Exposing CVEs From Black Bastas’ Chats
Black Basta chat logs revealed 62 unique CVEs, with 85.5% exploited and 70.9% listed in the CISA KEV catalog. They exploit known vulnerabilities in widely used enterprise technologies. Their discussions show a preference for targeting high-revenue firms in sensitive sectors and quickly discuss new CVEs post-advisory. They employ known exploits and consider developing new ones, reinforcing the need for rapid vulnerability remediation. Notably, a rejected CVE was mentioned that had evidence of exploitation.