Signals
Short, graph-backed reads on cyber risk. One topic, one chart, one page, built from our live research data. Each carries a badge: Weekly desks refresh with the data, Standing insights hold until the picture changes, Records mark a one-off event.
Updated 11 August 2026, 00:49 UTC
Latest
RecordCVE disclosure is on pace for a record year10 August 2026RecordWeakness shift: CWE-284 is now the #2 most common vulnerability type08 August 2026RecordThe quietest week for confirmed exploitation we have tracked04 August 2026StandingN-able Patch Gap Matches KEV and Campaign Data04 August 2026RecordVulnerabilities are being weaponized faster than we have ever measured03 August 2026StandingWhere the defensive playbook runs out11 August 2026StandingThirty AI risks, and the one that maps to nothing11 August 2026Standing170 AI attacks, four weaknesses11 August 2026
For your role
The weekly desk written for how you read this. Pick a role to focus.
Threats & exploitation 6
Confirmed exploitation, the actors behind it, and how fast flaws weaponize.
WeeklyLeak-Site WatchLeak-site watch: read the extortion feed, don't react to itUpdated 11 August 2026WeeklyThis Week in Cyber RiskThis week in cyber risk: 5 newly confirmed-exploited CVEsUpdated 11 August 2026WeeklyThreat Actor SpotlightThreat actor spotlight: PROMETHIUMUpdated 11 August 2026StandingAIAI Risk WatchAI risk watch: the Hype Index sits at 84/100Updated 11 August 2026StandingEU Saw It FirstENISA flags 6 exploited CVEs that CISA's KEV hasn't listedUpdated 11 August 2026StandingWeaponization SpeedWeaponization speed: the median new-KEV CVE was 13 days from disclosure to exploitedUpdated 11 August 2026
Flaws 14
The vulnerabilities and weakness types themselves.
WeeklyMapping NoteMapping note: the standard chain loses cross-site request forgeryUpdated 11 August 2026WeeklyWeakness Under-RatingThe weaknesses NVD marks up most: CWE-707 averages +2.4 over the vendorUpdated 11 August 2026WeeklyWeakness of the WeekWeakness of the week: CWE-79 (Cross-site Scripting) leads this week's new CVEsUpdated 11 August 2026StandingThe AI Attack Surface170 AI attacks, four weaknessesUpdated 11 August 2026StandingAIBlind Spots / Coverage GapsBlind spots: the AI weaknesses the standard catalogs barely useUpdated 11 August 2026StandingN-able Patch Gap Matches KEV and Campaign DataUpdated 04 August 2026StandingThe AI Risk GapThirty AI risks, and the one that maps to nothingUpdated 11 August 2026StandingThe Defensive GapWhere the defensive playbook runs outUpdated 11 August 2026
6 records in this area
CVE disclosure is on pace for a record year10 August 2026The quietest week for confirmed exploitation we have tracked04 August 2026Vulnerabilities are being weaponized faster than we have ever measured03 August 2026Weakness-type records 2latest 23 July 2026AI vulnerability records 1latest 25 July 2026
Scoring & data quality 7
How severity is scored, who scores it, and how far to trust it.
WeeklyScore DisagreementNVD and the vendor split hardest on CVE-2026-57926: a 7.2-point gapUpdated 11 August 2026StandingCVSS 4.0 AdoptionAbout one in three new CVEs now carries a CVSS 4.0 score (33% in 2026Q2)Updated 11 August 2026StandingSeverity InflationNVD is marking vendor scores up by more each year, +0.8 in 2026Updated 11 August 2026StandingSeverity Re-scoringNVD overrules the vendor's severity score on 80% of CVEs, mostly upwardUpdated 11 August 2026StandingWho Scores the ScoresNVD publishes its own severity score for only 34% of recent CVEsUpdated 11 August 2026StandingRegional Risk Watch (EU/UK)Regional risk watch: the EU and US agree on severity 93% of the timeUpdated 11 August 2026StandingCVSS Trust IndexWhose CVSS scores NVD overrules: Oracle at 3%, VulDB at 95%Updated 11 August 2026
Vendors & products 4
Which vendors and products are drawing exploitation and risk.
Controls & response 2
The controls and responses that address what's above.