Signals
Short, graph-backed reads on cyber risk. One topic, one chart, one page, built from our live research data. Each carries a badge: Weekly desks refresh with the data, Standing insights hold until the picture changes, Records mark a one-off event.
Updated 12 August 2026, 01:03 UTC
Latest
RecordCVE disclosure is on pace for a record year10 August 2026RecordWeakness shift: CWE-284 is now the #2 most common vulnerability type08 August 2026RecordThe quietest week for confirmed exploitation we have tracked04 August 2026StandingN-able Patch Gap Matches KEV and Campaign Data04 August 2026RecordVulnerabilities are being weaponized faster than we have ever measured03 August 2026StandingWhere the defensive playbook runs out31 July 2026StandingThirty AI risks, and the one that maps to nothing31 July 2026Standing170 AI attacks, four weaknesses30 July 2026
For your role
The weekly desk written for how you read this. Pick a role to focus.
Threats & exploitation 6
Confirmed exploitation, the actors behind it, and how fast flaws weaponize.
WeeklyLeak-Site WatchLeak-site watch: read the extortion feed, don't react to itUpdated 23 July 2026WeeklyThis Week in Cyber RiskThis week in cyber risk: 5 newly confirmed-exploited CVEsUpdated 23 July 2026WeeklyThreat Actor SpotlightThreat actor spotlight: PROMETHIUMUpdated 25 July 2026StandingAIAI Risk WatchAI risk watch: the Hype Index sits at 84/100Updated 24 July 2026StandingEU Saw It FirstENISA flags 6 exploited CVEs that CISA's KEV hasn't listedUpdated 24 July 2026StandingWeaponization SpeedWeaponization speed: the median new-KEV CVE was 0 days from disclosure to exploitedUpdated 24 July 2026
Flaws 14
The vulnerabilities and weakness types themselves.
WeeklyMapping NoteMapping note: the standard chain loses cross-site request forgeryUpdated 25 July 2026WeeklyWeakness Under-RatingThe weaknesses NVD marks up most: CWE-707 averages +2.4 over the vendorUpdated 24 July 2026WeeklyWeakness of the WeekWeakness of the week: CWE-79 (Cross-site Scripting) leads this week's new CVEsUpdated 24 July 2026StandingThe AI Attack Surface170 AI attacks, four weaknessesUpdated 30 July 2026StandingAIBlind Spots / Coverage GapsBlind spots: the AI weaknesses the standard catalogs barely useUpdated 23 July 2026StandingN-able Patch Gap Matches KEV and Campaign DataUpdated 04 August 2026StandingThe AI Risk GapThirty AI risks, and the one that maps to nothingUpdated 31 July 2026StandingThe Defensive GapWhere the defensive playbook runs outUpdated 31 July 2026
6 records in this area
CVE disclosure is on pace for a record year10 August 2026The quietest week for confirmed exploitation we have tracked04 August 2026Vulnerabilities are being weaponized faster than we have ever measured03 August 2026Weakness-type records 2latest 23 July 2026AI vulnerability records 1latest 25 July 2026
Scoring & data quality 7
How severity is scored, who scores it, and how far to trust it.
WeeklyScore DisagreementNVD and the vendor split hardest on CVE-2026-57926: a 7.2-point gapUpdated 24 July 2026StandingCVSS 4.0 AdoptionAbout one in three new CVEs now carries a CVSS 4.0 score (33% in 2026Q2)Updated 24 July 2026StandingSeverity InflationNVD is marking vendor scores up by more each year, +0.8 in 2026Updated 24 July 2026StandingSeverity Re-scoringNVD overrules the vendor's severity score on 80% of CVEs, mostly upwardUpdated 24 July 2026StandingWho Scores the ScoresNVD publishes its own severity score for only 34% of recent CVEsUpdated 24 July 2026StandingRegional Risk Watch (EU/UK)Regional risk watch: the EU and US agree on severity 93% of the timeUpdated 23 July 2026StandingCVSS Trust IndexWhose CVSS scores NVD overrules: Oracle at 3%, VulDB at 95%Updated 25 July 2026
Vendors & products 4
Which vendors and products are drawing exploitation and risk.
Controls & response 2
The controls and responses that address what's above.