skip to content
// engineering

How Midkernel Threat Intel publishes

Midkernel publishes a small public Threat Intel spine from Production data. The live board is Threat Intel. This note is the method behind those posts: which weekday each beat covers, how counts are measured, what a named citation requires, and when a beat ships or is skipped.

The product ranks and packages public signals already in circulation (CISA KEV, EPSS, advisories, weaponized listings, and web3 incident feeds) into Midkernel classes. Posts describe that ranked board. Day counts come from the Production evidence query, not from a spreadsheet or memory.

The weekday spine

Three beats, fixed weekdays:

PostDayWhat it covers
Database growthMondayCurated class growth when week-over-week unique-threat change is material
Threats changingWednesdayWeek-over-week change in a curated class, with named citations when they qualify
Scan-on-liveFridayA Scan run aimed at a live threat, only when such a result exists

Monday and Wednesday are board stories: equal windows, absolute unique-threat movement, citations that survive the evidence query. Friday is a Scan story. A beat with no material story is skipped rather than filled.

Production evidence

Published counts come from Production Midkernel Threat Intel.

After the October 2026 cutover (app pull request #259), packaging reads the live evidence ledger through Production's Threat Intel API (midkernel/evidence-api/v2). That read is the source of truth for public packaging. Public feeds and GitHub releases feed the product pipeline; they are not the ranked board Midkernel cites in posts. Public Notes and social copy do not name internal database tables.

Equal windows

Every week-over-week card uses equal-length date windows and source-effective publication dates. For each Midkernel class in the window, the query returns unique-threat counts and evidence references. The current interval is compared to the prior equal interval on those windowed unique-threat totals.

High absolute volume with a weak week-over-week delta is continuity context. Continuity context alone does not become the growth lead.

Before a beat is packaged, ingest currency for the claimed window is confirmed from the API (as-of and last-ingest relative to that window). Stale coverage skips the beat. Current ingest alone does not require a post.

Named citations

A named threat on a card carries four fields:

  1. a stable public identifier (CVE or GHSA),
  2. the title returned by the source advisory,
  3. an https citation URL,
  4. membership in the Midkernel class and date window under the Production evidence query.

Rows without a stable identifier are omitted. Titles are taken from the source; they are not invented for anonymous advisories. Window counts are retained public-source evidence entities in that interval. A single threat may sit under more than one class; overlap is noted when it affects interpretation.

Leading a class

Monday and Wednesday cards lead with windowed unique-threat movement in a curated class, using absolute counts. Prefer curated web2.* classes and meaningful web3 classes. EPSS-volume movement can lead only when the post treats EPSS as score flow rather than new CVE volume.

Severity ranks on the in-app board (watching, trending, active exploit) describe product board state when present. Board ranks alone do not select a social hero. Class unknown marks unmapped taxonomy volume and is not used as a public hero.

GROWING

A GROWING label marks a curated unique-threat increase over the prior equal window. Declines do not receive it. When the prior baseline is near zero, absolute unique-threat counts carry the story; percentage framing from a near-zero baseline does not.

When a beat ships

Skipped beats produce no stay-active post on the company account.

Charts, Notes pages, and company social for this spine publish after review. The standing exception is the weekly Research Briefing three-paper post on X when the corresponding website page is already live.

Catch-up ingest can restore missing days after a stall. Restored coverage alone does not prove that forward ingest is healthy. The freshness check above is the packaging rule.

Friday Scan-on-live

Friday uses the same Production source of truth and the same publish review. The post ships only when there is a concrete Scan-live result to report. Otherwise Friday is skipped.

// related
September 28, 2026// research
September 28th Research Briefing

A weekly publication of the top three papers from arXiv last week. Papers with arXiv v1 published 2026-09-21 through 2026-09-28 UTC.

September 21, 2026// research
September 21st Research Briefing

A weekly publication of the top three papers from arXiv last week. Papers with arXiv v1 published 2026-09-14 through 2026-09-21 UTC.

September 14, 2026// research
September 14th Research Briefing

A weekly publication of the top three papers from arXiv last week. Papers with arXiv v1 published 2026-09-07 through 2026-09-13 UTC.

Research notes, at most monthly. No spam.
← All research