惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

大猫的无限游戏
大猫的无限游戏
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园_首页
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
D
Docker
酷 壳 – CoolShell
酷 壳 – CoolShell
宝玉的分享
宝玉的分享
Martin Fowler
Martin Fowler
美团技术团队
量子位
M
MIT News - Artificial intelligence
Apple Machine Learning Research
Apple Machine Learning Research
阮一峰的网络日志
阮一峰的网络日志
博客园 - 叶小钗
博客园 - 三生石上(FineUI控件)
腾讯CDC
Hugging Face - Blog
Hugging Face - Blog
博客园 - 【当耐特】
小众软件
小众软件
博客园 - 司徒正美
罗磊的独立博客
云风的 BLOG
云风的 BLOG
B
Blog RSS Feed
博客园 - 聂微东

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
Microsoft Defender Vulnerability Management gets a smarte...
Anamarija Pogorelec · 2026-06-01 · via Help Net Security

Microsoft Defender Vulnerability Management’s updated exposure score model adds vulnerability risk signals and asset context to help teams understand where risk is concentrated and which remediation actions are likely to have the greatest impact. The model is available in public preview.

Microsoft Defender exposure score

“The updated model addresses these customer pain points by combining vulnerability risk, exploitability signals, and asset context into a more representative exposure score. The goal is to help security teams move from a score that explains ‘how severe are the vulnerabilities?’ to a score that helps answer ‘where should we focus remediation first, and why?’,” Moti Bani, Senior Product Manager at Microsoft, explained.

Changes to the exposure score model

Instead of relying primarily on CVSS severity, the updated model uses multiple vulnerability risk signals to assess CVE risk. One of the signals used to estimate exploitation likelihood is the Exploit Prediction Scoring System (EPSS).

CVSS (Common Vulnerability Scoring System) measures the severity of a security vulnerability. EPSS, a machine learning model, estimates the likelihood that a published CVE will be exploited in the wild within the next 30 days.

To improve scoring consistency, the model uses normalized CVE data from multiple vulnerability sources. This allows the score to better reflect which vulnerabilities are more likely to be exploited.

The asset exposure score now reflects all vulnerabilities affecting a device, with each weighted according to vulnerability risk and asset context.

This gives security teams a more complete view of device exposure. Remediation work performed on a device also contributes more directly to exposure reduction.

The model incorporates asset context, including whether a device is internet-facing and its criticality level. This helps prioritize vulnerabilities on assets that carry greater business or exposure risk. For example, the same vulnerability may require a different response depending on whether it affects an exposed or business-critical device.

To better connect organizational posture with the assets and vulnerabilities contributing to risk, the organization-level exposure score is derived from individual asset scores. This provides a more representative view of vulnerability exposure throughout the environment.

Microsoft also uses asset-CVE-level data to calculate remediation impact. This improves the relationship between the predicted impact shown in recommendations and the score changes expected after remediation is completed. The updated calculations are reflected in the product, making score impact easier to understand and track.

What customers can expect

When the updated model is enabled, scores may change because of the revised calculation methodology. A higher or lower score does not necessarily indicate a change in security posture or the presence of new vulnerabilities.

The updated score should be treated as a new baseline because it is not directly comparable to the previous version.

Recommendations may be reprioritized based on recalculated impact values.

Exposure scores are updated daily, and remediation changes may take up to 24 hours to appear. Score bands remain unchanged: low (0–29), medium (30–69), and high (70–100).