Methodology
What the desk reads, how it decides what matters, and what its confidence language actually means.
Where the material comes from
Every edition is built from the same public wire the desk reads each day. Ten feeds are polled continuously:
- CISA Advisories — the authoritative record of vulnerabilities confirmed as exploited, and the fix deadlines that follow.
- SANS Internet Storm Center — handler diaries and sensor data, usually the earliest signal that something is being scanned for at scale.
- Krebs on Security, The Record, BleepingComputer, SecurityWeek, Dark Reading, The Hacker News, Ars Technica — original reporting on incidents, breaches and threat actor activity.
- A rolling news search for breach, ransomware and extortion coverage, to catch stories that break outside the security press.
Nothing is republished. Each item is a pointer to somebody else's reporting, and the desk's job is the layer on top: what it means, what it corroborates, and what a defender should do about it. Every article lists the specific items it was built from, with links, so any claim can be traced back to the original.
How stories are chosen
Far more crosses the wire in a day than is worth writing about. Items are ranked before anything is written, on four things:
- Severity — how bad the outcome is if the thing described actually happens to you.
- Novelty — whether this is genuinely new, or the fifth restatement of a story the desk covered last week. Repetition is scored down deliberately.
- Temporal state — a vulnerability under active exploitation outranks a proof of concept, which outranks a theoretical weakness. What is happening now beats what might happen.
- Corroboration — when the same CVE, vendor or named group keeps surfacing across independent outlets, that is a bigger story than any single report's severity suggests. Multiple sources converging is treated as evidence; a single unreplicated claim is treated with more caution.
The desk also checks what it has already published, so recent topics are not covered twice in a week without a reason.
What the confidence language means
Articles say plainly how much weight a claim will carry, and the wording is not decorative:
- Confirmed — stated by the affected vendor, by CISA, or by a court or regulatory filing. First-party or official.
- Reported — carried by named reporting the desk considers reliable, but not yet acknowledged by the party involved.
- Claimed — asserted by an attacker, a leak site, or an anonymous source. Extortion groups lie about what they have taken, and claims are labelled as claims until somebody independent stands them up.
- Assessed — the desk's own read, drawn from the evidence in front of it. Where confidence is moderate rather than high, the article says so and says what would raise it.
Severity ratings describe the realistic worst case for a typical organisation running the affected software. They are not CVSS scores and are not a substitute for reading the vendor advisory.
Sections
Each edition runs in one of nine standing sections — Threat Wrap, Vulnerability Spotlight, Post-Mortem, Actor Profile, Sector Watch, Counterpoint, Patch Priorities, The Mailbag and By the Numbers. The section determines the angle and the depth: a Spotlight takes one vulnerability seriously, a Wrap takes the day as a whole. Which section runs depends on what the wire actually gave the desk that day, not on a fixed rota.
Corrections
The desk gets things wrong. When it does, the article is corrected and the correction is noted rather than quietly edited out. If something here is inaccurate — including a claim about your organisation, or a vulnerability described as exploited when it is not — write to editorial@theperimetersite.com and it will be fixed. Right of reply is offered to any named organisation that asks for it.
Limits
This is a reading of public reporting, produced quickly and at volume. It is not incident response, not legal advice, and not a substitute for your vendor's advisory or your own telemetry. The wire is checked, but it is not the desk's own primary research: if a source got it wrong, this site can repeat the error. Verify before you act, and follow the links.