← Blog // TAG

CVE

3 articles

From a CVE to a detection: from the advisory to a rule that catches the attack A CVE advisory tells you what breaks, not how to detect it. The method to go from an advisory to a detection: service a… Read → CVSS v3.1 vs v4.0: what changes and how to score it right CVSS v4.0 is not a tweak of v3.1: it changes the impact model (vulnerable vs subsequent systems), splits complexity fro… Read → Which CVE to patch first: prioritize with EPSS, KEV and context CVSS alone is not enough to prioritize patching. How to combine EPSS (exploit probability), CISA's KEV list and your re… Read →