Threat feed liveUpdated — 24.07.2026 09:37 CET30 dossiersMITRE ATT&CK mappingThreat feed liveUpdated — 24.07.2026 09:37 CET30 dossiersMITRE ATT&CK mapping

Methodology

How we verify — and why you can trust it

A threat-intelligence site is worth only as much as its sources and its honesty about its own uncertainty. This page explains, plainly, where the data comes from, how we verify it, and what we do when we get something wrong.

How we verify, in four steps

  1. 1
    Authoritative sources

    Only agency advisories, reports from the vendors who ran the incident, MITRE pages and the CVE registry. At least two independent sources.

  2. 2
    Checked against the official registry

    Every CVE is checked against the CVE Program registry: if it isn't PUBLISHED, we don't treat it as confirmed.

  3. 3
    Confirmed or rejected

    The VulnFeed pipeline assigns each item a status and records the reason in an audit log. No valid status, no publication.

  4. 4
    Published with the sources

    Primary sources are cited at the foot of every page and uncertainty is stated in the text. ATT&CK IDs are copied, never inferred.

Primary sources, always

Every dossier is built on verified primary sources: advisories from CISA, FBI, NCSC and ENISA; reports from the vendors who ran the incident response; official MITRE ATT&CK pages; records from the official CVE registry. The non-negotiable rule is at least two independent sources per dossier. If solid material isn't there, the dossier doesn't ship.

Every CVE is checked against the official registry

We don't trust a headline or an aggregator. Every cited CVE-ID is checked against the official CVE Program registry (cveawg.mitre.org): if it isn't PUBLISHED, we don't treat it as confirmed. This check is automated by VulnFeed, our internal pipeline, which assigns each item a status — confirmed, pre-disclosure, pending-registry, or rejected — and records the reason in an auditable log.

ATT&CK IDs are copied, not inferred

MITRE ATT&CK technique identifiers are copied from the advisories that list them. When a mapping is our own reasoned judgment, we say so explicitly in the text: we never pass a deduction off as an official fact.

Uncertainty is stated in the body

Disputed attribution, a single source, a CVSS not yet validated by NVD, diverging CNA scores: we write it inside the article. We prefer a dossier that admits what it doesn't know to one that fakes certainty.

Defensive, not offensive

We describe tactics and techniques at the same level of detail as a public advisory. We do not publish exploit code, payloads or step-by-step exploitation instructions.

Transparency about AI

Research and drafting are AI-assisted, and the video narration is synthetic — declared as such on TikTok too. Automation does not touch the rule above: every published fact is verified against the primary sources cited at the foot of the page. Editorial accountability stays human.

Authorized sources

Ingestion is allowed only from these sources.

SourceRole
CISA KEVExploited in the wild
CISA / FBI / NCSC / ENISAOfficial agency advisories
Registro CVE ProgramGround truth: official state of each CVE
NVD (NIST)CVSS / CPE enrichment
EUVD (ENISA)EU vulnerability database
GitHub Advisory / ZDIAuthoritative CNAs
Report dei vendor IRVendor incident-response reports
MITRE ATT&CKTactics & techniques mapping

Correction policy

If a dossier changes after publication — a source retracts, a CVSS is revised, an attribution collapses — the correction is written into the dossier with its date, and the page shows “Updated on …”. The dateModified field in the structured data follows that date. We don't rewrite history quietly. Error reports are welcome by email.

Report an error. Found an inaccuracy or a better source? Email me: civiero.riccardo03@gmail.com