Analysis of the leaked archive identified 62 unique CVEs referenced by Black Basta members, of which 53 are known to have been exploited in the wild. The list is the closest thing this corpus has to an attacker’s working inventory rather than a defender’s reconstruction of one.
The Products Are The Ones Everybody Runs
Citrix NetScaler, Fortinet FortiOS, Palo Alto PAN-OS, ConnectWise ScreenConnect, Check Point gateways, Atlassian Confluence, Cisco, Microsoft Exchange and Windows. CVE-2023-4966 — CitrixBleed — features prominently, as does the pair of ScreenConnect flaws from February 2024.
This corpus filed at 25-1107b that edge appliances split into two failure classes: zero-days, where the customer could do nothing, and known defects with fixes available. The leaked list contains both, and the older entries are the more damning. Zerologon, patched in 2020, is in there.
The Timing Is The Finding
Members discussed newly published vulnerabilities within days of the advisories appearing. In at least one reported case — a Fortinet FortiOS flaw — discussion preceded official publication.
That inverts the usual defensive framing. Patch windows are argued about as though the attacker learns of a vulnerability when the defender does. For this operation the advisory was not the starting gun; in at least one instance it was late.
It Also Gave Defenders A Live List
One scanning firm reported observing active exploitation of CVEs named in the chats after the leak, which is a two-edged outcome: the archive told defenders what to prioritise and told everybody else what worked.
This desk records that as an observation, not a causal claim. Exploitation of widely-known enterprise flaws was already continuous; nothing here establishes that publication of the archive increased it.
What The List Does Not Establish
A CVE discussed is not a CVE used. The count of 62 is a count of mentions, and the 53 figure describes those vulnerabilities’ exploitation generally, not Black Basta’s use of them. Neither number is a tally of successful intrusions.
That distinction is the same one this corpus applies to attacker volume claims at 25-0215 and to reachable-versus-taken at 25-0717. Discussed, attempted and succeeded are three populations.
Compiled from published vulnerability analyses of the leaked archive, listed below. This desk has not examined the archive. The CVE counts are as reported by the analysing firms and have not been independently recomputed. No claim is made here about which vulnerabilities produced successful intrusions. Corrections: corrections@forensicpost.com.
- Exposing CVEs from Black Basta’s chatsVulnCheck
- Leaked ransomware chat logs reveal Black Basta’s targeted CVEsCybersecurity Dive
- GreyNoise detects active exploitation of CVEs mentioned in Black Basta’s leaked chat logsGreyNoise
- Leaked Black Basta chat logs reveal inner workings and internal conflictsThe Hacker News