Threat Center: From CVE alarm to confirmed exposure
The blacklens.io Threat Center is your early warning system for new vulnerabilities: it shows which CVEs affect your systems and confirms it by scan.
- by blacklens.io Team
- Published
- 3 min read

Critical new vulnerabilities in firewalls, VPN gateways and mail servers now arrive week after week. The question that matters is never whether there is a new CVE. It is whether it affects your organisation. The Threat Center in blacklens.io answers exactly that: automatically, for your systems, with evidence.
What is the Threat Center?
The Threat Center is the blacklens.io early warning system for new vulnerabilities. It continuously matches newly published CVEs against the technologies your organisation runs and shows only the matches that really affect you. It builds on the inventory blacklens.io already creates from external scans, the Sentry agent and your cloud connectors. There is nothing extra to set up.
Behind it sits a threat feed of more than 140,000 CVEs, over 26,000 of them with a public exploit. From that volume, your team gets the short list of vulnerabilities that apply to your firewall, your Exchange server or your Citrix gateway.
Why a CVE newsletter is no longer enough
CVE newsletters and CERT warnings matter, but they are written for everyone. Whether the product runs in your environment, in which version and on which system, your team has to work out afterwards. With several critical notices a week, that search costs hours, and those are the hours in which attackers start scanning.
The Threat Center reverses the order. Instead of a general warning, you get a list of affected systems, each with the signals that matter for prioritisation:
- EPSS: how likely is exploitation within the next 30 days?
- CISA KEV: is the vulnerability already under active attack, and by when should it be fixed?
- Exploit: is attack code publicly available?
- CVSS: how severe is the vulnerability technically?
From warning to certainty
A match in the inventory is a suspicion. So blacklens.io checks it: where a verification template exists for the CVE, a targeted scan against the affected system starts automatically. The result is clear, either confirmed or not confirmed. Your team spends its time on real findings, not guesswork.

The detail view shows at a glance how critical a vulnerability is, whether it is already being exploited and which systems are affected. Confirmed matches become regular findings in the same vulnerability management workflow as everything else, with assignment, ticket and retest.
Fewer alarms, more impact
An early warning system that rings all the time gets ignored. The Threat Center is built to stay quiet:
- Threshold per workspace: alerts start at a CVSS score of your choice, 7 by default.
- Grouped, not one by one: new CVEs for the same product produce one alert, not dozens.
- To the right team: notification policies route alerts by e-mail, push or through integrations such as Jira, Microsoft Teams and Microsoft Sentinel.
- Escalated automatically: when exploitation is likely and an exploit is available, urgency rises on its own.

The Advisories view adds vendor security notices, so broader warnings sit in the same tool.
What this means for your organisation
The time between a vulnerability's disclosure and the first attack is the window in which you can act. The Threat Center shortens the path from "a new CVE is out" to "these systems are affected, it is confirmed, and the responsible team has the ticket".
At the same time, it builds a traceable record of which vulnerabilities were detected, checked and handled. That helps in audits and with requirements such as NIS2, which call for structured vulnerability handling.
Get started: the Threat Center is active in blacklens.io under Threat Center → Emerging Threats as soon as your technology inventory is in place. Read more about the early warning system for zero-days and new CVEs on the platform page.
Frequently asked questions
- The Threat Center is the blacklens.io early warning system for new vulnerabilities. It continuously matches newly published CVEs against the technologies your organisation actually runs and shows only the matches that affect you. Where a verification template exists, a targeted scan automatically confirms whether your system is vulnerable. Signals such as EPSS and CISA KEV show what needs fixing first.
More articles

NISG 2026: Austria's NIS2 deadlines from 1 October
Austria's NISG 2026 enters into force on 1 October. Which deadlines apply for registration and self-declaration, and what evidence you need to produce them.
- 5 min read

What First? Intelligent Vulnerability Prioritisation with blacklens
What first, why, and how? blacklens turns open findings into a prioritised remediation plan – sorted by risk reduction, with context on every finding.
- 5 min read

FortiBleed: When Tens of Thousands of Firewalls Become an Open Door
FortiGate firewalls exist to protect corporate networks. FortiBleed shows what happens when the firewall itself becomes the attack surface – and opens the door.
- 3 min read
See your attack surface within 24 hours.
We set up your workspace and walk you through the first findings.
- 14 days free, all features
- No credit card required
- We walk you through your first findings