2026-08-11 (Tuesday) Journal

Day summary: Today’s RSS activity: 2 item(s) from discourse.ossbase.org, infosec.exchange including “From a Research Paper to Running Code: Experimenting with Local Exploit Hazard in Vulnerability-Lookup”; “From a research paper to running open-source code in just a few days. We (with @cedric) have been experimenting in Vulnerability-Lookup with the concept of Local Exploit Hazard, based on the recent research paper “Modeling Local Exploit Hazard — A Bayesian Framework for Quantifying Exploit Risk and Operational Efficiency” by Stephen Shaffer and Laura Cristiana Voicu.The idea addresses an important question in vulnerability management:Not simply “How dangerous is this vulnerability globally?” but “How much exploitation risk does this vulnerability represent in my environment?”Instead of introducing yet another static vulnerability score, the model starts from exploit likelihood such as EPSS and combines it with local security controls, CVSS attack vectors, vulnerability age and KEV policy to estimate an exploitation hazard.We implemented an experimental version in Vulnerability-Lookup and connected it directly to operational workflows.For the full details: https://www.vulnerability-lookup.org/2026/08/11/local-exploit-hazard/#cve #gcve #vulnerabilitymanagement #vulnerability #opensource #opendata @circl”.

Hourly activity:

hour  00 01 02 03 04 05 06 07 08 09 10 11 12 13 14 15 16 17 18 19 20 21 22 23
pulse  .  .  .  .  .  .  .  .  .  .  @  .  .  .  .  .  @  .  .  .  .  .  .  .
count 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 01 00 00 00 00 00 00 00

adulau commented on an issue in misp-modules


From a Research Paper to Running Code: Experimenting with Local Exploit Hazard in Vulnerability-Lookup


From a research paper to running open-source code in just a few days. We (with @cedric) have been experimenting in Vulnerability-Lookup with the concept of Local Exploit Hazard, based on the recent research paper “Modeling Local Exploit Hazard — A Bayesian Framework for Quantifying Exploit Risk and Operational Efficiency” by Stephen Shaffer and Laura Cristiana Voicu.The idea addresses an important question in vulnerability management:Not simply “How dangerous is this vulnerability globally?” but “How much exploitation risk does this vulnerability represent in my environment?”Instead of introducing yet another static vulnerability score, the model starts from exploit likelihood such as EPSS and combines it with local security controls, CVSS attack vectors, vulnerability age and KEV policy to estimate an exploitation hazard.We implemented an experimental version in Vulnerability-Lookup and connected it directly to operational workflows.For the full details: https://www.vulnerability-lookup.org/2026/08/11/local-exploit-hazard/#cve #gcve #vulnerabilitymanagement #vulnerability #opensource #opendata @circl


adulau pushed gcve-enriched-dumps


adulau pushed gcve-enriched-dumps


adulau pushed gcve-enriched-dumps


adulau pushed gcve-enriched-dumps


adulau pushed gcve-enriched-dumps


adulau pushed gcve-enriched-dumps


adulau pushed gcve-enriched-dumps


adulau pushed gcve-enriched-dumps


adulau pushed gcve-enriched-dumps


adulau pushed gcve.eu


adulau pushed gcve.eu-directory