Cyber Resilience
Last updated: 22 August 2026 23:44 UTC
2026-08-22 · Today
US focus: CISA KEV & advisories →
EU & UK focus: EUVD criticals & NCSC →
APAC focus: Regional threat landscape →
🇪🇺 European context
EU and UK enrichment for the same CVE corpus — ENISA EUVD references, UK NCSC advisories, and regulatory framing (NIS2 / DORA / CRA / UK NIS Regs).
64
CVEs with EU CSIRT advisories
in the last 30 days
in the last 30 days
34
CISA-only KEVs
(ENISA: not exploited)
(ENISA: not exploited)
🌏 Asia-Pacific context
APAC framing for the same CVE corpus — ISO/IEC 27001 as the control baseline, JPCERT/CC advisories, and regional incident- reporting law. APAC landscape →
8
JPCERT/CC advisories indexed
Incident-reporting law
- APPI (Act on the Protection of Personal Information) (Japan)
Report qualifying personal-data breaches to the PPC promptly; sector incident guidance via METI and JPCERT/CC. - Security of Critical Infrastructure Act (SOCI) (Australia)
Critical-infrastructure operators must report cyber incidents to ASD/ACSC — 12 hours for a significant impact, 72 hours for a relevant impact. - Cybersecurity Act 2018 + PDPA (Singapore)
Critical-information-infrastructure owners report incidents to CSA; PDPA requires notifiable data breaches be reported to the PDPC within 72 hours.
Pick your lane
Security leaderBoard-ready riskWhat changed, whether it hits you, and what to tell the board.Lean IT orgsWhat to patch firstNo security team? The short list of what matters this week.ResearcherPivot the dataCVE → weakness → technique → actor → control, with provenance.MSPAcross your clientsOne weekly read to triage exposure across every stack you run.
See it live
Or browse by pillar: Vulnerabilities·Threats·Assets·Controls
The public feeds are raw material anyone can pull — the cleanup, the two-way mappings, and the decision layer on top are ours. Methodology →
Follow the daily brief: RSS · JSON point any reader at the RSS feed — no email needed.