Vulnerability Intelligence
Vulnerability intelligence from the cybercrime underground: know which CVEs criminals are discussing, weaponising and selling, mapped to the CVE IDs you track, often days before EPSS or KEV catch up.
The formal vulnerability stack is correct, and incomplete
CVE names a vulnerability. CVSS scores its theoretical severity. EPSS models the probability of exploitation from public signals. KEV confirms exploitation after it has been observed in the wild. Each does its job. None of them watches the criminal forums, closed channels and markets where exploits are built, tested, shared and sold. The gap between those two information layers is where attacks begin, and it is measurable.
Where the gap opens
When a CVE with full technical detail lands on the NVD, the description is a roadmap. A capable actor can diff the patched and unpatched code and work back to a working exploit in days, and AI-assisted analysis has made that faster. EPSS will not see it, because a forum post behind a criminal login is not in its training data. KEV will not list it until an incident is detected, confirmed and reported. For a tool running on developer laptops with no authentication logging, that chain breaks quietly.
Real-world example
CVE-2026-27825: from patch to criminal exploit
Two critical vulnerabilities in mcp-atlassian, the most widely deployed open-source MCP server for Jira and Confluence, scored CVSS 9.1 and 8.2. This is what the formal stack saw, and what KELA saw, on the same calendar.
- 24 February 2026. Version 0.17.0 ships the fix. CVE-2026-27825 (CVSS 9.1) and CVE-2026-27826 (CVSS 8.2) are issued.
- 26 February 2026. Pluto Security publishes the MCPwnfluence analysis. No active exploitation observed.
- 10 March 2026. Both CVEs are published on the NVD. The vulnerabilities are now public knowledge.
- 16 March 2026. KELA analysts identify a full exploitation writeup with a working proof of concept on XSS.PRO, a long-running Russian-language criminal forum, distributed through its .onion address.
- 9 September 2026. CVE-2026-27825 is still not in CISA’s KEV catalog. EPSS rates it 2.3%, Low.
Twenty days from patch to criminal exploit. Six days from public CVE to the same point. Every formal measure said low urgency and no confirmed use while a weaponised exploit was already in criminal hands.
How KELA closes the gap
KELA tracks the sequence from disclosure to weaponisation systematically, across the sources the formal stack cannot reach, and hands it to your vulnerability programme as evidence, not as another score.
Collection where exploits are built
Hacking forums including XSS.PRO, dark net communities, instant messaging channels and criminal platforms where exploitation tooling is developed, tested, shared and sold.
Mapped to the CVE IDs you already track
Discussion, tooling and proof-of-concept activity is tied to CVE identifiers, with the source, the date and how fast the gap is closing, so it drops into the process you run today.
Evidence that changes the patch order
A working exploit on a criminal forum moves a Low-EPSS, no-KEV vulnerability to the top of the queue. Alerts, API and integrations carry that finding to the people who patch.
Your infrastructure, seen the way attackers see it
Exploiting a public-facing application is now the leading way into an organisation: 40% of initial access in IBM X-Force’s 2025 data, up from 30% the year before. The exposure is yours, but the choice of which vulnerability to weaponise is theirs. KELA discovers the internet-facing assets you actually run, maps their software to the CVEs criminals are discussing and trading, and shows you where the two overlap: the infrastructure at risk right now, not the longest list of CVSS scores.
Source: IBM X-Force Threat Intelligence Index 2025, initial access vectors, 2025 versus 2024.
One place for every CVE
Search a CVE or a product and get the public record and the underground record side by side.
Search by CVE or product
Find a CVE ID or everything affecting an application, and filter the dashboard by severity, application and trend.
Scores side by side
The NIST summary, the static CVSS score and the predictive EPSS score, with KEV’s exploited and in-the-wild flags.
Mitigation steps
CISA’s remediation guidance and the official timeline, so the fix travels with the finding.
CWE to MITRE ATT&CK
Each weakness mapped to the techniques it enables, for detection and threat-hunting teams.
Book a Demo
Prefer to schedule a meeting right now? Click here.
Related Resources

Webinar
The TeamPCP arrests, from the inside
How KELA identified the operators behind TeamPCP and supported law enforcement, from the March supply chain cascade through…

Report
TeamPCP Threat Actor Profile
How KELA identified the man who led TeamPCP and handed law enforcement the identifier chain behind the arrest,…

Press Release
KELA research leads to alleged TeamPCP Members Arrested
KELA's Cyber Intelligence Center published the findings it shared with the AFP, WAPF and FBI in March and…
FAQ
What is vulnerability intelligence?
Vulnerability intelligence tells you which vulnerabilities attackers are actually working on, not only how severe they could be. KELA’s version comes from the cybercrime underground: the forums, channels and markets where exploits are discussed, built and sold, mapped to CVE identifiers and delivered into your vulnerability management process.
How is it different from CVSS, EPSS and KEV?
CVSS scores theoretical severity. EPSS models exploitation probability from public signals. KEV lists vulnerabilities after exploitation is confirmed in the wild. KELA watches the criminal sources none of them can see and reports activity while the gap is still open. For CVE-2026-27825 that meant a working proof of concept six days after NVD publication, with EPSS at 2.3% and no KEV entry.
Does this replace my vulnerability scanner or EPSS?
No. Scanners tell you what you run and the formal stack tells you what is severe and what is confirmed. KELA adds the missing layer: what criminals are doing right now, so the patch order reflects real activity instead of scores alone.
Does KELA show which of my assets are affected?
Yes. KELA’s exposure management discovers your internet-facing assets from a domain, with no agents, and maps the software they run to the CVEs criminals are targeting. The result is the short list of infrastructure at risk now, rather than every CVE with a high CVSS score.
How does the intelligence reach my team?
As alerts tied to CVE IDs, through the KELA platform, the API and integrations with SIEM, SOAR and ticketing tools. No agents or sensors are required.


