NEW: Group Profiler — instant APT intel lookup. Try it →

Security RSS feeds

A curated, continuously-checked directory of 58 threat-intelligence feeds — national CERT advisories, vendor PSIRTs, CVE data and security news. Every entry below has its own section with the exact feed URL as a working link, what that source actually publishes, and its live fetch status, so you can click straight through or paste the URL into a reader, SIEM or script. 51 are actively polled every 30 minutes by ThreatFilter, so the status shown is real rather than aspirational.

Want them pre-filtered instead of raw? The live feed merges all of these and lets you filter by vendor, severity and sector, and /feed.xml gives you the merged result as a single RSS feed.

Download all 50 feeds as OPML One file, grouped into folders by category. Import it into Feedly, Inoreader, NetNewsWire, Thunderbird or any reader instead of copying 50 URLs by hand. Building something instead? /feeds.json has the whole catalogue as JSON, CORS-open, and each category below has its own OPML.

Feeds that block datacenter IPs

These publish a working feed, but refuse requests from cloud/datacenter egress — they return 403 to a server while serving the same URL fine from a home connection. If you are polling from AWS, Cloudflare Workers, a VPS or a CI job, these will fail and the feed URL is not the problem. This is measured from our own polling, not documented anywhere by the publishers.

Security news & research (19) OPML

National CERTs & government advisories (14) OPML

Firewall & network security (6) OPML

Vulnerability management (6) OPML

Endpoint & EDR (4) OPML

Operating systems (3) OPML

SIEM & logging (2) OPML

Privileged access (1) OPML

DevOps & supply chain (1) OPML

Email security (1) OPML

Virtualisation (1)

About this directory

ThreatFilter polls every enabled feed above on a 30-minute cycle, parses RSS, Atom and JSON formats, de-duplicates by content hash and classifies each item by vendor, severity and sector. The status beside each feed is the result of the most recent real fetch. Feeds that break are marked rather than quietly dropped, and one that becomes permanently unreachable is retired with the reason recorded.

The description under each entry says what that source publishes and who should take it. Where the URL is not the one people expect, it says so plainly: Mandiant's research now lives on the Google Cloud blog, Apple's developer releases feed is a release notification rather than an advisory channel, and Check Point Research is a research blog rather than a product bulletin. No publication frequencies are claimed for individual publishers, because we measure our own polling, not their editorial calendars.