Skip to content
pwnsy
← pwnsy/blog

threat-intel

16 articles

Cybersecurity guides, tutorials, and insights about threat intel from Pwnsy.

beginner/17 min readJul 24, 2026

The Bug Bounty Economy: Platforms, Triage & Payouts

How the bug bounty economy works: platforms, triage and payouts, VDPs versus paid programs, researcher incentives, and what bounties do and do not cover.

beginner/16 min readJul 24, 2026

Coordinated Vulnerability Disclosure: From Finding to Fix

How responsible disclosure works: researcher to vendor to patch to publication, disclosure timelines, embargoes, and the full-disclosure debate.

beginner/16 min readJul 24, 2026

CVSS Explained: How Vulnerability Scoring Actually Works

A plain, complete guide to CVSS: what base, temporal and environmental metrics measure, how the 0-to-10 score is built, v3.1 vs v4.0, and its limits.

beginner/16 min readJul 24, 2026

Cybercrime-as-a-Service Explained: The Criminal Gig Economy

How the cybercrime-as-a-service economy works: RaaS, phishing kits, malware, access brokers, and bulletproof hosting, and why it lowered the skill bar.

beginner/16 min readJul 24, 2026

Dark Web Markets: How Criminal Marketplaces Work

A defensive guide to dark web markets: Tor hidden services, what gets traded, escrow and reputation, and why markets get seized and rebrand.

beginner/16 min readJul 24, 2026

EPSS Explained: Scoring How Likely a Vuln Is to Be Exploited

EPSS predicts the chance a CVE is exploited within 30 days. How the model works, reading the score and percentile, and pairing it with CVSS and KEV.

beginner/16 min readJul 24, 2026

Hacktivism Explained: When Hacking Is Driven by a Cause

Hacktivism is cause-driven hacking. Its common tactics, how it differs from criminal and state activity, and how to defend against it.

intermediate/16 min readJul 24, 2026

Initial Access Brokers: The Middlemen of Ransomware

Who initial access brokers are, the footholds they sell, how they get in through stealer logs and exposed RDP and VPN, and how they feed ransomware crews.

intermediate/16 min readJul 24, 2026

Insider Threats: Malicious, Negligent & Compromised

How insider threats work: the three insider types, warning indicators, the role of access and privilege, and how to build a prevention program.

beginner/16 min readJul 24, 2026

The KEV Catalog: CISA's List of Actively Exploited Bugs

What the CISA Known Exploited Vulnerabilities catalog is, how a CVE gets added, federal remediation deadlines, and why it means patch now.

intermediate/17 min readJul 24, 2026

The MITRE ATT&CK Framework: Tactics, Techniques & Coverage

What MITRE ATT&CK is: tactics vs techniques vs sub-techniques, the Enterprise, Mobile and ICS matrices, groups and software, and coverage mapping.

beginner/16 min readJul 24, 2026

MITRE ATT&CK Tactics: The 14 Enterprise Tactics in Order

A one-line reference to the 14 MITRE ATT&CK Enterprise tactics in order: tactic name, tactic ID, the attacker's goal, and one example technique for each.

intermediate/16 min readJul 24, 2026

Nation-State Hacking: State-Sponsored Cyber Operations

How state-sponsored cyber operations work: their goals, typical targets, the main sponsoring regions, and why they operate differently from criminals.

beginner/16 min readJul 24, 2026

The CVE System: How Vulnerabilities Get Their Names

How the CVE program works: CNAs, how an ID is reserved and assigned, the record lifecycle, and how CVE differs from the NVD that enriches it.

intermediate/16 min readJul 24, 2026

The Exploit Market: Bounties, Brokers & Zero-Day Trade

How the market for exploits works: bug bounties versus brokers versus the black market, what drives zero-day prices, and the ethics and policy debate.

intermediate/16 min readJul 24, 2026

What Is an APT? Advanced Persistent Threats Explained

What an Advanced Persistent Threat is: the three words decoded, how APTs differ from crime, the intrusion lifecycle, attribution, and naming schemes.