Security Guides
Evergreen explainers, maintained and updated over time — the reference layer under the daily news coverage. How to read the numbers, what the catalogs mean, and what to do first.
-
The CISA KEV Catalog, Explained
What the Known Exploited Vulnerabilities catalog is, what its due dates really oblige, and how to use KEV as the sharpest free patching signal available.
3 min read ·
-
Free Threat Intelligence Sources Worth Automating
The free feeds that earn a place in a small team's pipeline — KEV, NVD, EPSS, vendor advisories and curated RSS — and how to combine them without drowning.
3 min read ·
-
How to Read a CVSS Score (and When Not to Trust It)
What CVSS base scores actually measure, how the 0–10 ranges map to severity labels, and why a 9.8 that nobody exploits can matter less than a 7.2 in the KEV.
3 min read ·
-
How We Rate Severity (and Why 'Critical' Is Rare Here)
The exact rules behind RuntimeRebel's five severity levels: what each one requires, why exploitation evidence gates the top ratings, and what the labels can't tell you.
3 min read ·
-
Ransomware Response: The First 24 Hours
A defensive checklist for the first day of a ransomware incident: what to isolate, what to preserve, who to call, and the mistakes that make recovery harder.
3 min read ·