How the Cyber Threat Status works
The threat status is calculated from what we have published. No editor can set it by hand. Each level is the sum of the signals below, and every point links back to the stories that produced it.
Principles
- Only transparent, countable signals are used, such as confirmed exploitation, CISA KEV additions and government advisories.
- Each signal has a cap, so a burst of minor news cannot inflate the level.
- “Critical” also requires evidence of widespread exploitation or an active critical incident. Volume alone stops at “High”.
- Six audience indicators (Home, Small Business, Enterprise, AI, Web/Apps, Critical Infrastructure) use the same rules on the stories labelled for that audience.
- Classification errors are corrected by editors, and the status recalculates automatically.
Signals
| Signal | Points each | Cap | Window |
|---|---|---|---|
| Widespread exploitation Stories reporting mass or widespread exploitation. | 4 | 8 | 7 days |
| Critical, actively exploited Critical-severity stories with confirmed exploitation. | 3 | 12 | 3 days |
| KEV additions used by ransomware Vulnerabilities added to CISA KEV that are known to be used in ransomware campaigns. | 2 | 6 | 7 days |
| New KEV additions Vulnerabilities newly added to the CISA Known Exploited Vulnerabilities catalog. | 1 | 6 | 7 days |
| Government / CERT advisories High or critical advisories published by government agencies or CERTs. | 1 | 4 | 7 days |
| Developing critical incidents Critical stories that editors are actively tracking as developing or confirmed. | 5 | 10 | 14 days |
| High-severity news volume All other high or critical severity stories. | 0.5 | 4 | 3 days |
A story counts toward only its most serious matching signal, except the KEV signals, which describe the catalog and always count.
Levels
| Level | Total points |
|---|---|
| Normal | 0+ |
| Guarded | 4+ |
| Elevated | 8+ |
| High | 14+ |
| Critical | 22+ |
Critical additionally requires at least one widespread-exploitation story or one developing critical incident; volume alone caps at High.
Current status and its evidence
Cyber threat status — United States
High: driven by 7 new CISA KEV additions and 11 government/CERT advisories.
Why is the status high?
- Critical, actively exploited ×1+3 / 12 ptsCritical-severity stories with confirmed exploitation.Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2026-88779) is being actively exploited, CISA warns
- KEV additions used by ransomware ×1+2 / 6 ptsVulnerabilities added to CISA KEV that are known to be used in ransomware campaigns.Armatura LLC Armatura One
- New KEV additions ×7+6 / 6 ptsVulnerabilities newly added to the CISA Known Exploited Vulnerabilities catalog.Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2026-88779) is being actively exploited, CISA warnsZammad GmbH Zammad Improper Privilege Management Vulnerability (CVE-2026-102490) is being actively exploited, CISA warnsArmatura LLC Armatura One
- Government / CERT advisories ×11+4 / 4 ptsHigh or critical advisories published by government agencies or CERTs.Zammad GmbH Zammad Improper Privilege Management Vulnerability (CVE-2026-102490) is being actively exploited, CISA warnsArmatura LLC Armatura OneFortinet FortiMail Path Traversal Vulnerability (CVE-2026-104286) is being actively exploited, CISA warns
- High-severity news volume ×13+4 / 4 ptsAll other high or critical severity stories.ClingSTUN Turns Vulnerable IoT Devices Into Proxy NodesAlleged ShinyHunters member reportedly detained in Jordan, assisting law enforcementUkraine grocery chain ATB confirms cyberattack as hackers threaten to leak data
Calculated 2 hours ago from published signals only. Nobody sets this level by hand. Methodology v1.0
- HomeNormalDriven by 2 government/CERT advisories and 1 new CISA KEV addition.
- Small BusinessGuardedDriven by 2 new CISA KEV additions and 2 government/CERT advisories.
- EnterpriseElevatedDriven by 4 new CISA KEV additions and 1 critical actively exploited issue.
- AINormalNo significant threat signals in the measurement windows.
- Web / AppsElevatedDriven by 3 new CISA KEV additions and 3 government/CERT advisories.
- Critical InfrastructureGuardedDriven by 5 government/CERT advisories and 1 KEV addition used by ransomware.
Current limits: the calculation uses what our sources have published and what we have classified. It is not a measure of attacks against any particular organization. Questions or corrections: see our editorial standards.
