<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>PatchVex — Security for Developers</title>
    <link>https://patchvex.com</link>
    <description>Security research, CVE breakdowns, and engineering articles from PatchVex.</description>
    <language>en-us</language>
    <managingEditor>hello@patchvex.com (PatchVex)</managingEditor>
    <webMaster>hello@patchvex.com (PatchVex)</webMaster>
    <lastBuildDate>Fri, 18 Sep 2026 19:58:55 GMT</lastBuildDate>
    <atom:link href="https://patchvex.com/feed" rel="self" type="application/rss+xml"/>
    <image>
      <url>https://patchvex.com/og-default.png</url>
      <title>PatchVex</title>
      <link>https://patchvex.com</link>
    </image>
    <item>
      <title>CVSS vs EPSS vs CISA KEV: A Practical Comparison</title>
      <link>https://patchvex.com/blog/cvss-vs-epss-vs-cisa-kev</link>
      <guid isPermaLink="true">https://patchvex.com/blog/cvss-vs-epss-vs-cisa-kev</guid>
      <description>Three vulnerability signals, three different questions. A practical guide to what CVSS, EPSS, and CISA KEV each measure, how they disagree, and how to combine them into a real prioritization workflow.</description>
      <pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate>
      <author>PatchVex Engineering</author>
      <category>CVSS</category><category>EPSS</category><category>CISA KEV</category><category>Vulnerability Management</category><category>VulnPilot</category><category>Vulnerability Prioritization</category>
    </item>
    <item>
      <title>What Is CISA KEV and Why Does It Matter?</title>
      <link>https://patchvex.com/blog/what-is-cisa-kev</link>
      <guid isPermaLink="true">https://patchvex.com/blog/what-is-cisa-kev</guid>
      <description>CISA&#39;s Known Exploited Vulnerabilities catalog tracks CVEs with confirmed active exploitation. Here&#39;s what it is, why it&#39;s the strongest remediation signal available, and how to use it alongside CVSS.</description>
      <pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate>
      <author>PatchVex Engineering</author>
      <category>CISA KEV</category><category>CVSS</category><category>Vulnerability Management</category><category>VulnPilot</category>
    </item>
    <item>
      <title>What Is an EPSS Score? A Plain-English Explanation</title>
      <link>https://patchvex.com/blog/what-is-epss-score</link>
      <guid isPermaLink="true">https://patchvex.com/blog/what-is-epss-score</guid>
      <description>EPSS predicts the probability a CVE will be exploited in the next 30 days. Here&#39;s what the score actually represents, how it differs from CVSS, its limitations, and how to use it in prioritization.</description>
      <pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate>
      <author>PatchVex Engineering</author>
      <category>EPSS</category><category>CVSS</category><category>CISA KEV</category><category>Vulnerability Management</category><category>VulnPilot</category>
    </item>
    <item>
      <title>Security Checks Every AI-Built App Needs Before Launch</title>
      <link>https://patchvex.com/blog/security-checks-for-ai-built-apps</link>
      <guid isPermaLink="true">https://patchvex.com/blog/security-checks-for-ai-built-apps</guid>
      <description>LLMs write functional code fast. They also reproduce the same security gaps consistently. Here&#39;s what to check before you ship an app built with Cursor, Claude, or Copilot.</description>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <author>PatchVex Engineering</author>
      <category>AI Coding</category><category>Cursor</category><category>Claude Code</category><category>Security Headers</category><category>API Keys</category><category>Launch Checklist</category>
    </item>
    <item>
      <title>Why CVSS Alone Is Not Enough to Prioritize Vulnerabilities</title>
      <link>https://patchvex.com/blog/why-cvss-alone-is-not-enough</link>
      <guid isPermaLink="true">https://patchvex.com/blog/why-cvss-alone-is-not-enough</guid>
      <description>CVSS scores severity if exploited — not whether anyone is. Here&#39;s how CISA KEV and EPSS close that gap, with a practical composite scoring model.</description>
      <pubDate>Sat, 15 Nov 2025 00:00:00 GMT</pubDate>
      <author>PatchVex Engineering</author>
      <category>CVSS</category><category>EPSS</category><category>CISA KEV</category><category>Vulnerability Management</category><category>VulnPilot</category>
    </item>
  </channel>
</rss>