Flashpoint awarded patent for ransomware risk model
Flashpoint has received U.S. Patent No. 12,705,360 for its methodology that assesses the risk of newly disclosed vulnerabilities being targeted by ransomware groups.

Threat intelligence company Flashpoint announced it has been awarded U.S. Patent No. 12,705,360 for its Ransomware Risk model methodology. The patent, granted in August 2026, covers a method that rates newly disclosed vulnerabilities based on their similarity to vulnerabilities known to be exploited in ransomware attacks. This aims to help security teams prioritize patching efforts as soon as a flaw is disclosed.
Traditional vulnerability scoring systems, such as CVSS, measure potential severity but not the likelihood of exploitation. This gap is particularly significant with ransomware, which saw a 45% increase in attacks in the first half of 2026. Flashpoint's model provides security teams with a ransomware-specific signal that can be acted upon immediately after a vulnerability is disclosed, bypassing the weeks-long wait for exploitation reports.
The patented model analyzes over 60 technical characteristics of each vulnerability. These characteristics are mapped and compared against clusters of vulnerabilities historically used in real-world ransomware incidents. Each new vulnerability is then assigned a risk rating—Low, Medium, High, or Critical—based on its proximity to these identified ransomware exploitation patterns.
Flashpoint states that this model allows organizations to more effectively prioritize their patching strategies. A vulnerability with a low score in traditional severity metrics might still be identified as a high ransomware risk by this model, potentially preventing organizations from being caught off guard by evolving threats. The Ransomware Risk score has been available within Flashpoint Vulnerability Intelligence since 2022.