The live counts on this page come from the latest edition, generated by the system they describe. The rest is how the system works.
Sources, graded.
100+ curated sources: security press, government advisories, CERT teams, vendor bulletins, CVE databases. Every classified source carries a grade, A to C, and the grade shows on the story. An unclassified source shows no grade until it earns one.
Read, then filtered.
Articles are fetched as they publish, around the clock. Three filters decide what counts as security signal: URL rules that drop careers pages and webinars, per-source rules that drop each outlet's known noise, and a relevance classifier with an explicit bias: when in doubt, keep. Rejections are recorded, not guessed.
Clustered into stories.
Twelve outlets covering one breach is one story. Articles are matched by meaning, not keywords, with thresholds that tighten as a story ages: a fresh story accepts related coverage loosely, a week-old story demands real overlap.
Understood.
Every story is read and rewritten to say what it means: which trust boundary broke, what actually changed, who is affected, whether the patch closes the risk. A separate analysis pass extracts the lead insight and calibrates confidence, and every story carries its meaning as a first-class field, the sentence you'd want a colleague to tell you.
Enriched.
CVEs are joined against NVD records, EPSS exploit-probability scores, the CISA KEV list, and vendor patch data from MSRC and GHSA. KEV deadlines become tracker entries with dates. One deliberate design choice, quoted from the ranking code: KEV status is compliance context, not a ranking boost. Being on a list doesn't make a story matter more; being exploited does.
Ranked, then selected.
A composite score weighs confirmed exploitation, source quality, breadth of impact, and recency. Then a fixed selection order: quality gate, duplicate removal, one story per campaign, no single source above 40% of an edition, and topic penalties so one theme can't flood the day. The first story is first because it most warrants your attention.
Published four ways.
Web, email, audio, and MCP for your agent: four interfaces to the same edition. When you've read, listened, or asked, you're current. Finished is finished.
What we don't do
We read public reporting. We don't scan your infrastructure, and the all-clear means nothing in today's briefing affects your stack, never a promise about your network. Editions ship weekday mornings at 7:00; the pipeline keeps reading through weekends, and what it learns lands in Monday's edition.
For your agent
Everything above is one MCP call away: pre-read, pre-ranked, current, scoped to your stack. The alternative is your agent crawling and de-duplicating every morning and still not knowing that twelve articles are one story.