Skip to main content

Cybersecurity Weather

Global observatory

Methodology

Version CW-1.0 · Daily public observatory

What Cyber Weather Index is

The Cyber Weather Index (0–100) is a composite measure of publicly observable cybersecurity activity from authoritative feeds. It is updated daily after ingestion, not in real time.

It is not a probability of attack, breach, or organisational risk. It describes observable signal pressure from public data.

Severity bands

  • 019 CALM Limited observable pressure across monitored public signals.
  • 2039 QUIET Some notable vulnerabilities or malicious activity are present, but overall pressure is low.
  • 4059 ACTIVE Observable cybersecurity activity is present across one or more monitored signals.
  • 6074 ELEVATED Cybersecurity pressure is above normal across one or more signal categories.
  • 7589 SEVERE Multiple significant observable cyber signals are active.
  • 90100 EXTREME Exceptional levels of observable vulnerability or malicious activity pressure.

Categories and weights

  • Exploitation — weight 0.3
  • Vulnerability Pressure — weight 0.25
  • Ransomware — weight 0.2
  • Malware — weight 0.15
  • Identity Attacks — weight 0
  • Cloud Activity — weight 0.1
  • Supply Chain — weight 0
  • Breach Activity — weight 0

Data sources

  • cisa-kev — feeds exploitation, ransomware
  • nvd — feeds vulnerability pressure
  • epss — feeds vulnerability pressure
  • urlhaus — feeds malware
  • msrc — feeds cloud activity, vulnerability pressure

Collection schedule

Sources are collected once daily around 4:00 AM Australia/Sydney via an automated pipeline. Freshness allows a grace period after the scheduled run before marking data stale.

Geographic methodology

The global map shows observable signals associated with infrastructure or source-reported geography where defensible country-level data exists — primarily malware infrastructure from URLhaus host/IP inference.

Vulnerability, exploitation, EPSS, and most vendor advisories do not provide victim or attacker geography. The map does not display geographic data for those categories unless an individual event record includes defensible location metadata.

Geography never implies attacker origin, victim location, or attack attribution unless a source explicitly establishes that (currently not used for attribution on this site).

Coverage by category

  • Exploitationstrong: CISA Known Exploited Vulnerabilities catalogue
  • Vulnerability Pressurestrong: NVD, EPSS, and vendor advisories
  • Malwarestrong: URLhaus malware infrastructure observations
  • Ransomwarelimited: Derived from KEV ransomware flags and URLhaus tags; no dedicated ransomware feed
  • Cloud Activitydeveloping: Microsoft security updates and cloud-related advisories
  • Identity Attackslimited: No dedicated public feed in CW-1.0
  • Supply Chainlimited: No dedicated public feed in CW-1.0
  • Breach Activitylimited: No dedicated public feed in CW-1.0

Confidence

Data confidence reflects completeness and freshness of monitored sources — not statistical certainty that attacks will occur. Lower confidence is explained when sources are stale, degraded, or never collected.

Recency and deduplication

Recent activity contributes more than older activity. Multiple reports of the same underlying CVE or URL are deduplicated through deterministic event identity before scoring.

Limitations

This observatory cannot see private incidents, all global cyber activity, or future attacks. Ransomware coverage is limited to indirect public signals. Cloud activity coverage is developing. Identity, supply chain, and breach categories lack dedicated feeds in CW-1.0.