Superhuman. Offensive Intelligence.

The Signal

Designed to improve your signal-to-noise ratio. A monthly report curated by our Offensive Security Operations Center (OSOC), delivering timely insights into emerging vulnerabilities, threat trends, and the exposures that matter most.
Published monthly
Curated by our OSOC
Recommended action for every entry

GET THE NEXT ISSUE

A monthly report delivered straight to your inbox
Why this one is different?

Most vulnerability feeds tell you what was published

There were thousands of CVEs disclosed last month. A handful of them were used against real organizations. This digest only covers the second group.

Active exploitation in the wild not merely disclosure is the threshold for inclusion.

Editorial standard, every issue

What is being exploited?

The vulnerabilities our operators and threat intelligence sources have observed under active attack, each with severity, CVSS, and the systems at risk. Every entry is validated against public threat actor reporting and CISA advisories.

Who is doing it?

Profiles of the actors driving the month's activity — origin, targeting, motivation, and the techniques they reach for.

What to do about it?

A specific recommended action for every entry: the version to upgrade to, the component to disable, the indicator to hunt for. Written to be handed to whoever owns the patch cycle.
A look inside

Sneak peek

Designed to improve your signal-to-noise ratio. A monthly report curated by our Offensive Security Operations Center, delivering timely insight into emerging vulnerabilities, threat trends, and the exposures that matter most.
Who reads it

Written for the people who have to act on it

CISOs

Know which of this month's disclosures actually warrant an emergency change window, and which can wait for the normal cycle.

Red Team Leaders

Identify the vulnerabilities worth validating, understand how attackers are likely to chain them, and prioritize testing based on real-world exploitability instead of CVSS scores alone.
Blue circular icon with three white user figures representing a group or community.

Vulnerability Management Teams

Focus remediation where it matters most with clear prioritization, actionable guidance, and practical context that helps reduce risk without overwhelming your team.

FAQ’s

What does it cost?

Nothing. There is no paid tier and no gated appendix.

How is this different from CISA KEV alerts?

NothKEV tells you a vulnerability is being exploited. The digest tells you who is exploiting it, how the intrusion typically unfolds, and what to do first — with our operators' judgment applied to which entries deserve your attention this month. We include the full KEV additions table as well, with federal remediation deadlines.ing. There is no paid tier and no gated appendix.

Where does the intelligence come from?

Public advisories from CISA and affected vendors, threat intelligence vendor reporting, and attack telemetry observed across our assessment work. Every entry names its sources. The analysis, prioritization, and recommended actions are our own.

How often does it arrive, and will I get anything else?

Once a month.

Can I share it with my team?

Yes, forward it freely. If you would rather each person receive their own copy, they can subscribe here.