Empirical Foundation: The Next Frontier Of Cyber Defense Modelling

Over 100 vendors trust our models today. Open almost any exposure-management platform and EPSS is already inside it. Some examples include:

Microsoft (Defender, plus GitHub Dependabot and the GitHub Advisory Database), Amazon (AWS Inspector), Alphabet/Google (Mandiant, and Wiz), Cisco, ServiceNow, IBM (Concert), Palo Alto Networks (Prisma Cloud and Xpanse), Datadog, Crowdstrike, Elastic, Tanium, SentinelOne, Snyk, Tenable, Qualys, Armis, Axonius, Veracode, Rapid7, Docker, Orca, Aqua Security, NetSPI, SecurityScorecard, Flashpoint, HackerOne, Semgrep, Brinqa, Black Kite, Endor Labs, Cowbell, Nucleus Security.

A full list is available on https://www.first.org/epss/who_is_using/.

The reason is unglamorous but simple. A calibrated exploitation forecast is expensive to build, and EPSS is free and refreshed daily, and lives on FIRST.org for anyone who wants it. “How likely is this to be exploited soon?” is a question CVSS was never built to answer, though people keep pressing it into service anyway. So vendors reach for the model that was built for the job, and customers have come to expect data driven models in exposure management.

We’re incredibly proud of the work our team has done for the security community, most recently in releasing EPSS V5. That said, we have our ears to the ground. Here is the objection we hear most often: Why predict exploitation when some of it is simply observed? If attackers are hitting a vulnerability today, you already know what to do about it. That objection is correct.

Our own telemetry watches more than 18,000 exploited CVEs, and even that understates reality, because "no observed activity" only means we did not see it. Exploitation also decays over time. A vulnerability exploited this week can fall silent for months, then wake up with no warning at all. Foundation therefore refuses to treat prediction and observation as rivals. It folds live exploitation telemetry and EPSS into thousands of other signals, then returns a single calibrated probability. The world’s largest repository of exploitation evidence goes in and a forecast comes out.

A security program that can answer "why are we fixing this one first?" with a probability instead of a shrug is one that can be efficient in reducing measured risk. EPSS is the floor. Because it’s trained on donated data, it ignores real-time exploitation telemetry that Foundation includes with hourly updates. EPSS is free and updated every day, which makes it the obvious first step for any team ready to abandon severity-driven busywork. Foundation is next. It is the same prediction, now fused with real-time internet exploitation telemetry and refreshed hourly for organizations whose exposure justifies more than a baseline, and whose response times are faster than ever. Start with the free forecast. Prioritize what the evidence says is actually coming, and finally be ahead of attackers.

Previous
Previous

Kinda Chic to Prioritize with Proof

Next
Next

August 2026 CVE of the Month: The 7-Zip Bug Every Scorecard Says to Ignore (CVE-2026-58052)