CODERED VTA
Advisories on the vulnerabilities and campaigns our analysts are tracking, with the indicators and mitigation your team needs to act the same day.
What we publish
Our analysts write advisories on the vulnerabilities and campaigns they are tracking, drawing on what they see across the estates we monitor and on the intelligence feeds behind the CodeRed platform. Each advisory carries a severity, the CVE where one has been assigned, a CVSS score, the indicators your team can hunt for, and the mitigation we recommend.
We write for the engineer who has to decide before the weekend whether this affects their systems. That means naming affected versions and giving you something to search for, rather than summarising a vendor bulletin you could have read yourself.
How intelligence becomes an advisory
Feeds are ingested daily and mapped into findings, with deduplication and noise filtering applied at the mapping step. A feed record we do not recognise is dropped and logged rather than guessed at, because a guessed mapping is worse than a gap.
Noisy feeds sit behind a review gate. Their findings land in our analyst queue and reach you only after someone has checked them. Trusted feeds release straight to you with an email.
Why you are not drowning in indicators
Two mechanisms keep the signal usable.
We raise a case only when the indicator was reached. A malicious address appearing in a feed is not an event. A malicious address that your environment touched is. Gating case creation on contact rather than on mere presence is what stops reputation data turning into alert fatigue.
Reputation checks fail closed. We query every enabled intelligence source and take the worst verdict. A source that is unknown or unreachable never counts as a confirmation of malice. That matters most in the response layer, where only an independently confirmed indicator may ever be blocked without a human.
Known exploited vulnerabilities
CVEs listed on the known-exploited catalogue are flagged in advisories and weighted heavily in your AEAS score. A vulnerability that attackers are already using is a different class of problem from one that is theoretical, and your prioritisation should reflect that.
Getting them
Advisories are published at provintell.com/advisories and can be filtered by severity. That page also carries the Global Threat View of live cyber-threat activity.
Managed customers get advisories by email as we publish, on the Threat Responder mobile app, and by phone when one affects your estate. You can mute notifications per module, ticket type and severity, though our SOC is always notified regardless of what you have muted.
Where advisories sit in the service
An advisory tells you a threat exists. CodeRed ASM tells you whether you are exposed to it. AI SOC for MXDR watches for it reaching you. The three are meant to be read together, and our analysts work them that way.