Ranked by the most recent reset (smallest number across any column). Vendors at the top have had the loudest public signal lately — which is a measure of newsworthiness, not of quality.
| Vendor | CVE | Breach | Demo | Lab miss | Launch | Min |
|---|---|---|---|---|---|---|
| Microsoft | 13d | 5d | 3d | 117d | 6d | 3d |
| CrowdStrike | 126d | — | 32d | 117d | 5d | 5d |
| Palo Alto Networks | 31d | — | 28d | — | 5d | 5d |
| SentinelOne | — | — | 10d | — | 19d | 10d |
| Check Point | — | — | 28d | — | — | 28d |
| Fortinet | — | — | 28d | — | — | 28d |
| Sophos | — | — | — | 117d | 85d | 85d |
| CyberArk | — | — | — | — | 99d | 99d |
| K7 | — | — | — | 117d | — | 117d |
| VIPRE | — | — | — | 117d | — | 117d |
| Trellix | — | — | — | 117d | — | 117d |
| Cisco | — | — | — | 117d | — | 117d |
| ManageEngine | — | — | — | 117d | — | 117d |
| G Data | — | — | — | 117d | — | 117d |
| SenseOn | — | — | — | 117d | — | 117d |
≤ 7 days = fresh reset · ≤ 30 = recent · ≤ 90 = current window · > 90 = cold · — = no event of this type on file. "Min" is the smallest days-since across all five columns — the vendor's last public reset.
The Exposure Clock isn't a score. It's five independent counters, each tracking a different kind of event that resets to zero whenever public signal documents one:
A small number is not bad; a large number is not good. A vendor with a fresh CVE counter is in the news because researchers found something — possibly because they ship a lot of code, possibly because they ship sloppy code. The clock surfaces the timing; the reader brings the judgment.
ColdRecon turns every reset into a daily intelligence brief from the seller's seat — what triggered it, who's affected, what to say in the room. Request clearance and the first lands tomorrow at 0600.
Request Clearance →