Back to all incidents

Verification Standard & Philosophy

A neutral, high-signal index of security incident statuses and verifiable milestone timelines, powered by open weights correlation and community-driven GitHub PR editing.

1. Neutral Intelligence Through Open Curation

Modern security incident reporting is plagued by corporate PR ambiguity, premature categorization, and recycled claims. We provide a reliable and neutral source of cybersecurity intelligence by curating security data across its entire lifecycle, ranging from early dark web rumors to formal regulatory disclosures.

To deliver maximum clarity, we establish clear levels of confidence and correlate diverse data sources using open weights. Built entirely on open editing through GitHub pull requests, securityincident.net empowers security professionals, researchers, and organizations to maintain a transparent, verifiable, and high-signal record of security incidents without corporate bias or editorial filler.

2. Granular Open Weights Correlation Model (v2.0)

Unlike opaque black-box AI scores or proprietary vendor risk ratings, our confidence scoring is 100% deterministic, auditable, and open-source. Defined in sources/weights.json and executed in scripts/weights.js, confidence is evaluated continuously across four orthogonal dimensions rather than clumping into coarse tiers:

Verification Tier Primary Authority Baseline Primary Sources
CONFIRMED BY REGULATOR 0.65 (65%) SEC Form 8-K Item 1.05, State AG breach portals, HHS OCR, CISA KEV advisory.
CONFIRMED BY TARGET 0.50 (50%) Official corporate press release, company security blog, direct target status bulletin.
INDEPENDENT VERIFICATION 0.32 (32%) Reputable cybersecurity researcher analysis, HaveIBeenPwned audit, forensic investigative reporting.
ACKNOWLEDGED 0.18 (18%) Target publicly confirms operational disruption or active investigation without confirming data compromise.
UNVERIFIED CLAIM 0.06 (6%) Threat actor leak blog, dark web forum listing, unverified community chatter (low baseline floor).
REFUTED 0.00 (0%) Proven false alarm, recycled historical data, or web scrape mislabeled as a breach.

Multi-Dimensional Scoring Dimensions:

  • 1. Primary Authority Base: 6% baseline for raw unverified claims up to 65% for statutory regulatory disclosures.
  • 2. Evidence Specificity & Data Quality (+0% to +23%): Statutory regulatory filings (+12%), verified primary domain (+3%), disclosed compromised data classes (+4%), and quantified affected records (+4%).
  • 3. Corroboration & Multi-Source Curve (+0% to +25%): Logarithmic curve for independent source domains (2 domains: +7%, 3 domains: +12%, 4 domains: +16%, 5+ domains: +20%), plus a +5% cross-tier correlation boost when threat telemetry is corroborated by target or regulatory disclosure.
  • 4. Temporal Dynamics & Unverified Staleness Decay (-10% to +5%): Milestone timeline depth (+3% for ≥3 milestones, +5% for ≥5 milestones). Dormant uncorroborated darkweb claims decay over time (-3% at 14 days, -5% at 30 days) to prevent adversary bluffs from retaining confidence.

3. The 5 Observable Statuses

CONFIRMED

Highest assurance: Officially verified by the target or government regulator (e.g. SEC Form 8-K Item 1.05, State AG breach portals, formal press releases).

ACKNOWLEDGED

Target publicly confirms an "IT disruption" or active investigation, but has not yet confirmed a breach or data loss.

DEVELOPING

Corroborated intelligence: independent researchers verify samples or observable outages align with claims before target response.

EMERGING

Early threat actor claims, dark web forum leaks, or unverified community chatter before target comment.

REFUTED

Proven false alarm, recycled historical leak, or public web scrape mislabeled as a breach.

4. 100% Git-Native & Transparent

Every incident is stored as an open Markdown document in our GitHub repository. We use GitHub Actions to automate indexing from regulatory RSS and infosec feeds, with zero complex databases. Anyone can audit our sources, examine historical revisions in Git, or submit updates via Pull Request.

5. How to Contribute via GitHub PR

Because all incidents are stored as flat Markdown files in Git, you don't need special permissions or database access to contribute. You can propose updates in two easy ways:

For detailed schema requirements and verification standards, read our Contributing Guidelines on GitHub.