Flashpoint Secured Patent for Ransomware Scoring Model
The firm patented a system that evaluates vulnerability risk using patterns from active ransomware campaigns.
Updated on Oct. 1, 2026 in Cybersecurity

Live Poll
Do you trust specialized risk scoring models to identify which software security patches matter most?
The U.S. Patent and Trademark Office granted U.S. Patent No. 12,705,360 to Flashpoint on August 11, 2026, for its methodology in scoring ransomware risk. This system, which has been in operation since 2022, identifies potential threats by profiling vulnerabilities against real-world attack data.
Why it matters
As ransomware attacks rose by 45% during the first half of 2026, organizations face increasing pressure to prioritize defensive resources. This scoring model helps security teams isolate vulnerabilities that mirror the characteristics of confirmed ransomware exploits.
Flashpoint utilizes 60 distinct technical factors to profile vulnerabilities and calculates their risk based on spatial proximity to known ransomware vectors. The intelligence platform tracks over 105,000 vulnerabilities not currently indexed in standard CVE or NVD databases.
The players
Flashpoint
A threat intelligence company that provides vulnerability monitoring, risk assessment, and dark web surveillance tools.
U.S. Patent and Trademark Office
The federal agency responsible for evaluating and granting intellectual property rights for new inventions.
The details
The system identifies risks by mapping vulnerabilities into clusters based on shared attributes found in previous ransomware attacks. By analyzing the structural similarities between a new vulnerability and confirmed exploit vectors, the model assigns a risk rating to guide patching decisions. This approach contrasts with standard scoring systems by focusing specifically on the high-probability threats that characterize current ransomware campaigns.
Timeline
2022: Flashpoint launched the Ransomware Risk scoring model.
H1 2026: Ransomware attacks rose by 45% period-over-period.
August 11, 2026: U.S. Patent No. 12,705,360 was granted.
The Tech Race
Flashpoint differentiates its security stack by tracking 105,000 vulnerabilities that lie outside the standard National Vulnerability Database indexing process. This move aligns with a broader industry effort to move beyond public vulnerability disclosures toward predictive risk modeling.
Security teams currently utilizing the Flashpoint intelligence platform can incorporate this scored vulnerability data into their automated patching workflows. Organizations without access to this proprietary data rely on traditional CVE-based prioritization, which lacks these specific ransomware-focused metrics.
The takeaway
Security leaders should evaluate how proprietary risk models integrate with their existing vulnerability management dashboards to combat rising attack volumes. Watch for future updates to the Flashpoint intelligence platform regarding how these 60 technical factors adjust to shifting exploit patterns.
Further reading
For more on the current state of threat intelligence, see our full coverage in Cybersecurity.
Live Poll
Do you trust specialized risk scoring models to identify which software security patches matter most?









