Introduction:
Cybersecurity forecasting requires timely signals that reveal how public threat visibility changes before these signals are formalised in incident repositories, vulnerability databases, or institutional risk assessments. This study develops a forecast-ready cyber threat salience framework that transforms global cybersecurity news metadata into temporal, thematic, and source-aware indicators for cyber risk monitoring.
Methods:
The study analyses 18,307 usable cybersecurity news records collected between 3 October 2023 and 2 June 2026. Temporal analysis uses 18,263 complete month records across 32 months, derived from 190 source domains, 18,248 unique title strings, and 17,922 unique URLs. The framework combines title level multi label thematic coding, monthly aggregation, early to late salience comparison, Jensen–Shannon divergence, and source concentration metrics. Eleven cyber threat themes were measured, including vulnerabilities and exploits, malware and botnets, AI security, nation state activity, phishing, data breaches, ransomware, cloud and identity, critical infrastructure, supply chain compromise, and cryptocurrency-related risks.
Results:
Cybersecurity reporting behaved as an episodic forecasting signal, with a 3.4-fold difference between the highest and lowest complete month volumes. The most visible theme was vulnerabilities and exploits, appearing in 2,816 records, or 15.4% of usable records, followed by malware and botnets with 1,509 records and AI security with 1,407 records. Late period salience increased most strongly for vulnerabilities and exploits, from 13.5% to 21.3%, and AI security, from 6.0% to 13.6%, while ransomware declined from 5.8% to 1.6%. Source concentration was high, with the top five domains contributing 60.9% of all records.
Conclusions:
The framework supports cyber forecasting by converting public cybersecurity reporting into measurable salience signals for horizon scanning, AI security monitoring, and source-aware cyber risk intelligence.