ITSECURITYWHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Editorial standards

Editorial standards

How pieces are written and checked.

Three kinds of thing appear here: reporting from other outlets, carried as a headline and a link; advisory records, which come from vendors and agencies and carry their identifiers and dates; and pieces written here under our own byline.

Some pieces are written with machine assistance under editorial direction. Where that is so the piece carries our byline and our responsibility, and every rule below applies to it identically.

A CVE identifier is only published if it is on the advisory record the piece was written from. A CVSS score is only published if it matches the vector — the two are arithmetic, so a disagreement means one was invented.

An upgrade instruction always names the vendor advisory it came from. A version number from anywhere else is a rumour.

An attribution always names the researcher, vendor or agency that made it. Attribution is contested even when it is right.

Anything describing active exploitation, a breach, an attribution or exploit material is read by a person before it publishes.