A municipal SOC learns of emerging VPN appliance flaws from open-source intel, an ISAC bulletin, and a paid feed, then raises patch priority for city remote-access gateways. What vulnerability-management practice is the team applying?
Select an answer to reveal the explanation.
Short Explanation
Threat feeds are the early-warning radio for city IT—OSINT, ISACs, and commercial intel tip you off that a VPN bug is hot, so you bump those boxes up the queue. You are folding outside intel into how you find and prioritize vulns, not shutting remote access forever or waiting a year.
Full Explanation
Threat feeds—including OSINT, information-sharing communities such as ISACs, and proprietary intelligence—surface emerging CVEs and exploit activity that help teams identify and prioritize exposures. Municipal remote-access infrastructure is a common high-value target, so feed-driven prioritization improves vulnerability management responsiveness. Annual scans alone or unrelated password campaigns do not replace intelligence-informed triage.