Ranked by the most recent reset (smallest number across any column). Vendors at the top have had the loudest public signal lately — which is a measure of newsworthiness, not of quality.
| Vendor | CVE | Breach | Demo | Lab miss | Launch | Min |
|---|---|---|---|---|---|---|
| Microsoft | 60d | — | 2d | 85d | 1d | 1d |
| Palo Alto Networks | 41d | — | 2d | — | 8d | 2d |
| CrowdStrike | 94d | — | 16d | 85d | 7d | 7d |
| SentinelOne | — | — | 22d | — | 16d | 16d |
| Sophos | — | — | — | 85d | 53d | 53d |
| Fortinet | — | 55d | 60d | — | — | 55d |
| CyberArk | — | — | — | — | 67d | 67d |
| K7 | — | — | — | 85d | — | 85d |
| ManageEngine | — | — | — | 85d | — | 85d |
| Trellix | — | — | — | 85d | — | 85d |
| VIPRE | — | — | — | 85d | — | 85d |
| SenseOn | — | — | — | 85d | — | 85d |
| G Data | — | — | — | 85d | — | 85d |
| Cisco | — | — | — | 85d | — | 85d |
≤ 7 days = fresh reset · ≤ 30 = recent · ≤ 90 = current window · > 90 = cold · — = no event of this type on file. "Min" is the smallest days-since across all five columns — the vendor's last public reset.
The Exposure Clock isn't a score. It's five independent counters, each tracking a different kind of event that resets to zero whenever public signal documents one:
A small number is not bad; a large number is not good. A vendor with a fresh CVE counter is in the news because researchers found something — possibly because they ship a lot of code, possibly because they ship sloppy code. The clock surfaces the timing; the reader brings the judgment.
ColdRecon turns every reset into a daily intelligence brief from the seller's seat — what triggered it, who's affected, what to say in the room. Request clearance and the first lands tomorrow at 0600.
Request Clearance →