Ranked by the most recent reset (smallest number across any column). Vendors at the top have had the loudest public signal lately — which is a measure of newsworthiness, not of quality.
| Vendor | CVE | Breach | Demo | Lab miss | Launch | Min |
|---|---|---|---|---|---|---|
| Microsoft | 58d | — | 20d | 162d | 1d | 1d |
| CrowdStrike | 171d | — | 30d | 162d | 3d | 3d |
| Palo Alto Networks | 76d | — | 73d | — | 5d | 5d |
| SentinelOne | — | 6d | 6d | — | 27d | 6d |
| K7 | — | 8d | — | 162d | — | 8d |
| CyberArk | — | — | — | — | 41d | 41d |
| Check Point | — | — | 73d | — | — | 73d |
| Fortinet | — | — | 73d | — | — | 73d |
| Sophos | — | — | — | 162d | 130d | 130d |
| ManageEngine | — | — | — | 162d | — | 162d |
| Cisco | — | — | — | 162d | — | 162d |
| VIPRE | — | — | — | 162d | — | 162d |
| G Data | — | — | — | 162d | — | 162d |
| Trellix | — | — | — | 162d | — | 162d |
| SenseOn | — | — | — | 162d | — | 162d |
≤ 7 days = fresh reset · ≤ 30 = recent · ≤ 90 = current window · > 90 = cold · — = no event of this type on file. "Min" is the smallest days-since across all five columns — the vendor's last public reset.
The Exposure Clock isn't a score. It's five independent counters, each tracking a different kind of event that resets to zero whenever public signal documents one:
A small number is not bad; a large number is not good. A vendor with a fresh CVE counter is in the news because researchers found something — possibly because they ship a lot of code, possibly because they ship sloppy code. The clock surfaces the timing; the reader brings the judgment.
ColdRecon turns every reset into a daily intelligence brief from the seller's seat — what triggered it, who's affected, what to say in the room. Request clearance and the first lands tomorrow at 0600.
Request Clearance →