●
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a …
52 threat-intel feeds. Filter by vendor, severity, exploitation status, region, sector, and a selectable timeframe. Hourly updates. Free, no login.
Look up APT groups, TTPs, and intel context in seconds.
ThreatFilter pulls fresh advisories hourly from 52 public sources (CISA KEV, NVD, vendor PSIRTs, regional CERTs, and independent security press). The freshness dot in the header shows how recently a source was fetched.
Vendor / severity / exploitation / sector tagging shown here is currently heuristic — it is derived in your browser by matching each item's title and summary against a 349-vendor alias catalog with word-boundary keyword rules. It is intentionally conservative (no loose substring hits) but it is not a substitute for the dedicated ML classifier; treat tags as a strong hint, and always open the source for ground truth.
Use the filter bar to narrow by vendor, severity, exploitation status, region, and sector. The Timeframe control (24h · 48h · 7d · 30d · 90d · All, default 7 days) sets how far back the feed reaches — picking a longer window fetches deeper history, not just the most recent items. Counts on each tile reflect the loaded window of items, not all-time.
Boolean search syntax
cisco vpn — both words must appear (implicit AND)cisco OR fortinet — either wordcisco AND vpn NOT ios — combine; NOT excludes"zero day" — exact phrase in quotes(rce OR "remote code") AND linux — parenthesised groupscve-2024 — plain words still substring-match for back-compatCase-insensitive. Operators are case-sensitive (must be uppercase).
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a …
A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. Thi…
A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected device to execute arbitrary code with root pri…
A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an unauthenticated, remote attacker to cause the device manager, SSH…
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected devi…
A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-sid…
A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted…
With the new Advanced Flow for sideloading being rolled out, it's time to discuss what sideloading is and how to do it more safely.
Cloud providers typically expose a REST API at 169.254.169.254 that allows code running on virtual machines to retrieve machine-specific data. Some of the data is more or less harmless, such as the re…
Oracle released its August edition of Critical Patch Update. The update received patches for 943 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one pro…
Latvia’s road traffic agency confirmed that hackers stole data connected to about two-thirds of the country’s population in a major cyberattack that has prompted calls for senior officials to resign.
CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained. The post Virtual Event To…
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) famil…
The Justice Department accused 17 alleged hackers with ties to the Iranian government of breaching email accounts at U.S. government agencies and stealing intellectual property from dozens of universi…
Cássio De Alcântara is Director, LATAM Sales at Rapid7.Across Latin America, organizations are embracing cloud, AI, and digital transformation to drive innovation and business growth. These technologi…
Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All …
The previously bootstrapped company helps organizations securely and reliably operate AI agents at scale. The post Prevalent AI Raises $22 Million to Expand Data Fabric Platform appeared first on Secu…
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two auth…
The 17 members of the Mabna Institute targeted hundreds of universities and organizations in the US and abroad. The post US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them appeare…
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It st…
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stole…
The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision. The post Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign appe…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited i…
We found wallet-checking sites impersonating real anti-money laundering services that trick people into approving access to scammers.
No items match. Try widening filters or clearing region.
Couldn't reach the feed
The advisory API didn't respond. It's usually a brief hiccup — give it a moment and try again.