ThreatWire publishes vulnerabilities, public proof-of-concept status, exploit status, and security reporting. The point of the site is to make those into separate, readable facts.
A record names the CVE, the affected products, the fixed versions, the CVSS score, the CWE, and the primary sources. It also names what we do not know. Unknown is a valid published state. Active exploitation is not inferred from a GitHub link, a rumor, or a leak-site claim.
The editor lives with the content. Articles and CVE records are files in this repository. Publishing is a status and a date, not a deploy script you edit by hand. Drafts stay private. A future date stays private until it arrives.
Feeds from NVD, CISA KEV, GitHub advisories, vendor pages, researchers, and X can be added later. They will be allowed to propose drafts. They will not be allowed to publish.
Short updates belong on X. Anything that needs a severity, a status, and a source belongs here.