Vulnerability intelligence is the work between “a CVE was published” and “we know what to patch first”. It covers how vulnerabilities are discovered, catalogued and enriched, how exploitation is detected and forecast, and how all of that turns into decisions defenders can act on.
Here I write about:
- Catalogues and identifiers: CVE, CPE, CWE and how vulnerability databases keep (or lose) consistency.
- Exploitation signals: known-exploited lists (KEV), exploit prediction (EPSS) and early-warning indicators.
- Advisories and disclosure: CSAF, coordinated vulnerability disclosure and vendor advisories.
- Prioritisation: turning many data sources into a ranked, defensible patching decision.
Posts in this section are listed below.