Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      10 Top Node.js Development Companies for Enterprise-Scale Projects (2025-2026 Ranked & Reviewed)

      July 4, 2025

      12 Must-Know Cost Factors When Hiring Node.js Developers for Your Enterprise

      July 4, 2025

      Mirantis reveals Lens Prism, an AI copilot for operating Kubernetes clusters

      July 3, 2025

      Avoid these common platform engineering mistakes

      July 3, 2025

      “A fantastic device for creative users” — this $550 discount on ASUS’s 3K OLED creator laptop disappears before Prime Day

      July 5, 2025

      Distribution Release: Rhino Linux 2025.3

      July 5, 2025

      Just days after joining Game Pass, the Xbox PC edition of Call of Duty: WW2 is taken offline for “an issue”

      July 5, 2025

      Xbox layoffs and game cuts wreak havoc on talented developers and the company’s future portfolio — Weekend discussion 💬

      July 5, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Flaget – new small 5kB CLI argument parser

      July 5, 2025
      Recent

      Flaget – new small 5kB CLI argument parser

      July 5, 2025

      The dog days of JavaScript summer

      July 4, 2025

      Databricks Lakebase – Database Branching in Action

      July 4, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      “A fantastic device for creative users” — this $550 discount on ASUS’s 3K OLED creator laptop disappears before Prime Day

      July 5, 2025
      Recent

      “A fantastic device for creative users” — this $550 discount on ASUS’s 3K OLED creator laptop disappears before Prime Day

      July 5, 2025

      Distribution Release: Rhino Linux 2025.3

      July 5, 2025

      EmptyEpsilon – spaceship bridge simulator game

      July 5, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»CISA, NIST Researchers Develop Metric to Determine Likelihood of Vulnerability Exploitation

    CISA, NIST Researchers Develop Metric to Determine Likelihood of Vulnerability Exploitation

    May 20, 2025

    vulnerability exploit exploitation likelihood

    Researchers from the U.S. National Institute of Standards and Technology (NIST) and the Cybersecurity and Infrastructure Security Agency (CISA) have developed a new security metric to determine the likelihood that a vulnerability has been exploited.

    In a paper published this week, Peter Mell, formerly of NIST, and CISA’s Jonathan Spring outlined their vulnerability exploit metric that augments the work of the Exploit Prediction Scoring System (EPSS) and CISA’s Known Exploited Vulnerabilities (KEV) catalog.

    Mell and Spring cited studies that have found that only 5% of vulnerabilities have been observed to be exploited in the wild, while the monthly vulnerability remediation rate for companies is 16%.

    “The remediation rate is so low because it is expensive for companies to address vulnerabilities,” they wrote. “…This situation would not be a problem if the 16% were to cover the 5%, but metrology is lacking to accurately make that calculation. Thus, predicting which vulnerabilities will be exploited is critically important for the efficiency and cost-effectiveness of enterprise vulnerability remediation efforts.”

    Vulnerability Exploit Metric Builds on EPSS

    Mell and Spring noted known shortcomings in EPSS and the CISA KEV catalog.

    EPSS “has known inaccurate values,” they wrote, while KEV is likely not comprehensive. Their proposed likelihood metric could help augment EPSS remediation by correcting some inaccuracies, and could build on the KEV catalog by “enabling measurements of comprehensiveness.”

    EPSS provides probabilities that a vulnerability will be observed to be exploited in the wild within the next 30 days, the NIST and CISA researchers said. “However, its probabilities are known to be inaccurate for vulnerabilities that have been previously observed to be exploited,” they wrote. “… Fortunately, the probabilities are not randomly inaccurate; they underestimate the true probability.”

    Mell and Spring call their formula Likely Exploited Vulnerabilities (LEV) probabilities. LEV probabilities have at least four use cases, they said. These include:

    1. Measuring the expected number and proportion of vulnerabilities that actors have exploited
    2. Estimating the comprehensiveness of the KEV catalog
    3. Augmenting KEV-based vulnerability remediation prioritization by “identifying higher probability vulnerabilities that may be missing”
    4. Augmenting EPSS-based vulnerability remediation prioritization by “identifying vulnerabilities that may be underscored.”

    Results: Hundreds of Vulnerabilities with High Probability of Exploitation

    The paper listed two vulnerabilities where LEV and EPSS probabilities differed.

    For CVE-2023-1730, a SQL injection vulnerability in the SupportCandy WordPress plugin before 3.1.5, the LEV probability was 0.70, while the peak EPSS score was 0.16.

    For CVE-2023-29373, a Microsoft ODBC Driver Remote Code Execution vulnerability, the LEV probability was 0.54350, while the peak EPSS probability was 0.08.

    Their work also identified several hundred vulnerabilities with a probability approaching 1.0.

    “Interestingly, many of these vulnerabilities are not included in tested KEV lists,” Mell and Spring wrote. “… This is one reason that LEV lists cannot replace KEV lists. LEV cannot identify which of the many low probability vulnerabilities will be exploited, it can only help compute how many of them are expected to be exploited. KEV lists identify the exact ones that have been exploited.”

    Mell and Spring said they’re looking for industry partners to collaborate with to obtain performance measurements of the LEV metric.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleInnovating with MongoDB | Customer Successes, May 2025
    Next Article Hazy Hawk Exploits DNS Records to Hijack CDC, Corporate Domains for Malware Delivery

    Related Posts

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-1317 – Apache HTTP Server Remote Code Execution Vulnerability

    July 5, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-1318 – CVE-2022-1234: Cisco WebEx Meeting Center Unvalidated Redirect

    July 5, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    CVE-2025-6467 – Code-projects Online Bidding System SQL Injection

    Common Vulnerabilities and Exposures (CVEs)

    LifelongAgentBench: A Benchmark for Evaluating Continuous Learning in LLM-Based Agents

    Machine Learning

    CodeSOD: The Last Last Name

    News & Updates

    Don’t buy into Microsoft’s “Windows 11 PCs are up to 2.3x faster than Windows 10 PCs” claim — Here’s why it’s stretching the truth

    News & Updates

    Highlights

    AI unleashes more advanced scams. Here’s what to look out for (and how to stay protected)

    April 16, 2025

    Microsoft’s Cyber Signals report identifies AI-driven deception in the workplace. Source: Latest news 

    Novels That Offer Peace After Long Days

    April 2, 2025

    May report 2025

    June 2, 2025

    CVE-2025-5951 – CVE-2022-1234: Apache HTTP Server Unauthenticated Remote Code Execution

    June 28, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.