Methodology

How this was built, and what to distrust

Sourcing

Data was collected across five independent research passes — Patch Tuesday, CVE macro trends, AI-discovery evidence, attacker/exploitation trends, and CWE type shifts — each required to return both the signal and the counter-signal. Every figure traces to a named, dated source. Two independent sources were sought for each annual CVE total.

What we corrected

An early recall-based pass produced anomalous 2026 Patch Tuesday totals (July "621", June "208"). These were re-verified against live Zero Day Initiative, Tenable, and Krebs pages and corrected to 569 and 200 Microsoft CVEs. The "622" figure some outlets ran for July includes third-party and Chromium republished advisories; this site uses Microsoft's own new-CVE count throughout for consistency.

Known limitations

Stance

This site is deliberately neutral. It does not conclude that AI "favors" attackers or defenders. It reports what the disclosure, exploitation, and type data show, separates that from what vendors claim, and marks the questions the data can't answer. The raw data files behind every chart are public in Substrate.

The standing analysis

The Analysis page re-asks the same questions across every dataset — are breaches rising because of AI, what mechanisms the data supports, and what it can't answer. It is bound to the data by a build gate: adding a data source without covering it in the analysis fails the build, so the synthesis cannot silently go stale.