Flashpoint Patents Ransomware Risk Model, Tying Vulnerabilites to Likelihood of Attack
Cybersecurity company Flashpoint recently announced it
has received U.S. Patent No. 12,705,360
for its Ransomware Risk model, a methodology designed to help security teams determine which newly disclosed vulnerabilities more closely resemble those historically used in ransomware attacks.
The patent comes at a time when security teams are confronting a growing vulnerability problem: Flashpoint's Global Threat Intelligence Report: 2026 Midyear Edition tracked 21,667 vulnerability disclosures during the first half of 2026, an 8% increase.
Of those, 4,015, or around 19 percent, already had public or functional exploit code. Flashpoint also reported a 45 percent increase in Ransomware-as-a-Service (RaaS) attacks during the period.
The patent was granted August 11 2026, although the underlying Ransomware Risk model isn't new. It has been available through Flashpoint Vulnerability Intelligence since 2022.
Looking Beyond Severity
The model addresses a basic vulnerability-management problem: severity and real-world ransomware risk aren't necessarily the same thing, because severity scores do not necessarily indicate which flaws attackers are most likely to target.
The Common Vulnerability Scoring System, or CVSS, measures how severe a vulnerability could be. The Exploit Prediction Scoring System, or EPSS, estimates the probability of exploitation more broadly.
Flashpoint's Ransomware Risk model adds another dimension by comparing newly disclosed vulnerabilities with the characteristics of flaws previously exploited in ransomware attacks.
That could change where a vulnerability lands in an organization's patching queue. A lower-severity flaw might normally sit behind numerous critical vulnerabilities. But if its characteristics closely resemble vulnerabilities repeatedly targeted by ransomware operators, security teams may have reason to move it higher.
"A severity score alone can't tell you which vulnerabilities pose the greatest real-world risk of exploitation by ransomware actors," Flashpoint CEO Josh Lefkowitz said. "Our patented Ransomware Risk model applies years of threat intelligence to that problem, giving customers an earlier signal and helping them prioritize based on how attackers actually operate."
The firm's midyear research also illustrates the scale of the prioritization problem. Its vulnerability intelligence covers traditional IT systems as well as cloud, IoT, operational technology, open source software. and third-party libraries.
The company says it also tracks more than 105,000 vulnerabilities that aren't represented in CVE or the National Vulnerability Database, expanding the pool of flaws that security teams may need to evaluate.
Building a Ransomware Fingerprint
The cybersecurity company's patented methodology profiles vulnerabilities using more than 60 technical characteristics, including whether a flaw can be exploited remotely without authentication, whether it affects operational technology systems, and how exploitation could affect data availability.
Those characteristics form a multi-factor fingerprint. The model maps each vulnerability against clusters containing flaws previously exploited in ransomware attacks and assigns a Low, Medium, High, or Critical Ransomware Risk rating.
Flashpoint says the rating can be generated when a vulnerability is disclosed, rather than requiring security teams to wait for public evidence of active exploitation. Ratings are then updated as new ransomware activity and threat intelligence emerge.
Within Flashpoint Ignite, Ransomware Risk appears alongside CVSS, EPSS, Social Risk, and exploit maturity. The idea isn't to replace existing scoring systems, but to give administrators additional information when deciding what to remediate first.
Nor does a High or Critical Ransomware Risk rating mean a vulnerability will necessarily be exploited. The model measures how closely its characteristics resemble vulnerabilities historically associated with ransomware attacks.
For security teams facing thousands of potential vulnerabilities, that distinction matters. The flaw carrying the highest severity score isn't necessarily the one that most closely resembles what ransomware operators have historically chosen to attack.
"Despite being the most popular indicator for priority, we know that severity alone doesn't tell you whether a vulnerability will be exploited or used in ransomware," said Ben Haynes, Data Science & Analytics Lead at Flashpoint and co-inventor of the patented methodology.
"A vulnerability can score low on a traditional severity scale and still share the characteristics we repeatedly see in ransomware attacks."
For more information, visit the Flashpoint site.