Flashpoint Awarded Patent for Ransomware Risk Model That Scores Vulnerabilities at Disclosure
Flashpoint received U.S. Patent No. 12,705,360 on August 11, 2026, covering the methodology behind its Ransomware Risk score, a model that rates newly disclosed vulnerabilities by how closely they resemble vulnerabilities already confirmed in ransomware attacks [2]. The model has been available inside Flashpoint Vulnerability Intelligence (VI) since 2022 [2]. The patent formalizes what the company has been shipping for four years and signals that the underlying scoring methodology is now protected intellectual property.
The timing of the patent announcement matters for one specific reason: Flashpoint reported a 45% increase in Ransomware-as-a-Service attacks in the first half of 2026 [2][5]. RaaS operators do not select vulnerabilities randomly. They target technical conditions that make exploitation fast, repeatable, and scalable across affiliate networks. A generic CVSS score tells you nothing about that operational preference.
The Problem With CVSS for Ransomware Prioritization
CVSS measures theoretical severity. It does not measure attacker intent or operational preference. That distinction has real consequences for vulnerability management teams trying to reduce exposure to ransomware specifically.
Traditional CVE and NVD data is unaware of nearly a third of known vulnerability risk and lacks the contextual metadata needed to triage extortion events effectively [1]. VulnDB, Flashpoint's vulnerability database built through its Risk Based Security subsidiary, covers more than 300,000 known vulnerabilities, including over 96,000 flaws absent from NVD entirely [3][4]. A team relying exclusively on NVD for patch prioritization is working from an incomplete picture by definition.
The gap between "this vulnerability is severe" and "ransomware actors will use this vulnerability" is where organizations get burned. CVSS was designed for general risk communication. RaaS groups are not general threat actors. They have toolchains, affiliate structures, and specific technical requirements.
How the Patented Model Works
The Ransomware Risk model analyzes more than 60 vulnerability characteristics at the time of disclosure [2]. It compares a newly disclosed flaw against the profile of vulnerabilities with confirmed ransomware exploitation history and outputs a score reflecting how closely that flaw matches known ransomware-targeted conditions.
The intent is to deliver a usable signal the moment a vulnerability is disclosed, before exploitation reports arrive weeks or months later [2][5]. That early signal is where the operational value sits. Patch prioritization decisions made before active exploitation pressure are structurally less expensive than decisions made under incident conditions.
Josh Lefkowitz, Co-Founder and CEO of Flashpoint, described the core problem the model addresses: "A severity score alone can't tell you which vulnerabilities pose the greatest real-world risk of exploitation by ransomware actors" [2][5]. The model applies accumulated threat intelligence data against that specific question rather than the broader severity question CVSS answers.
The Vulnerability Volume Problem
The volume of CVEs published annually has made triage a resource problem as much as a technical one. Jake Kouns, then CEO of Risk Based Security, framed the model's purpose plainly when it launched in 2022: "Our intention is to take 300,000 vulnerabilities and lens them down to the ones you can fix" [3].
Organizations with smaller security teams feel this pressure most acutely. A ranked list of 20,000 high or critical CVSS scores is not actionable. A list filtered to the vulnerabilities that match the operational profile of ransomware groups provides a materially different starting point for a patch cycle.
The Ransomware Risk score does not replace other prioritization signals. It adds a ransomware-specific layer that CVSS, EPSS, and vendor severity ratings do not provide on their own.
Ransomware Economics Make This Signal Worth Having
U.S. financial institutions filed $1.2 billion in ransomware-related costs in 2021, nearly double the 2020 figure, according to U.S. Treasury data [4][7]. The FBI reported a 62% increase in ransomware events compared to 2021 [1]. CISA has confirmed ransomware attacks against 14 of 16 critical U.S. infrastructure sectors [1].
At those volumes and costs, the operational question for vulnerability management is no longer whether to prioritize ransomware-relevant flaws but how to identify them accurately at scale. The Flashpoint model is one answer to that specific question.
Flashpoint also monitors threat actor discussions in illicit communities to provide early warning of attack planning, complementing the vulnerability-side scoring with demand-side intelligence from RaaS forums and affiliate chatter [6].
Analysis
Patenting the scoring methodology is a commercial move as much as a technical one. Flashpoint is staking a proprietary claim on a specific approach to ransomware-driven vulnerability prioritization. Competitors building similar scoring systems will now face IP friction if their methodology is too similar. For buyers evaluating threat intelligence platforms, the patent signals that Flashpoint considers this model a durable differentiator rather than a feature that can be easily replicated.
The model's limitation, which the sources do not address directly, is that it is backward-looking by design. It compares new vulnerabilities against confirmed ransomware exploitation history. Novel attack paths that do not resemble prior ransomware techniques would not score highly until exploitation data accumulates. That is a structural constraint of any similarity-based scoring approach, and procurement teams should account for it.
The 45% RaaS increase Flashpoint observed in the first half of 2026 is the more pressing data point. RaaS affiliate programs lower the technical barrier for exploitation. When affiliates can pick from a menu of proven techniques and pre-built toolkits, the vulnerabilities that score high on a ransomware similarity model become higher-probability targets faster than they would in a world of independent threat actors.
Takeaway
Vulnerability management teams running CVSS-only prioritization are missing a specific signal about attacker operational preference. The Flashpoint Ransomware Risk model, now patented under U.S. Patent No. 12,705,360, fills that gap by scoring disclosures against confirmed ransomware exploitation profiles across more than 60 characteristics. With RaaS activity up 45% in early 2026, the window between disclosure and active exploitation is narrowing for the flaws ransomware operators prefer. Teams that can filter to those flaws earlier in the disclosure cycle are better positioned to patch before that window closes.
Red Sheep Assessment
The patent matters less as a legal instrument than as a market signal: Flashpoint is betting that ransomware-specific vulnerability scoring will become a required layer in enterprise vulnerability management programs, not an optional add-on. If that assessment is correct, expect other threat intelligence vendors to either license similar methodology or ship competing models within the next 18 months. Confidence: moderate. The underlying demand is clear, but the market has been slow to move beyond CVSS despite years of evidence that CVSS alone is insufficient for operational prioritization.
Sources
- Preventing Future Ransomware Attacks With Flashpoint Vulnerability Intelligence - https://flashpoint.io/blog/vulndb-prevent-ransomware-attacks/
- Flashpoint Patents Ransomware Risk Model (PRWeb) - https://www.prweb.com/releases/flashpoint-patents-ransomware-risk-model-that-helps-security-teams-prioritize-the-vulnerabilities-ransomware-groups-are-most-likely-to-target-302895819.html
- Flashpoint launches new ransomware prediction model (TechTarget) - https://www.techtarget.com/cybersecurity/news/252527183/Flashpoint-launches-new-ransomware-prediction-model
- Flashpoint Releases Ransomware Prediction Model for Vulnerabilities (Dark Reading) - https://www.darkreading.com/cyber-risk/flashpoint-releases-ransomware-prediction-model-for-vulnerabilities
- Flashpoint Patents Ransomware Risk Model (VMBlog) - https://vmblog.com/news/flashpoint-patents-ransomware-risk-model-that-helps-security-teams-prioritize-the-vulnerabilities-ransomware-groups-are-most-likely-to-target/
- Ransomware and Data Extortion (Flashpoint) - https://flashpoint.io/intelligence-solutions/ransomware/
- Flashpoint releases a new ransomware prediction model (Security Brief Asia) - https://securitybrief.asia/story/flashpoint-releases-a-new-ransomware-prediction-model
- Threat Readiness and Response (Flashpoint) - https://flashpoint.io/services/ransomware/