How it works
How The Zero Day collects security news, groups stories across outlets, links them to CVEs, scores patch priority, detects spikes and checks its briefings.
Collecting
Each source's feed is read every 15 minutes; promotional posts are skipped.
Grouping stories
Articles within 5 days of each other join a story when their text is similar, they share a CVE, or they share a rare name.
Threat types
Keyword rules give each article one of 12 threat types.
Linking news to CVEs
Headlines, excerpts and article bodies are scanned for CVE IDs.
Vulnerability data
NVD every 30 minutes; CISA KEV; FIRST EPSS and Exploit-DB and Metasploit every 6 hours; government advisory counts; fix status from references.
Patch priority
0 to 100: severity up to 35, exploitation up to 40, agency advisories up to 15 and news coverage up to 10. Act now at 70, High at 50, Medium at 30.
Spike alerts
Each UTC day is compared with the 28 days before it.
Briefings
A language model writes from the stored headlines and summaries; every sentence is checked mechanically and by a second model call, and failing sentences are removed. Today so far covers the current UTC day up to the last full hour and is rewritten each hour.