CISA Known Exploited Vulnerabilities (KEV) Catalog (opens in a new tab)
Why: CISA's catalogue of vulnerabilities known to be exploited in the wild — the practical must-patch list for teams prioritising fixes that attackers are already using.
Real-world insight. Expert validated. Purpose built for impact.
254 current resources across 18 categories
Strong starting points from the current catalogue.
Why: CISA's catalogue of vulnerabilities known to be exploited in the wild — the practical must-patch list for teams prioritising fixes that attackers are already using.
Why: Prioritised, actionable safeguards that help teams sequence hardening work by impact.
Why: US whole-of-government ransomware hub consolidating prevention, response and recovery guidance plus #StopRansomware advisories.
Why: UK NCSC guidance that helps boards oversee cyber risk, culture and investment with clear questions and expectations for organisational leadership.
Why: Living knowledge base of adversary tactics and techniques for threat-informed detection and defence.
Why: Voluntary CISA baseline protections for critical infrastructure (CPGs 2.0, aligned to NIST CSF 2.0) that help organisations prioritise practical safeguards when starting a maturity journey.
Browse by topic. Each page lists every current resource in that category.