{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-438-separate-original-and-current-device-impact-in-the-vulnerability-event-timeline/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-438-separate-original-and-current-device-impact-in-the-vulnerability-event-timeline/",
        "slug": "dse-20260909-438-separate-original-and-current-device-impact-in-the-vulnerability-event-timeline",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-438-separate-original-and-current-device-impact-in-the-vulnerability-event-timeline/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-438-separate-original-and-current-device-impact-in-the-vulnerability-event-timeline.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-438-separate-original-and-current-device-impact-in-the-vulnerability-event-timeline/"
        },
        "title": "Separate original and current device impact in the vulnerability event timeline",
        "summary": "Does a vulnerability event's original affected-device count describe the devices still affected now?",
        "format": {
            "slug": "explainer",
            "name": "Explainer"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:24:38+00:00",
        "modified_at": "2026-09-10T02:04:57+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 253,
        "potentially_affected": "Microsoft Defender Vulnerability Management Event timeline investigations.",
        "dse_recommendation": "Use the current impact column for present work and retain original impact as historical context.",
        "primary_source": {
            "name": "Event timeline - Microsoft Defender Vulnerability Management | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-vulnerability-management/threat-and-vuln-mgt-event-timeline",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Defender Vulnerability Management&#8217;s Event timeline distinguishes the devices affected when an event occurred from those affected now. The current-impact column can be added through Customize columns. The two headline totals count new and exploitable vulnerabilities, not timeline events: one event can involve several vulnerabilities, and one vulnerability can appear in several events. <a href=\"https://learn.microsoft.com/en-us/defender-vulnerability-management/threat-and-vuln-mgt-event-timeline\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<p>Selecting an event opens its details and current CVEs affecting devices, with a route to the associated security recommendation. The timeline includes vulnerability publications, exploit developments and configuration assessments. <a href=\"https://learn.microsoft.com/en-us/defender-vulnerability-management/threat-and-vuln-mgt-event-timeline\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this distinction in Microsoft Defender Vulnerability Management Event timeline investigations. Keep the date being investigated and the time of the current observation visible; this brief does not treat the timeline as a list of confirmed local attacks.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends recording original and current impact in separate fields when an event becomes a remediation work item. Use the current population to identify remaining work, while preserving the original value to explain the event&#8217;s initial significance. Avoid adding event counts to vulnerability totals or interpreting a repeated vulnerability as several independent weaknesses. Follow the specific recommendation rather than acting from a headline number alone.</p>\n<h2>Verification</h2>\n<p>Open a representative event, expose its current-impact column and compare the linked device and CVE details with the proposed work item. Confirm that the event date and observation time are not being conflated. After an approved remediation, review the current affected population again and retain unresolved devices explicitly without rewriting the historical impact.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-vulnerability-management/threat-and-vuln-mgt-event-timeline\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Event timeline</a>.</p>",
        "content_text": "Source facts\nDefender Vulnerability Management’s Event timeline distinguishes the devices affected when an event occurred from those affected now. The current-impact column can be added through Customize columns. The two headline totals count new and exploitable vulnerabilities, not timeline events: one event can involve several vulnerabilities, and one vulnerability can appear in several events. Microsoft Learn.\nSelecting an event opens its details and current CVEs affecting devices, with a route to the associated security recommendation. The timeline includes vulnerability publications, exploit developments and configuration assessments. Microsoft Learn.\nApplicability\nUse this distinction in Microsoft Defender Vulnerability Management Event timeline investigations. Keep the date being investigated and the time of the current observation visible; this brief does not treat the timeline as a list of confirmed local attacks.\nDSE recommendation\nDSE recommends recording original and current impact in separate fields when an event becomes a remediation work item. Use the current population to identify remaining work, while preserving the original value to explain the event’s initial significance. Avoid adding event counts to vulnerability totals or interpreting a repeated vulnerability as several independent weaknesses. Follow the specific recommendation rather than acting from a headline number alone.\nVerification\nOpen a representative event, expose its current-impact column and compare the linked device and CVE details with the proposed work item. Confirm that the event date and observation time are not being conflated. After an approved remediation, review the current affected population again and retain unresolved devices explicitly without rewriting the historical impact.\nOfficial references\nMicrosoft Learn: Event timeline.",
        "content_markdown": "## Source facts\n\nDefender Vulnerability Management’s Event timeline distinguishes the devices affected when an event occurred from those affected now. The current-impact column can be added through Customize columns. The two headline totals count new and exploitable vulnerabilities, not timeline events: one event can involve several vulnerabilities, and one vulnerability can appear in several events. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-vulnerability-management/threat-and-vuln-mgt-event-timeline).\n\nSelecting an event opens its details and current CVEs affecting devices, with a route to the associated security recommendation. The timeline includes vulnerability publications, exploit developments and configuration assessments. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-vulnerability-management/threat-and-vuln-mgt-event-timeline).\n\n## Applicability\n\nUse this distinction in Microsoft Defender Vulnerability Management Event timeline investigations. Keep the date being investigated and the time of the current observation visible; this brief does not treat the timeline as a list of confirmed local attacks.\n\n## DSE recommendation\n\nDSE recommends recording original and current impact in separate fields when an event becomes a remediation work item. Use the current population to identify remaining work, while preserving the original value to explain the event’s initial significance. Avoid adding event counts to vulnerability totals or interpreting a repeated vulnerability as several independent weaknesses. Follow the specific recommendation rather than acting from a headline number alone.\n\n## Verification\n\nOpen a representative event, expose its current-impact column and compare the linked device and CVE details with the proposed work item. Confirm that the event date and observation time are not being conflated. After an approved remediation, review the current affected population again and retain unresolved devices explicitly without rewriting the historical impact.\n\n## Official references\n\n[Microsoft Learn: Event timeline](https://learn.microsoft.com/en-us/defender-vulnerability-management/threat-and-vuln-mgt-event-timeline)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-438-separate-original-and-current-device-impact-in-the-vulnerability-event-timeline/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-438-separate-original-and-current-device-impact-in-the-vulnerability-event-timeline/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-438-separate-original-and-current-device-impact-in-the-vulnerability-event-timeline/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Separate original and current device impact in the vulnerability event timeline",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-438-separate-original-and-current-device-impact-in-the-vulnerability-event-timeline/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-438-separate-original-and-current-device-impact-in-the-vulnerability-event-timeline/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-438-separate-original-and-current-device-impact-in-the-vulnerability-event-timeline/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-438-separate-original-and-current-device-impact-in-the-vulnerability-event-timeline/",
                "headline": "Separate original and current device impact in the vulnerability event timeline",
                "description": "Does a vulnerability event's original affected-device count describe the devices still affected now?",
                "abstract": "Does a vulnerability event's original affected-device count describe the devices still affected now?",
                "articleBody": "Source facts\nDefender Vulnerability Management’s Event timeline distinguishes the devices affected when an event occurred from those affected now. The current-impact column can be added through Customize columns. The two headline totals count new and exploitable vulnerabilities, not timeline events: one event can involve several vulnerabilities, and one vulnerability can appear in several events. Microsoft Learn.\nSelecting an event opens its details and current CVEs affecting devices, with a route to the associated security recommendation. The timeline includes vulnerability publications, exploit developments and configuration assessments. Microsoft Learn.\nApplicability\nUse this distinction in Microsoft Defender Vulnerability Management Event timeline investigations. Keep the date being investigated and the time of the current observation visible; this brief does not treat the timeline as a list of confirmed local attacks.\nDSE recommendation\nDSE recommends recording original and current impact in separate fields when an event becomes a remediation work item. Use the current population to identify remaining work, while preserving the original value to explain the event’s initial significance. Avoid adding event counts to vulnerability totals or interpreting a repeated vulnerability as several independent weaknesses. Follow the specific recommendation rather than acting from a headline number alone.\nVerification\nOpen a representative event, expose its current-impact column and compare the linked device and CVE details with the proposed work item. Confirm that the event date and observation time are not being conflated. After an approved remediation, review the current affected population again and retain unresolved devices explicitly without rewriting the historical impact.\nOfficial references\nMicrosoft Learn: Event timeline.",
                "datePublished": "2026-09-10T00:24:38+00:00",
                "dateModified": "2026-09-10T02:04:57+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-438-separate-original-and-current-device-impact-in-the-vulnerability-event-timeline/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-438-separate-original-and-current-device-impact-in-the-vulnerability-event-timeline/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Separate original and current device impact in the vulnerability event timeline"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Explainer",
                    "Information priority"
                ],
                "genre": "Explainer",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 253,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Event timeline - Microsoft Defender Vulnerability Management | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-vulnerability-management/threat-and-vuln-mgt-event-timeline"
                }
            }
        ]
    }
}