NEW: Group Profiler — instant APT intel lookup. Try it →

Click your stack. See only what matters.

52 threat-intel feeds. Filter by vendor, severity, exploitation status, region, sector, and a selectable timeframe. Hourly updates. Free, no login.

New tool

Group Profiler

Look up APT groups, TTPs, and intel context in seconds.

How this works & data freshness

ThreatFilter pulls fresh advisories hourly from 52 public sources (CISA KEV, NVD, vendor PSIRTs, regional CERTs, and independent security press). The freshness dot in the header shows how recently a source was fetched.

Vendor / severity / exploitation / sector tagging shown here is currently heuristic — it is derived in your browser by matching each item's title and summary against a 349-vendor alias catalog with word-boundary keyword rules. It is intentionally conservative (no loose substring hits) but it is not a substitute for the dedicated ML classifier; treat tags as a strong hint, and always open the source for ground truth.

Use the filter bar to narrow by vendor, severity, exploitation status, region, and sector. The Timeframe control (24h · 48h · 7d · 30d · 90d · All, default 7 days) sets how far back the feed reaches — picking a longer window fetches deeper history, not just the most recent items. Counts on each tile reflect the loaded window of items, not all-time.

Pick your vendors

optional · narrow the feed to your stack
Timeframe
Severity
Status
?

Boolean search syntax

  • cisco vpn — both words must appear (implicit AND)
  • cisco OR fortinet — either word
  • cisco AND vpn NOT ios — combine; NOT excludes
  • "zero day" — exact phrase in quotes
  • (rce OR "remote code") AND linux — parenthesised groups
  • cve-2024 — plain words still substring-match for back-compat

Case-insensitive. Operators are case-sensitive (must be uppercase).

loading…

●

The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions. The post New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining appeared first on Secu…

securityweek

●

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involv…

thehackernews

●

The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents a…

thehackernews

●

OpenAI’s CEO said there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.” The post OpenAI Says Its Models Engaged With US Government We…

securityweek

●

Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts…

thehackernews

●

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) ca…

thehackernews

●

Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber a…

thehackernews

●

Unit 42 security experts address critical cybersecurity misconceptions, offering practical insights to help your organization reinforce its enterprise defenses. The post 3 Consulting Myths Debunked by…

unit42

●

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced t…

krebs-on-security

●

I feel like someone who reads this blog will want to go to this: Families are invited to dive into the fascinating world of marine biology during an exciting, hands-on Family Squid Dissection at the H…

schneier

●

Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to …

the-record

●

Security changes include creating an incident response plan for vendor security failings, limiting how much data Labcorp shares with vendors and building an expansive risk management team charged with…

the-record

●

When autonomous AI agents "escape the sandbox," the real story isn't rogue machines — it's the same access-control failures we've seen for decades.

darkreading

●

In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from Google Gemini models breaking containment to ShinyHunters ratting on TeamPCP hackers.

darkreading

●

Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and prov…

microsoft-security-blog

●

The CEO said the company has a User Protection Fund that has over $464 million and those funds will be used to cover the losses.

the-record

●

Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul. The post In Othe…

securityweek

●

The platform is adding new checks as AI makes profiles easier to forge. But scammers can still invent a company to recruit for.

malwarebytes-labs

●

Dyfed-Powys Police in Wales said a cyberattack affecting the force disrupted some non-emergency systems and may have compromised staff information.

the-record

●

Kothamine uses a legitimate Tailscale tool to receive attackers’ commands through an encrypted connection with no malicious domain to block.

malwarebytes-labs

●

Training human-resource managers in the latest tactics and warning signs goes a long way toward blunting the threat, but automated analysis can help even more.

darkreading

●

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign…

thehackernews

●

rapid7-blog

●

Bitget’s security systems caught the unauthorized transfers on September 24, and some wallet addresses linked to the attacker have been frozen. The post North Korea Suspected in $351 Million Bitget Cr…

securityweek

●

Introduction As an update to the June 2026 post, ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit, Mandiant and Google Threat Intelligence Group (GTIG) have identified renewed mass…

mandiant-blog