The Precursor Brief is a free weekly threat intelligence newsletter from Precursor Intelligence, delivered every Friday morning. Each edition is written from live platform data and covers new CISA KEV additions, the week's biggest EPSS movers, exploitation surges seen in honeypot telemetry, supply-chain package hijacks, trending malware families and fresh C2 indicators, in a read of about five minutes. Subscribers also receive early-warning alerts between editions when a critical threat breaks mid-week.
The Week's Threat Landscape,
Decoded in Five Minutes.
A weekly threat intelligence roundup written from the live data inside our platform. New KEV entries, the biggest exploit-probability movers, what honeypots are catching, supply-chain hijacks and trending malware, every Friday morning. And when something critical breaks mid-week, you get an early warning instead of waiting for the edition.
What Lands in Your Inbox Every Friday
Up to ten data-driven sections, each written from the platform's live feeds. When a section has nothing worth your time that week, we drop it rather than pad it. And when something critical can't wait for Friday, you get an alert the day it breaks.
KEV watch
Every CVE CISA adds to the Known Exploited Vulnerabilities catalogue that week, with severity and the action to take.
Biggest movers
The week's largest EPSS jumps. Exploit probability rising fast is the warning you want before the headlines, not after.
Surging in the wild
CVEs running far above their own 30-day honeypot baseline. Exploitation spikes, caught as they happen.
The KEV gap
Vulnerabilities being exploited at scale that haven't made the KEV catalogue yet. Your earliest warning, weeks ahead of the list.
Supply-chain spotlight
Package hijacks and malicious releases across npm, PyPI and beyond, with the affected packages and versions named.
Malware trending
The families moving up the charts and the week's fresh C2 indicators, so your blocklists stay ahead of the campaigns.
Scanning radar
What attackers are probing the internet for right now, drawn from global honeypot telemetry. Reconnaissance is the tell.
The Precursor take
The editorial close: what mattered this week, why it mattered, and what belongs on Monday morning's list.
Built From Live Data, Not Recycled Headlines
The Brief is written from the same pipeline that powers the Precursor Intelligence platform: NVD publications, CISA KEV, EPSS scoring, honeypot telemetry, C2 trackers and malware sandboxes, aggregated and read for you every week.
Figures from a recent edition. Every Brief is rebuilt from that week's live data.
Why Readers Actually Open It
Early warning, not a recap
Sections like the KEV gap and biggest movers surface what's about to matter: exploitation visible in honeypots before it reaches an official catalogue or a news cycle. And when a threat breaks mid-week, an alert goes out the same day rather than waiting for the next edition.
Written for technical readers
Real CVE IDs, EPSS deltas, honeypot connection counts and a clear action line on every item. Forward it to your engineers without translating it first.
Five minutes, start to finish
Ten sections is the ceiling, not the target. A quiet week gets a shorter Brief, never filler. Your time is the budget we optimise for.
Friday morning, fully briefed.
The KEV additions, exploit surges and package hijacks that matter, every Friday. Plus an alert the moment something critical breaks.
Questions, Answered
The Brief lands every Friday morning, UK time. Between editions, you'll only hear from us when something genuinely can't wait: a vulnerability under active mass exploitation or a supply-chain compromise in something you probably run. Never product announcements dressed up as intelligence.
The Brief every Friday.
An alert when it can't wait.
Join the Friday Brief and get the week's KEV additions, exploit surges, supply-chain hijacks and malware trends, with an early warning in between whenever a critical threat breaks.
Unsubscribe in one click, in any edition.