DugganUSA Threat Intelligence

KEV-Lead Ledger

For every CISA Known Exploited Vulnerabilities catalog addition in the recent window, this page shows the earliest DugganUSA receipt that named the CVE or its operator constellation. The federal regulator is the validation baseline. We are the early-warning layer that lands ahead of it. See pricing →

Mean lead (days)
Median lead (days)
Max lead (days)
Positive-lead receipts
CVE / CampaignKEV addOur receiptLead
Loading ledger…

Methodology

For each CISA KEV addition, we search the DugganUSA blog and IOC indexes for receipts that explicitly name the CVE, the campaign codename, or the affected vendor/product. We credit the earliest qualifying receipt (max positive lead). Negative leads — cases where the KEV add preceded our coverage — are recorded for full honesty but excluded from the headline averages.

The architecture that produces the lead time has six load-bearing components: per-IOC BDE scoring, the 6-hour exploit-harvester cron, Pattern 38–54 supply-chain detectors, the PreCog signal layer (Sandtrout / decentralized C2 / Trycloudflare velocity), OTX pulse ingest, and same-day publish posture. Full deep-dive →