CISA KEV burst
Counts vulnerabilities CISA added during the latest seven days, compares that count with 26 prior non-overlapping weeks using a median/MAD robust z-score, then adds disclosed ransomware and urgent-deadline terms.
30-day exploitation pressure
Loading the latest accepted warning snapshot…
Reproducible method · version 2.0
This index measures global exploitation pressure for analyst triage. It is not an organisation-specific breach probability and does not claim that a product is present in any network.
Counts vulnerabilities CISA added during the latest seven days, compares that count with 26 prior non-overlapping weeks using a median/MAD robust z-score, then adds disclosed ransomware and urgent-deadline terms.
Examines the highest EPSS probabilities above 0.10 that are not yet in KEV. Current probability and seven-day acceleration identify vulnerabilities moving toward observed exploitation during EPSS’s next-30-day horizon.
Measures named-source confirmation of weaponization, mass scanning, perimeter access, and campaign-shift phrases. Repeated items from the same named source count once for cross-source confirmation.