ITSECURITYWHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Alerts

Alerts

One notification, for one thing.

An alert fires when a vulnerability in something you told us you run enters CISA’s Known Exploited Vulnerabilities catalogue. That is a published fact about what is being used against real targets right now, not a prediction, and it is the only thing here worth interrupting somebody for.

It does not fire on a high CVSS score. It does not fire on a high EPSS probability. Those are estimates, and an alert that goes off for an estimate is an alert you turn off.

What we store is the list of products you pick. Not the versions — the version is the half that says whether you are behind, which is the half worth stealing, and we do not need it to tell you that something you run is being exploited. Not your email address, which we never ask for. Not an address you browsed from.

That means the notification cannot tell you whether you are affected, only that you should go and look. It links to the advisory, where the affected range is set out and you can check your own version. This is the same rule as everywhere else here: we will not tell you that you are safe, because we do not know.

Turning it off deletes what we hold, from the same control that turned it on. Your browser also has a switch of its own, and if you use that one instead the subscription stops working and we drop it the next time we try to reach it.

Alerts need JavaScript and a browser that supports Web Push, so the control only appears when both are true. Nothing else on this site needs either.