Trust & methodology
Updated 23 September 2026·Fix First updated 22 Sept
How SecPulse works
Every item gets a verdict: Act now, Watch or Noise. The verdict comes from a rubric, not a feeling, and the evidence behind it is printed on the item itself.
The rubric
| Signal | Points |
|---|---|
| On CISA KEV (confirmed exploitation) | 40 |
| EPSS 90%+ / 50%+ / 10%+ | 30 / 20 / 8 |
| Known ransomware use | 15 |
| Exploit code or in-the-wild activity reported | 10 |
| Usually internet-facing product | 10 |
| Exploitable over the network with no login | 10 |
| CVSS 9.0+ / 7.0+ | 10 / 5 |
| CISA deadline within 14 days | 5 |
Act now is 55 points or more. Watch is 25 to 54. Noise is below 25.
Authenticity labels on news
- Confirmed by primary source — the vendor or a government agency said it directly.
- Reported by N outlets — independent coverage from more than one newsroom.
- Single source — only one outlet has reported it so far.
- Claimed, not confirmed — usually an attacker's claim, not verified.
Where the facts come from
- CISA Known Exploited Vulnerabilities catalog
- NVD for severity, weakness type and affected products
- FIRST EPSS for exploitation probability
- Named news outlets, quoted briefly and linked, never rewritten
How AI is used
Facts, verdicts and the Fix First list are produced by code from official data, with no AI involved. A human writes the "In short" and "For leaders" sections, with AI assistance, using only the facts above. Nothing is published without human review.
Corrections
Mistakes get a dated line in the item's changelog and a note here. If something is wrong, tell us and it gets fixed.
Current tally
| Verdict | Published items |
|---|---|
| Act now | 0 |
| Watch | 0 |
| Noise | 0 |
Every verdict is re-checked daily against CISA KEV and EPSS. The running tally, and every miss, is on the accuracy scorecard.