CISA is ending its weekly vulnerability roundups and telling you to score what is actually exposed and exploited. The same news cycle, the Coast Guard and FBI boarded two oil tankers after malicious cyber activity on the VL Prosperity, still unattributed in public. If your cybersecurity program still treats the CVE inbox as the job, you are ranking paper. Blast radius is the score that matters.

Weekly lists trained teams to equate volume with diligence. Attackers chain loaders through a quote request in mail, hide command and control on a public blockchain, and hit ships whose firewall never logged a CVE for the bridge network. Risk-based work means you pick the paths that take you down, then you cut them.

CISA Ends Weekly Vuln Roundups; Scoring Shifts to Exploited Exposure

The agency is dropping the Friday CVE pile in favor of a risk-based focus, which matches advice it has been giving for years: prioritize the vulnerabilities that actually matter. That is an operational contract change. You now own the ranking. Nobody in Arlington is going to sort your backlog into “will get you ransomed” versus “will pad a slide.”

CISA shifts from weekly vulnerability roundups to risk-based scoring
CISA is replacing weekly vuln roundups with a push to score exploited exposure, not inbox volume.

Microsoft’s exposure-management guidance landed in the same window and said the quiet part out loud. Fundamentals still move risk. Identity hygiene, least privilege, patching of internet-facing services, and logging that a human can query during an incident beat another dashboard that counts CVEs. Cisco Talos made a parallel argument on the so-called AI slowdown: keep your eyes on basics while vendors argue about model calendars. You already knew that. The useful part is the permission to stop pretending a roundup is a control.

Score three things together or the ranking is theater. Exploitability in the wild. Reachability from where attackers already sit. Business consequence if that host dies or dumps data. A CVSS 9.8 on an isolated lab box loses to a 7.5 on the VPN concentrator your contractors live on. KEV-class bugs still jump the queue. Everything else waits behind evidence that the path is open.

This is a bad look for teams that staffed “vuln management” as a newsletter job. The real problem here is a queue with no owner for residual risk. When CISA stops feeding the inbox, that owner has to be you.

Coast Guard and FBI Board Two Tankers After Confirmed Activity

Two oil tankers drew a boarding party. The Coast Guard confirmed malicious cyber activity on the VL Prosperity and has not pinned it on Iran in public. That is incident response with a hull number. Your playbook that assumes a SOC ticket, a firewall change, and a Teams thread does not cover a vessel, a crew, and federal agents walking the OT closet.

Oil tanker at sea after reported malicious cyber activity
Federal boarding of two tankers after malicious activity is IR that leaves the ticket queue and walks the OT closet.

Maritime and industrial networks love the story that they are air-gapped. Vendor laptops, satellite links, and “temporary” Windows jump boxes punch holes you never put in the diagram. Defense in depth on a ship or a plant is boring on purpose: no inbound admin from the business VLAN, signed allowlists for engineering software, out-of-band logs that survive a wiped HMI, and a known-good image you can rebuild without calling the OEM at 3 a.m.

Threat detection has to include process and network baselines on controllers and the Windows boxes that talk to them. If your only alert is “something scanned the public website,” you will learn about the tanker from the news. Rehearse incident response with the people who can take a pump offline and the people who can pull disk. Split-brain IR is how dwell time becomes a press conference.

You will not get a weekly CVE that says “your satellite modem’s management plane is on the internet.” Risk-based scoring has to inventory those paths the same way it inventories Exchange and VPN. Treat OT-adjacent Windows as production. Treat vendor remote access as an identity provider you did not choose.

LausivLoader and MovieReaper Move Data Outside the CVE Calendar

Late August, a mail gateway quarantine caught a quote request for a fiber optic system. It impersonated an employee at a real company and asked for a price on attached requirements. SANS ISC’s write-up of LausivLoader is about the unglamorous part: how stages pass data to each other after the first click. Initial access is a document. Persistence and C2 arrive later, often with fewer indicators because the first stage already did the messy work.

Kaspersky’s MovieReaper campaign is the consumer-side twin. Compromised torrents, including titles riding The Odyssey, drop a multi-stage Trojan and park command infrastructure on the Solana blockchain so takedowns chase a moving address. Users in multiple countries. Same lesson as the fiber-optic malspam: delivery and C2 never needed a CVE assigned to your brand.

MovieReaper multi-stage Trojan spreading through compromised movie torrents
MovieReaper hides C2 on Solana and rides torrent filenames. Your weekly CVE list never listed that path.

Threat-protection that only watches exploit kits against last week’s CVEs will miss both. Mail detonation, attachment type blocks for the roles that never need macros, and DNS plus egress controls that flag newly registered or blockchain-adjacent resolvers do more than another patch exception meeting. Brute-force against VPN, RDP, and mail still sits next to these loaders as the dumb path that works. If you rate-limit and lock out at the edge, you shrink the time attackers spend guessing while the clever stage waits on a human to open the quote.

Stage-aware logging is the gap. Capture the first file hash, the child process, the outbound beacon, and the second-stage payload as one incident, or your analysts close “phishing, user educated” while the loader finishes setup. Cyber security work here is glue: mail, endpoint, and proxy have to share a case ID before the second stage names itself.

Cybersecurity Risk Scoring: Cut Exposure, Then Prove Detection

Do this on the network you have, with the staff you have. Vendor-neutral on purpose. Security hardening is the control. The score is how you choose where to apply it.

Immediate, this week:

  • Export every internet-facing service, VPN, mail gateway, OT jump box, and vendor remote-access host. If it is missing from the list, it is unranked, which means it is accepted risk with no owner.
  • Rank the list by evidence of exploit in the wild, identity privilege behind the service, and whether a compromise dumps data or stops operations. Patch or remove the top slice in 72 hours. Disable unused listeners instead of “monitoring” them.
  • Turn on lockout and rate limits for admin and remote-access logins. Brute-force is still a working access method; treat it as an exposure bug, not background noise.
  • Prove one detection per remaining high-rank path: failed-then-success auth, new child process from office files, and unexpected egress from OT-adjacent Windows. If the alert cannot page a human, it does not count.

Ongoing, every sprint: recut the ranking when CISA or your intel feed marks a bug as exploited, when a vendor adds a management port, and when a business unit stands up “just a test” RDP. Defense in depth means the next layer still works after the first control lies. Network ACLs that deny east-west admin, separate jump identities, and backups that restore without the same C2 path the attacker already owns.

Keep incident response runbooks that name the box. Who pulls disk on the mail gateway. Who can isolate a tanker-equivalent: the PLC VLAN, the warehouse RF scanner subnet, the contractor Citrix. Who revokes tokens. Walk that once a quarter with production-like data, or you will discover the missing phone tree while the FBI is already on someone else’s vessel.

CISA handed you the scoring job. The tankers and the loaders are the reminder that the queue includes hosts and stages no weekly roundup ever listed. Rank those. Cut what you cannot watch. Page on what you still have to keep.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.