Skip to content
SPECIAL

THREATS TO CRITICAL INFRASTRUCTURE IN IRAN CONFLICT

READ MORE

CISA highlights CVE program, KEV catalog and cyber collaboration at Black Hat 2025

(McCrary Institute)

By Don Kauffman

In a conversation recorded at Black Hat 2025 for the Cyber Focus podcast, two senior officials from the Cybersecurity and Infrastructure Security Agency (CISA) mounted a clear defense of the agency’s mission while urging Congress to renew a cornerstone cyber information-sharing law – and they paired the policy talk with concrete, operator-level tools.

CISA Acting Executive Assistant Director for the Cybersecurity Division Chris Butera and Chief Information Officer Bob Costello stressed that the volume and tempo of cyber threats demand both sustained public-private collaboration and faster, more disciplined response. Costello opened with a vote of confidence in the team: “I’m really honored to work with some of the most experienced cyber professionals I think that exists anywhere in the world. … We’re seeing people step up into new roles, leadership positions, work on new technical projects that maybe they weren’t before. And we’re just hitting grand slams every day.”

Speaking about the Hill, both backed reauthorization of the Cybersecurity Information Sharing Act of 2015 – legislation that predates CISA’s creation but still underpins the way government and industry exchange cyber threat intelligence. “We absolutely support reauthorization of [the 2015 information sharing law] … collaboration is what we’re all about. We talk about cyber being a team sport and this helps make all the teams play a lot better together,” Costello said.

Operationally, Butera detailed how CISA is leaning harder on existing levers rather than inventing new ones – especially the Known Exploited Vulnerabilities (KEV) catalog. The KEV database isn’t new, but CISA is using it more aggressively to compress federal patch timelines when exploitation is confirmed. “It was the first time we had a 24-hour deadline for the federal agencies to patch,” he said of a recent Citrix issue. “A few weeks later for the SharePoint vulnerabilities … we also added those to the KEV with the 24-hour patch cycle as well.”

That rapid prioritization builds on a broader foundation CISA has been steadily reinforcing for years – the Common Vulnerabilities and Exposures (CVE) program. Butera walked through its expansion from 24 CVE Numbering Authorities (CNAs) in 2016 to more than 460 worldwide by 2024, and from 6,400 published records annually to over 40,000 – growth that enabled today’s pivot from a “growth era” to a “quality era,” with vendors expected to provide richer, standardized fields (including Common Weakness Enumeration mappings) that support automation and secure-by-design fixes. He emphasized that CISA isn’t just a sponsor of the CVE program; it’s one of the largest consumers of CVE data in day-to-day operations. Costello made the commitment explicit: CISA will continue funding the CVE program and is seeking deeper community engagement to improve data quality and tooling.

That commitment is visible in how CISA operationalizes CVE database entries. Butera said the agency enriches relevant vulnerability records with exploitability and other categorizations to help owners prioritize risk, alongside the KEV catalog. In practice, the same approach drove recent 24-hour federal patch directives once exploitation was confirmed, and a “fog-of-war” weekend that ended with KEV entries, public guidance and an emergency directive – compressing the time from discovery to action. Paired with usability upgrades – automating Cyber Hygiene for 11,000 customers and launching an industry engagement portal before the end of the fiscal year – the signal is clear: The CVE program isn’t bookkeeping, but the backbone for prioritization, automation and faster recovery across networks.

From there, the focus turned to recovery. Butera highlighted CISA’s Eviction Strategies Tool – a resource that takes an organization’s observed adversary techniques and builds a tailored eviction and restoration playbook, ready for use in either a live incident or a tabletop exercise. “[How] can you continue your mission without access to some of your critical systems? … A lot of organizations don’t have those kinds of plans in place,” he said.

CISA is also pushing on OT risk at the edge. “One of the things that we are trying to do every single day is remove some of those OT systems from the Internet,” Butera said, citing the agency’s use of administrative subpoenas with ISPs to identify owners. “Today we’ve already notified over 3,000 entities … and we’ve had an 80% success rate in them actually removing the systems from the Internet.”

The through line from Black Hat: defend the mission, renew the legal plumbing that enables sharing, and strengthen the technical scaffolding – from the CISA CVE program to the KEV catalog to tailored recovery plans – that shortens response time and improves resilience. Not flashy, but exactly the kind of progress operators can use on Monday.

The full Cyber Focus episode can be found here, or you can subscribe in your favorite podcast app. 

This article was updated on 8/19/25

Click to listen highlighted text!