---
title: "Ransomware Attacks: New Ways to Exploit Old Vulnerabilities"
description: "This article exposes how cybercriminals exploit old vulnerabilities with new tech, details the rise in ransomware threats, and outlines essential…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Person",
      "@id": "https://christianespinosa.com/#person",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "image": "https://christianespinosa.com/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg",
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ],
      "jobTitle": "Bestselling Author, Keynote Speaker, Entrepreneur",
      "worksFor": {
        "@type": "Organization",
        "name": "Blue Goat Cyber",
        "url": "https://bluegoatcyber.com/"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://christianespinosa.com/#website",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "publisher": {
        "@id": "https://christianespinosa.com/#organization"
      },
      "inLanguage": "en-US"
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://christianespinosa.com/#organization",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "logo": {
        "@type": "ImageObject",
        "url": "https://christianespinosa.com/logo.svg"
      },
      "founder": {
        "@id": "https://christianespinosa.com/#person"
      },
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Ransomware Attacks: New Ways to Exploit Old Vulnerabilities - Christian Espinosa",
      "description": "This article exposes how cybercriminals exploit old vulnerabilities with new tech, details the rise in ransomware threats, and outlines essential…",
      "image": "https://christianespinosa.com/__l5e/assets-v1/84da4be9-c4f0-4ac8-afe3-b54ed5583025/ransomware-attacks-new-ways-to-exploit-old-vulnerabilities-card.png",
      "datePublished": "2023-04-13T16:18:19+00:00",
      "dateModified": "2026-06-26T05:36:40.270Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://christianespinosa.com/blog/ransomware-attacks-new-ways-to-exploit-old-vulnerabilities"
      },
      "author": {
        "@type": "Person",
        "name": "Christian Espinosa",
        "url": "https://christianespinosa.com/about"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Christian Espinosa",
        "logo": {
          "@type": "ImageObject",
          "url": "https://christianespinosa.com/logo.svg"
        }
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is the core idea behind \"Ransomware Attacks: New Ways to Exploit Old Vulnerabilities - Christian Espinosa\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Cybercriminals are using old weaknesses with the latest in AI and machine learning to maximize ransomware impact."
          }
        },
        {
          "@type": "Question",
          "name": "Who is this post for?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Honestly, security leaders, medical device teams, and technical operators who want the honest version, not the vendor version. If you want a listicle, this is not that. If you want the honest version of what I have actually lived and worked through, keep reading."
          }
        },
        {
          "@type": "Question",
          "name": "How do I actually apply this, not just nod along?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Pick the single line in the post that made you flinch or look away, and change one thing in your week because of it. One choice this week beats a whole framework you never touch."
          }
        }
      ]
    }
  ]
---

[Skip to content](#main)

[](/)

[About](/about)[Speaking](/speaking)[Cybersecurity](/cybersecurity)[Programs](/programs)[Books](/books)[Media](/media)

Writing

Search Ctrl K[Connect](/connect)

[Cybersecurity](/blog/category/cybersecurity)

# Ransomware Attacks: New Ways to Exploit Old Vulnerabilities

April 13, 2023 7 min read 1,586 words 

I've seen the headlines, especially when they hit healthcare, education, and finance. But the reality is, there's nothing new here. In fact, 76% of the vulnerabilities currently being exploited were first discovered between 2010 and 2019. Cybercriminals are using these old weaknesses with the latest in AI and machine learning to maximize their impact.

![](/__l5e/assets-v1/ba877d46-a4d4-4a02-87ce-dd64a65de716/ransomware-attacks-new-ways-to-exploit-old-vulnerabilities-hero.webp)

The takeaways

1.  01 
    
    In fact, 76% of the vulnerabilities currently being exploited were first discovered between 2010 and 2019.
    
    What to do next Add fact to the next leadership review as a standing item, not a one-time slide.
    
2.  02 
    
    Cybercriminals are using these old weaknesses with the latest in AI and machine learning to maximize their impact.
    
    What to do next Add cybercriminals to the next leadership review as a standing item, not a one-time slide.
    
3.  03 
    
    Ransomware Is on the Rise, and You’ll Never Be 100% Prepared The increase in these attacks is something on the minds of most security leaders.
    
    What to do next Add attacks to the next leadership review as a standing item, not a one-time slide.
    
4.  04 
    
    It’s not just a breach; it’s the inability to access your data and disruption to your customers.
    
    What to do next Open your current breach plan today and identify the one gap you would not want an auditor to find.
    

I've seen the headlines, especially when they hit healthcare, education, and finance. But the reality is, there's nothing new here. In fact, [76% of the vulnerabilities](https://cybersecurityworks.com/ransomware/) currently being exploited were first discovered between 2010 and 2019. Cybercriminals are using these old weaknesses with the latest in AI and machine learning to maximize their impact.

This statistic comes from a new report on ransomware, which I've been going through to determine why old vulnerabilities are still a problem. Looking at this through the lens of "Is it a people problem?" could also shed some light on the future of ransomware attacks.

## Ransomware Is on the Rise, and You’ll Never Be 100% Prepared

The increase in these attacks is something on the minds of most security leaders. When they happen, it’s cataclysmic and chaotic. It’s not just a breach; it’s the inability to access your data and disruption to your customers. There are monetary and reputational ramifications. The question is always, "[Should you pay?](https://christianespinosa.com/blog/ransomware-should-you-pay/)"

It’s a polarizing question, with many adamant that not paying will convince other hackers not to attack them. That, of course, is flawed logic. I can tell you that cybercriminals don’t care what your position is. They are trying to maximize their return by infiltrating as many systems as possible. The answer changes when the stakes are higher, like [exploiting vulnerabilities in medical devices](https://bluegoatcyber.com/blog/vulnerabilities-in-medical-device-cybersecurity-puts-patient-lives-at-risk/).

This is rare, so the answer depends on your preparedness for such an attack. Do you have backups that are current? How fast can you restore systems? How advanced are your forensics?

If you’re not in a position to ensure business continuity, you can make strides to do this, and you should. Along with this prep, you’ll need to be proactive and forward-thinking. It’s impossible to mitigate every risk, as we learn in the report, _Ransomware Through the Lens of Threat & Vulnerability Management_.

Next, we’ll review some of the report’s biggest findings.

## Breaking Down the Ransomware Report

This study has some great data in it that you and your team can learn from. Here’s my take on the findings:

### Ransomware Vulnerabilities Increase

The report lists a 19% increase in vulnerabilities associated with ransomware, bringing the total in 2022 to 344. Researchers also mapped these to MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK). In doing so, they found 57 highly dangerous out of 81 unique end-to-end products. The most common were Microsoft, Oracle, VMWare, Atlassian, Apache, and SonicWall.

### Scanning Tools Aren’t Catching These Vulnerabilities

You likely depend on scanning tools, like Nessus, Nexpose, or Qualys, but they aren’t detecting some of the serious issues. A total of 20 vulnerabilities were not detectable with these popular scanners, and all of these were old and discovered between 2010 and 2019. It’s not too abnormal for this, as [cybercriminals are always reinventing their attack strategies](https://christianespinosa.com/blog/cybercriminals-are-always-evolving-their-techniques-your-cyber-team-should-too/). They are constantly refining and seeking to get past your defenses.

### Trending: New CWEs

The report found that 80 CWEs (Common Weakness Enumerations) are contributing vulnerabilities that ransomware can exploit. This is a 54% increase over 2021. The problem; it seems, is that companies are releasing software and applications without a thorough evaluation of the code. Such a statistic highlights the race to get a product to market and extend releases. It would seem that [DevSecOps](https://christianespinosa.com/blog/why-organizations-should-pivot-to-devsecops/) adoption may be faltering.

Whether you’re a cyber professional or a regular software user, there’s an expectation that the application will be secure by design. It points to a larger conversation about why security and development aren’t tighter. Security and innovation can play well together; they are not foes. To me, you can’t deliver the best software experience without weaving security throughout its design.

### Ransomware Attackers Are Highly Sophisticated

Many of the groups launching ransomware attacks aren’t your everyday hackers. They belong to APT (Advanced Persistent Threat) groups. Many have connections to nation-states and seek to cause havoc to infrastructure. So, it’s not all about the potential for money. The report highlights the rise of ransomware before the actual war between Russia and Ukraine. Russian hacking groups targeted critical infrastructure in Ukraine.

Researchers also named China and North Korea as countries with APTs, and they believe this trend will only rise. Cyberwar is the newest playing field for conflict.

### Old Vulnerabilities, New Attacks

As noted in the opening, 76% of ransomware-associated vulnerabilities date back to pre-2020. There is cause for concern when digging into this a bit more. The report calls out 264 old vulnerabilities, and 208 have publicly available exploits. The most significant data point from this section is that 119 of these are actively trending on the dark web as of interest to hackers.

Next, the analysts examined which products had these old vulnerabilities, with Windows 11, Enterprise Linux, openSUSE, and Linux having the most. Recall also that 20 of these were not detectable by the best scanners.

All of this points to the issue of cyber hygiene. It’s a good time to examine how you maintain system health and improve security. Much of this can be associated with the same-old challenges of legacy systems, unpatched components, and “shadow” IT assets. They are the favorite entryways for hackers, and as long as we, the good guys, don’t address them, they have an easy way to get inside and do damage.

Putting a spotlight on this will beget greater visibility, but this may be a deeper problem that has a lot to do with your people. I don’t mean your technical folks aren’t good at cybersecurity. They likely are. What they often aren’t good at is communication, adaptability, flexibility, and uncertainty. However, these are attributes of the job. When they don’t evolve their mindset, security vulnerabilities will persist. They prefer the status quo and certainly don’t want anyone challenging them. That’s when they get defensive, and that’s not the type of defense you want them playing.

It’s a problem that encircles some other trends.

### More Ransomware Trends and Predictions

The report also offers some insights on what to expect. In 2022, phishing, email compromise, stolen credentials, and vulnerabilities enabled ransomware attacks. These have been standard entryways, so the focus goes back to what’s happening with vulnerability management.

The foundations of a good program are processes, people, and technology. Technology can assist, but you need strong protocols and people that will think critically and act, which requires them to move outside their comfort zone. So, yes, this is a people problem, too.

Another trend I’ve written about is the [proliferation of AI](https://christianespinosa.com/blog/will-ai-and-machine-learning-help-or-hurt-cybersecurity/). It’s become very accessible, which has pros and cons. Bad guys will use it the same way the good guys are.

So, what does all this mean in the picture of how your people will evolve and be better at combatting ransomware?

So, there are a lot of people gaps in protecting against ransomware. It’s not something you can’t change. I developed a system to do just that with the [Secure Methodology](https://christianespinosa.com/blog/the-secure-methodology-and-cybersecurity-leadership/) ™. It’s a seven-step guide to help cyber leaders transform staff into highly communicative, collaborative, and adaptable professionals.

## The Future of Ransomware Defense: People Matter

Your cyber team won’t magically change overnight and develop the people skills they need to win the cyber war. It’s a process, which is why there are seven steps. Each of these connects to how technical people act and feel. The problem is that they have little awareness of how these actions and feelings heighten risk and deter collaboration. You have the opportunity to open their minds to this and connect it to being a better cyber professional (and, possibly, person!).

If you present this to them as something that’s not threatening, they’ll be more receptive. It’s still change, which is hard for anyone in any situation. Remember, these people don’t like to be wrong. They want to be the smartest person in the room. So, they’ll resist when they hear they aren’t and need to adapt. But that’s the point of becoming better at work or in life.

Here are the main things that the Secure Methodology can do for you and your team.

-   It can teach them real skills on how to [communicate](https://christianespinosa.com/blog/the-secure-methodology-step-four-communication/?roistat_visit=172849), which includes listening and understanding nonverbal cues. They’ll have to leave behind their geek speak and adopt a more inclusive language. There are exercises in the Secure Methodology to facilitate this.
-   It can expand their mindset. People can’t grow when they have a closed mindset. Opening up will help them reframe their perspective, which can create some “aha” moments.
-   It can help them be more empathetic. Empathy is an essential trait for technical people. If they can understand the position of others, even hackers, they’ll be better prepared to defend against them. Empathy within the team also cultivates trust and respect.

Ransomware will continue to be a considerable threat to any organization. The numbers tell the story, and you have to be creative in how to thwart it. Your people are the most crucial component, and the more you can develop their non-technical skills, the better.

You can learn more about the Secure Methodology by reading my book, [_The Smartest Person in the Room_](https://christianespinosa.com/books/the-smartest-person-in-the-room/), and [checking out the course](https://programs.christianespinosa.com/the-secure-methodology), now available.

Frequently asked

### What is the core idea behind "Ransomware Attacks: New Ways to Exploit Old Vulnerabilities - Christian Espinosa"?

### Who is this post for?

### How do I actually apply this, not just nod along?

### Work with me

I help founders and cybersecurity leaders build teams that ship, not teams that stall. If that's the problem you're trying to solve, let's talk.

[Start a conversation](/contact)

Share this essay

[X ](https://twitter.com/intent/tweet?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fransomware-attacks-new-ways-to-exploit-old-vulnerabilities&text=Ransomware%20Attacks%3A%20New%20Ways%20to%20Exploit%20Old%20Vulnerabilities) [LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fransomware-attacks-new-ways-to-exploit-old-vulnerabilities) [Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fransomware-attacks-new-ways-to-exploit-old-vulnerabilities) [Email](mailto:?subject=Ransomware%20Attacks%3A%20New%20Ways%20to%20Exploit%20Old%20Vulnerabilities&body=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fransomware-attacks-new-ways-to-exploit-old-vulnerabilities)Copy link 

![Christian Espinosa, headshot](/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg)

About the author

[Christian Espinosa](/about) · Founder & CEO, Blue Goat Cyber

Christian is the founder and CEO of Blue Goat Cyber, a medical device cybersecurity firm. He's an Air Force Academy graduate, 24x Ironman, climber of two of the Seven Summits, and the author of The Smartest Person in the Room and The In-Between: Life in the Micro.

Keep reading

-   [
    
    ### The Latest on Supply Chain Security: How Cyber Professionals Can Move the Needle - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/the-latest-on-supply-chain-security-how-cyber-professionals-can-move-the-needle)
-   [
    
    ### The Latest Cybersecurity Incidents and What You Can Learn from Them - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/what-the-latest-cybersecurity-breaches-can-teach-us)
-   [
    
    ### Will AI and Machine Learning Help or Hurt Cybersecurity? - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/will-ai-and-machine-learning-help-or-hurt-cybersecurity)

[← Previous essay 

The Latest on Supply Chain Security: How Cyber Professionals Can Move the Needle - Christian Espinosa

](/blog/the-latest-on-supply-chain-security-how-cyber-professionals-can-move-the-needle)[Next essay → 

Cybersecurity Strategy Pitfalls: How to Get Back on the Right Path - Christian Espinosa

](/blog/cybersecurity-strategy-pitfalls-how-to-get-back-on-the-right-path)

Related, Cybersecurity

### Need medical-device or offensive security expertise?

Blue Goat Cyber, Christian's firm, runs FDA-aligned premarket submissions, penetration testing, and SBOM/SOUP analysis for medtech and high-stakes industries.

[Explore Blue Goat Cyber](/cybersecurity)

Christian Espinosa

Bestselling author, keynote speaker, and Founding CEO of [Blue Goat Cyber](https://bluegoatcyber.com/). Helping technical leaders develop the soft skills that turn brilliance into impact.

[](https://www.linkedin.com/in/christianespinosa/)[](https://x.com/Ironracer)[](https://www.instagram.com/christian.espinosa.official/)[](https://www.youtube.com/@ChristianEspinosaOfficial)[](https://www.facebook.com/christian.espinosa.official)

Explore

-   [About](/about)
-   [Timeline](/timeline)
-   [Speaking](/speaking)
-   [Cybersecurity](/cybersecurity)
-   [Programs](/programs)

Read

-   [Books](/books)
-   [Guides](/guides)
-   [Blog](/blog)
-   [Media](/media)
-   [Podcast Interviews](/podcasts)
-   [Success Stories](/success-stories)

Connect

-   [Contact Christian](/connect)
-   [LinkedIn ↗](https://www.linkedin.com/in/christianespinosa/)
-   [Blue Goat Cyber ↗](https://bluegoatcyber.com/)
-   [Resources](/resources)

© 2026 Christian Espinosa. All rights reserved.

[Privacy](/privacy-policy)[Terms](/terms-of-use)