Editorial standards
Verify. Attribute. Protect. Explain.
How the desk separates confirmed fact from reported claim, and what it will not publish.
Verify
Claims are separated from confirmed facts.
Attribute
Every report links to the primary sources it relies on.
Protect
Victim data is never reproduced for spectacle.
Explain
Threat reporting should make the reader harder to attack.
Sourcing
A fact is reported as confirmed only when it comes from a primary source — the affected organisation, a regulator or government agency, a court filing, or a securities filing — or from two independent, reputable outlets. Everything else is attributed to whoever said it.
Criminal claims
Leak-site posts and statements by criminal groups are treated as claims, never as fact. We say who made the claim and whether the victim has confirmed or disputed it. We do not visit leak sites to download data, and we never reproduce it.
Attribution
We attribute an attack to a named threat actor only when a government agency, the victim, or an established security vendor has done so publicly, and we say who made the attribution.
Severity labels
- Critical — active exploitation or major operational disruption with broad impact.
- High — confirmed compromise or data theft at significant scale.
- Medium — advisories, policy and enforcement actions defenders should act on.
- Low — context and background.
Severity is an editorial judgement about the story, not a CVSS score.
Dates and updates
Each report shows its publication date. When a report is materially updated, we add an updated date and describe the change at the end of the article.
Independence
CyberShitty.com is not paid to cover or avoid any vendor, product or organisation. If that ever changes, it will be disclosed on the page concerned.
Mistakes
We correct errors promptly and visibly. See the corrections policy.