Why This Exists

The national cyber agencies of allied nations publish a steady stream of advisories, technical guidance, and threat alerts — but each one lives on its own website, in its own format, on its own schedule. This project brings the publicly available cybersecurity guidance of close partner nations into a single, searchable place so that defenders don't have to monitor six or seven sites separately to stay current.

The participating agencies already work as a community. Many of their most important publications are co-sealed — jointly authored and released simultaneously by several agencies across different countries. A single ransomware advisory might carry the names of CISA, the FBI, the NSA, the UK's NCSC, and Australia's ACSC all at once. Aggregating these sources reflects how the guidance is actually produced: as a shared, cross-border effort. Surfacing who co-authored what, and when, is one of the core goals of this monitor.

The Value of Tracking Guidance Over Time

A live dashboard answers "what's new today." A historical record answers something more valuable: "how is the threat landscape changing." By capturing each publication with its date, issuing agencies, and subject matter, the monitor builds a longitudinal dataset that makes trends visible that no single advisory reveals on its own.

Vulnerability abuse trends

Tracking which vulnerability classes and techniques recur across advisories over months reveals what attackers are actually exploiting in the wild — and which weaknesses keep resurfacing despite available patches.

Detection maturity

The gap between when a technique first appears in threat reporting and when detection and mitigation guidance follows is a measurable signal of how quickly the defender community is catching up to emerging tradecraft.

Cross-agency consensus

When multiple agencies independently or jointly flag the same threat, that convergence is a strong prioritization signal. Co-sealing patterns over time show where allied consensus is forming.

Campaign continuity

Threat actors and campaigns reappear. A searchable archive lets analysts connect a current alert to related guidance issued months earlier, rather than treating each publication as an isolated event.

Sources & Their Stated Purpose

Each source below is described using that agency's own stated mission, followed by the licensing terms under which their published material may be linked to and summarized. This project links to and summarizes content; it does not republish documents wholesale, and it reproduces no agency logos, crests, or trademarks.

CISA — Cybersecurity and Infrastructure Security Agency

United States

CISA's stated mission is to lead the national effort to understand, manage, and reduce risk to the cyber and physical infrastructure Americans rely on, working with partners to defend against threats and build a more secure and resilient infrastructure.

Public Domain (U.S. Government work)

FBI Cyber Division

United States

The FBI's stated purpose in the cyber domain is to protect the United States from cyber threats by investigating intrusions and imposing consequences on malicious actors, while sharing threat intelligence with the public and private sectors through alerts and Flash reports.

Public Domain (U.S. Government work)

NSA Cybersecurity Directorate

United States

The NSA's Cybersecurity Directorate states its mission as preventing and eradicating threats to U.S. national security systems and the defense industrial base, with a focus on issuing actionable guidance that hardens systems against nation-state adversaries.

Public Domain (U.S. Government work)

NCSC — National Cyber Security Centre

United Kingdom

The UK NCSC states its purpose as helping to make the UK the safest place to live and work online, acting as the bridge between industry and government and providing a unified national response to cyber incidents.

Open Government Licence (Crown Copyright)

ACSC — Australian Cyber Security Centre

Australia

The ACSC, part of the Australian Signals Directorate, states its purpose as leading the Australian Government's efforts to improve national cyber security, providing advice and assistance and publishing guidance to help organisations protect themselves.

Creative Commons Attribution 4.0 (CC BY 4.0)

NCSC — National Cyber Security Centre

New Zealand

New Zealand's NCSC states its role as improving the cyber security and resilience of nationally significant organisations and the wider public, publishing guidance and operating public-facing resources such as Own Your Online.

Creative Commons Attribution 4.0 (Crown Copyright)

CERT-EU — Computer Emergency Response Team for the EU Institutions

European Union

CERT-EU states its mission as contributing to the cybersecurity of the EU institutions, bodies, and agencies by providing proactive cybersecurity advisory and assistance services, publishing security advisories on actively exploited vulnerabilities and issuing security guidance on hardening, threat detection, and incident response for the broader community.

EU Standard Reuse Policy (© European Union)

JPCERT/CC — Japan Computer Emergency Response Team Coordination Center

Japan

JPCERT/CC states its role as Japan's first CSIRT: a neutral coordination center that receives computer security incident reports, supports response, monitors internet threats, and works with domestic and international partners — publishing Security Alerts on vulnerabilities and threats affecting widely used software.

© JPCERT/CC — Quotation permitted with attribution

Vulnerability & Exploit Tracking: How to Read the Sources

Beyond agency guidance, this project tracks individual vulnerabilities (CVEs) across several kinds of sources — and those sources make very different claims. A CVE listed in CISA's KEV catalog, a CVE scored in CISA's Vulnrichment program, and a CVE named by an exploit framework are three different statements with three different levels of evidence. They are presented together, but they should not be read as equivalent.

CISA Known Exploited Vulnerabilities (KEV) Catalog

Observed in the wild
Confirmed exploitation

A KEV listing means CISA has reliable evidence that the vulnerability has been exploited against real systems. It is the strongest claim tracked here — but also a deliberately conservative one. Vulnerabilities typically appear in KEV only after exploitation is confirmed, which can be weeks or months after working exploit code first circulates. KEV answers "has this been used against someone," not "could it be."

CISA Vulnrichment

Analyst assessment
Expert assessment

Vulnrichment is CISA's public enrichment program: analysts add SSVC decision points — exploitation status (none / proof-of-concept / active), whether exploitation is automatable, and technical impact — plus CVSS scores and weakness classifications (CWE) to CVE records that would otherwise lack them. Unlike KEV, this is an assessment rather than a sighting: it tells you how dangerous a vulnerability looks to an experienced analyst, updated as evidence changes.

Weaponization Evidence — Offensive & Testing Tools

Exploit availability

The project also records when a CVE shows up in offensive security and testing tools. This measures weaponization — how easy it has become to exploit a vulnerability. Different kinds of project answer different questions, so each signal is labelled by what it tells you rather than ranked against the others:

Direct — curated exploit code

Metasploit · Exploit-DB · Nuclei templates

A merged Metasploit module or a published Nuclei template is working, reviewed exploit or detection code that anyone can download and run. When a CVE appears here, the barrier to exploiting it has collapsed to "install a free tool."

Indirect — framework references

Empire · Sliver · Havoc · Mythic · PoshC2 · Atomic Red Team

These are mentions of a CVE in the code, commits, or documentation of post-exploitation and adversary-emulation frameworks. A reference usually signals real attacker interest, but it may be a partial implementation, a test case, or detection content rather than a complete working exploit.

Availability — distribution & packaging

BlackArch Linux · Parrot Security OS · MITRE CALDERA

Security distributions and plugin catalogs curate and package tooling built elsewhere, which is a different job from authoring an exploit and one they do well. A CVE appearing here tells you the relevant tooling is packaged and easy to obtain. Because entries often arrive as bulk imports, the recorded date usually reflects when something was packaged rather than when it first existed. Set beside a merged Metasploit module for the same CVE, the two answer separate questions: the module establishes that reviewed exploit code exists, while the package establishes how readily available it now is. Both matter, and neither substitutes for the other.

Read together, the sources form a timeline for each vulnerability: Vulnrichment says how bad it could be, the tool trackers say how easy it has become, and KEV says it has actually happened. When all three agree, that convergence is the loudest prioritization signal this project can offer.

How This Material Is Used

Across all sources, this project does three things: it links to the original publication on the issuing agency's own website, it presents a short summary or the document's own title and metadata, and it records structured data such as the publication date and co-sealing agencies. Visitors are always directed to the authoritative original for the full text.

Linking and summarizing is permitted under every licence above — public domain for the U.S. agencies, the Open Government Licence for the UK agencies, Creative Commons Attribution for the Australian and New Zealand agencies, the EU standard reuse policy for CERT-EU, and JPCERT/CC's quotation terms, which permit citation with source name, title, and URL. Each of these frameworks explicitly allows the reuse and adaptation of information with appropriate attribution.

Detection & Scanning Collections: Licensing

The Detection & Exploitation panel on each CVE page reports whether public rules, templates or modules reference that vulnerability, and the Distribution Status and vendor-assessment panels report what the supplier themselves has published about it. Those collections are maintained by independent projects and vendors under their own licences, which are separate from the government sources above. CyberzSOC stores only the mapping — which CVE a rule refers to, the rule's identifier, and a link back to it — never the rule content itself.

CollectionLayerLicence
Nuclei templates Scan MIT
Greenbone Community Feed (OpenVAS NVT) Scan Database: ODbL v1.0 · individual tests: GNU GPL v2
Emerging Threats Open (Suricata & Snort builds) Network BSD (ET rules) · GNU GPL v2 (legacy sids)
Snort community rules Network GNU GPL v2
Sigma Host / SIEM Rules: Detection Rule License 1.1 · specification: public domain
YARA — signature-base Host / SIEM Detection Rule License 1.1
YARA — Yara-Rules Host / SIEM GNU GPL v2
Metasploit Framework Exploit BSD 3-clause
Debian Security Tracker Remediation MIT (Expat) or GNU GPL v2+
Microsoft Security Response Center Vendor Published by the vendor via the MSRC Security Update Guide; see MSRC for their terms
Exploit-DB Exploit GNU GPL v2
FIRST EPSS (Exploit Prediction Scoring System) Prediction Published freely by FIRST with no registration; attribution requested and given

Debian is used in preference to Ubuntu for distribution remediation state: Ubuntu publishes the equivalent data under CC-BY-SA 4.0, whose share-alike clause would attach an obligation to this site, while Debian's is MIT or GPLv2+. Debian is also upstream of Ubuntu, so this takes the same facts from their origin rather than from a derivative.

EPSS history is kept rather than today's score, because the useful fact for a timeline is the date a vulnerability's exploitation probability moved. FIRST's own time-series endpoint reaches back only 30 days, so the history is assembled from their archived daily snapshots instead: weekly from December 2021 to fill in the past, daily from here on. FIRST notes that the 0.10 threshold this project uses to call a rise a spike is common in the field but carries no special authority from EPSS, and periodic recalibrations of the model move every score at once; those dates are detected and set aside so a change in the model is never presented as an event in a vulnerability's own history.

The Greenbone Community Feed is the one to read closely: the ODbL is a share-alike licence covering the database as a whole, and it asks that any public use carry a notice of the licence. That notice appears on every CVE page drawing on the feed. Greenbone also asks that the feed be synchronised no more than once at a time, which this project respects with a single weekly job.

Vulnerability identifiers and weakness classifications come from the CVE Program and CWE, and countermeasure mappings from MITRE D3FEND, all used under their respective terms of use.

Disclaimer & attribution.

This is an independent aggregation project. It is not affiliated with, endorsed by, or operated on behalf of any of the agencies listed above. Agency names, logos, seals, crests, and trademarks remain the property of their respective owners and are not reproduced here.

The summaries and metadata shown are derived from publicly available sources and are provided for convenience only. They are not a substitute for the authoritative original publications. Licensing terms are summarized here for transparency; always consult the source's own copyright page for current terms.