Skip to content

Malware Brief editorial policy

The Malware Brief editorial policy explains how we choose and check stories about malware & ransomware, cyber attacks, threat intelligence, vulnerabilities, data breaches, cloud security. Those stories are drawn from more than 50 sources, such as the National Vulnerability Database and the CISA Known Exploited Vulnerabilities catalog. The policy also sets out how AI is used in the newsroom and what we do when we get something wrong.

Sourcing

We publish facts only when they appear in a primary source or a named, linked news report. We do not invent quotes, figures or victims.

Automation and AI

We use software to monitor sources and AI tools to help draft articles. Drafts are checked automatically against the source material; figures, quotations, attributions, severity ratings and patch claims that the sources do not support are rejected.

Updates

Breaking stories may start as short briefs and be expanded as details emerge. Updated articles show the update time.

Guides

Our reference guides explain established security practice. They carry no invented statistics, name no victims and recommend no commercial products. Each guide shows the date of its last review.

Independence

No vendor or agency reviews a Malware Brief story before it is published. Security advice in our articles is general; follow your vendor's official advisory for the exact steps.

Corrections

Errors are fixed in the article and marked with the update time. See corrections for how to report one.

Cybersecurity news without the noiseDaily Briefing