What you can hold us to
Commitments, each enforced by the pipeline rather than by good intentions. A surprising ranking can always be explained by printing the arithmetic behind it — one is printed in full below.
What we keep out
Most of the work here is deciding what you will not see. In a field this saturated with vendor incentive, that matters more than finding things first. Two rules do most of it, and both are hard caps rather than penalties — a sufficiently loud claim can out-shout a penalty, but it cannot pass a cap.
- Vendor-only sourcing cannot lead an issue. A company reporting a threat its own product solves is making a claim, not a finding, until somebody independent repeats it.
- A single low-authority source is capped at one line. One trade outlet, nobody else carrying it, no primary record behind it.
Most weeks more is cut than kept, and the numbers are printed, not claimed: each issue's sidebar carries its own ratio and how many times the caps fired that week.
No model decides what matters
The model writes sentences; the arithmetic sets the rank; a named editor signs the result. A language model's only job here is turning source material into a headline and a paragraph — it never ranks, never decides what is included, and never sets a confidence level. The weights were chosen once, are stated in public, and apply identically to every story.
One score, printed
Issue 01's lead — CISA adding the Cisco FMC hard-coded password to the exploited-vulnerabilities catalog — derived in full, values as computed on 3 August 2026:
signal value weight contribution
authority 0.950 × 0.20 = 0.190 (CISA: highest-authority source)
corroboration 0.387 × 0.24 = 0.093 (1 independent source)
recency 0.288 × 0.06 = 0.017
hard_event 1.000 × 0.14 = 0.140 (confirmed-exploitation language)
exploitation 1.000 × 0.12 = 0.120 (in the KEV catalog)
convergence · storyline · burst = 0.000 (nothing this story)
-----
significance 0.560 → score 56.0
band decision exploitation=active · language=confirmed
· corroboration=1 independent · momentum=baseline
→ read this: active exploitation
confidence confirmed (primary source: CISA)
Why only "read this" at 56? The top band demands corroboration or momentum on top of observed exploitation, and a lone CISA entry on a quiet story has neither. The tree said so, and the page you are reading is the reason it can.
What we will never do
No analytics scripts, no tracking pixels, no fingerprinting — the pages you are reading load nothing from anyone but us, and the content-security policy enforces it. No affiliate links: an outbound link earns us nothing. No list sharing, sale, or rental, ever. Sponsors, when they exist, buy a clearly marked slot and never an item, a score, or a placement.
The one measurement that exists: our delivery provider records whether an email was opened, in aggregate. We see an open rate and nothing else — no per-reader profile, no click tracking, no follow-up. If that ever changes, this page changes first.
Corrections
A publication that grades its own confidence has to be willing to be wrong in public. If something here does not hold up, it will be said plainly in the next issue rather than quietly edited out of the archive. Corrections and tips: james.webb@harmsurface.com.
Who found it first
The bottleneck on this beat has never been discovery — it is distribution. Stories are routinely found by one researcher with a few hundred followers and reported days later by outlets crediting whoever amplified them. Where the record shows who was first, this brief names them, whether or not anyone else did.
The credit is a standing offer. If you published the technical reality of an incident before the trade press carried it, one email — james.webb@harmsurface.com — is enough; the timestamps do the rest. Being first here is checkable, and it stays on the record.
The vocabulary behind the chips — every band and confidence label in an issue links to its definition here.
Severity is about you, not about volume
The band on each item answers "how much should a practitioner care", never "how loud was the coverage". Bands are assigned by a decision tree over computed facts — active exploitation, event language, corroboration, cross-domain convergence, momentum — so every band has a printable reason (see one below); the significance score orders items within a band. On a week when nothing earns the top band, nothing gets it.
Confidence is stated in intelligence language
Severity and confidence are separate axes: something can matter enormously and still be poorly established. Both are always shown, so you never have to guess which you are reading. Every band and confidence chip in an issue links back to this page.
Where an item rests on a single outlet, it says so in the item itself rather than in a footnote.
Read it weekly
What changed, how much to care, and what to do about it.
One email a week. Unsubscribe in one click. No tracking beyond opens.