Exploit maturity
The underground's own CVE lifecycle: PoC posted, "private exploit" for sale, then bundled into kits and partnerkas. Each stage changes the price, and your patch window with it.
Why it matters to you
A CVE being traded is a different emergency than a CVE with a CVSS score. Watch the market's pricing alongside the scoring calculators.
Where we meet it
The market prices exploitation before any public catalogue records it. Every post we index is parsed for the CVEs it names, so a CVE id is a filter you can run across the forum and Jabber archive and read the thread that priced it.
Connected terms
Partnerka
An affiliate program: the franchise model behind ransomware and stealer operations. The operator supplies malware and infrastructure; affiliates supply victims and split the revenue.
Initial Access Broker (IAB)
A specialist who breaks into organizations and sells the access (VPN, RDP, domain admin) instead of using it. The wholesale layer between opportunistic infection and targeted ransomware.
Ransomware-as-a-Service (RaaS)
Ransomware sold as a product: the operator builds the encryptor, the panel and the leak site, affiliates bring the victims, and the ransom splits between them. The reason a small crew can run an enterprise-grade extortion campaign.
Read elsewhere
Where this term stops being vocabulary
Cvekit is where you watch it happen to you
Knowing the word is the cheap half. The platform is the half where the term arrives attached to your domain, with a timestamp and the source it came from.
More from the playbook
Adversary-in-the-middle phishing
A phishing page that proxies the real login instead of imitating it. The victim authenticates against the genuine site through the attacker's server, completes multi-factor as normal, and the attacker keeps the resulting session cookie.
Business Email Compromise (BEC)
Fraud committed from inside a real mailbox: the attacker reads the thread, waits for an invoice and answers it with different bank details. No malware, no attachment, nothing for a scanner to find.
Callback phishing
An email that carries no link and no attachment, only a plausible invoice or subscription notice and a phone number to dispute it. The attack begins when the victim calls, and the person who answers walks them into installing remote access software.
Checker
A tool that tests stolen credentials against a target service in bulk and sorts the live ones from the dead. The industrialized step between a combolist and an account takeover.