Verisight Help Center Support ticket Open portal

Stack Watch

Get one daily email when software you run is affected by a new vulnerability or found to be malicious.

Stack Watch keeps an inventory of the software you run and checks it every day against new vulnerabilities, actively exploited flaws and malicious-package reports. Available on every paid plan.

What you can watch

  • Products from the catalogue: firewalls, VPNs, email servers, CMSs and other common products (FortiOS, Microsoft Exchange, Citrix…). Add the version you run if you can. Without it, you hear about every advisory for the product, not just those affecting your version.
  • Every lockfile and manifest in Settings → Software, the same files used by the Supply Chain Check. Uploaded files keep being watched after the one-off check.
Plan Watched items
Essentials 50
Managed 250
vCISO Unlimited

One catalogue product or one uploaded file counts as one item.

Where the intelligence comes from

  • OSV.dev, including GitHub advisories and the OpenSSF malicious-packages feed, for open-source packages;
  • NVD for CVEs affecting catalogue products;
  • CISA KEV, the list of vulnerabilities known to be exploited;
  • EPSS scores, to rank by likelihood of exploitation.

Only public product and package names and versions are looked up. Nothing identifying your organization is sent.

Alerts

  • The first time you add something, current matches are a baseline. They're shown on the page, but emailed only if they're malicious, actively exploited or critical at your known version.
  • After that, each daily check sends at most one email with everything new, actively exploited and malicious items first. Nothing new means no email.
  • A match is announced once. Re-uploading a file, or an upgrade that is still vulnerable to the same advisory, doesn't send it again.

On the Stack Watch page, Open advisories lists what currently affects you, with Exploited or malicious items called out.