advisories in the series","pct":28,"advisory_ids":["AA22-181A","AA22-223A","AA22-249A","AA22-294A","AA22-321A","AA22-335A","AA23-040A"],"how_to_recompute":"CSV: count rows where in_cisa_curated_stopransomware_index == 'no'."},{"id":"no_version_history_block","statement":"Advisories that publish no version-history or revisions block at all. Recorded NULL, not zero.","n":6,"denominator":25,"denominator_label":"all 25 advisories in the series","pct":24,"advisory_ids":["AA23-040A","AA23-075A","AA23-158A","AA23-284A","AA23-352A","AA24-242A"],"how_to_recompute":"CSV: count rows where version_history_published == 'no'. From source: look for a heading whose TEXT is 'Revisions' or 'Version History'; the text is wrapped in <strong> inside the heading tag, so match the heading's stripped text, not its inner HTML."},{"id":"t1110_under_initial_access","statement":"Advisories that print T1110 Brute Force under the Initial Access tactic.","n":0,"denominator":25,"denominator_label":"all 25 advisories in the series","pct":0,"note":"T1110 Brute Force, or one of its sub-techniques, is cited in four advisories; in all four the row is printed under Credential Access. Two of the four (AA23-263A, AA24-242A) print only a sub-technique row. This is why no 'brute force' framing appears anywhere in the study.","how_to_recompute":"CSV: no row's initial_access_techniques_* column contains T1110. See data/research/.../normalised/attack_t1110_audit.json for the four citations and the tactic each is printed under."}],"page":{"title":"What CISA’s own ransomware advisories name","standfirst":"CISA has published 25 advisories under its own '#StopRansomware:' banner. We read all 25 and counted what they name. 11 of them - 44.0% - go from title to mitigations without naming a single CVE.","headline":"11 of the 25 advisories in CISA's #StopRansomware series (44.0%) name no CVE anywhere in the page CISA serves. On an HTML-or-PDF basis, 11 do (44.0%).","as_at_line":"cisa.gov, 2026-09-29. n = 25 advisories. A census of a named series, not a sample.","wording_rules":["Every figure is a statement about CISA's documents, never about ransomware.","Never write 'ransomware families' for the population: AA23-040A is not a family advisory and AA22-249A is one advisory at two URLs. The noun is 'advisories'.","Always state the basis - HTML as served, or HTML or companion PDF - in the same sentence as the headline figure.","Never use 'brute force' in any framing: T1110 is coded under Initial Access in zero of the 25 advisories.","No claim of being first, ever. We found no prior count; that is a negative search result and is described as one.","No UK or global claim. This is a census of one US agency's document series.","No CISA logo, no DHS seal, nothing implying endorsement. Each advisory's own non-endorsement wording travels with any quotation from it.","State n for every cut. Suppress percentages on the per-year cuts, the largest of which has a denominator of eleven."],"headlines":[{"metric":"Advisories naming no CVE (HTML as served)","value":"11 of 25","pct":44,"denominator":"all 25 advisories in the #StopRansomware series"},{"metric":"Advisories naming no CVE (HTML or companion PDF)","value":"11 of 25","pct":44,"denominator":"all 25 advisories in the #StopRansomware series"},{"metric":"Distinct CVEs named across the whole series","value":48,"denominator":"64 advisory-CVE mentions"},{"metric":"Named CVEs present in CISA's KEV catalogue","value":"48 of 48","pct":100,"denominator":"the distinct CVEs named by the series"},{"metric":"Advisories CISA's own curated StopRansomware index omits","value":"7 of 25","pct":28,"denominator":"all 25 advisories in the series"},{"metric":"Advisories publishing no version history at all","value":"6 of 25","pct":24,"denominator":"all 25 advisories in the series"},{"metric":"Advisories printing T1110 Brute Force under Initial Access","value":"0 of 25","pct":0,"denominator":"all 25 advisories in the series"}],"sections":[{"id":"what-was-counted","heading":"What was counted","finding":"Every cybersecurity advisory CISA publishes whose own title begins '#StopRansomware:' - 25 advisories, from AA22-181A (MedusaLocker, first published 30 June 2022) to AA26-222A (Gunra, 10 August 2026). For each one: the CVEs it names, the ATT&CK Initial Access techniques it lists, whether it publishes a version history, and whether CISA's own curated StopRansomware index links it.","figures":[{"label":"Advisories in the series","value":25,"denominator":"census, not a sample"},{"label":"Advisory URLs in the sitemap","value":175,"denominator":"15,172 sitemap entries"}]},{"id":"headline","heading":"Eleven of the twenty-five name no CVE on the page as served","finding":"11 of the 25 #StopRansomware advisory pages, as published on cisa.gov on 2026-09-29, name no CVE identifier anywhere in the body text - 44.0% of the series. Reading each advisory's current companion PDF as well does not change that: the same 11 name none there either. The remaining 14 name 64 CVE mentions between them, 48 distinct identifiers, from none to eleven per advisory.","guard":"This is a count of what CISA's documents name. An advisory that names no CVE is not evidence that the ransomware family exploits no vulnerability.","figures":[{"label":"Name no CVE (HTML as served)","value":"11 of 25","pct":44,"denominator":"all 25 advisories in the series"},{"label":"Name no CVE (HTML or current companion PDF)","value":"11 of 25","pct":44,"denominator":"all 25 advisories in the series"},{"label":"Name no CVE (HTML or any attached PDF, superseded revisions included)","value":"10 of 25","pct":40,"denominator":"all 25 advisories in the series"},{"label":"Distinct CVEs named across the series","value":48,"denominator":"64 advisory-CVE mentions"},{"label":"Most CVEs in one advisory","value":11,"denominator":"AA25-050A, Ghost (Cring)"}]},{"id":"kev","heading":"Every CVE the series names is in CISA's KEV catalogue","finding":"All 48 distinct CVEs named across the series appear in CISA's Known Exploited Vulnerabilities catalogue (catalogVersion 2026.09.27, 1,728 entries), and all 48 carry knownRansomwareCampaignUse = 'Known'. The catalogue-wide rate for that flag is 361 of 1,728, 20.9%.","caution":"CISA maintains both the advisories and the KEV flag. Read this as internal consistency between two CISA products, not as independent corroboration.","figures":[{"label":"Named CVEs in KEV","value":"48 of 48","pct":100,"denominator":"the distinct CVEs named by the series"},{"label":"KEV base rate for 'Known' ransomware use","value":"361 of 1,728","pct":20.9,"denominator":"the whole KEV catalogue"}]},{"id":"initial-access","heading":"What the advisories list under Initial Access","finding":"On the whole-document rule, the 25 advisories print 62 advisory-technique pairs under Initial Access, with 2 of 25 listing none. On the tables-only rule the totals are 59 pairs and 3 of 25 listing none. The two rules differ on exactly one advisory, AA23-040A, and no figure here should be quoted without naming its rule. T1190 Exploit Public-Facing Application is the identifier most advisories list under Initial Access: 17 of 25 on the whole-document rule, 16 of 25 on the tables-only rule. T1133 External Remote Services follows at 13 and 12 of 25, and the T1566 Phishing family stands at 13 of 25 on both rules.","both_rules_required":true,"rule_a_tables_only":{"advisory_technique_pairs":59,"advisories_listing_none":{"n":3,"denominator":25,"denominator_label":"all 25 advisories in the series","pct":12,"small_denominator":false},"advisory_ids_listing_none":["AA23-040A","AA23-325A","AA23-353A"],"techniques_per_advisory":{"min":0,"median":2,"mean":2.36,"max":6},"by_exact_technique_id":[{"technique_id":"T1190","advisories":16,"denominator":25,"pct":64},{"technique_id":"T1133","advisories":12,"denominator":25,"pct":48},{"technique_id":"T1566","advisories":10,"denominator":25,"pct":40},{"technique_id":"T1078","advisories":10,"denominator":25,"pct":40},{"technique_id":"T1566.001","advisories":4,"denominator":25,"pct":16},{"technique_id":"T1566.002","advisories":2,"denominator":25,"pct":8},{"technique_id":"T1189","advisories":2,"denominator":25,"pct":8},{"technique_id":"T1021.001","advisories":1,"denominator":25,"pct":4},{"technique_id":"T1059.001","advisories":1,"denominator":25,"pct":4},{"technique_id":"T1566.004","advisories":1,"denominator":25,"pct":4}],"by_technique_family":[{"technique_family":"T1190","advisories":16,"denominator":25,"pct":64},{"technique_family":"T1566","advisories":13,"denominator":25,"pct":52},{"technique_family":"T1133","advisories":12,"denominator":25,"pct":48},{"technique_family":"T1078","advisories":10,"denominator":25,"pct":40},{"technique_family":"T1189","advisories":2,"denominator":25,"pct":8},{"technique_family":"T1021","advisories":1,"denominator":25,"pct":4},{"technique_family":"T1059","advisories":1,"denominator":25,"pct":4}]},"rule_b_whole_document":{"advisory_technique_pairs":62,"advisories_listing_none":{"n":2,"denominator":25,"denominator_label":"all 25 advisories in the series","pct":8,"small_denominator":false},"advisory_ids_listing_none":["AA23-325A","AA23-353A"],"techniques_per_advisory":{"min":0,"median":2,"mean":2.48,"max":6},"by_exact_technique_id":[{"technique_id":"T1190","advisories":17,"denominator":25,"pct":68},{"technique_id":"T1133","advisories":13,"denominator":25,"pct":52},{"technique_id":"T1566","advisories":10,"denominator":25,"pct":40},{"technique_id":"T1078","advisories":10,"denominator":25,"pct":40},{"technique_id":"T1566.001","advisories":4,"denominator":25,"pct":16},{"technique_id":"T1566.002","advisories":2,"denominator":25,"pct":8},{"technique_id":"T1189","advisories":2,"denominator":25,"pct":8},{"technique_id":"T1195","advisories":1,"denominator":25,"pct":4},{"technique_id":"T1021.001","advisories":1,"denominator":25,"pct":4},{"technique_id":"T1059.001","advisories":1,"denominator":25,"pct":4},{"technique_id":"T1566.004","advisories":1,"denominator":25,"pct":4}],"by_technique_family":[{"technique_family":"T1190","advisories":17,"denominator":25,"pct":68},{"technique_family":"T1133","advisories":13,"denominator":25,"pct":52},{"technique_family":"T1566","advisories":13,"denominator":25,"pct":52},{"technique_family":"T1078","advisories":10,"denominator":25,"pct":40},{"technique_family":"T1189","advisories":2,"denominator":25,"pct":8},{"technique_family":"T1195","advisories":1,"denominator":25,"pct":4},{"technique_family":"T1021","advisories":1,"denominator":25,"pct":4},{"technique_family":"T1059","advisories":1,"denominator":25,"pct":4}]},"t1110":{"advisories_citing_t1110_anywhere":4,"advisories_printing_t1110_under_initial_access":0,"denominator":25,"note":"T1110 Brute Force, or one of its sub-techniques, is cited in four of the 25 advisories, and in all four the row is printed under Credential Access. No advisory in the series codes it under Initial Access. AA24-242A's T1110.003 row nonetheless reads 'RansomHub affiliates may use password spraying to obtain initial access'; the coding follows the tactic each advisory prints, not its row text."},"guard":"These are counts of what each advisory's ATT&CK section prints. They are not a measure of how any ransomware family gains access."},{"id":"version-history","heading":"Nineteen of the twenty-five publish a version-history block; six publish none","finding":"19 of the 25 advisories publish a version-history or revisions block; 6 publish none and are recorded NULL, not zero - the series does not say whether they were never revised or whether the block is simply absent. Among the 19 that publish one, the entry count runs from 1 to 6 (AA23-061A, BlackSuit/Royal). The heading is written 'Revisions' on 2022 advisories and 'Version History', in mixed or upper case, from 2023 onwards, and entries appear in both orders.","figures":[{"label":"Publish a version-history block","value":"19 of 25","pct":76,"denominator":"all 25 advisories"},{"label":"Publish none (recorded NULL, not 0)","value":"6 of 25","pct":24,"denominator":"all 25 advisories"},{"label":"Most revision entries","value":6,"denominator":"AA23-061A, BlackSuit (Royal)"}],"advisory_ids_with_no_block":["AA23-040A","AA23-075A","AA23-158A","AA23-284A","AA23-352A","AA24-242A"]},{"id":"curated-index","heading":"Seven of the twenty-five are not linked from CISA's curated StopRansomware index","finding":"18 of the 25 advisories in the series appear in CISA's curated StopRansomware index; 7 do not - every 2022 advisory in the series plus AA23-040A. The index carries 38 advisory links in total, 20 of which are not part of the branded series at all, reaching back to AA18-337A (SamSam) and AA19-339A (Dridex).","figures":[{"label":"In CISA's curated index","value":"18 of 25","pct":72,"denominator":"all 25 advisories in the series"},{"label":"Absent from it","value":"7 of 25","pct":28,"denominator":"all 25 advisories in the series"},{"label":"Index links outside the series","value":20,"denominator":"38 links on the index"}],"absent_advisory_ids":["AA22-181A","AA22-223A","AA22-249A","AA22-294A","AA22-321A","AA22-335A","AA23-040A"]},{"id":"series-break","heading":"Advisories by year of first publication","finding":"The series starts on 30 June 2022 and the annual counts are small and vary: six advisories in 2022, eleven in 2023, four in 2024, three in 2025 and one so far in 2026. No annual cut has a denominator above eleven, so they are reported as counts and no percentage is given on them.","per_year":[{"year":"2022","advisories_first_published":6,"naming_no_cve":3,"pct_suppressed":true,"note":"3 of 6. Denominator of 6; reported as a count, not a percentage."},{"year":"2023","advisories_first_published":11,"naming_no_cve":6,"pct_suppressed":true,"note":"6 of 11. Denominator of 11; reported as a count, not a percentage."},{"year":"2024","advisories_first_published":4,"naming_no_cve":1,"pct_suppressed":true,"note":"1 of 4. Denominator of 4; reported as a count, not a percentage."},{"year":"2025","advisories_first_published":3,"naming_no_cve":1,"pct_suppressed":true,"note":"1 of 3. Denominator of 3; reported as a count, not a percentage."},{"year":"2026","advisories_first_published":1,"naming_no_cve":0,"pct_suppressed":true,"note":"0 of 1. Denominator of 1; reported as a count, not a percentage."}],"breaks":["2022 to 2023: the ATT&CK table convention changes from one combined table with tactic row-groups to one table per tactic with the tactic in the caption. A parser written for either form alone misses the other.","2022 to 2023: the version-history heading changes from 'Revisions' to 'Version History'.","AA23-040A breaks the per-family pattern: it is in the series by title but describes state-sponsored activity, not a named ransomware family.","Advisories are edited in place, so an advisory's content can change year to year without a new advisory number. AA25-071A's history records an August 2026 update."]}],"caveats":["This is a count of what CISA's documents name. An advisory that names no CVE is not evidence that the ransomware family exploits no vulnerability. AA23-075A (LockBit 3.0) names no CVE while telling readers to 'prioritize remediating known exploited vulnerabilities'.","AA23-325A is the clearest warning against misreading this dataset. It lists no Initial Access technique at all, yet it is specifically about exploitation of Citrix Bleed (CVE-2023-4966), which is named in its own title.","AA24-242A's T1110.003 row reads 'RansomHub affiliates may use password spraying to obtain initial access' - CISA's own words - yet the row is printed under Credential Access. The prose and the coding disagree inside one cell of one advisory.","n = 25. This is a census of a named series, not a sample, so there is no sampling error; but it is a small corpus, one advisory is four percentage points, and every cell has to be right. Each row carries its source URL, retrieval timestamp and the sha256 of the exact page parsed so any cell can be checked.","Percentages on the per-year cuts are suppressed. No year has more than eleven advisories (2022: 6, 2023: 11, 2024: 4, 2025: 3, 2026: 1 to date), so those cuts are reported as counts and no percentage is given on them.","These are living documents. Advisories carry version histories, and revisions are made inside table cells as well. Everything here is the versions retrieved on 2026-09-29; the counts can move when CISA revises an advisory.","AA22-249A (Vice Society) is published at two URLs, /aa22-249a and /aa22-249a-0, with the same title, the same date, the same two CVEs and the same technique IDs. Counted once. A naive title match over every advisory URL returns 26 URLs for 25 advisories.","The prefix test is applied case-insensitively as a defensive measure, because CISA's hashtag casing is not guaranteed across a series published over four years. It makes no difference to this population: all 26 strict-prefix pages carry the exact string '#StopRansomware:', so a case-sensitive test returns the same 26 URLs and the same 25 advisories.","AA23-325A writes 'CVE 2023-4966' with a space in its own title, and AA23-040A writes 'CVE 2021-44228'. The extraction is hyphen-tolerant. Across all 178 advisory pages fetched, 11 contain an unhyphenated rendering; in none of them does it change the CVE set, because the same identifier also appears hyphenated elsewhere on the page. The tolerant pattern is correct practice but it rescued nothing here.","CVEs are counted from the visible text, not from the markup. AA23-325A links to Citrix's own security bulletin, and that link's URL and title both carry CVE-2023-4967 - an identifier that appears nowhere in CISA's visible prose. A scan of the raw HTML would credit CISA with naming it. This is the only advisory in the series where the two rules differ, and it does not change the headline either way.","Six advisories publish no version-history block at all. Their revision count is NULL, not zero: the series does not say whether they were never revised or whether the block is simply absent. Fifteen advisories show a 'Last Revised' date in the page header, and one of those - AA23-352A - carries no block, so revision counts are a floor.","AA23-040A is in the series by the title rule but is not a per-family advisory: it describes state-sponsored activity funded by ransomware. 'Ransomware families' therefore describes 24 of the 25; the correct noun for the population is 'advisories'.","Advisories cite five different MITRE ATT&CK framework versions (v12, v15, v16, v17, v19). Technique IDs and tactic placement can move between versions, so a technique coded under Initial Access in one advisory is not automatically the same coding as in another.","Two advisories print, in their Initial Access tables, techniques ATT&CK assigns elsewhere: AA23-061A lists T1021.001 (Lateral Movement in ATT&CK) and AA23-352A lists T1059.001 (Execution). They are counted exactly as CISA printed them and listed separately, not silently corrected or dropped.","AA25-071A puts the TACTIC id TA0001 in the ID column of its Initial Access table. It is not a technique id and is not counted as one.","All 48 distinct CVEs named by the series are in CISA's KEV catalogue and all 48 are flagged knownRansomwareCampaignUse 'Known', against a catalogue base rate of 361 of 1,728 (20.9%). CISA maintains both the advisories and the flag, so this is internal consistency, not independent corroboration.","CISA runs three StopRansomware listings and no two of them hold the same set. The maintained index at /stopransomware/official-alerts-statements-cisa links 38 advisories, 18 of them in the series. A second listing at /stopransomware/stopransomware runs newest first, and its newest entry is the Black Basta advisory of 10 May 2024 (AA24-131A), whose headline it prints as '#STOPRANSOMARE: BLACK BASTA'. A third sits at /stopransomware/alerts. None of them claims to cover the whole series, which is why the population was built from the sitemap and each advisory's own title, never from an index label.","The reported ATT&CK coding is one machine-structural pass reconciled against one hand-coded pass, plus a third-method re-derivation and a cross-check against a separately written implementation that agreed on 24 of 25. It is not two blind human passes, and is not described as one.","We found no prior published count of this series, and no machine-readable publication of CISA's AA-numbered advisories: CISA publishes CSAF for its ICS series only. That is a negative search result, not proof that no such count exists, and no claim of being first is made anywhere in this study.","Three advisories - AA23-319A, AA23-352A and AA24-131A - link a superseded PDF revision alongside the current one. The companion PDF is taken to be the newest advisory-specific PDF the page links, dated by the /YYYY-MM/ segment of its own URL, which on all three is also the file CISA lists first. Read that way the HTML and companion-PDF bases give the same count. Read the superseded revisions as well and one advisory moves: AA23-319A's withdrawn November 2023 file names CVE-2020-1472, which neither its current PDF nor its HTML does.","No individual is named in the dataset, in any finding or in any figure. Prior work cited on this page is credited to the organisation or project that published it, which is what the ODbL and CC BY licences on that work require.","No leak-site data, no dark-web source, no victim organisation and no personal data was used or is published. Every fact comes from CISA's own published documents."],"method":{"what_was_measured":"For each advisory in CISA's #StopRansomware series: the CVE identifiers its page names, the ATT&CK Initial Access techniques it lists, whether it publishes a version history and how many entries that history has, whether CISA's own curated StopRansomware index links it, and whether its companion PDF agrees with its HTML on the CVE set.","what_was_not_measured":"How any ransomware family actually gains access, how often vulnerabilities are exploited, and anything about victims. None of those is in this dataset.","when":"Collected 2026-09-29 UTC. Analysis stage makes no network request and runs from the stored snapshot.","population":"Established three ways rather than inherited: the sitemap frame, the faceted fulltext listing and CISA's curated index. The first two agree exactly; the third is a subset and supplies the reconciliation. All three are CISA's own indexes, and two of them are subsets of the sitemap, so an advisory missing from CISA's sitemap would be missed by all three. Completeness is asserted against CISA's published indexes, not independently of them.","how":["robots.txt was fetched first and stored as evidence. It disallows /core/, /profiles/, /admin/, /search/, /media/oembed and four specific /user/ paths (register, password, login, logout), and gives PetalBot Disallow: /. It sets no Crawl-delay and excludes none of the paths used here.","The sitemap was walked and every /news-events/cybersecurity-advisories/ URL fetched - 178 pages, of which 175 match the regular aaNN-NNNx slug and 3 do not - so that no advisory could be excluded by an assumption about URL shape. One of the irregular slugs, /aa22-249a-0, turns out to be in the series.","Membership of the series was decided on each advisory's own served title, case-insensitively, never on an index label or a URL pattern.","CVEs were extracted with a hyphen-tolerant pattern over the page's visible text - tags stripped first, so that an identifier carried only in a link's URL or title attribute is not credited to CISA - then re-extracted with a second, differently written pattern as a check.","Version history was read from the block headed 'Revisions' or 'Version History'. Advisories publishing no block are NULL, not zero.","ATT&CK Initial Access was coded twice by different methods and reconciled, then re-derived a third way, then cross-checked against a separately written implementation. Both counting rules are published.","The CVEs were joined to CISA's KEV catalogue with count-equals-length assertions on both sides.","Fetching ran one request in flight at 1.2-second spacing with an identifying User-Agent. The stored manifests record 625 snapshot requests across 238 distinct URLs and a 178-page sweep of every advisory URL in the sitemap, every one of them HTTP 200, with no 429 and no 5xx. A further 22 requests were made for licence, policy and prior-art context: 18 returned 200, 3 returned 404 and 1 failed to connect. The failures are reported rather than hidden; none of those pages carries a figure in this study."],"unit_of_measurement":"The HTML page CISA serves. Two advisories attach no PDF at all, so a PDF-based census cannot be run across the series. The PDF basis is published alongside as an alternative.","counting_rules":{"cve":"A CVE is counted where its identifier appears in the advisory's body text, including in the title. Duplicates within one advisory count once.","initial_access":"Both rules are published. Rule A counts technique IDs printed in a table scoped to the Initial Access tactic. Rule B counts technique IDs the document names under Initial Access anywhere, including in prose under a sub-heading the advisory has itself tagged TA0001.","companion_pdf":"The companion PDF is the newest advisory-specific PDF the advisory page links, dated by the /sites/default/files/YYYY-MM/ segment of its own URL. Where an advisory links more than one, CISA also lists the newest first in its attachment block, so the two rules agree on every advisory in the series. Three advisories link a superseded revision as well; the union of every attached PDF is carried as its own separately labelled column and basis.","revisions":"NULL where no block is published. Never zero.","duplicates":"An advisory served at more than one URL counts once."},"personal_data":"None was collected or published. The advisories carry a CISA reporting mailbox, which is an organisational address and is not reproduced in the dataset. No individual is named in the dataset, in any finding or in any figure. Prior work cited on this page is credited to the organisation or project that published it, as its licence requires.","reproducibility":"This analysis makes no network request. Re-running scripts/research/stopransomware-advisory-census-2026/analyse.py against the stored snapshot reproduces the CSV byte for byte.","attribution_and_licence":{"source":"CISA advisories and the KEV catalogue are works of the US federal government and are not subject to US copyright under 17 U.S.C. 105(a). The KEV catalogue additionally carries an explicit CC0 1.0 dedication.","endorsement":"CISA's own rules prohibit use of the DHS seal or CISA logo in any way implying endorsement. Neither is reproduced. Each advisory's own non-endorsement wording is stored per advisory and travels with any quotation from it.","clauses_published":23,"clauses_denominator":25,"distinct_wordings":19}},"sources":[{"name":"CISA sitemap (population frame A)","url":"https://www.cisa.gov/default/sitemap.xml","retrieved_utc":"2026-09-29T06:58:41Z","sha256":"cf673d339d0a445262e65daaacbbf628c6591f0ad1042de007ed256a6edb2bd0","licence":"US federal government work, not subject to US copyright under 17 U.S.C. 105(a)","licence_note":"CISA publishes no explicit public-domain notice. The position rests on the statute and on CISA's TLP:CLEAR default, so this study does not say that CISA declares its own content public domain.","what_it_gave":"15,172 <loc> entries, 178 cybersecurity advisory URLs - 175 on the regular aaNN-NNNx pattern and 3 irregular slugs (aa21-0000a, aa22-249a-0, aa23-108), all of them fetched"},{"name":"CISA cybersecurity advisories, faceted fulltext listing (frame B)","url":"https://www.cisa.gov/news-events/cybersecurity-advisories?search_api_fulltext=stopransomware&f%5B0%5D=advisory_type%3A94","retrieved_utc":"2026-09-29","licence":"US federal government work, 17 U.S.C. 105(a)","what_it_gave":"46 distinct advisories over 10 pages"},{"name":"CISA StopRansomware curated index (frame C, and the reconciliation)","url":"https://www.cisa.gov/stopransomware/official-alerts-statements-cisa","retrieved_utc":"2026-09-29T06:59:40Z","sha256":"63839326b6302ac8103ac30da96f61bd10e505d097412c6c8c5a431ae346f3b2","licence":"US federal government work, 17 U.S.C. 105(a)","what_it_gave":"38 distinct advisories"},{"name":"CISA Known Exploited Vulnerabilities catalogue","url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","retrieved_utc":"2026-09-29T07:06:10Z","sha256":"164f2f100c3a2a810745500f49a8dd9041d59f9542c0ac1316d71578f25cb80b","licence":"CC0 1.0 Universal (public domain dedication)","licence_url":"https://www.cisa.gov/sites/default/files/licenses/kev/license.txt","what_it_gave":"catalogVersion 2026.09.27, 1,728 entries"},{"name":"The 25 advisory pages themselves","url":"https://www.cisa.gov/news-events/cybersecurity-advisories","retrieved_utc":"2026-09-29","licence":"US federal government work, 17 U.S.C. 105(a)","what_it_gave":"every figure in this study. Each of the 25 advisories is linked individually from the census table, and each row of the dataset carries its own source URL, retrieval timestamp and page sha256","attribution_note":"Each advisory carries its own non-endorsement wording and it travels with any quotation from that advisory. No CISA logo or DHS seal is reproduced, and nothing here implies CISA endorsement."},{"name":"MITRE ATT&CK®","url":"https://attack.mitre.org/","retrieved_utc":"2026-09-29","licence":"MITRE ATT&CK® Terms of Use: a non-exclusive, royalty-free licence to use ATT&CK for research, development and commercial purposes, on condition that MITRE's copyright notice and licence terms are reproduced.","licence_url":"https://attack.mitre.org/resources/legal-and-branding/terms-of-use/","required_attribution":"© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.","what_it_gave":"the plain-language names printed beside the technique identifiers (T1190 Exploit Public-Facing Application and the rest) and the Initial Access tactic those identifiers are grouped under. The technique identifiers themselves, and which of them each advisory lists, are read from the advisories","attribution_note":"ATT&CK® is a registered trade mark of The MITRE Corporation. No endorsement by MITRE is implied."}],"disagreements":[{"about":"How many advisories publish a version-history block","positions":[{"source":"collection stream 'population-and-facts'","value":6,"statement":"19 publish a block, 6 do not"},{"source":"collection stream 'advisory-facts' (headline_aggregates.json)","value":16,"statement":"9 publish a block, 16 do not"}],"resolved":true,"resolution":"Re-derived here from the stored HTML. The heading is written <h2><strong>Version History</strong></h2>, so a pattern that matches the heading tag's inner HTML rather than its stripped text misses it. AA22-181A, for example, publishes 'June 30, 2022: Initial Version' under an h3 'Revisions'. The published figure is 19 publishing a block and 6 not.","published_value":"6 of 25 publish no block"},{"about":"How to code ATT&CK Initial Access for AA23-040A","positions":[{"source":"rule A, tables only","value":59,"statement":"59 advisory-technique pairs; 3 advisories list none"},{"source":"rule B, whole document","value":62,"statement":"62 advisory-technique pairs; 2 advisories list none"}],"resolved":false,"resolution":"Not resolved, and deliberately so. AA23-040A publishes no ATT&CK table but names T1190, T1133 and T1195 in prose under a sub-heading it has itself tagged TA0001 (Initial Access). Rule A counts tables only; rule B counts what the document names anywhere. The two coding streams chose differently and agree on the other 24 of 25. Both are published, in the JSON and as separate CSV columns. Any prose must name the rule it uses and must not mix them.","published_value":"both rules, side by side"},{"about":"Which PDF counts as an advisory's companion PDF","positions":[{"source":"the first PDF stored for each advisory","value":10,"statement":"10 of 25 name no CVE in the HTML or that PDF - the figure an earlier draft of this study published"},{"source":"the newest advisory-specific PDF the page links","value":11,"statement":"11 of 25, the same set as the HTML basis"}],"resolved":true,"resolution":"Three advisories - AA23-319A, AA23-352A and AA24-131A - link a superseded PDF revision alongside the current one, and an earlier draft of this analysis read whichever file it had stored first. On AA23-319A that was the November 2023 file, which names CVE-2020-1472; the April 2025 revision CISA now serves names no CVE at all. The rule is now stated and applied: the companion PDF is the newest advisory-specific PDF the page links, dated by the /YYYY-MM/ segment of its own URL, which on all three advisories is also the file CISA lists first. On that rule the HTML and companion-PDF bases agree exactly, at 11 of 25. The superseded-PDF reading is kept as a third, separately labelled basis rather than dropped.","published_value":"11 of 25 on the HTML basis and the same 11 of 25 on the companion-PDF basis; 10 of 25 if superseded PDF revisions are read as well"},{"about":"The collection date","positions":[{"source":"the study brief","value":"2026-09-20","statement":"20 September 2026"},{"source":"the machine clock and every HTTP response","value":"2026-09-29","statement":"29 September 2026"}],"resolved":true,"resolution":"Every retrieval timestamp in every manifest records 29 September 2026. The study dates its collection from those timestamps.","published_value":"2026-09-29"}],"prior_art":[{"id":"enisa-ransomware-2022","work":"ENISA Threat Landscape for Ransomware Attacks","publisher":"European Union Agency for Cybersecurity (ENISA)","published":"July 2022","url":"https://www.enisa.europa.eu/sites/default/files/publications/ENISA%20Threat%20Landscape%20for%20Ransomware%20Attacks.pdf","licence":"CC BY 4.0 (verified in the PDF's own copyright notice)","what_it_measured":"623 ransomware incidents in the EU, UK and US, May 2021 to June 2022, coded against MITRE ATT&CK.","adjacent_finding":"ENISA could not establish an initial-access route for 594 of the 623 incidents it studied, or 95.3%. Only 29 incidents carried an initial-access technique at all, the most common being T1133 External Remote Services, at 12.","why_it_matters":"This is the closest prior work IN SHAPE: a public body counting what the record does not say, and reporting the gap as the finding.","how_ours_differs":"ENISA counted incident reports from many publishers about incidents. We count one publisher's own advisory series, document by document, and report per-document what each one names. Our denominator is a closed, nameable set of CISA documents that anyone can re-derive; ENISA's was an open collection of third-party reports.","verified":"primary PDF downloaded and text-searched locally"},{"id":"enisa-etl-2026","work":"ENISA Threat Landscape 2026","publisher":"ENISA","published":"September 2026","url":"https://www.enisa.europa.eu/sites/default/files/2026-09/ENISA%20Threat%20Landscape%202026_Final.pdf","licence":"CC BY 4.0; document marked TLP:CLEAR","what_it_measured":"8,257 incidents recorded 1 January 2025 to 31 December 2025.","adjacent_finding":"Across unauthorised-access incidents for which ENISA could identify an intrusion vector (5.2%), 60.4% leveraged a vulnerability. Separately, for state-nexus intrusion sets, ENISA identified an initial intrusion vector in only 20% of recorded incidents, and vulnerability exploitation was 70% of that subset.","why_it_matters":"The current edition of the same series, and again a statement about coverage of the record.","how_ours_differs":"Same distinction as above. Also a caution: several secondary summaries attribute '4,875 incidents, July 2024 to June 2025' to the 2026 edition; that is the 2025 edition. We checked the PDF.","verified":"primary PDF downloaded and text-searched locally"},{"id":"ics-advisory-project","work":"ICS Advisory Project","publisher":"ICS Advisory Project (community project)","published":"ongoing since 2022","url":"https://github.com/icsadvprj/ICS-Advisory-Project","licence":"Open Database License (ODbL) v1.0; contents under the Database Contents License (DbCL) 1.0","what_it_measured":"CISA's ICS advisories converted to CSV and dashboards, enriched with vendor location, product and critical-infrastructure sector.","adjacent_finding":"Establishes that CISA's advisory output is worth counting and that the community does count it - for one series.","why_it_matters":"Direct methodological precedent for treating a CISA advisory series as a countable corpus.","how_ours_differs":"It covers the ICS advisory series (ICSA/ICSMA), not the #StopRansomware series, and it republishes those advisories as structured CSV. The #StopRansomware advisories are prose - HTML and PDF - with no structured publication behind them, so the same approach does not reach them.","verified":"README fetched and read"},{"id":"open-ics-advisory-dataset","work":"Open ICS Advisory Dataset (OICSAD) v0.1.0","publisher":"Open ICS Advisory Dataset project","published":"26 September 2026","url":"https://github.com/foikwuogu/open-ics-advisory-dataset","licence":"MIT for the code, CC BY 4.0 for the data; upstream CISA CSAF is a US government work and KEV is CC0 1.0","what_it_measured":"3,937 CISA advisories (3,749 ICSA, 188 ICSMA) from 27 February 2010 to 24 September 2026 in CSAF form, parsed into three tables, 14,487 advisory-CVE links, 12,346 unique CVEs, 848 vendors, joined to CISA KEV.","adjacent_finding":"The nearest thing that exists to what we are doing: a census of a CISA advisory series joined to KEV.","why_it_matters":"It sets the bar for provenance and for the KEV join, and it is the work most likely to be cited alongside ours.","how_ours_differs":"Different corpus and a harder extraction problem. OICSAD reads structured CSAF, where the CVE list is a field. No CSAF exists for the #StopRansomware advisories, so every CVE in our census is read out of prose and every ATT&CK technique is hand-coded from tables whose layout changes between advisories.","verified":"repository page fetched and read"},{"id":"sophos-state-of-ransomware-2026","work":"The State of Ransomware 2026","publisher":"Sophos","published":"July 2026","url":"https://www.sophos.com/en-us/content/state-of-ransomware","licence":"All rights reserved (c) 2026 Sophos Ltd. No open licence. Cite, do not reproduce tables.","what_it_measured":"Vendor survey: 2,158 IT and cybersecurity leaders in 17 countries, fieldwork January to March 2026, recalling the previous 12 months.","adjacent_finding":"Reports root causes of ransomware attacks from a victim survey. Sophos's own published materials say malicious email and phishing are now the top root causes and together account for about half of incidents. Individual root-cause percentages circulating in press coverage of the launch are not reproduced here: they could not be checked against a Sophos primary document in this pass, so they are left out rather than repeated.","why_it_matters":"This is the kind of figure our own live page currently borrows, and the figure a reader will reach for when they see our headline.","how_ours_differs":"Sophos asks victims what happened to them, in a survey, under one vendor's methodology. We count what is written in a fixed set of public documents. The two answer different questions and neither substitutes for the other.","verified":"Survey size, country count and fieldwork window checked against sophos.com. Individual root-cause percentages were not checkable against a Sophos primary document and are not carried."},{"id":"cisa-top-routinely-exploited","work":"Top Routinely Exploited Vulnerabilities (annual joint advisory series)","publisher":"CISA with international partners","published":"annual, e.g. AA24-317A for 2023","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a","licence":"US government work, 17 U.S.C. 105(a)","what_it_measured":"CISA's own ranked list of the CVEs most routinely exploited in a year.","adjacent_finding":"CISA does publish CVE counts, in a different series and about exploitation generally rather than about ransomware families. The 2023 edition, AA24-317A of 12 November 2024, names 50 distinct CVE identifiers on one page - two more than the whole #StopRansomware series names across 25 advisories.","why_it_matters":"Pre-empts the obvious objection that CISA already tells you which CVEs matter. It does, elsewhere. The question here is what the #StopRansomware advisories themselves name.","how_ours_differs":"We count the #StopRansomware series only, and we count per advisory, not per vulnerability.","verified":"Page is in the study's own snapshot (raw/snapshot-2026-09-29/advisories/aa24-317a.html, retrieved 2026-09-29T07:03:16Z, one of the 178 advisory pages fetched); title, publication date and the 50 distinct CVE identifiers re-read from those stored bytes."},{"id":"greynoise-kev-ransomware-flips","work":"The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates","publisher":"GreyNoise","published":"2 February 2026","url":"https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates","licence":"Commercial site, all rights reserved","what_it_measured":"Changes to the knownRansomwareCampaignUse field in CISA's KEV catalogue during 2025: 59 entries moved from 'Unknown' to 'Known' with no announcement, with breakdowns by vendor, device class and month.","adjacent_finding":"The nearest published work on CISA's own ransomware metadata, and the reason a KEV flag should not be read as a fixed property of a CVE.","why_it_matters":"Our KEV section prints a catalogue-wide base rate for the same flag. A reader who knows this work will ask whether that rate is stable; it is a snapshot of one catalogue version, and we say so.","how_ours_differs":"GreyNoise tracks how the flag changes over time across the whole catalogue. We take one catalogue version as a fixed reference point and use it only as context for a document census; we do not track change and make no claim about when any flag was set.","verified":"Post fetched and read 2026-09-29: publication date, the headline count of 59 flips during 2025 and the vendor and device-class breakdowns are as described."},{"id":"tidal-cyber-ransomware-matrix","work":"Ransomware and Data Extortion Landscape TTP matrix","publisher":"Tidal Cyber","published":"28 February 2023 (post); matrix ongoing","url":"https://www.tidalcyber.com/blog/ransomware-threat-profiling-prioritizing-indiscriminate-threats","licence":"Commercial site, all rights reserved","what_it_measured":"ATT&CK technique collections for 29 recently active ransomware groups and families, assembled from public reporting.","adjacent_finding":"Aggregates ATT&CK techniques per ransomware family across many sources.","why_it_matters":"The nearest commercial equivalent for the ATT&CK half of our census.","how_ours_differs":"Tidal pools sources to describe a family. We deliberately do not pool: we record what one named document says, so the count is checkable against that document. Tidal's post does not claim to catalogue the #StopRansomware series.","verified":"post fetched and read; it does not mention cataloguing the #StopRansomware series"}],"novelty":{"claim":"We found no prior published count of what CISA's own #StopRansomware advisory series names.","basis":"CISA publishes CSAF machine-readable output for its ICS advisory series only. The AA-numbered advisories are prose - HTML and PDF and we found no equivalent machine-readable publication of them.","search_result":"Four search framings found no existing count of the series. That is a negative search result.","not_claimed":"Not described as a first. The house rule against 'first ever' applies, and this evidence could not carry the claim in any case.","closest_prior_work":"ENISA's Threat Landscape for Ransomware Attacks (2022), which could not establish an initial-access route for 594 of the 623 incidents it studied - 95.3%. That is the closest work in shape: a public body counting what the record does not say. It counted third-party incident reports; we count one publisher's own document series, document by document."},"differentiation":{"placement":"a short box after the method section, before the table","heading":"How this differs from our backup-targeting page","body":"We also keep a page on <a href=\"/research/ransomware-backup-targeting-statistics-2026\">ransomware and backup targeting</a>. That page collects figures other organisations published about ransomware incidents: victim surveys, vendor telemetry, recovery rates. This page counts something different and much narrower - the contents of a fixed set of documents. It reports which CVEs CISA's own #StopRansomware advisories name. It does not report how often ransomware exploits a vulnerability, and no figure here should be read that way."},"internal_links":{"mechanism":"NOT lib/related-mesh.ts: that file is generated daily by scripts/mesh/build-mesh.mjs and a hand-added entry would be overwritten on the next run. The reciprocal link is carried where it survives a regeneration - an in-body link each way plus the backup page's own related[] entry in lib/program-content/p070.ts, which the renderer already gates on the release date. The census page links the backup page from its differentiation section and its footer.","mesh_entry_for_backup_page":{"href":"/research/stopransomware-advisory-census-2026","label":"What CISA's own ransomware advisories actually name"},"mesh_entry_for_census_page":{"href":"/research/ransomware-backup-targeting-statistics-2026","label":"Ransomware Backup Targeting Statistics 2026: The Data Study"},"anchor_text_rules":["Never anchor the census page on 'how ransomware gets in' or any initial-access phrasing.","Anchor on what the documents name: 'what CISA's advisories name', 'our count of CISA's ransomware advisories'.","One link each way in the body, plus the mesh entries. No more - these are neighbouring pages, not a hub."]},"dataset":{"csv":"/research/stopransomware-advisory-census-2026.csv","readme":"/research/stopransomware-advisory-census-2026-README.txt","rows":25,"licence":"Source: US federal government work, 17 U.S.C. 105(a); KEV fields CC0 1.0. Our derived dataset: CC BY 4.0.","csv_sha256":"8102816f6af292feecdd07529a13a5e69cf48b92b6f70ce3089a2107ca815317"}},"data":{"headline":{"population":25,"names_no_cve_html":{"n":11,"denominator":25,"denominator_label":"all 25 advisories in the series","pct":44,"small_denominator":false},"names_no_cve_html_or_companion_pdf":{"n":11,"denominator":25,"denominator_label":"all 25 advisories in the series","pct":44,"small_denominator":false},"names_no_cve_html_or_any_attached_pdf":{"n":10,"denominator":25,"denominator_label":"all 25 advisories in the series","pct":40,"small_denominator":false},"names_at_least_one_cve_html":{"n":14,"denominator":25,"denominator_label":"all 25 advisories in the series","pct":56,"small_denominator":false},"advisory_ids_naming_no_cve_html":["AA22-181A","AA22-223A","AA22-294A","AA23-061A","AA23-075A","AA23-263A","AA23-284A","AA23-319A","AA23-353A","AA24-060A","AA25-203A"],"advisory_ids_naming_no_cve_html_or_companion_pdf":["AA22-181A","AA22-223A","AA22-294A","AA23-061A","AA23-075A","AA23-263A","AA23-284A","AA23-319A","AA23-353A","AA24-060A","AA25-203A"],"advisory_ids_naming_no_cve_html_or_any_attached_pdf":["AA22-181A","AA22-223A","AA22-294A","AA23-061A","AA23-075A","AA23-263A","AA23-284A","AA23-353A","AA24-060A","AA25-203A"],"bases_agree":true,"basis_difference":[],"superseded_pdf_basis_difference":["AA23-319A"],"basis_note":"The published basis is the HTML page CISA serves. Reading each advisory's current companion PDF as well returns the same advisories. The count only moves if superseded PDF revisions are read too, which is a third and separately labelled basis."},"cves":{"mentions":64,"distinct":48,"distinct_list":["CVE-2009-3960","CVE-2010-2861","CVE-2014-1812","CVE-2017-0143","CVE-2017-0144","CVE-2018-13379","CVE-2019-0604","CVE-2020-0787","CVE-2020-1472","CVE-2020-3259","CVE-2020-3580","CVE-2020-12812","CVE-2021-1675","CVE-2021-20038","CVE-2021-31207","CVE-2021-34473","CVE-2021-34523","CVE-2021-34527","CVE-2021-42278","CVE-2021-42287","CVE-2021-42321","CVE-2021-44228","CVE-2022-24521","CVE-2022-24990","CVE-2022-37969","CVE-2022-41040","CVE-2022-41082","CVE-2023-0669","CVE-2023-3519","CVE-2023-4966","CVE-2023-20269","CVE-2023-22515","CVE-2023-27532","CVE-2023-27997","CVE-2023-28252","CVE-2023-34362","CVE-2023-46604","CVE-2023-46747","CVE-2023-48788","CVE-2024-1709","CVE-2024-37085","CVE-2024-40711","CVE-2024-40766","CVE-2024-55591","CVE-2024-57727","CVE-2025-10035","CVE-2025-24472","CVE-2026-1731"],"per_advisory":{"min":0,"median":2,"mean":2.56,"max":11,"max_advisory":"AA25-050A","denominator":25},"distribution":[{"cve_count":0,"advisories":11,"denominator":25},{"cve_count":1,"advisories":1,"denominator":25},{"cve_count":2,"advisories":4,"denominator":25},{"cve_count":3,"advisories":1,"denominator":25},{"cve_count":4,"advisories":1,"denominator":25},{"cve_count":5,"advisories":4,"denominator":25},{"cve_count":8,"advisories":1,"denominator":25},{"cve_count":9,"advisories":1,"denominator":25},{"cve_count":11,"advisories":1,"denominator":25}]},"kev":{"catalog_version":"2026.09.27","date_released":"2026-09-27T21:30:35.5521Z","entries":1728,"declared_count_equals_array_length":true,"sha256":"164f2f100c3a2a810745500f49a8dd9041d59f9542c0ac1316d71578f25cb80b","named_cves_in_kev":{"n":48,"denominator":48,"denominator_label":"the 48 distinct CVEs named by the series","pct":100,"small_denominator":false},"named_cves_flagged_known_ransomware_use":{"n":48,"denominator":48,"denominator_label":"the 48 distinct CVEs named by the series","pct":100,"small_denominator":false},"catalogue_base_rate_known":{"n":361,"denominator":1728,"denominator_label":"the whole KEV catalogue","pct":20.9,"small_denominator":false},"circularity_note":"CISA maintains both the advisories and the KEV flag. This is a consistency check between two CISA products, not external validation."},"initial_access":{"rule_a_tables_only":{"advisory_technique_pairs":59,"advisories_listing_none":{"n":3,"denominator":25,"denominator_label":"all 25 advisories in the series","pct":12,"small_denominator":false},"advisory_ids_listing_none":["AA23-040A","AA23-325A","AA23-353A"],"techniques_per_advisory":{"min":0,"median":2,"mean":2.36,"max":6},"by_exact_technique_id":[{"technique_id":"T1190","advisories":16,"denominator":25,"pct":64},{"technique_id":"T1133","advisories":12,"denominator":25,"pct":48},{"technique_id":"T1566","advisories":10,"denominator":25,"pct":40},{"technique_id":"T1078","advisories":10,"denominator":25,"pct":40},{"technique_id":"T1566.001","advisories":4,"denominator":25,"pct":16},{"technique_id":"T1566.002","advisories":2,"denominator":25,"pct":8},{"technique_id":"T1189","advisories":2,"denominator":25,"pct":8},{"technique_id":"T1021.001","advisories":1,"denominator":25,"pct":4},{"technique_id":"T1059.001","advisories":1,"denominator":25,"pct":4},{"technique_id":"T1566.004","advisories":1,"denominator":25,"pct":4}],"by_technique_family":[{"technique_family":"T1190","advisories":16,"denominator":25,"pct":64},{"technique_family":"T1566","advisories":13,"denominator":25,"pct":52},{"technique_family":"T1133","advisories":12,"denominator":25,"pct":48},{"technique_family":"T1078","advisories":10,"denominator":25,"pct":40},{"technique_family":"T1189","advisories":2,"denominator":25,"pct":8},{"technique_family":"T1021","advisories":1,"denominator":25,"pct":4},{"technique_family":"T1059","advisories":1,"denominator":25,"pct":4}]},"rule_b_whole_document":{"advisory_technique_pairs":62,"advisories_listing_none":{"n":2,"denominator":25,"denominator_label":"all 25 advisories in the series","pct":8,"small_denominator":false},"advisory_ids_listing_none":["AA23-325A","AA23-353A"],"techniques_per_advisory":{"min":0,"median":2,"mean":2.48,"max":6},"by_exact_technique_id":[{"technique_id":"T1190","advisories":17,"denominator":25,"pct":68},{"technique_id":"T1133","advisories":13,"denominator":25,"pct":52},{"technique_id":"T1566","advisories":10,"denominator":25,"pct":40},{"technique_id":"T1078","advisories":10,"denominator":25,"pct":40},{"technique_id":"T1566.001","advisories":4,"denominator":25,"pct":16},{"technique_id":"T1566.002","advisories":2,"denominator":25,"pct":8},{"technique_id":"T1189","advisories":2,"denominator":25,"pct":8},{"technique_id":"T1195","advisories":1,"denominator":25,"pct":4},{"technique_id":"T1021.001","advisories":1,"denominator":25,"pct":4},{"technique_id":"T1059.001","advisories":1,"denominator":25,"pct":4},{"technique_id":"T1566.004","advisories":1,"denominator":25,"pct":4}],"by_technique_family":[{"technique_family":"T1190","advisories":17,"denominator":25,"pct":68},{"technique_family":"T1133","advisories":13,"denominator":25,"pct":52},{"technique_family":"T1566","advisories":13,"denominator":25,"pct":52},{"technique_family":"T1078","advisories":10,"denominator":25,"pct":40},{"technique_family":"T1189","advisories":2,"denominator":25,"pct":8},{"technique_family":"T1195","advisories":1,"denominator":25,"pct":4},{"technique_family":"T1021","advisories":1,"denominator":25,"pct":4},{"technique_family":"T1059","advisories":1,"denominator":25,"pct":4}]},"rules_differ_on":["AA23-040A"],"cross_stream_agreement":{"advisories_compared":25,"agreed":24,"pct":96,"note":"two separately written implementations; the single difference is the AA23-040A coding rule, not an error on either side"},"t1110_audit":[{"advisory_id":"aa23-263a","t1110_ids_present":["T1110","T1110.001"],"placements":[{"tactic_as_printed":"Credential Access","row":"Brute Force: Password Guessing | T1110.001 | Snatch threat actors use brute force to obtain administrator credentials for a victim’s network."}]},{"advisory_id":"aa24-060a","t1110_ids_present":["T1110"],"placements":[{"tactic_as_printed":"Credential Access","row":"Brute Force | T1110 | Phobos actors may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained."}]},{"advisory_id":"aa24-109a","t1110_ids_present":["T1110","T1110.003"],"placements":[{"tactic_as_printed":"Credential Access","row":"Brute Force | T1110 | Akira threat actors gain access by brute-forcing VPN logins and SSH endpoints."},{"tactic_as_printed":"Credential Access","row":"Brute Force: Password Spraying | T1110.003 | Akira threat actors use tools like SharpDomainSpray for password spraying."}]},{"advisory_id":"aa24-242a","t1110_ids_present":["T1110","T1110.003"],"placements":[{"tactic_as_printed":"Credential Access","row":"Brute Force: Password Spraying | T1110.003 | RansomHub affiliates may use password spraying to obtain initial access."}]}],"table_layouts":[{"layout":"L0","advisories":["aa23-040a"],"count":1},{"layout":"L1","advisories":["aa23-061a","aa23-136a","aa23-263a","aa23-319a","aa23-325a","aa23-352a","aa23-353a","aa24-060a","aa24-109a","aa24-131a","aa24-242a","aa25-050a","aa25-071a","aa25-203a","aa26-222a"],"count":15},{"layout":"L1|L4","advisories":["aa23-158a","aa23-284a"],"count":2},{"layout":"L2","advisories":["aa22-223a","aa22-249a","aa22-294a","aa22-321a","aa22-335a","aa23-075a"],"count":6},{"layout":"L4","advisories":["aa22-181a"],"count":1}],"layout_key":{"L0":"no ATT&CK table; technique IDs cited inline in prose","L1":"one table per tactic, tactic named in the caption","L2":"combined table, tactic carried by a full-width row-group header","L3":"combined table, tactic carried by a rowspan cell in column 1","L4":"combined table, tactic in column 1 of a row whose other cells are empty"},"off_tactic_rows":[{"advisory_id":"aa23-061a","technique_id":"T1021.001","note":"ATT&CK places T1021.001 under Lateral Movement"},{"advisory_id":"aa23-352a","technique_id":"T1059.001","note":"ATT&CK places T1059.001 under Execution"}]},"version_history":{"publishes_block":{"n":19,"denominator":25,"denominator_label":"all 25 advisories in the series","pct":76,"small_denominator":false},"publishes_none":{"n":6,"denominator":25,"denominator_label":"all 25 advisories in the series","pct":24,"small_denominator":false},"advisory_ids_with_no_block":["AA23-040A","AA23-075A","AA23-158A","AA23-284A","AA23-352A","AA24-242A"],"entries_among_publishers":{"min":1,"median":1,"max":6,"denominator":19,"denominator_label":"the 19 advisories that publish a block"},"null_not_zero":"An advisory with no block is NULL. The series does not say whether it was never revised or whether the block is absent.","heading_variants":["Revisions (2022 advisories, 6)","Version History (2023 onwards, 9)","VERSION HISTORY in block capitals (2023 onwards, 4)"],"entry_order_variants":["October 21, 2022: Initial version","Initial Publication: October 21, 2022"],"derived_from":"data/research/stopransomware-advisory-census-2026/raw/advisories"},"curated_index":{"index_links":38,"in_series_and_index":{"n":18,"denominator":25,"denominator_label":"all 25 advisories in the series","pct":72,"small_denominator":false},"in_series_not_index":{"n":7,"denominator":25,"denominator_label":"all 25 advisories in the series","pct":28,"small_denominator":false},"index_not_series":20,"absent_advisory_ids":["AA22-181A","AA22-223A","AA22-249A","AA22-294A","AA22-321A","AA22-335A","AA23-040A"],"index_entries_outside_series":[{"advisory_id":"AA18-337A","title":"SamSam Ransomware"},{"advisory_id":"AA19-339A","title":"Dridex Malware"},{"advisory_id":"AA20-010A","title":"Continued Exploitation of Pulse Secure VPN Vulnerability"},{"advisory_id":"AA20-049A","title":"Ransomware Impacting Pipeline Operations"},{"advisory_id":"AA20-106A","title":"Guidance on the North Korean Cyber Threat"},{"advisory_id":"AA20-107A","title":"Continued Threat Actor Exploitation Post Pulse Secure VPN Patching"},{"advisory_id":"AA20-183A","title":"Defending Against Malicious Cyber Activity Originating from Tor"},{"advisory_id":"AA20-280A","title":"Emotet Malware"},{"advisory_id":"AA20-302A","title":"Ransomware Activity Targeting the Healthcare and Public Health Sector"},{"advisory_id":"AA20-345A","title":"Cyber Actors Target K-12 Distance Learning Education to Cause Disruptions and Steal Data"},{"advisory_id":"AA21-076A","title":"TrickBot Malware"},{"advisory_id":"AA21-131A","title":"DarkSide Ransomware: Best Practices for Preventing Business Disruption from Ransomware Attacks"},{"advisory_id":"AA21-287A","title":"Ongoing Cyber Threats to U.S. Water and Wastewater Systems"},{"advisory_id":"AA21-291A","title":"BlackMatter Ransomware"},{"advisory_id":"AA21-321A","title":"Iranian Government-Sponsored APT Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities in Furtherance of Malicious Activities"},{"advisory_id":"AA22-152A","title":"Karakurt Data Extortion Group"},{"advisory_id":"AA22-216A","title":"2021 Top Malware Strains"},{"advisory_id":"AA23-039A","title":"ESXiArgs Ransomware Virtual Machine Recovery Guidance"},{"advisory_id":"AA23-165A","title":"Understanding Ransomware Threat Actors: LockBit"},{"advisory_id":"AA25-163A","title":"Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider"}],"note":"The index does not claim to cover the series - it describes itself as 'official CISA updates' - and it cannot be used as the population frame. CISA runs three StopRansomware listings and no two of them hold the same set: this one, a second at /stopransomware/stopransomware whose newest entry is the Black Basta advisory of 10 May 2024 and which prints that headline as '#STOPRANSOMARE: BLACK BASTA', and a third at /stopransomware/alerts."},"html_vs_pdf":{"advisories_with_a_pdf":{"n":23,"denominator":25,"denominator_label":"all 25 advisories in the series","pct":92,"small_denominator":false},"advisories_with_no_pdf":["AA22-249A","AA23-040A"],"companion_pdf_rule":"The companion PDF is the newest advisory-specific PDF the advisory page links, dated by the /sites/default/files/YYYY-MM/ segment of its own URL. Where an advisory links more than one, CISA also lists the newest first in its attachment block, so the two rules agree on every advisory in the series.","advisories_attaching_more_than_one_pdf":["AA23-319A","AA23-352A","AA24-131A"],"disagreements":[],"detail":{"companion_pdf_rule":"The companion PDF is the newest advisory-specific PDF the advisory page links, dated by the /sites/default/files/YYYY-MM/ segment of its own URL. Where an advisory links more than one, CISA also lists the newest first in its attachment block, so the two rules agree on every advisory in the series.","advisories_attaching_more_than_one_pdf":["AA23-319A","AA23-352A","AA24-131A"],"basis_html_as_served":{"names_zero_cves_n":11,"population_n":25,"pct":44,"codes":["AA22-181A","AA22-223A","AA22-294A","AA23-061A","AA23-075A","AA23-263A","AA23-284A","AA23-319A","AA23-353A","AA24-060A","AA25-203A"],"definition":"CVE identifiers appearing in the advisory's HTML page as served on 2026-09-29. This is the published basis: it is the live document, and it is the only artefact every advisory in the series has."},"basis_html_or_current_companion_pdf":{"names_zero_cves_n":11,"population_n":25,"pct":44,"codes":["AA22-181A","AA22-223A","AA22-294A","AA23-061A","AA23-075A","AA23-263A","AA23-284A","AA23-319A","AA23-353A","AA24-060A","AA25-203A"],"definition":"CVE identifiers appearing in EITHER the HTML page or the advisory's current companion PDF - the newest advisory-specific PDF the page links."},"basis_html_or_any_attached_pdf":{"names_zero_cves_n":10,"population_n":25,"pct":40,"codes":["AA22-181A","AA22-223A","AA22-294A","AA23-061A","AA23-075A","AA23-263A","AA23-284A","AA23-353A","AA24-060A","AA25-203A"],"definition":"CVE identifiers appearing in the HTML page or in ANY PDF the page links, including superseded revisions CISA leaves attached beside the current file."},"advisories_that_change_basis":{"html_vs_current_companion_pdf":[],"html_vs_any_attached_pdf":["AA23-319A"]},"change_detail":{"AA23-319A":"Rhysida. The HTML page names no CVE, and neither does the current companion PDF (April 2025 revision). The advisory also still links the superseded November 2023 PDF, and that file does name one, in the sentence 'actors have been observed exploiting Zerologon (CVE-2020-1472)—a critical elevation of privileges vulnerability in Microsoft's Netlogon Remote Protocol [T1190]'. The April 2025 revision rewrote that section. This is the only advisory in the series where reading the superseded PDF as well as the current one changes the count."},"html_vs_current_companion_pdf_disagreements":[],"advisories_with_no_companion_pdf":["AA22-249A","AA23-040A"],"basis_note_for_readers":"Both published bases give the same figure. Eleven of the twenty-five advisories name no CVE on the page CISA serves, and the same eleven name none in their current companion PDF either. The figure only moves if superseded PDF revisions are read as well, which is a third and differently labelled basis: on that reading it is ten of twenty-five, because AA23-319A's withdrawn November 2023 file names CVE-2020-1472. Any figure taken from this study should name the artefact it was counted from."}},"by_year":[{"year":"2022","advisories_first_published":6,"naming_no_cve":3,"pct_suppressed":true,"note":"3 of 6. Denominator of 6; reported as a count, not a percentage."},{"year":"2023","advisories_first_published":11,"naming_no_cve":6,"pct_suppressed":true,"note":"6 of 11. Denominator of 11; reported as a count, not a percentage."},{"year":"2024","advisories_first_published":4,"naming_no_cve":1,"pct_suppressed":true,"note":"1 of 4. Denominator of 4; reported as a count, not a percentage."},{"year":"2025","advisories_first_published":3,"naming_no_cve":1,"pct_suppressed":true,"note":"1 of 3. Denominator of 3; reported as a count, not a percentage."},{"year":"2026","advisories_first_published":1,"naming_no_cve":0,"pct_suppressed":true,"note":"0 of 1. Denominator of 1; reported as a count, not a percentage."}],"non_endorsement":{"advisories_carrying_a_clause":{"n":23,"denominator":25,"denominator_label":"all 25 advisories in the series","pct":92,"small_denominator":false},"distinct_wordings":19,"note":"The wording differs in which agencies it names. Each clause is stored per advisory so the right one travels with the right quotation.","clauses_by_advisory":{"AA22-181A":null,"AA22-223A":"Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA or the FBI.","AA22-249A":"Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by the FBI, CISA, or the MS-ISAC.","AA22-294A":"Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI, CISA, or HHS.","AA22-321A":"Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI, CISA, or HHS.","AA22-335A":"Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI or CISA.","AA23-040A":null,"AA23-061A":"Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI and CISA.","AA23-075A":"Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by the FBI, CISA, or the MS-ISAC.","AA23-136A":"Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI, CISA, or ASD’S ACSC.","AA23-158A":"Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA or the FBI.","AA23-263A":"Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI or CISA.","AA23-284A":"Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA and FBI.","AA23-319A":"Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI, CISA, and the MS-ISAC.","AA23-325A":"Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA and the authoring organizations.","AA23-352A":"Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA or FBI.","AA23-353A":"Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI, CISA, and HHS.","AA24-060A":"Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise does not constitute or imply endorsement, recommendation, or favoring by CISA, the FBI, and the MS-ISAC.","AA24-109A":"Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favor by FBI and co-sealers.","AA24-131A":"Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI, CISA, HHS, and MS-ISAC.","AA24-242A":"Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by the authoring organizations.","AA25-050A":"Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by the FBI, CISA, and the MS-ISAC.","AA25-071A":"Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA and the authoring agencies.","AA25-203A":"Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favor by the authoring agencies.","AA26-222A":"Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA and co-sealers."}},"advisories":[{"id":"AA22-181A","title":"#StopRansomware: MedusaLocker","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-181a","first_published":"2022-06-30","names_cve_html":false,"cve_count_html":0,"cves_html":[],"names_cve_html_or_companion_pdf":false,"names_cve_html_or_any_attached_pdf":false,"attached_pdf_count":1,"ia_tables_only":["T1133","T1566"],"ia_whole_document":["T1133","T1566"],"attack_layout":"L4","version_history":true,"revision_entries":1,"in_curated_index":false,"duplicate_urls":1},{"id":"AA22-223A","title":"#StopRansomware: Zeppelin Ransomware","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-223a","first_published":"2022-08-11","names_cve_html":false,"cve_count_html":0,"cves_html":[],"names_cve_html_or_companion_pdf":false,"names_cve_html_or_any_attached_pdf":false,"attached_pdf_count":1,"ia_tables_only":["T1133","T1190","T1566"],"ia_whole_document":["T1133","T1190","T1566"],"attack_layout":"L2","version_history":true,"revision_entries":1,"in_curated_index":false,"duplicate_urls":1},{"id":"AA22-249A","title":"#StopRansomware: Vice Society","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-249a","first_published":"2022-09-06","names_cve_html":true,"cve_count_html":2,"cves_html":["CVE-2021-1675","CVE-2021-34527"],"names_cve_html_or_companion_pdf":true,"names_cve_html_or_any_attached_pdf":true,"attached_pdf_count":0,"ia_tables_only":["T1078","T1190"],"ia_whole_document":["T1078","T1190"],"attack_layout":"L2","version_history":true,"revision_entries":1,"in_curated_index":false,"duplicate_urls":2},{"id":"AA22-294A","title":"#StopRansomware: Daixin Team","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-294a","first_published":"2022-10-21","names_cve_html":false,"cve_count_html":0,"cves_html":[],"names_cve_html_or_companion_pdf":false,"names_cve_html_or_any_attached_pdf":false,"attached_pdf_count":1,"ia_tables_only":["T1078","T1190"],"ia_whole_document":["T1078","T1190"],"attack_layout":"L2","version_history":true,"revision_entries":1,"in_curated_index":false,"duplicate_urls":1},{"id":"AA22-321A","title":"#StopRansomware: Hive Ransomware","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-321a","first_published":"2022-11-17","names_cve_html":true,"cve_count_html":5,"cves_html":["CVE-2020-12812","CVE-2021-31207","CVE-2021-34473","CVE-2021-34523","CVE-2021-42321"],"names_cve_html_or_companion_pdf":true,"names_cve_html_or_any_attached_pdf":true,"attached_pdf_count":1,"ia_tables_only":["T1133","T1190","T1566.001"],"ia_whole_document":["T1133","T1190","T1566.001"],"attack_layout":"L2","version_history":true,"revision_entries":1,"in_curated_index":false,"duplicate_urls":1},{"id":"AA22-335A","title":"#StopRansomware: Cuba Ransomware","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-335a","first_published":"2022-12-01","names_cve_html":true,"cve_count_html":2,"cves_html":["CVE-2020-1472","CVE-2022-24521"],"names_cve_html_or_companion_pdf":true,"names_cve_html_or_any_attached_pdf":true,"attached_pdf_count":1,"ia_tables_only":["T1078","T1133","T1190","T1566"],"ia_whole_document":["T1078","T1133","T1190","T1566"],"attack_layout":"L2","version_history":true,"revision_entries":2,"in_curated_index":false,"duplicate_urls":1},{"id":"AA23-040A","title":"#StopRansomware: Ransomware Attacks on Critical Infrastructure Fund DPRK Malicious Cyber Activities","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-040a","first_published":"2023-02-09","names_cve_html":true,"cve_count_html":3,"cves_html":["CVE-2021-20038","CVE-2021-44228","CVE-2022-24990"],"names_cve_html_or_companion_pdf":true,"names_cve_html_or_any_attached_pdf":true,"attached_pdf_count":0,"ia_tables_only":[],"ia_whole_document":["T1133","T1190","T1195"],"attack_layout":"L0","version_history":false,"revision_entries":null,"in_curated_index":false,"duplicate_urls":1},{"id":"AA23-061A","title":"#StopRansomware: Blacksuit (Royal) Ransomware","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-061a","first_published":"2023-03-02","names_cve_html":false,"cve_count_html":0,"cves_html":[],"names_cve_html_or_companion_pdf":false,"names_cve_html_or_any_attached_pdf":false,"attached_pdf_count":1,"ia_tables_only":["T1021.001","T1133","T1190","T1566","T1566.001","T1566.002"],"ia_whole_document":["T1021.001","T1133","T1190","T1566","T1566.001","T1566.002"],"attack_layout":"L1","version_history":true,"revision_entries":6,"in_curated_index":true,"duplicate_urls":1},{"id":"AA23-075A","title":"#StopRansomware: LockBit 3.0","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-075a","first_published":"2023-03-16","names_cve_html":false,"cve_count_html":0,"cves_html":[],"names_cve_html_or_companion_pdf":false,"names_cve_html_or_any_attached_pdf":false,"attached_pdf_count":1,"ia_tables_only":["T1078","T1133","T1189","T1190","T1566"],"ia_whole_document":["T1078","T1133","T1189","T1190","T1566"],"attack_layout":"L2","version_history":false,"revision_entries":null,"in_curated_index":true,"duplicate_urls":1},{"id":"AA23-136A","title":"#StopRansomware: BianLian Ransomware Group","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-136a","first_published":"2023-05-16","names_cve_html":true,"cve_count_html":5,"cves_html":["CVE-2020-1472","CVE-2021-31207","CVE-2021-34473","CVE-2021-34523","CVE-2022-37969"],"names_cve_html_or_companion_pdf":true,"names_cve_html_or_any_attached_pdf":true,"attached_pdf_count":1,"ia_tables_only":["T1078","T1133","T1190","T1566"],"ia_whole_document":["T1078","T1133","T1190","T1566"],"attack_layout":"L1","version_history":true,"revision_entries":2,"in_curated_index":true,"duplicate_urls":1},{"id":"AA23-158A","title":"#StopRansomware: CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a","first_published":"2023-06-07","names_cve_html":true,"cve_count_html":2,"cves_html":["CVE-2023-0669","CVE-2023-34362"],"names_cve_html_or_companion_pdf":true,"names_cve_html_or_any_attached_pdf":true,"attached_pdf_count":1,"ia_tables_only":["T1190","T1566"],"ia_whole_document":["T1190","T1566"],"attack_layout":"L1|L4","version_history":false,"revision_entries":null,"in_curated_index":true,"duplicate_urls":1},{"id":"AA23-263A","title":"#StopRansomware: Snatch Ransomware","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-263a","first_published":"2023-09-20","names_cve_html":false,"cve_count_html":0,"cves_html":[],"names_cve_html_or_companion_pdf":false,"names_cve_html_or_any_attached_pdf":false,"attached_pdf_count":1,"ia_tables_only":["T1078","T1133"],"ia_whole_document":["T1078","T1133"],"attack_layout":"L1","version_history":true,"revision_entries":1,"in_curated_index":true,"duplicate_urls":1},{"id":"AA23-284A","title":"#StopRansomware: AvosLocker Ransomware (Update)","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-284a","first_published":"2023-10-11","names_cve_html":false,"cve_count_html":0,"cves_html":[],"names_cve_html_or_companion_pdf":false,"names_cve_html_or_any_attached_pdf":false,"attached_pdf_count":1,"ia_tables_only":["T1133"],"ia_whole_document":["T1133"],"attack_layout":"L1|L4","version_history":false,"revision_entries":null,"in_curated_index":true,"duplicate_urls":1},{"id":"AA23-319A","title":"#StopRansomware: Rhysida Ransomware","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-319a","first_published":"2023-11-15","names_cve_html":false,"cve_count_html":0,"cves_html":[],"names_cve_html_or_companion_pdf":false,"names_cve_html_or_any_attached_pdf":true,"attached_pdf_count":2,"ia_tables_only":["T1078"],"ia_whole_document":["T1078"],"attack_layout":"L1","version_history":true,"revision_entries":2,"in_curated_index":true,"duplicate_urls":1},{"id":"AA23-325A","title":"#StopRansomware: LockBit 3.0 Ransomware Affiliates Exploit CVE 2023-4966 Citrix Bleed Vulnerability","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-325a","first_published":"2023-11-21","names_cve_html":true,"cve_count_html":1,"cves_html":["CVE-2023-4966"],"names_cve_html_or_companion_pdf":true,"names_cve_html_or_any_attached_pdf":true,"attached_pdf_count":1,"ia_tables_only":[],"ia_whole_document":[],"attack_layout":"L1","version_history":true,"revision_entries":1,"in_curated_index":true,"duplicate_urls":1},{"id":"AA23-352A","title":"#StopRansomware: Play Ransomware","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-352a","first_published":"2023-12-18","names_cve_html":true,"cve_count_html":5,"cves_html":["CVE-2018-13379","CVE-2020-12812","CVE-2022-41040","CVE-2022-41082","CVE-2024-57727"],"names_cve_html_or_companion_pdf":true,"names_cve_html_or_any_attached_pdf":true,"attached_pdf_count":2,"ia_tables_only":["T1059.001","T1078","T1133","T1190"],"ia_whole_document":["T1059.001","T1078","T1133","T1190"],"attack_layout":"L1","version_history":false,"revision_entries":null,"in_curated_index":true,"duplicate_urls":1},{"id":"AA23-353A","title":"#StopRansomware: ALPHV Blackcat","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a","first_published":"2023-12-19","names_cve_html":false,"cve_count_html":0,"cves_html":[],"names_cve_html_or_companion_pdf":false,"names_cve_html_or_any_attached_pdf":false,"attached_pdf_count":1,"ia_tables_only":[],"ia_whole_document":[],"attack_layout":"L1","version_history":true,"revision_entries":2,"in_curated_index":true,"duplicate_urls":1},{"id":"AA24-060A","title":"#StopRansomware: Phobos Ransomware","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060a","first_published":"2024-02-29","names_cve_html":false,"cve_count_html":0,"cves_html":[],"names_cve_html_or_companion_pdf":false,"names_cve_html_or_any_attached_pdf":false,"attached_pdf_count":1,"ia_tables_only":["T1078","T1133","T1566.001"],"ia_whole_document":["T1078","T1133","T1566.001"],"attack_layout":"L1","version_history":true,"revision_entries":1,"in_curated_index":true,"duplicate_urls":1},{"id":"AA24-109A","title":"#StopRansomware: Akira Ransomware","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a","first_published":"2024-04-18","names_cve_html":true,"cve_count_html":8,"cves_html":["CVE-2020-3259","CVE-2020-3580","CVE-2023-20269","CVE-2023-27532","CVE-2023-28252","CVE-2024-37085","CVE-2024-40711","CVE-2024-40766"],"names_cve_html_or_companion_pdf":true,"names_cve_html_or_any_attached_pdf":true,"attached_pdf_count":1,"ia_tables_only":["T1078","T1133","T1190","T1566.001","T1566.002"],"ia_whole_document":["T1078","T1133","T1190","T1566.001","T1566.002"],"attack_layout":"L1","version_history":true,"revision_entries":2,"in_curated_index":true,"duplicate_urls":1},{"id":"AA24-131A","title":"#StopRansomware: Black Basta","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a","first_published":"2024-05-10","names_cve_html":true,"cve_count_html":5,"cves_html":["CVE-2020-1472","CVE-2021-34527","CVE-2021-42278","CVE-2021-42287","CVE-2024-1709"],"names_cve_html_or_companion_pdf":true,"names_cve_html_or_any_attached_pdf":true,"attached_pdf_count":2,"ia_tables_only":["T1190","T1566","T1566.004"],"ia_whole_document":["T1190","T1566","T1566.004"],"attack_layout":"L1","version_history":true,"revision_entries":2,"in_curated_index":true,"duplicate_urls":1},{"id":"AA24-242A","title":"#StopRansomware: RansomHub Ransomware","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-242a","first_published":"2024-08-29","names_cve_html":true,"cve_count_html":9,"cves_html":["CVE-2017-0144","CVE-2020-0787","CVE-2020-1472","CVE-2023-3519","CVE-2023-22515","CVE-2023-27997","CVE-2023-46604","CVE-2023-46747","CVE-2023-48788"],"names_cve_html_or_companion_pdf":true,"names_cve_html_or_any_attached_pdf":true,"attached_pdf_count":1,"ia_tables_only":["T1190","T1566"],"ia_whole_document":["T1190","T1566"],"attack_layout":"L1","version_history":false,"revision_entries":null,"in_curated_index":true,"duplicate_urls":1},{"id":"AA25-050A","title":"#StopRansomware: Ghost (Cring) Ransomware","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-050a","first_published":"2025-02-19","names_cve_html":true,"cve_count_html":11,"cves_html":["CVE-2009-3960","CVE-2010-2861","CVE-2014-1812","CVE-2017-0143","CVE-2017-0144","CVE-2018-13379","CVE-2019-0604","CVE-2020-1472","CVE-2021-31207","CVE-2021-34473","CVE-2021-34523"],"names_cve_html_or_companion_pdf":true,"names_cve_html_or_any_attached_pdf":true,"attached_pdf_count":1,"ia_tables_only":["T1190"],"ia_whole_document":["T1190"],"attack_layout":"L1","version_history":true,"revision_entries":1,"in_curated_index":true,"duplicate_urls":1},{"id":"AA25-071A","title":"#StopRansomware: Medusa Ransomware","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a","first_published":"2025-03-12","names_cve_html":true,"cve_count_html":4,"cves_html":["CVE-2023-48788","CVE-2024-1709","CVE-2025-10035","CVE-2026-1731"],"names_cve_html_or_companion_pdf":true,"names_cve_html_or_any_attached_pdf":true,"attached_pdf_count":1,"ia_tables_only":["T1190","T1566"],"ia_whole_document":["T1190","T1566"],"attack_layout":"L1","version_history":true,"revision_entries":2,"in_curated_index":true,"duplicate_urls":1},{"id":"AA25-203A","title":"#StopRansomware: Interlock","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-203a","first_published":"2025-07-22","names_cve_html":false,"cve_count_html":0,"cves_html":[],"names_cve_html_or_companion_pdf":false,"names_cve_html_or_any_attached_pdf":false,"attached_pdf_count":1,"ia_tables_only":["T1189"],"ia_whole_document":["T1189"],"attack_layout":"L1","version_history":true,"revision_entries":1,"in_curated_index":true,"duplicate_urls":1},{"id":"AA26-222A","title":"#StopRansomware: Gunra Ransomware","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a","first_published":"2026-08-10","names_cve_html":true,"cve_count_html":2,"cves_html":["CVE-2024-55591","CVE-2025-24472"],"names_cve_html_or_companion_pdf":true,"names_cve_html_or_any_attached_pdf":true,"attached_pdf_count":1,"ia_tables_only":["T1190"],"ia_whole_document":["T1190"],"attack_layout":"L1","version_history":true,"revision_entries":1,"in_curated_index":true,"duplicate_urls":1}],"advisories_note":"One record per advisory, copied from the published CSV (sha256 recorded in dataset.csv_sha256) by scripts/research/stopransomware-advisory-census-2026/11_page_rows.py. revision_entries is null, never 0, where the advisory publishes no version-history block."},"verification":{"rule":"Any pre-registered figure that does not reproduce exactly is a failure, not a rounding difference. This is a census: the counts are integers and there is no sampling error to absorb a mismatch.","snapshot":"2026-09-29","what_a_checker_should_recompute":["The population. Walk the CISA sitemap, take every /news-events/cybersecurity-advisories/ URL, fetch each page, and keep those whose own <h1> or <title> begins '#StopRansomware:' case-insensitively. Expect 178 advisory URLs in the sitemap, 26 of them carrying the prefix, one of which is the irregular slug /aa22-249a-0. Collapse AA22-249A's two URLs to one advisory. Expect 25.","The headline. Count CSV rows where names_any_cve_html == 'no'. Expect 11, which is 44.0% of 25.","The second basis. Count rows where names_any_cve_html_or_companion_pdf == 'no'. Expect 11, the same advisories as the HTML basis. Then count rows where names_any_cve_html_or_any_attached_pdf == 'no': expect 10, the difference being AA23-319A and nothing else. Choosing the wrong PDF for an advisory that attaches two is the single easiest way to get this wrong.","The CVE totals. Sum cve_count_html across the 25 rows: expect 64. Take the distinct set from cves_named_html: expect 48.","The CVE extraction itself, with a hyphen-tolerant pattern. 'CVE 2023-4966' in AA23-325A's title and 'CVE 2021-44228' in AA23-040A must both be caught, and catching them must not change either advisory's CVE set.","The KEV join. Every one of the 48 distinct CVEs must be present in KEV catalogVersion 2026.09.27, and the join row count must equal the sum of per-advisory CVE counts (64).","The version-history count. Match on the heading's stripped TEXT, not its inner HTML - the text is wrapped in <strong>. Expect 19 publishing a block and 6 not. Advisories with no block must be NULL in revision_entries, never 0.","The curated-index reconciliation. Expect 18 of 25 present and 7 absent, the absent set being the six 2022 advisories plus AA23-040A.","Both ATT&CK rules. Tables-only must give 59 pairs and 3 advisories listing none; whole-document must give 62 pairs and 2. They must differ on AA23-040A only.","T1110. No row's Initial Access columns may contain T1110 under either rule.","The prose. Read every heading, figure caption, meta description and FAQ answer and check that each one is a statement about what CISA's documents name, never about how ransomware behaves. Any sentence that survives the substitution 'these families do not exploit vulnerabilities' is wrong and must be rewritten.","The arithmetic. zero-CVE plus at-least-one-CVE must equal 25 on both bases; in-index plus absent must equal 25; version-history published plus absent must equal 25."],"internal_assertions_run_by_this_script":["population has 25 rows with 25 distinct ids","zero-CVE count plus non-zero count equals 25","CVE mentions equals the KEV join row count","the distinct CVE set matches the collection stream's list exactly","per-advisory KEV join rows equal that advisory's CVE count"],"independent_rederivation_from_raw_html":{"ran":true,"strict_prefix_pages_found":26,"distinct_advisories_after_collapsing_duplicate_urls":25,"duplicate_url_collapsed":"AA22-249A, served at /aa22-249a and /aa22-249a-0","method":"The stored HTML bytes were re-read by this script with a separately written parser: the strict-prefix test applied to both the <h1> and the <title> element, a hyphen-tolerant CVE pattern, and a version-history extractor that matches the heading's stripped text.","cve_disagreements":[],"version_history_source":"this re-derivation"},"problems_found_at_analysis_time":[]},"fetch_provenance":{"snapshot":{"requests":625,"distinct_urls":238,"by_status":{"200":625}},"sitemap_sweep":{"requests":178,"by_status":{"200":178}},"context":{"requests":22,"by_status":{"200":18,"404":3,"000":1}},"computed_from":["raw/**/*.meta.json","frame_a_manifest.jsonl","raw/context-2026-09-29/_manifest.tsv"]}}