Building a Cybersecurity News Aggregator: Story Clustering, Seven Importance Signals and Strict Filtering Thresholds
The concept of a dedicated information security news aggregator originated several years ago. The objective was to receive only the most important developments without information noise.
Initial implementations used the rut5_base_sum_gazeta summarization model together with TextRank for importance ranking, yet results were inconsistent. Later commercial services that curate feeds still failed to balance breadth and relevance, often covering either everything or only narrow topics.
After weeks of prompt tuning proved ineffective, a hybrid architecture was adopted. Importance is now calculated by a formula consisting of seven explicit, logged features whose weights can be inspected and adjusted. A language model performs two supporting tasks: filtering out non-relevant items and generating readable text.
Core data flow and filtering funnel
Approximately one thousand materials arrive daily from more than 200 sources. Only around 0.5 percent reach publication. The first stage applies the seven-feature formula; the second stage uses the model to discard irrelevant content.
Seven importance features
- Confirmation β number of independent outlets covering the same event
- Severity β CVSS score above 9 receives maximum weight; active exploitation in the wild grants full weight regardless of CVSS
- Primary source β presence of a CERT, KEV catalog entry, or original vendor research
- Reader proximity β Russian company or Russian-context stories receive higher weight
- Analysis depth β detailed technical breakdowns and novel attack classes score higher
- Authority β best source tier present in the cluster (primary, research, security media)
- Speed β time between first and last publication; one post per hour or faster earns full points
Penalties are subtracted for vacancies, webinars, awards, and vendor self-promotion unless an independent outlet later confirms the story.
Story clustering methods
Materials describing the same incident are merged into a single story using three decreasingly strict techniques: shared CVE, GHSA, Microsoft KB or BDU identifiers; overlapping trigrams within the same language; and shared named entities such as Microsoft, SharePoint or Fortinet that link Russian and English reports.
Related articles
Why Russian Educators Prepare Sixth Graders for Ninth-Grade All-Russian Olympiads in Robotics and Information Security
Maxim Ivankov, who has run robotics and programming schools for children for nine years in a small Russian town, explains the decision to train students starting from fifth grade for the All-Russian Olympiad for Schoolchildren in the ninth-grade category. The strategy addresses the fact that regional and final stages begin only at ninth grade, while earlier participation yields only certificates with no benefits such as BVI university admission or regional prizes. The approach gives students up to five attempts instead of one, allowing systematic skill building similar to consistent athletic training. Challenges include extremely low enrollment despite free classes and widespread use of neural networks to solve school-stage tasks remotely, which distorts results and lacks regulatory prohibitions. The 2025/26 season introduced four separate profiles under informatics, including information security and robotics, both of which grant the same BVI privileges as mathematics or physics. Detailed analysis of past tasks shows a steep difficulty jump from municipal to regional stages, with topics such as the RANSAC algorithm and ten-dimensional hypercube traversal appearing only at the final level.
Corporate Boomerang: WordPress Founder Matt Mullenweg Survives Board Coup at Automattic
Automattic experienced a rapid corporate power struggle when its board placed founder and CEO Matt Mullenweg on forced paid leave. Within two days Mullenweg regained control by leveraging his shareholder voting rights and removed opposing administrators from the company Slack. The original board members who supported his ouster are now departing the company. The brief conflict highlighted how corporate governance rules allowed shareholders to ultimately determine board composition. Mullenweg described his restored position as that of a pirate before announcing renewed alignment with the board. Public support from WordPress leadership helped solidify his return to leadership.
Russian Transport Ministry Ready to Provide Regulatory Framework for Poplar Fluff Vacuum Robots
The Russian Ministry of Transport has signaled readiness to develop necessary regulations if municipal services express interest in specialized robots designed to collect poplar fluff from city streets. The statement from Minister Andrey Nikitin follows a viral meme that originated from a two-year-old video created by the agency Out Digital. Although no real machines called ΠΏΡΡ ΠΎΡΠΎΡ exist and no serial production has been launched, the fictional concept gained widespread attention after being presented as an actual Moscow development. The Department of Housing and Utilities in Moscow playfully expanded the joke by introducing additional fictional devices named Zasosyor, Musorozhor, and Gazonyukh. Linguistic experts at Gramota.ru later analyzed the newly coined term, further amplifying the meme's reach across Russian media and social networks. The minister emphasized that any future regulatory support would depend entirely on demand from communal services rather than proactive development by the ministry itself.
Context is Everything: How to Avoid Drowning in Security Incidents and Distinguish Employees from Attackers
The article explains that false positives in security systems often stem from missing business context rather than technical flaws. It outlines three levels of filtering that combine process rules, access logs, and job-specific behavior to rank risk accurately. Behavioral analysis tools like UEBA can help but require proper training and human oversight to avoid generating more noise. Key metrics focus on reducing false alerts, improving MTTD and MTTR, and minimizing daily administration time. For smaller companies without dedicated SOC teams, the guidance emphasizes starting with log collection, identifying existential risks, and aligning policies with real business processes. The piece stresses that technology alone cannot replace analysts who deeply understand company operations.