[ system :: pulse ]

Pulse .

A public, free, no-account cybersecurity news aggregator that tells you the state of a thing before you read ten articles about it.

[ topic :: cve-2026-x ] 12 sources · last 2h
Critical RCE in widely-deployed network appliance
KEV LISTED EXPLOIT · WEAPONIZED CVSS 9.1 PATCH · 7.0.5 VENDOR · ACK WORKAROUND · YES
first reported 2026-05-22
last update 2 hours ago

[ 00 / brief ]

If you’re a practitioner, you already know the loop. A CVE drops. You read four articles. One says “actively exploited,” one says “no public exploit yet,” one says “vendor confirms patch,” one says “no comment from vendor.” You’re now responsible for figuring out which is current.

Pulse fixes that. We aggregate cybersecurity news from a wide set of authoritative and editorial sources, cluster every article into a topic — one per CVE, breach, vendor product family, ransomware family, campaign — and surface a structured status overlay at the top of every topic page. Patch availability. KEV listing. Exploit status. Vendor advisory state. All pulled from authoritative sources. So you can see the state of the situation before you start reading.

Pulse is free to read. No account, no signup. It’s a public-good project — the practitioner community deserves a navigable view of the news, and a structured one. That’s the whole point.

[ 01 / what’s covered ]

  1. Topics, not articles — The unit of content is the topic. A topic accumulates updates over time as new coverage appears. Every topic has its own permanent URL. When two clusters turn out to be about the same thing, they merge cleanly and the old URLs still resolve.

  2. The structured status overlay — At the top of every topic page: CVSS score, CISA KEV listing, public exploit status (none / PoC / weaponized / in-the-wild), active exploitation observed, patch availability, workaround availability, vendor advisory status, affected products, first reported date, last meaningful update, coverage breadth across sources, time since the last development. All pulled from authoritative structured sources. No editorial weighting.

  3. What we report, not what we conclude — Pulse summarizes what sources are saying. We don’t add an editorial layer of our own. Attribution claims appear in the article citations, with the source that made them — never as a Pulse top-line statement. We stay out of the lanes where the sources themselves don’t agree.

  4. Bulletins, three cadences — Daily, weekly, and monthly bulletins synthesized from topic activity. The daily is short and action-oriented. The weekly is the week’s significant events. The monthly is bigger-picture trend coverage. One-form opt-in, one-click unsubscribe.

  5. RSS the way RSS is supposed to work — Global feed, per-vendor feeds, per-status feeds (everything new in KEV, everything with active exploitation, etc.). For the people who still build their own workflows.

  6. Search and browse — Search by vendor, product, CVE, breach name, threat-family name. Browse the archive by date. Vendor pages aggregate everything we’ve ever seen about a vendor or product family.

[ 02 / who this is for ]

  • SOC analysts and IR responders triaging “should I care about this in the next hour” and tired of reading the same story four times.
  • CISOs and security leads who want a defensible view of the week’s incidents and exposures without a vendor’s marketing breath on the back of their neck.
  • IT generalists at organizations without a dedicated security team, who need a place to land when “is this thing bad” hits the chat at 9 a.m.
  • Researchers and journalists working a story and wanting the structured-source view alongside the editorial coverage.
  • Anyone who wants to read cybersecurity news without giving up an email address. The site works fully without one.

[ 03 / how it fits ]

  • Pulse links to Intel for the structured threat-intel view. When a topic is about a specific CVE or actor, the topic page cross-references our threat intelligence platform for the deeper structured record. Pulse stays a news surface; Intel stays the data layer.
  • Cortex does the clustering and the summaries. Topic clustering, topic summary generation, and bulletin synthesis all run on operational AI on hardware we own. The “Pulse reports what sources say” principle holds end-to-end: Cortex summarizes coverage, never asserts.
  • No accounts in the public surface. Reading Pulse and subscribing to bulletins don’t route through the identity plane that the rest of the products use. The other products need it; a news reader doesn’t.

[ 04 / where we are ]

Pulse is in testing. The clusterer’s been working through the launch source list — NVD and the CVE feeds, CISA KEV, US-CERT, the major vendor advisories, and the practitioner publications you’d expect — and pulling everything into topic clusters. The public site is what’s next, and it’s close.

If you’d like an early look, or you’ve got a source we ought to be pulling before launch, the address below is the place.

[ ready :: contact ]

Talk to us.

Got a source we should be pulling? Coverage you think we're missing? Want to know when the public site opens? We'd like to hear from you.