How Cobalt Brings Real-Time Exploit and Threat Intelligence to Vulnerability Findings

Common Vulnerabilities and Exposures (CVE) identify known vulnerabilities in specific components. They don't confirm whether you're exposed or whether attackers are actively exploiting a vulnerability. The additional context from adding reliable threat intelligence and known CVE information to your pentest findings can make the difference between wasting time on research and triage and quickly identifying pressing risks that your business needs to address.

Cobalt integrated CVE intelligence from VulnCheck directly into the Cobalt Offensive Security Platform. This new real-time exploit and threat intelligence shows up on suggested findings (for pentesters) and on validated findings delivered to customers.

Now, on any finding tied to a CVE, we automatically surface:

  • EPSS score: Probability of exploitation in the wild within 30 days
  • KEV status: Whether it's on CISA's Known Exploited Vulnerabilities list
  • MITRE ATT&CK techniques: How attackers actually use this vulnerability
  • Publicly available exploits: Sources, PoC links, and dates

Threat intelligence gives you the macro view of what tools adversaries are building across the internet. Offensive security research and pentest finding validation from Cobalt give you the ground truth: whether that flaw is reachable in your stack, how it connects to your broader attack tree, and what an adversary can actually do with it once they get in.

Not every finding has a CVE

Not all pentest findings are tied to known CVEs. CVEs catalog publicly disclosed security flaws in third-party software and hardware, whereas penetration tests frequently expose custom application errors, operational misconfigurations, and business logic flaws that will never receive a CVE.

Common non-CVE pentest findings:

  • Business logic flaws: Defects in how proprietary application code processes workflows, such as altering item prices during a checkout process or bypassing step-up authentication.
  • Access control weaknesses: Insecure Direct Object References (IDOR/BOLA) and broken authorization models where authenticated users can view or modify another user's private data.
  • Security misconfigurations: Weak password policies, default credentials, exposed cloud storage buckets, permissive CORS policies, or improper TLS/SSL configurations.
  • Zero-day vulnerabilities: Newly discovered flaws in third-party software identified by the tester before the vendor or public database has assigned an official CVE identifier.
  • Human and physical security gaps: Vulnerabilities uncovered through social engineering (phishing, pretexting), tailgating into secure facilities, or cleartext credentials stored on internal documentation sites.

What if the finding does have an associated CVE?

A finding tied to a known CVE (sometimes) comes with a severity rating or CVSS score. The Common Vulnerability Scoring System is the open industry standard used to calculate a vulnerability's technical severity on a scale from 0.0 to 10.0. But severity rating alone isn’t enough to decide what to fix first. Additional context is needed, including:

  • Is there a working exploit in the wild?
  • Has this been weaponized by ransomware operators?
  • Is it on CISA's radar for tracking?

Obtaining this information without a partner is no easy task. The data is scattered across the National Vulnerability Database (NVD), the CISA Known Exploited Vulnerabilities (KEV) catalog, exploit repositories, and threat reports that you may or may not have access to. Researching all the necessary information is manual and time-consuming, pulling pentesters and security teams out of the work that matters most: finding more of the critical vulnerabilities in your systems.

Cobalt added CVE context for faster discovery and remediation

Cobalt pentesters already validate whether a CVE represents real exposure in your environment. They manually verify that the issue is reachable and exploitable in the target scope. For our expert testers, having instant access to exploit payloads and telemetry speeds up their manual verification, helping them test attack paths faster and back up their findings with real-world threat data.

What gets surfaced

If there's a known CVE in your environment, we enrich the finding in the Cobalt Platform with:

  • EPSS score: The probability a vulnerability will be exploited in the wild within 30 days. Model-driven and updated daily, so it reflects current risk, not a static rating.
  • KEV status: Inclusion on CISA's Known Exploited Vulnerabilities list confirms active exploitation in the wild, which helps teams prioritize the fix and meet compliance deadlines.
  • MITRE ATT&CK techniques: The adversary techniques mapped to the vulnerability. This connects the flaw to how attackers actually use it in an intrusion, not just that it exists.
  • Exploited by: The categories of threat activity tied to the CVE: threat actors, ransomware, botnets, VulnCheck canaries, and honeypots. It shows not just that a vulnerability has been exploited, but what kind of adversary activity has been observed.
  • Publicly available exploits: References tied to the CVE, from GitHub repositories to blog posts, each tagged by publication date and classified as proof-of-concept or weaponized, so you can tell a known technique from ready-to-deploy tooling.

Cobalt CVE Exploit Threat Intel Vulnerability Findings

Why it matters for customers

Remediation capacity is finite. Every security team faces more findings than it can fix at once, especially with the uptick in AI-assisted and AI-generated findings, and severity alone is insufficient for deciding what goes to the top of the queue. If you’re relying solely on severity rating for prioritization, a critical-rated CVE that no one is exploiting will outrank a moderate CVE that ransomware operators are actively using. Additionally, real attackers do not look at vulnerabilities in isolation. They look at attack chains: pairing a known CVE in an external component with custom application weaknesses, like an authorization flaw or a cloud misconfiguration, to pivot deeper into an environment.

Translating a finding into a remediation decision usually means making the case twice: to engineering to prioritize the work, and to leadership to justify the urgency. Severity alone rarely settles either conversation. Exploit and threat intelligence does. When a validated finding arrives with a high EPSS score, a KEV listing, weaponized exploits, or confirmed exploitation activity, the priority is not a matter of interpretation. It is a vulnerability to fix now, with the evidence already attached. That gives your security team the language to move findings from backlog to remediation, and to show the business why it mattered.

Why Cobalt chose VulnCheck

VulnCheck provides the relevant data to make prioritization of your Cobalt findings easier, so you can remediate the most consequential vulnerabilities that threaten your business. Most vulnerability data is purely vulnerability-centric. It describes the flaw only, not the impact or if and how it’s being used in the real world. VulnCheck pairs vulnerability intelligence with exploit intelligence, aggregated from hundreds of sources, including its own exploit developers and honeypot canaries, adding the necessary context to streamline remediation.

Available now

The enrichment is live across suggested findings for pentesters and validated findings delivered to customers. There is nothing to enable or configure. When a CVE is identified on a finding, the available exploit intelligence is populated automatically.

Prioritizing vulnerabilities has always been hard. With exploit and threat intelligence built into the finding in the Cobalt Platform, our pentesters verify attack vectors faster, and our customers get the context they need to act with confidence.

If you have any questions, please reach out to your Cobalt team. If you’re interested in learning more about our products and services, request a demo today.

Back to Blog
About Molly Finn
Molly Finn is the Senior Product Manager at Cobalt. With over 12 years of product leadership experience, she helps bring to life the Cobalt mission to take Pentest as a Service (PtaaS) further with an Offensive Security Testing Platform. Molly partners closely with engineering, design, and our customers to deliver end-to-end security testing across your attack surface. More By Molly Finn