What’s new
Recently added or changed features, newest first. Pages reached from this list open the relevant view.
- 19 August 2026 featureThe first six-figure year
- 18 August 2026 featureMSP Weekly — subscribe
- 18 August 2026 featureMSP action list
- 10 August 2026 articleOne control to satisfy them all? We measured the Secure Controls Framework against its own set theory
- 10 August 2026 articleThe compliance hub you cannot audit: reading the Unified Compliance Framework through its patents
- 30 July 2026 researchWhere the defensive playbook runs out
- 30 July 2026 articleWas the Hugging Face incident just human misconfiguration?
- 29 July 2026 researchArticle: Thirty AI risks, and the one that maps to nothing
- 29 July 2026 researchArticle: 170 AI attacks, four weaknesses
- 26 July 2026 researchWhich control framework should you actually adopt?
- 26 July 2026 researchCoverage is not a single number
- 26 July 2026 researchThe framework everything maps through
- 26 July 2026 researchWhat ASVS verifies, and what it skips
- 26 July 2026 researchThe broad catalog and the deep one
- 26 July 2026 researchWhat a control framework can and cannot prevent
- 25 July 2026 researchThe shortcut that always had an answer
- 25 July 2026 articleSoftware is not an industry
- 25 July 2026 articleHow to read a vendor's CVE count
- 25 July 2026 researchNVD does not have a word for prompt injection
- 25 July 2026 articleAbsent beats derived
- 24 July 2026 featureCoverage Demonstrator
- 24 July 2026 featureWho NVD overrules on CVSS severity (and why the EU inherits it)
- 21 July 2026 featureSecurity services for MSPs
- 21 July 2026 featureSecurity as a maintenance window
- 18 July 2026 featureYour toolchain
- 18 July 2026 featurePortfolio exposure
- 18 July 2026 featureClient advisory
- 18 July 2026 articleThe flood that came in slow
- 18 July 2026 featureMSP Weekly
- 15 July 2026 featureLean IT Orgs Monthly
- 14 July 2026 featureSMB & Lean-IT Monthly
- 11 July 2026 featureVulnerability types — glossary
- 11 July 2026 featureCVSS versions explained
- 11 July 2026 articleENISA Threat Landscape, read from the vulnerability side
- 10 July 2026 featureEmbeddable widgets
- 08 July 2026 featureCISO Briefing — week ending 08 July 2026
- 08 July 2026 featureActor × vendor attribution | Cyber Posture
- 04 July 2026 primerConcepts — a plain-language glossary
- 04 July 2026 featureVendor compare
- 04 July 2026 featureLLM Vuln-Discovery Adoption Index
- 03 July 2026 articleWhere LLM-driven code scanning earns its keep — and where it doesn’t | Cyber Posture
- 03 July 2026 articleGrading the machine: how reliable are LLM-authored security cross-walks?
- 01 July 2026 featureCVE → actor lookup
- 01 July 2026 featureThreat-actor methodology
- 30 June 2026 featureLandmark cyber incidents
- 30 June 2026 featureActor similarity graph
- 30 June 2026 featureCompare threat actors
- 29 June 2026 featureIndustrial espionage
- 28 June 2026 featureThreat-actor circles by victim
- 28 June 2026 featureThreat-actor coverage by sector
- 28 June 2026 featurePublic breach notifications
- 26 June 2026 articleWe Still Need Offensive AI for Defense
- 25 June 2026 featureENISA Threat Landscape
- 25 June 2026 featureHow we score CVE risk
- 25 June 2026 featureENISA EUVD critical vulnerabilities
- 25 June 2026 featureWhere the EU and NVD disagree on severity
- 06 June 2026 researchFive European CSIRTs, five different beats
- 04 June 2026 primerReading the security surface in four dimensions
- 04 June 2026 researchLLMs Discovering Vulnerabilities
- 02 June 2026 articleThe customer side of the LLM-CVE arms race
- 02 June 2026 featureThreat-actor campaigns
- 01 June 2026 featureThreat actors
- 01 June 2026 researchAttributed CVEs — research scatter
- 30 May 2026 articleThe patch-obfuscation crossover
- 30 May 2026 articleHow much fake LLM credit can our chart absorb?
- 29 May 2026 featureNamed CVEs
- 23 May 2026 articleThe cross-walk illusion — why “mapped to” isn’t “equivalent to”
- 23 May 2026 articleReading cross-walks — how the framework chips on this site work
- 22 May 2026 featureHost hardening checklists — 12 DISA STIGs, 3,616 rules (Windows + Linux)
- 22 May 2026 featureNIST Cybersecurity Framework 2.0 (6 Functions, 22 Categories, 106 Subcategories)
- 22 May 2026 featureOWASP ASVS 5.0 verification requirements (345 across 17 chapters)
- 21 May 2026 featureEU and UK vulnerability context now on every CVE page (ENISA EUVD + UK NCSC)
- 21 May 2026 featureOWASP Top 10 for Web Applications 2025 mappings
- 20 May 2026 primerWhat is Distributed Denial of Service (DDoS)?
- 13 May 2026 featureReal-time publication pulse on the Daily CVE Tracker
- 13 May 2026 featureSearch by CVE, CWE, NIST control, or ATT&CK ID — from any page
- 13 May 2026 featureCross-references between configuration rules (AWS, Azure, GCP) and NIST 800-53 r5 controls
- 12 May 2026 articleHow will attackers react?
- 12 May 2026 primerWhat is Remote Code Execution (RCE)?
- 12 May 2026 primerWhat is Local Privilege Escalation (LPE)?
- 06 May 2026 featureCVEs credited to an LLM
- 05 May 2026 featureTrends
- 05 May 2026 featureCWEs
- 03 May 2026 featureSupport for MITRE ATT&CK 19.0
- 03 May 2026 featureMobile-friendly site
- 02 May 2026 featureMythos Hype Index