Patented methodology analyzes more than 60 vulnerability characteristics to assess ransomware risk at disclosure
WASHINGTON, Oct. 1, 2026 /PRNewswire-PRWeb/ — Flashpoint, the global leader in threat intelligence, today announced that it has been awarded U.S. Patent No. 12,705,360 for its Ransomware Risk model. The model rates newly disclosed vulnerabilities by how closely they resemble vulnerabilities known to be used in ransomware attacks, helping security teams prioritize patching as soon as a flaw is disclosed. The patent, granted August 11, 2026, covers the method behind the Ransomware Risk score, which has been available in Flashpoint Vulnerability Intelligence (VI) since 2022.
Traditional vulnerability scoring frameworks, such as CVSS, measure how severe a vulnerability could be, but not whether attackers are likely to use it. That gap is especially costly with ransomware. Ransomware-as-a-Service (RaaS) groups increasingly go after specific technical conditions that make exploitation fast and repeatable, and Flashpoint observed a 45% increase in RaaS attacks in the first half of 2026. The Ransomware Risk model gives defenders a ransomware-specific signal they can act on the moment a vulnerability is disclosed, without waiting weeks for exploitation reports.
“As vulnerability disclosures surge, prioritization is more important than ever for security teams,” said Josh Lefkowitz, Co-Founder and CEO of Flashpoint. “A severity score alone can’t tell you which vulnerabilities pose the greatest real-world risk of exploitation by ransomware actors. Our patented Ransomware Risk model applies years of threat intelligence to that problem, giving customers an earlier signal and helping them prioritize based on how attackers actually operate.”
HOW THE PATENTED MODEL WORKS
The Ransomware Risk model evaluates every vulnerability in four steps:
- Multi-factor fingerprinting: Each vulnerability is profiled against more than 60 technical factors, including whether it can be exploited remotely without authentication, whether it affects operational technology (OT) systems, and how it could affect data availability.
- Coordinate mapping: The model turns each multi-factor fingerprint into a set of values that place it as a single point on a map, so vulnerabilities with similar profiles land close together.
- Cluster check: Historical threat data identifies the clusters where vulnerabilities exploited in real-world ransomware attacks group together.
- Likelihood rating: Each new vulnerability is rated Low, Medium, High, or Critical based on how close it lands to those clusters.
The model updates as new ransomware activity is confirmed, so ratings reflect current attack patterns. It also covers every vulnerability tracked by Flashpoint VI, including more than 105,000 that are not in CVE or the National Vulnerability Database (NVD).
In Flashpoint Ignite, the Ransomware Risk score appears alongside CVSS (v3 and v4), EPSS, Social Risk, and exploit maturity. This lets teams flag lower-severity vulnerabilities that CVSS alone would deprioritize but that closely match ransomware targets.
The four-step method, developed by Flashpoint’s Ben Haynes and Jacob Kouns, is the basis of U.S. Patent No. 12,705,360.
“Despite being the most popular indicator for priority, we know that severity alone doesn’t tell you whether a vulnerability will be exploited or used in ransomware,” said Ben Haynes, Data Science & Analytics Lead at Flashpoint and co-inventor of the patented methodology. “A vulnerability can score low on a traditional severity scale and still share the characteristics we repeatedly see in ransomware attacks. This highlights the importance of having a multi-faceted prioritization strategy, or else organizations can get caught off guard by our complex and ever-changing threat landscape.”
To learn more about Flashpoint’s patented Ransomware Risk model, read the blog post or request a demo at flashpoint.io/demo.
FREQUENTLY ASKED QUESTIONS
Q: What is Flashpoint announcing?
Flashpoint has been awarded U.S. Patent No. 12,705,360 for the methodology behind its Ransomware Risk model. The model, available within Flashpoint Vulnerability Intelligence since 2022, evaluates how closely newly disclosed vulnerabilities resemble vulnerabilities previously exploited in ransomware attacks.
Q: What does Flashpoint’s ransomware patent cover?
The patent covers Flashpoint’s method for rating how likely a vulnerability is to be used in a ransomware event. Vulnerabilities are profiled across more than 60 factors and compared with vulnerabilities historically used in ransomware attacks. Based on their similarity to those patterns, vulnerabilities receive a Low, Medium, High, or Critical Ransomware Risk rating.
Q: How is Ransomware Risk different from CVSS and EPSS?
CVSS measures the potential severity of a vulnerability, while EPSS estimates the probability that a vulnerability will be exploited in general. Flashpoint Ransomware Risk adds ransomware-specific context by assessing how closely a vulnerability resembles those historically used in ransomware attacks. Within Flashpoint Ignite, organizations can evaluate these signals together.
Q: How quickly does Flashpoint assign a Ransomware Risk rating?
Flashpoint rates vulnerabilities upon disclosure, providing security teams with a ransomware-specific signal before confirmed exploitation may be publicly reported. Scores continue to update as new vulnerability and threat intelligence becomes available.
Q: How does Ransomware Risk help vulnerability management teams prioritize remediation?
Ransomware Risk provides an additional signal beyond severity alone. For example, a vulnerability with a CVSS score between 1.0 and 6.9 may still warrant greater attention if its characteristics place it within a High or Critical ransomware cluster. This helps teams identify exposures that more closely resemble vulnerabilities ransomware operators have historically targeted.
ABOUT FLASHPOINT
Flashpoint is the leader and largest private provider of threat data and intelligence. We empower mission-critical businesses and governments worldwide to decisively confront complex security challenges, reduce risk, and improve operational resilience amid fast-evolving threats. Powered by Flashpoint Primary Source Collection, our proprietary approach to collecting intelligence directly from the digital spaces where threats originate, the Flashpoint Ignite platform delivers unmatched depth, speed, and relevance from open and hard-to-reach sources, enriched by human expertise and scaled by AI. Our solutions span cyber threat intelligence, vulnerability intelligence, geopolitical risk, physical security, fraud, and brand protection. The result: our customers safeguard critical assets, avoid financial loss, and protect lives. Discover more at flashpoint.io.
Join the conversation. Follow us on LinkedIn.
Media Contact
Kari Walker, RedIron PR for Flashpoint, 1 7039288886, [email protected]
SOURCE Flashpoint

Click Here For The Original Source.