Data sources and thanks

The live security data on senserva.com, the patch trackers, the exploited-CVE feeds, the per-CVE and per-KB pages, and the daily reads, exists because public institutions, vendors, researchers, and journalists publish their work openly. This page names and thanks every one of them.

Our rule is simple: always quote or attribute, never take without credit. For articles and advisories we use titles, links, and dates only, and send readers to the original. Where we reproduce a data field or a sentence verbatim, it is quoted, attributed, and linked to its source. If you run one of these sources and want a credit changed, added, or removed, write to info@senserva.com and we will fix it.

Vulnerability and patch data

The factual backbone of the trackers and detail pages: what shipped, what is exploited, and how severe it is.

Microsoft Security Response Center (MSRC)

Monthly security release data from the Security Update Guide's public CVRF API: CVEs, KBs, products, and Severity, reproduced as Microsoft publishes them.

Pulled from Microsoft's public programmatic API and always linked back to MSRC.

CISA Known Exploited Vulnerabilities (KEV)

The exploited-in-the-wild signal across the site: KEV listings, due dates, and required actions, quoted verbatim and attributed.

Used under the KEV catalog's free-use license, with attribution to CISA. CISA does not endorse this site.

FIRST.org EPSS

Exploit Prediction Scoring System probabilities, the "how likely is this to be exploited" axis in our rankings.

EPSS scores are provided freely by FIRST.org; we cite EPSS wherever the scores appear.

NIST National Vulnerability Database (NVD)

CVSS scores and vectors for enrichment across the CVE pages and trackers.

This product uses the NVD API but is not endorsed or certified by the NVD.

The CVE Program (MITRE)

The CVE identifiers that everything else keys on.

CVE is a registered mark of The MITRE Corporation; IDs are used per the CVE Terms of Use.

CIRCL Vulnerability-Lookup

Open CVSS and vulnerability metadata from the Computer Incident Response Center Luxembourg, our fallback enrichment path.

Open data, gratefully used with attribution.

OSV.dev

Open-source vulnerability data behind the open-source fixes tracker.

Open API; underlying advisories carry their own open licenses, linked per item.

GitHub Advisory Database

Reviewed open-source security advisories.

Licensed by GitHub under Creative Commons Attribution 4.0.

VulnCheck KEV

Community exploitation intelligence that widens the exploited-CVE picture beyond the CISA catalog.

Used with a VulnCheck community license, with attribution to VulnCheck.

ENISA EU Vulnerability Database (EUVD)

The European Union's vulnerability database, a cross-check and enrichment source.

Public EU service, used with attribution to ENISA.

endoflife.date

End-of-support dates behind the end-of-life tracker.

A community open-source project; data used with thanks and linkback.

Government and regional advisories

The advisory lanes on the regional security pages: headlines, links, and dates only, with every item pointing at the issuing agency.

CISA (United States)

Cybersecurity advisories and alerts for the US federal lane.

US government work, used with attribution. CISA does not endorse this site.

NCSC (United Kingdom)

Guidance and advisories for the UK lane.

Contains public sector information licensed under the Open Government Licence v3.0.

CERT-EU

Security advisories for the EU lane.

Public advisories, used with attribution to CERT-EU.

ACSC (Australia)

Alerts and advisories for the Australia lane, including Essential Eight guidance.

Australian Government material used under Creative Commons Attribution 4.0.

Security press and research

The analyst and press coverage on the Patch Tuesday page, the trackers, and the per-CVE article links. We take RSS titles, links, and dates only, never the article body, and every citation sends the reader to the original. Thank you for the reporting.

Microsoft Security Blog and MSRC Blog

Microsoft's own analysis and release commentary.

Zero Day Initiative

Trend Micro ZDI's Patch Tuesday analysis and advisories.

BleepingComputer

Breaking coverage of patches, exploits, and incidents.

Dark Reading

Security news and analysis.

SANS Internet Storm Center

Daily diaries and Patch Tuesday breakdowns.

Krebs on Security

Investigative security journalism.

Cisco Talos

Threat research and Patch Tuesday coverage.

Tenable

Vulnerability analysis and Patch Tuesday reviews.

Rapid7

Vulnerability research and patch analysis.

CrowdStrike

Threat intelligence and patch commentary.

Qualys

Patch Tuesday and vulnerability research.

Help Net Security

Security news and industry coverage.

The Record

Cybersecurity news from Recorded Future News.

SecurityWeek

Security industry news and analysis.

Rod Trent, Microsoft Security Insights

Microsoft security news and commentary on Substack.

Titles, links, and dates via the public RSS feed; quotes always verbatim, attributed, and linked to Rod's post. Thank you, Rod.

Breach disclosures

The Data Breaches page quotes primary sources verbatim, names and dates only plus each source's own short description, and links every item to the original record.

Have I Been Pwned

Troy Hunt's confirmed-breach catalog: what leaked and how many accounts.

Breach data licensed under Creative Commons Attribution 4.0. Thank you, Troy.

SEC EDGAR

8-K "Material Cybersecurity Incidents" filings: public companies disclosing incidents in their own words.

US government public records, accessed per SEC EDGAR access guidelines.

Community signal

The "what people are talking about" view measures where the security conversation is happening. Counts and links only; the discussion stays where it lives.

Hacker News

Discussion volume on hot CVEs and topics, via the Algolia HN Search API.

Every count links to the thread on news.ycombinator.com.

Stack Exchange

Question activity on security topics, via the public Stack Exchange API.

Stack Exchange content is licensed under CC BY-SA; every item links to the original post.

Google Trends

A best-effort, directional read on search interest.

Directional signal only; we publish no raw Trends data.

Substack

Publishing and reader engagement on security topics: post titles and links only.

Every item links to the author's own publication.

The Senserva EULA in plain language

We hold ourselves to clear terms too. Siemserva by Senserva is licensed under the Senserva End User License Agreement. These are the points users ask about most; the full Agreement is what governs, and this summary does not replace it.

Your data stays local

Siemserva runs on your own devices. Scans, analysis, and report generation happen locally, and your security assessment data is not transmitted to Senserva or any third party. Only anonymized usage statistics (feature usage, error logs, performance metrics) may be collected, never your findings or configurations.

EULA Sections 6 and 10.

Read-only assessment

Siemserva reads security configuration through Microsoft Graph APIs with read-only permissions and makes no modifications to your Microsoft 365 tenant.

EULA Section 5.

Licensed, not sold

Siemserva is licensed for your internal business use (including service delivery to your own customers where permitted). All intellectual property in the product remains with Senserva, LLC.

EULA Sections 1 through 3.

Findings are informational

Security findings and remediation recommendations are provided for informational purposes only. They are not legal, compliance, or security advice, and Siemserva does not guarantee compliance with any framework, regulation, or standard.

EULA Section 11.

Warranty terms by license

Paid Annual Licenses carry a 30-day limited warranty. Complimentary licenses are provided as is.

EULA Section 11.

Third-party components keep their own licenses

Software, content, or data in Siemserva owned by others stays under its own license terms, the same respect this page shows the data sources above.

EULA Section 4.

Our attribution promise

  • We always quote or attribute, and we never take without credit.
  • Articles and advisories appear as titles, links, and dates only; the full story is read at its source.
  • Verbatim text is always quoted, attributed, and linked; required license notices stay on the page.
  • Before we add a source, we check that its terms allow our use; if a source asks us to change or remove a use of its data, we do it. Reach us at info@senserva.com.

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.