Methodology

How this was built, and what to distrust

Sourcing

Data was collected across five independent research passes — Patch Tuesday, CVE macro trends, AI-discovery evidence, attacker/exploitation trends, and CWE type shifts — each required to return both the signal and the counter-signal. Every figure traces to a named, dated source. Two independent sources were sought for each annual CVE total.

What we corrected

An early recall-based pass produced anomalous 2026 Patch Tuesday totals (July "621", June "208"). These were re-verified against live Zero Day Initiative, Tenable, and Krebs pages and corrected to 569 and 200 Microsoft CVEs. The "622" figure some outlets ran for July includes third-party and Chromium republished advisories; this site uses Microsoft's own new-CVE count throughout for consistency.

Known limitations

Stance

This site is deliberately neutral. It does not conclude that AI "favors" attackers or defenders. It reports what the disclosure, exploitation, and type data show, separates that from what vendors claim, and marks the questions the data can't answer. The raw data files behind every chart are available on request.