This media is not supported in your browser
VIEW IN TELEGRAM
Another bleeding-edge version of VEDAS is out now ๐๐ฅณ
Many network-exploitable vulnerabilities, such as CVE-2025-47188, remains delayed, poorly documented and lack meaningful enrichment. Despite being actively exploited since May 2025, this vulnerability is still not enriched by NVD, EPSS or proprietary vulnerability databases.
VEDAS can be used for Mining Exploit Intelligence linked to vulnerability identifiers like CVE, EUVD, CNNVD, and BDU and can be helpful in developing custom Nuclei templates and extending its coverage, supporting the growing community of security teams, researchers, and ASM providers.
Read More: https://www.osintteam.com/mining-exploit-intelligence-to-develop-custom-nuclei-templates-for-cve-euvd-cnnvd-bdu/
Many network-exploitable vulnerabilities, such as CVE-2025-47188, remains delayed, poorly documented and lack meaningful enrichment. Despite being actively exploited since May 2025, this vulnerability is still not enriched by NVD, EPSS or proprietary vulnerability databases.
VEDAS can be used for Mining Exploit Intelligence linked to vulnerability identifiers like CVE, EUVD, CNNVD, and BDU and can be helpful in developing custom Nuclei templates and extending its coverage, supporting the growing community of security teams, researchers, and ASM providers.
Read More: https://www.osintteam.com/mining-exploit-intelligence-to-develop-custom-nuclei-templates-for-cve-euvd-cnnvd-bdu/
On 9th August 2018, the concept of Exploit/Exploitation Prediction was first introduced at BlackHat, followed by the publication of its first paper on 30th August 2019. EPSS initially prioritized mass exploitation indicators over concrete exploit evidence. While recent updates have added exploit data, these rely on only a handful of sources, resulting in narrow coverage, a lot of false negatives, and delayed recognition of active threats.
Moreover, EPSS and similar systems still lack the ability to fully interpret exploit intelligence. They cannot reliably or autonomously map exploits to CVEs with sufficient accuracy, which limits their real-world effectiveness. VEDAS provides a far more reliable alternative to EPSS. Unlike EPSS, VEDAS does not attempt to predict future exploitation; instead, it estimates the prevalence of a vulnerability identifier and the maturity of its associated exploits.
It has now been five years since the idea of using a score to โpredictโ or โestimateโ the likelihood of CVE exploitation within the next 30 days was proposedโthough. Till this date, there is no evidence explaining how or why this 30-day timeframe was chosen or supporting if these prediction, that is just based on mass exploitation and public exploits, can actually be validated by the cybersecurity community as factor that can predict exploitation before mass exploitation trend or exploits appear. Hence, from the outset, we have consistently cautioned against this predictive narrative.
Register for our upcoming webinar to learn more:
https://webinar.arpsyndicate.io
Moreover, EPSS and similar systems still lack the ability to fully interpret exploit intelligence. They cannot reliably or autonomously map exploits to CVEs with sufficient accuracy, which limits their real-world effectiveness. VEDAS provides a far more reliable alternative to EPSS. Unlike EPSS, VEDAS does not attempt to predict future exploitation; instead, it estimates the prevalence of a vulnerability identifier and the maturity of its associated exploits.
It has now been five years since the idea of using a score to โpredictโ or โestimateโ the likelihood of CVE exploitation within the next 30 days was proposedโthough. Till this date, there is no evidence explaining how or why this 30-day timeframe was chosen or supporting if these prediction, that is just based on mass exploitation and public exploits, can actually be validated by the cybersecurity community as factor that can predict exploitation before mass exploitation trend or exploits appear. Hence, from the outset, we have consistently cautioned against this predictive narrative.
Register for our upcoming webinar to learn more:
https://webinar.arpsyndicate.io
โค3
Anthropic reported that in mid-September 2025 a Chinese state-sponsored group ran a large espionage campaign using AI agents to carry out most of the work. About 30 organizations in tech, finance, manufacturing and government were targeted. The attackers used their AI system with Claude Code to handle reconnaissance, vulnerability finding, credential harvesting, back-door setup, data theft and record keeping, while humans stepped in only a few times per operation.
https://www.anthropic.com/news/disrupting-AI-espionage
https://www.anthropic.com/news/disrupting-AI-espionage
Eugenio Benincasa writes that in Chinaโs case, many government disclosures by the U.S. and other Western countries have pointed to APT groups and individual operators allegedly linked to provincial bureaus of the Ministry of State Security (MSS), Chinaโs premier civilian intelligence agency. These bureaus function as the operational nerve centres of Chinaโs cyber apparatus. The MSS is not a monolith: it is highly provincialized, with bureaus that cultivate their own bureaucratic interests, talent pipelines, and trusted ecosystems of companies and individual professionals and researchers.
https://nattothoughts.substack.com/p/the-many-arms-of-the-mss-why-provincial
https://nattothoughts.substack.com/p/the-many-arms-of-the-mss-why-provincial
Nattothoughts
The Many Arms of the MSS: Why Provincial Bureaus Matter in Chinaโs Cyber Operations
Provincial bureaus of the Chinese Ministry of State Security likely operate with their own tasking priorities, resources, and local ecosystems for cyber operations
vedas-webinar.pdf
8 MB
Vulnerability prioritization frameworks such as KEV and EPSS are fundamentally limited because they rely on mass exploitation telemetry and sensor-networkโdriven signals that act as lagging indicators and miss emerging, high-impact threats. These systems overemphasize low-effort, automated exploitation activity, lack full-spectrum exploit intelligence, and are unable to reliably interpret exploit artifacts or autonomously map them to CVE, resulting in false negatives and delayed response.
In contrast, ARPSyndicateโs Vulnerability & Exploit Data Aggregation System (VEDAS) (https://vedas.arpsyndicate.io) is an early-warning standard that crawls, comprehends, and clusters real-world exploit artifacts globally, assigns its own identifiers to exploitable vulnerabilities, and prioritizes exploit maturity and discovery over noisy mass-exploitation metrics. This approach enabled VEDAS to consistently outperform EPSS and KEV throughout 2025 by surfacing actionable threats before they appeared on conventional radars.
In contrast, ARPSyndicateโs Vulnerability & Exploit Data Aggregation System (VEDAS) (https://vedas.arpsyndicate.io) is an early-warning standard that crawls, comprehends, and clusters real-world exploit artifacts globally, assigns its own identifiers to exploitable vulnerabilities, and prioritizes exploit maturity and discovery over noisy mass-exploitation metrics. This approach enabled VEDAS to consistently outperform EPSS and KEV throughout 2025 by surfacing actionable threats before they appeared on conventional radars.
Today, we introduce the VEDAS-driven autonomous generation of Suricata rules for CVEs on GitHub.
This repository is intended to function as an open, collaborative validation environment for Suricata rules autonomously produced by ARPSyndicateโs Vulnerability & Exploit Data Aggregation System (VEDAS). While VEDAS is often associated with offensive research, its capabilities extend strongly into defensive security as well.
Although AI enables the rapid, large-scale generation of detection rules from vulnerability and exploit intelligence, effective security detection depends on transparency, human oversight, and validation in real-world conditions.
By releasing these AI-generated rules openly, we aim to empower the security community to review, test, and refine detection logic through issues and pull requests.
Our objective is to combine AI-driven automation with open-source collaboration to enhance reliability and accelerate intelligence-led detection engineering for everyone.
https://github.com/ARPSyndicate/suricata-vedas
This repository is intended to function as an open, collaborative validation environment for Suricata rules autonomously produced by ARPSyndicateโs Vulnerability & Exploit Data Aggregation System (VEDAS). While VEDAS is often associated with offensive research, its capabilities extend strongly into defensive security as well.
Although AI enables the rapid, large-scale generation of detection rules from vulnerability and exploit intelligence, effective security detection depends on transparency, human oversight, and validation in real-world conditions.
By releasing these AI-generated rules openly, we aim to empower the security community to review, test, and refine detection logic through issues and pull requests.
Our objective is to combine AI-driven automation with open-source collaboration to enhance reliability and accelerate intelligence-led detection engineering for everyone.
https://github.com/ARPSyndicate/suricata-vedas
GitHub
GitHub - ARPSyndicate/suricata-vedas: VEDAS-Driven Autonomous Generation of Suricata Rules for CVEs
VEDAS-Driven Autonomous Generation of Suricata Rules for CVEs - ARPSyndicate/suricata-vedas
โค1
DomainTools Investigation reveals that tools like ZoomEye and the Critical Infrastructure Target Library give China a global reconnaissance system that catalogs millions of foreign IPs, domains, and organizations mapped by sector, geography, and strategic value. Massive datasets containing real names, ID numbers, mobile phones, emails, and credentials allow Knownsec and its government clients to correlate infrastructure with people, enabling rapid deanonymization, targeting, and social engineering.
https://dti.domaintools.com/the-knownsec-leak-yet-another-leak-of-chinas-contractor-driven-cyber-espionage-ecosystem/
https://dti.domaintools.com/the-knownsec-leak-yet-another-leak-of-chinas-contractor-driven-cyber-espionage-ecosystem/
Domaintools
DomainTools Investigations | THE KNOWNSEC LEAK: Yet Another Leak of Chinaโs Contractor-Driven Cyber-Espionage Ecosystem
Leaked Knownsec documents reveal Chinaโs cyberespionage ecosystem. Analyze TargetDB, GhostX, and 404 Labโs role in global reconnaissance and critical infrastructure targeting.
ARPSyndicate is proud to support CSAIโs Cyber Security Centre for Research & Innovations (C3IR) in this initiative.
As part of our involvement with C3IR, we are actively hiring interns for this Offensive Security Research Internship. If you are passionate about CVE analysis, vulnerability research, reverse engineering, embedded security, or low-level software analysis, applications are welcome.
All details are in the link below.
https://www.linkedin.com/posts/nkgoyals_cybersecurity-internship-cybersecurityinternship-share-7469639258463473664-MoiW
As part of our involvement with C3IR, we are actively hiring interns for this Offensive Security Research Internship. If you are passionate about CVE analysis, vulnerability research, reverse engineering, embedded security, or low-level software analysis, applications are welcome.
All details are in the link below.
https://www.linkedin.com/posts/nkgoyals_cybersecurity-internship-cybersecurityinternship-share-7469639258463473664-MoiW
LinkedIn
#cybersecurity #internship #cybersecurityinternship #vulnerabilityresearch #reverseengineering #embeddedsecurity #exploitdevelopmentโฆ
๐ ๐๐๐ข๐ ๐๐๐ฆ๐จ๐ญ๐ ๐๐ฒ๐๐๐ซ ๐๐๐๐ฎ๐ซ๐ข๐ญ๐ฒ ๐๐๐ฌ๐๐๐ซ๐๐ก ๐๐ง๐ญ๐๐ซ๐ง๐ฌ๐ก๐ข๐ฉ - ๐๐ฉ๐ฉ๐ฅ๐ข๐๐๐ญ๐ข๐จ๐ง๐ฌ ๐๐ฉ๐๐ง!
Ready to work on real-world cybersecurity challenges and gain hands-on experience in vulnerability research, reverse engineering, embedded security, and exploit development?
๐ CSAIโsโฆ
Ready to work on real-world cybersecurity challenges and gain hands-on experience in vulnerability research, reverse engineering, embedded security, and exploit development?
๐ CSAIโsโฆ
๐ง๐ต๐ฒ ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ ๐๐ผ ๐ป๐ฎ๐๐ถ๐ด๐ฎ๐๐ฒ ๐๐ป๐ฐ๐ฒ๐ฟ๐๐ฎ๐ถ๐ป๐๐ ๐ถ๐ ๐ถ๐ป ๐ผ๐๐ฟ ๐ด๐ฒ๐ป๐ฒ๐. ๐๐ป๐ฑ ๐๐ผ ๐ถ๐ ๐๐ต๐ฒ ๐๐ถ๐น๐น ๐๐ผ ๐๐ฒ๐ฐ๐๐ฟ๐ฒ ๐๐ต๐ฎ๐ ๐๐ฒ'๐๐ฒ ๐ฏ๐๐ถ๐น๐.
Industry. Academia. Defence. One resilient unit. This week's National Conference on Telecom Security in the Era of AI & Quantum Computing, convened by Cyber Security Association of India, brought together some of India's most consequential voices in national security including Mr. Narendra Nath Gangavarapu (Joint Secretary, NSCS), Lt. Gen (Dr.) Rajesh Pant (Former National Cyber Security Coordinator), and Lt. Gen. Vivek Dogra (Signal Officer-in-Chief) shaped a conversation that went far beyond policy.
๐ง๐ต๐ฒ ๐๐ต๐ฟ๐ฒ๐ฎ๐ ๐น๐ฎ๐ป๐ฑ๐๐ฐ๐ฎ๐ฝ๐ฒ ๐ต๐ฎ๐ ๐ณ๐๐ป๐ฑ๐ฎ๐บ๐ฒ๐ป๐๐ฎ๐น๐น๐ ๐ฐ๐ต๐ฎ๐ป๐ด๐ฒ๐ฑ.
National security no longer ends at land, air, and sea. It extends into every network, every chip, every line of code running critical infrastructure. Of India's 8 critical sectors, 2 are super-critical: Power and Telecom. Everything else runs on top of these two.
๐ช๐ฒ ๐บ๐๐๐ ๐ฟ๐ถ๐๐ฒ ๐ฎ๐ฏ๐ผ๐๐ฒ ๐๐ฒ๐ฟ๐ผ-๐ฑ๐ฎ๐๐, ๐ฎ๐ป๐ฑ ๐ฝ๐ฟ๐ฒ๐ฝ๐ฎ๐ฟ๐ฒ ๐ณ๐ผ๐ฟ ๐ค-๐ฑ๐ฎ๐.
The quantum threat is not theoretical. It is a countdown. The National Quantum Mission carries a โน6,000 crore mandate, but security, beyond just cyber, was absent from its original design. That gap must be closed before the clock runs out.
๐ง๐ฒ๐ฐ๐ต๐ป๐ผ๐น๐ผ๐ด๐ ๐ฎ๐น๐ผ๐ป๐ฒ ๐ถ๐ ๐ป๐ผ๐ ๐๐ต๐ฒ ๐ฎ๐ป๐๐๐ฒ๐ฟ. ๐๐บ๐ฝ๐น๐ฒ๐บ๐ฒ๐ป๐๐ฎ๐๐ถ๐ผ๐ป ๐ถ๐.
Bad implementation of great products is itself an attack surface. The guidelines and documentation exist. What is missing is execution, governance frameworks that convert capability into protection. Policy scaffolding is not bureaucracy. It is the difference between a tool and a weapon pointed the right way. The National Cyber Range, built in partnership with Russia, begins operations in July. But a range is only as powerful as the scenarios run on it.
๐ฆ๐ผ๐๐ฒ๐ฟ๐ฒ๐ถ๐ด๐ป๐๐ ๐ฏ๐ฒ๐ด๐ถ๐ป๐ ๐ฎ๐ ๐๐ต๐ฒ ๐ฐ๐ถ๐ฟ๐ฐ๐๐ถ๐ ๐ฏ๐ผ๐ฎ๐ฟ๐ฑ.
PCB design must happen in India, built on Indian components. Equipment that cannot be verified cannot be trusted. The design of our machines is as strategic as the doctrine that deploys them.
๐ง๐ต๐ฒ ๐ต๐๐บ๐ฎ๐ป ๐ฏ๐ฒ๐ต๐ถ๐ป๐ฑ ๐๐ต๐ฒ ๐บ๐ฎ๐ฐ๐ต๐ถ๐ป๐ฒ ๐ถ๐ ๐๐๐ถ๐น๐น ๐ถ๐ฟ๐ฟ๐ฒ๐ฝ๐น๐ฎ๐ฐ๐ฒ๐ฎ๐ฏ๐น๐ฒ.
AI must maximise speed and scale: but ultimate decisions must remain in the hands of a scientist or a general. We must invest in problem-solvers anchored in one sector, trained deeply, trusted fully. GoI is spending thousands of crores on this. That investment must produce long-tenure, sector-dedicated expertise and not generalists cycling across verticals.
These conversations don't happen by accident. Thank you Prof NK Goyal for creating the space and for making sure the right people were in it.
Industry. Academia. Defence. One resilient unit. This week's National Conference on Telecom Security in the Era of AI & Quantum Computing, convened by Cyber Security Association of India, brought together some of India's most consequential voices in national security including Mr. Narendra Nath Gangavarapu (Joint Secretary, NSCS), Lt. Gen (Dr.) Rajesh Pant (Former National Cyber Security Coordinator), and Lt. Gen. Vivek Dogra (Signal Officer-in-Chief) shaped a conversation that went far beyond policy.
๐ง๐ต๐ฒ ๐๐ต๐ฟ๐ฒ๐ฎ๐ ๐น๐ฎ๐ป๐ฑ๐๐ฐ๐ฎ๐ฝ๐ฒ ๐ต๐ฎ๐ ๐ณ๐๐ป๐ฑ๐ฎ๐บ๐ฒ๐ป๐๐ฎ๐น๐น๐ ๐ฐ๐ต๐ฎ๐ป๐ด๐ฒ๐ฑ.
National security no longer ends at land, air, and sea. It extends into every network, every chip, every line of code running critical infrastructure. Of India's 8 critical sectors, 2 are super-critical: Power and Telecom. Everything else runs on top of these two.
๐ช๐ฒ ๐บ๐๐๐ ๐ฟ๐ถ๐๐ฒ ๐ฎ๐ฏ๐ผ๐๐ฒ ๐๐ฒ๐ฟ๐ผ-๐ฑ๐ฎ๐๐, ๐ฎ๐ป๐ฑ ๐ฝ๐ฟ๐ฒ๐ฝ๐ฎ๐ฟ๐ฒ ๐ณ๐ผ๐ฟ ๐ค-๐ฑ๐ฎ๐.
The quantum threat is not theoretical. It is a countdown. The National Quantum Mission carries a โน6,000 crore mandate, but security, beyond just cyber, was absent from its original design. That gap must be closed before the clock runs out.
๐ง๐ฒ๐ฐ๐ต๐ป๐ผ๐น๐ผ๐ด๐ ๐ฎ๐น๐ผ๐ป๐ฒ ๐ถ๐ ๐ป๐ผ๐ ๐๐ต๐ฒ ๐ฎ๐ป๐๐๐ฒ๐ฟ. ๐๐บ๐ฝ๐น๐ฒ๐บ๐ฒ๐ป๐๐ฎ๐๐ถ๐ผ๐ป ๐ถ๐.
Bad implementation of great products is itself an attack surface. The guidelines and documentation exist. What is missing is execution, governance frameworks that convert capability into protection. Policy scaffolding is not bureaucracy. It is the difference between a tool and a weapon pointed the right way. The National Cyber Range, built in partnership with Russia, begins operations in July. But a range is only as powerful as the scenarios run on it.
๐ฆ๐ผ๐๐ฒ๐ฟ๐ฒ๐ถ๐ด๐ป๐๐ ๐ฏ๐ฒ๐ด๐ถ๐ป๐ ๐ฎ๐ ๐๐ต๐ฒ ๐ฐ๐ถ๐ฟ๐ฐ๐๐ถ๐ ๐ฏ๐ผ๐ฎ๐ฟ๐ฑ.
PCB design must happen in India, built on Indian components. Equipment that cannot be verified cannot be trusted. The design of our machines is as strategic as the doctrine that deploys them.
๐ง๐ต๐ฒ ๐ต๐๐บ๐ฎ๐ป ๐ฏ๐ฒ๐ต๐ถ๐ป๐ฑ ๐๐ต๐ฒ ๐บ๐ฎ๐ฐ๐ต๐ถ๐ป๐ฒ ๐ถ๐ ๐๐๐ถ๐น๐น ๐ถ๐ฟ๐ฟ๐ฒ๐ฝ๐น๐ฎ๐ฐ๐ฒ๐ฎ๐ฏ๐น๐ฒ.
AI must maximise speed and scale: but ultimate decisions must remain in the hands of a scientist or a general. We must invest in problem-solvers anchored in one sector, trained deeply, trusted fully. GoI is spending thousands of crores on this. That investment must produce long-tenure, sector-dedicated expertise and not generalists cycling across verticals.
These conversations don't happen by accident. Thank you Prof NK Goyal for creating the space and for making sure the right people were in it.