Transparency

Our sources

We favor primary sources: government advisories, CERTs, vendor security advisories and original research. Every story links to the sources it was built from, and each source's type is shown next to it so reporting and advisories are never confused.

Government agency

SourceWeightNotesLast checked
CISA Known Exploited Vulnerabilities98/100Authoritative US government list of vulnerabilities with confirmed exploitation.3 hours ago
CISA Cybersecurity Advisories97/100—2 hours ago
UK National Cyber Security Centre92/100—2 hours ago

CERT

SourceWeightNotesLast checked
CERT/CC Vulnerability Notes93/100—2 hours ago

Vendor security advisory

SourceWeightNotesLast checked
Google Chrome Releases90/100Mixed feed; only posts with security fixes are ingested.2 hours ago
Microsoft Security Blog & MSRC90/100—2 hours ago

Security research

SourceWeightNotesLast checked
Google Project Zero92/100—4 hours ago
Cisco Talos Intelligence88/100—3 hours ago
Palo Alto Networks Unit 4288/100—3 hours ago
SANS Internet Storm Center85/100—3 hours ago
Schneier on Security80/100—4 hours ago

Security publication

SourceWeightNotesLast checked
Krebs on Security88/100—3 hours ago
The Record by Recorded Future News86/100—2 hours ago
BleepingComputer85/100—2 hours ago
SecurityWeek82/100—2 hours ago
Dark Reading80/100—2 hours ago
The Hacker News78/100Includes sponsored posts; items are reviewed before publishing.2 hours ago

Weight reflects our editorial judgment of a source's reliability for security claims. It decides which source leads a story when several report the same event, and it feeds into ranking. It is not a rating of a publication overall.