Xploitwire uses software tools as part of how articles get researched, drafted, and checked. Here's what that involves.
How articles are produced
Source reporting — RSS coverage from established security/tech outlets, or structured vulnerability data from CISA, NVD, and GitHub Security Advisories — is rewritten into an original Xploitwire article: headline, narrative structure, framing, and analysis. A category, tags, and a photo are also selected for each piece.
How articles are checked
Before publication, every draft is compared against its source text and checked for any claim, quote, number, or link that isn't traceable back to it. Findings are categorized by severity — a fabricated fact, quote, or number blocks publication outright; lower-severity issues (like a date reference that isn't precisely grounded) can also block publication depending on the check. Numeric claims (CVE IDs, dollar figures, percentages) go through an additional deterministic check.
Editorial oversight
Xploitwire is founded and edited by Iliyas, who sets the editorial policies and confidence-labeling rules this runs under - the fact-checking thresholds, source-corroboration requirements, and correction process described on this page and in our Editorial Policy.
Limitations
Individual articles are not read one-by-one by a human editor before they go live - a story publishes once a draft passes its checks, under the policies above. We don't currently contact companies for comment before publishing, and legal review isn't performed on every story before publication. Stories involving named individuals or accusations of wrongdoing are flagged internally for a human to follow up on comment/legal review, but that follow-up happens after publication, not before.
Confidence labeling
Every article carries a confidence label — Confirmed, Developing, or Unverified — derived automatically from how the story is sourced (an official advisory or vendor statement, versus a single outlet's as-yet-uncorroborated report). See our Editorial Policy for exactly how each label is determined.
Why we do it this way
Full automation lets us cover a much broader range of stories than a small team could manually report. We think that's only defensible if we're honest about the tradeoff — hence labeling every story's confidence level, disclosing our automation plainly, and logging corrections publicly rather than quietly editing mistakes away.