Security RSS feeds
A curated, continuously-checked directory of 58 threat-intelligence feeds — national CERT advisories, vendor PSIRTs, CVE data and security news. Every entry below has its own section with the exact feed URL as a working link, what that source actually publishes, and its live fetch status, so you can click straight through or paste the URL into a reader, SIEM or script. 51 are actively polled every 30 minutes by ThreatFilter, so the status shown is real rather than aspirational.
Want them pre-filtered instead of raw? The live feed merges all of these and lets you filter by vendor, severity and sector, and /feed.xml gives you the merged result as a single RSS feed.
Download all 50 feeds as OPML One file, grouped into folders by category. Import it into Feedly, Inoreader, NetNewsWire, Thunderbird or any reader instead of copying 50 URLs by hand. Building something instead? /feeds.json has the whole catalogue as JSON, CORS-open, and each category below has its own OPML.
Feeds that block datacenter IPs
These publish a working feed, but refuse requests from cloud/datacenter egress — they return 403 to a server while serving the same URL fine from a home connection. If you are polling from AWS, Cloudflare Workers, a VPS or a CI job, these will fail and the feed URL is not the problem. This is measured from our own polling, not documented anywhere by the publishers.
- ACSC Australia —
https://www.cyber.gov.au/about-us/news/rssAkamai 403 to CF Workers egress (verified 2026-05-21). No public RSS alternative. - BleepingComputer —
https://www.bleepingcomputer.com/feed/HTTP 403
Security news & research (19) OPML
-
BleepingComputer
RSS not polledBleepingComputer's site-wide feed. It mixes breaking incident coverage (breaches, ransomware, extortion leaks) with practical technical write-ups and Windows security news, usually carrying more detail than mainstream outlets do. Because this is the whole-site feed rather than a security-only slice, expect some general software and consumer items alongside.
HTTP 403
-
Cisco Talos Intelligence
RSS not_modifiedCisco Talos's research blog. It covers malware analysis, campaign reporting, incident-response trends and the vulnerabilities Talos researchers find in third-party software, which is why it is worth taking even if you run no Cisco equipment. Technical and indicator-rich, and separate from the Cisco PSIRT advisory feed.
-
Dark Reading
RSS okDark Reading's site-wide RSS. Industry news, analysis and vendor-neutral commentary pitched as much at security leadership as at practitioners, including the business side: budgets, staffing, regulation and breach fallout. Useful as a context feed alongside the vendor research blogs.
-
ESET WeLiveSecurity
RSS okWeLiveSecurity is ESET's publication. It mixes accessible explainers written for a general audience with the ESET research team's technical APT and malware work, so depth varies a lot between items. The research posts are the reason to take it: named campaign write-ups, generally with indicators.
-
Google Threat Analysis Group
Atom okThe Google Security Blog, served as Atom. It is where the Threat Analysis Group publishes its public reporting on government-backed attackers, commercial spyware vendors and coordinated influence operations, but the feed is broader than TAG alone and also carries Google's other security engineering posts. Take it for state-sponsored targeting research and in-the-wild zero-day write-ups.
-
GreyNoise Labs
RSS not_modifiedGreyNoise runs a large sensor network that watches opportunistic internet scanning and exploitation attempts, and this blog is where they publish what it sees. That makes their posts unusually good at answering whether a new CVE is actually being sprayed at the internet, and from when. Take it if you need exploitation evidence rather than vulnerability announcements.
-
Group-IB Blog
RSS okGroup-IB's research blog. Their investigations follow the operators and the money as much as the malware: cybercrime groups, fraud and scam infrastructure, carding, and work alongside law enforcement. A different angle to the endpoint-vendor research blogs.
-
Krebs on Security
RSS okBrian Krebs's independent investigative blog. It runs long-form investigations into cybercrime, fraud infrastructure and the people operating it, frequently naming individuals and companies, rather than reporting vulnerability announcements. If you care about who is behind an operation more than which CVE they used, this is the feed.
-
Malwarebytes Labs
RSS okMalwarebytes Labs covers the consumer and small-business end of the threat landscape: scams, malvertising, stalkerware, browser threats and ransomware aimed at organisations with no security team, alongside deeper malware analysis. A useful counterweight to feeds written entirely for large enterprises.
-
Mandiant Blog
RSS okMandiant's research now publishes under Google Cloud, so this Google Cloud blog topic feed is the current home of what used to be the mandiant.com blog. It carries incident-response findings, threat-actor profiles under the UNC and APT naming Mandiant maintains, and campaign analysis aimed at IR and threat-intelligence teams. If you are hunting for a Mandiant RSS URL, this is the one that still resolves.
-
Palo Alto Unit 42
RSS not_modifiedUnit 42 is Palo Alto Networks' threat research and incident response team, and this is their research blog: malware analysis, actor tracking and IR case studies, often with indicators of compromise listed in the post itself. It is a different feed to the Palo Alto Networks PSIRT stream, which is where product advisories go.
-
SANS Internet Storm Center
RSS okThe SANS Internet Storm Center, in its full-text form (rssfeed_full.xml rather than the summary variant). Handler diaries are short operational notes on what is actually being observed: scanning surges, exploit attempts against fresh CVEs, odd samples and honeypot traffic. Very little else in this directory is observation rather than announcement, which makes it unusually good at answering “is this being exploited yet”.
-
Schneier on Security
Atom not_modifiedBruce Schneier's long-running blog, served as Atom. It is commentary and analysis on security, cryptography, privacy, surveillance and policy rather than an operational source, and posts routinely link out to research worth reading in full. Take it for framing and the policy angle, not for anything you would page an on-call engineer about.
-
Securelist (Kaspersky)
RSS not_modifiedSecurelist is Kaspersky's research blog: APT campaign reports, malware family teardowns, statistical roundups and incident analysis, generally with indicators included. The technical work is detailed and widely cited. Note the sourcing if your organisation has policy constraints on Kaspersky content, since several governments restrict it.
-
SecurityWeek
RSS not_modifiedSecurityWeek's main feed, covering breaches, vulnerabilities, funding rounds, acquisitions and the industry moves around them. The slant is enterprise and CISO oriented rather than reverse-engineering deep, so it pairs well with one or two of the research blogs listed here.
-
Sophos News — Threat Research
RSS okThe threat-research category of the Sophos blog specifically, so the URL path filters out the product and company posts on the same site. Expect incident-response case studies, ransomware and active-adversary analysis, and write-ups of the tooling seen in real intrusions.
-
The Hacker News
RSS okThe Hacker News, distributed through a FeedBurner address rather than a thehackernews.com one, which is the endpoint the publisher itself hands out. Broad coverage of breaches, vulnerabilities, malware and law-enforcement action, written short and for a general technical audience. Follow the links to primary sources before acting on any single item.
-
The Record by Recorded Future
RSS okThe Record is the news publication run by Recorded Future, written as journalism rather than vendor research. It covers breaches, ransomware, cybercrime prosecutions, sanctions and government cyber policy, with reporters who chase primary sources. Take it for the reporting; it is not an advisory feed and will not tell you what to patch.
-
Trend Micro Research
RSS okTrend Micro's research output, distributed through a FeedBurner address under the Simply Security name. It covers malware analysis, vulnerability research, and cloud, container and OT threats. Trend Micro also runs the Zero Day Initiative, listed separately in this directory, so the two together give you both the research and the coordinated-disclosure advisories.
National CERTs & government advisories (14) OPML
-
ACSC Australia
RSS not polledThe Australian Cyber Security Centre's news and advisory channel, run out of the Australian Signals Directorate, carrying alerts and guidance aimed at Australian organisations.
Retired: Akamai geo/UA-block returns 403 to Cloudflare Workers egress IPs (verified 2026-05-21). No public RSS alternative.
Akamai 403 to CF Workers egress (verified 2026-05-21). No public RSS alternative.
-
CERT-EU Security Advisories
RSS okThe official advisory feed of CERT-EU, the cyber security service for the European Union's institutions, bodies and agencies. Each item is a numbered CERT-EU advisory summarising a vulnerability or campaign, listing the affected products and a recommended action, written to be short and actionable rather than exhaustive. If you want the European counterpart to CISA's advisory stream in your reader, this is the URL.
-
CERT-FR Alertes
RSS not_modifiedCERT-FR's “alerte” feed, the escalated half of ANSSI's advisory output, used for issues the agency treats as urgent rather than routine. Because an alerte is the exception and not CERT-FR's day-to-day publishing, this suits a channel that actually notifies someone rather than a folder you read later. Items are published in French.
-
CERT-FR Avis de sécurité
RSS not_modifiedThe “avis de sécurité” feed from CERT-FR, the French national CERT operated by ANSSI. CERT-FR splits its output in two: avis are the routine vulnerability advisories, naming affected versions and vendor fixes, while alertes are reserved for the urgent cases. Items are published in French.
-
CISA Blog
RSS okLonger-form posts from CISA: guidance write-ups, programme explainers and commentary from agency leadership. It is not an advisory channel and nothing here replaces the advisories feed, but it is where the reasoning behind a directive or a secure-by-design push gets explained.
-
CISA Current Activity (US-CERT)
RSS okThe National Cyber Awareness System “Current Activity” feed, still served from the legacy us-cert.cisa.gov host. Items are short notices about current security issues, active exploitation and vendor updates worth acting on. It predates the consolidated cybersecurity-advisories URL, so expect overlap if you subscribe to both.
-
CISA Cybersecurity Advisories
RSS okThe consolidated advisory stream from CISA, covering everything published under Cybersecurity Advisories: alerts, ICS and medical-device advisories, analysis reports, and the joint advisories written with partner agencies. It is one URL for the whole section, which is why it is usually the only CISA feed a defender needs. Anyone running US critical-infrastructure or OT equipment should have it in a reader.
-
CISA Known Exploited Vulnerabilities
JSON not_modifiedCISA's Known Exploited Vulnerabilities catalogue, published as a JSON document rather than a subscribable feed, so a reader cannot import it. Every record names a CVE that CISA has confirmed is being exploited in the wild, with the affected vendor and product, the required action and the remediation deadline that binds US federal civilian agencies. Treat it as a patch-priority list: if a CVE appears here, exploitation is no longer theoretical.
-
CISA News
RSS okCISA's general news channel: press releases, programme announcements and agency updates rather than technical advisories. Useful if you track US federal cyber policy, leadership statements and guidance releases. For the vulnerability advisories themselves, take CISA Cybersecurity Advisories instead.
-
ENISA News
Atom not polledNews from ENISA, the European Union Agency for Cybersecurity: threat landscape reporting, certification and policy work, and programme announcements.
Retired: ENISA removed all RSS feeds during their 2025 site redesign. /news/feed and every probed alternative return 404.
ENISA removed all RSS feeds during 2025 site redesign. No working endpoint as of 2026-05-21.
-
JPCERT/CC
RSS not_modifiedThe English-language feed from JPCERT/CC, Japan's national computer emergency response team. It carries their advisories, alerts and analysis write-ups, and the RDF file is the English edition specifically rather than the Japanese one. Take it if your threat picture needs Japan and wider APAC coverage rather than only US and EU sources.
-
NCSC UK
RSS not_modifiedThe reports feed from the UK's National Cyber Security Centre, the defensive arm of GCHQ. This is the substantial half of their output: threat reports, technical guidance and the joint advisories they co-author with allied agencies. Pair it with NCSC UK News if you also want the announcements.
-
NCSC UK News
RSS not_modifiedThe news half of the NCSC's output: announcements, statements and press items, including the public calls to action aimed at UK organisations. Shorter and quicker to skim than the reports feed, and a reasonable single subscription if you only want to know when the UK's national authority says something.
-
NVD CVE 2.0 API
JSON okThe US National Vulnerability Database, served through NIST's CVE API. It answers with JSON rather than XML, carries CVSS scores and CPE product matches alongside each CVE record, and takes query parameters for keyword and date-range lookups. This is what you build against when enriching CVE ids in a pipeline; it is not something to subscribe to in a reader.
Firewall & network security (6) OPML
-
Check Point Research
RSS not_modifiedCheck Point Research (CPR) is Check Point's threat intelligence arm, and this is their research blog: malware analysis, vulnerability research, actor tracking and campaign reporting on the wider landscape rather than only Check Point products. It is not Check Point's product security bulletin channel, so do not rely on it to tell you when a Check Point appliance needs patching.
-
Cisco PSIRT
RSS okCisco's PSIRT advisory feed, served in RSS form from sec.cloudapps.cisco.com. It spans the whole Cisco estate, from IOS and IOS XE through ASA and Firepower to Webex and the collaboration products, with CVSS scores, affected versions and fixed releases on each advisory. Essential if you run Cisco network or security equipment.
-
F5 Networks Security Advisories
RSS not polledF5's security advisory channel for BIG-IP and the rest of their application delivery and security line.
Retired: F5 retired support.f5.com; my.f5.com replacement requires authenticated Salesforce session. No public RSS replacement.
support.f5.com retired; my.f5.com replacement requires Salesforce auth. No public feed.
-
Fortinet PSIRT
RSS okFortiGuard Labs' PSIRT advisory endpoint, the machine-readable form of Fortinet's advisory list, covering FortiOS, FortiGate, FortiManager, FortiClient and the wider Fortinet range. Advisories carry a severity, the affected versions and the release that fixes them. Fortinet appliances appear repeatedly in CISA's Known Exploited Vulnerabilities catalogue, so this belongs in an alerting channel rather than a reading folder.
-
Juniper SIRT
RSS not polledJuniper's SIRT advisory channel, covering Junos OS and the routing, switching and SRX security platforms.
Retired: Juniper retired the supportportal RSS feed and the S3 fallback (advisory.juniper.net/rss/JSA.xml). No public replacement.
Juniper retired supportportal RSS + the S3 advisory.juniper.net fallback. No public feed.
-
Palo Alto Networks PSIRT
RSS okThe product security advisory feed from Palo Alto Networks' PSIRT portal. It publishes CVEs affecting PAN-OS, GlobalProtect, Prisma, Cortex and the rest of the product line, each with a severity, the affected versions and the fixed release. If you run Palo Alto equipment this is the feed that tells you to patch; Unit 42's blog is research and does not serve that purpose.
Vulnerability management (6) OPML
-
Google Project Zero
Atom not_modifiedGoogle Project Zero's blog, served as Atom. The posts are long, deeply technical write-ups: full exploit chains, root-cause analysis, fuzzing methodology and retrospectives on in-the-wild zero-days. Individual bug reports live in Project Zero's issue tracker rather than here, so this feed is the analysis rather than the disclosure stream.
-
Qualys Security Blog
RSS not_modifiedQualys's security blog, including work from the Qualys Threat Research Unit, which has a record of finding serious Linux and OpenSSH vulnerabilities itself and publishing the analysis here. Vulnerability research, exploitation write-ups, and compliance and product content share the one feed.
-
Rapid7 Blog
RSS okRapid7's blog feed, carrying emergent-threat reports on actively exploited vulnerabilities, vulnerability analysis and product posts in one stream. Rapid7 maintains Metasploit and AttackerKB, and their write-ups are framed around exploitability, which is exactly the question a CVE number on its own does not answer.
-
Tenable Research
RSS okTenable's blog feed, which is where Tenable Research publishes: analysis of newly disclosed vulnerabilities, cyber exposure alerts on whichever CVE is currently causing a scramble, and their own discoveries. Note this is the blog and not Tenable's product security advisories, which live under tenable.com/security as numbered TNS entries. Subscribe for the research and the exploitation context rather than for plugin updates.
-
Zero Day Initiative — Published Advisories
RSS okThe Zero Day Initiative's published advisory stream. ZDI acquires vulnerabilities from researchers and runs the coordinated disclosure, so each item is a numbered ZDI advisory naming the affected product, a CVSS score and the disclosure timeline, including the cases ZDI publishes without a vendor patch once its disclosure deadline has expired. One of the better ways to watch third-party software vulnerabilities become public.
-
Zero Day Initiative Blog
RSS not_modifiedThe Zero Day Initiative's blog rather than its advisory stream: Pwn2Own results, bug-hunting and patch-analysis write-ups, and commentary on disclosure practice. Note the URL carries a ?format=rss query string that has to survive intact when you paste it into a reader.
Endpoint & EDR (4) OPML
-
CrowdStrike Blog
RSS okCrowdStrike's blog feed. It carries their threat research, including adversary tracking under the BEAR, PANDA and SPIDER naming scheme, alongside product, platform and company posts, because this is the whole blog rather than a research-only slice. Take it for the intelligence write-ups and expect to skim past the marketing.
-
Huntress Blog
RSS okHuntress publishes threat write-ups, detection notes and incident findings out of its managed detection and response practice. The company works largely with small and mid-sized organisations and the IT providers who serve them, and the material reflects that, so it reads as practical defence rather than nation-state set pieces.
-
SentinelLabs
RSS okSentinelLabs is SentinelOne's research team, and this feed is the labs section of their site rather than the corporate blog. Content runs to malware reverse engineering, threat-actor campaign analysis and tooling write-ups, usually with indicators. Vendor-authored, but written for reversers.
-
Trellix Security Advisories
RSS not polledTrellix product security advisories, covering the McAfee Enterprise and FireEye product lines the company was formed from.
Retired: kcm.trellix.com/kc/rss returns Cloudflare 522 (origin timeout). Trellix has not published a new advisory RSS endpoint.
kcm.trellix.com/kc/rss returns CF 522 (origin timeout); no replacement endpoint published.
Operating systems (3) OPML
-
Apple Security / Releases
RSS okApple's developer releases feed, announcing new iOS, iPadOS, macOS, tvOS, watchOS and Xcode builds as they ship. It is a release notification rather than an advisory channel: the security content notes for each release are published on Apple's support site, not in this feed. Use it as the trigger to go and read those notes, which is why it earns a place in this directory.
-
Microsoft MSRC
RSS not_modifiedThe MSRC Security Update Guide feed: Microsoft's machine-readable disclosure channel for CVEs across Windows, Office, Azure, Edge, Dynamics and the rest of the estate. It is the same data behind Patch Tuesday, which makes it the feed to plan monthly patching around. Served from an API host, so it is as easy to consume from a script as from a reader.
-
Microsoft Security Blog
RSS not_modifiedMicrosoft's security blog. It carries Microsoft Threat Intelligence actor reporting, using the Storm and weather-themed naming scheme, alongside Defender, Entra and Purview product posts and broader security guidance. Take it for the threat intelligence write-ups; the patch data belongs to the MSRC feed instead.
SIEM & logging (2) OPML
-
Elastic Security Labs
RSS not_modifiedElastic Security Labs publishes malware analysis, campaign research and detection-engineering write-ups, including the reasoning behind Elastic's own detection rules. Because those rules are published openly, much of the material transfers to other platforms, so it is worth taking even if your SIEM is not Elastic.
-
Splunk Security Advisories
RSS not_modifiedSplunk's product security advisories, from their dedicated advisory host. Items cover CVEs in Splunk Enterprise, Splunk Cloud and the supported apps, with a severity and the versions that fix them. If you run Splunk, this is the feed that tells you the SIEM itself needs patching, which is an easy thing to leave off a patch programme.
Privileged access (1) OPML
-
CyberArk Blog
RSS okCyberArk's blog, covering identity and privileged access security: credential theft technique, secrets management, cloud entitlements, and research from CyberArk Labs on what an attacker does once they already have a foothold. Research and product content share the one feed.
DevOps & supply chain (1) OPML
-
GitLab Security Releases
Atom not_modifiedGitLab's security release feed, served as Atom. Every GitLab patch release that fixes a security issue is announced here with its CVEs, severities and affected versions. If you self-host GitLab this is not optional: a self-managed instance stays vulnerable until someone applies the release, and this is the notification that one exists.
Email security (1) OPML
-
Proofpoint Threat Insight
RSS okProofpoint's site RSS, which is where their Threat Insight research appears: phishing kits, malicious attachment and URL campaigns, initial access brokers and the TA-numbered actor profiles Proofpoint maintains. It is a site-wide rather than research-only endpoint, so product and company posts arrive in the same stream.
Virtualisation (1)
-
VMware Security Advisories
RSS not polledVMware's VMSA security advisory channel, covering vSphere, ESXi, vCenter, Workstation and Fusion.
Retired: Broadcom acquisition removed all vmware.com and support.broadcom.com RSS endpoints. Web page exists but no feed.
Broadcom acquisition removed all vmware.com/support.broadcom.com RSS endpoints.
About this directory
ThreatFilter polls every enabled feed above on a 30-minute cycle, parses RSS, Atom and JSON formats, de-duplicates by content hash and classifies each item by vendor, severity and sector. The status beside each feed is the result of the most recent real fetch. Feeds that break are marked rather than quietly dropped, and one that becomes permanently unreachable is retired with the reason recorded.
The description under each entry says what that source publishes and who should take it. Where the URL is not the one people expect, it says so plainly: Mandiant's research now lives on the Google Cloud blog, Apple's developer releases feed is a release notification rather than an advisory channel, and Check Point Research is a research blog rather than a product bulletin. No publication frequencies are claimed for individual publishers, because we measure our own polling, not their editorial calendars.