Threat type
Industry
  1. 1

    September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs

    Zero-Day Data Breach Vulnerability CrowdStrike Blog The Hacker News Check Point Research Graham Cluley +13 more · 24 September 2026, 12:21 GMT · 17 outlets
    0.86 High

    For the latest discoveries in cyber research for the week of 21st Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Japan’s Digital Agency, which operates the Government Solution Service used by multiple ministries, has confirmed a data breach after attackers exploited a vulnerability in a VPN appliance. Approximately 246,000 records were exposed, […] The post 21st September – Threat Intelligence Report appeared first on Check Point Research .

  2. 2

    Forcepoint security advisory (AV26-960)

    BEC Vulnerability Canadian Centre for Cyber Security Microsoft Security Blog The Hacker News Graham Cluley +12 more · 23 September 2026, 19:11 GMT · 16 outlets
    0.81 High

    Serial Number: AV26-960 Date: September 23, 2026 As of September 23, 2026, Forcepoint is affected by a vulnerability in the following product: Forcepoint Security Engine (NGFW) Versions 7.1.0 to 7.1.13 Versions 7.3.0 to 7.3.1 Version 7.33 Version 7.4.0 to 7.4.1 Version 7.5.0 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Forcepoint Hub Forcepoint Help and Resource Center

  3. 3

    Google Chrome security advisory (AV26-955)

    BEC Vulnerability Canadian Centre for Cyber Security The Hacker News The New York Times Technology CERT-FR (ANSSI) +5 more · 23 September 2026, 17:47 GMT · 9 outlets
    0.81 High

    Serial number: AV26-955 Date: September 23, 2026 As of September 22, 2026, Google published a security advisory to address vulnerabilities in the following product: Stable Channel Chrome for Desktop Versions prior to 154.0.8037.57/.58 (Windows/Mac), and 54.0.8037.57 (Linux) The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.

  4. 4

    Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

    Vulnerability The Hacker News · 24 September 2026, 05:36 GMT
    0.75 High

    Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE). "An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file

  5. 5

    Malicious npm Packages That Evade Defenses

    APT Typosquatting Malware Schneier on Security The Hacker News Malwarebytes Labs BleepingComputer +2 more · 24 September 2026, 11:07 GMT · 6 outlets
    0.71 High

    This is an impressive piece of malware . Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.

    Government Media
  6. 6

    Chromium CVE-2026-87489: Memory corruption in V8

    Other Microsoft MSRC TechCrunch Sky News Technology The Hacker News +15 more · 23 September 2026, 08:43 GMT · 19 outlets
    0.71 High

    Information published.

  7. 7

    Chromium CVE-2026-87536: Use after free in V8

    Other Microsoft MSRC TechCrunch The Hacker News NBC News Technology +8 more · 23 September 2026, 08:42 GMT · 12 outlets
    0.71 High

    Information published.

  8. 8

    TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

    Vulnerability The Hacker News Infosecurity Magazine Dark Reading · 24 September 2026, 06:32 GMT · 3 outlets
    0.70 Medium

    Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. "The campaign compromised 7 accounts –

  9. 9

    Research on Models Engaging in Genie-Like Behavior

    Vulnerability Schneier on Security The Hacker News NBC News Technology Cyber Scoop +4 more · 23 September 2026, 11:03 GMT · 8 outlets
    0.62 Medium

    New paper: “ Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training .” Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies to circumvent their own safety guardrails. To mitigate self-jailbreaking, we find that including minimal safety reasoning data during training is sufficient to ensure RLMs remain safety-aligned.

  10. 10

    MacSync under the microscope: new delivery methods and a new payload

    Malware Securelist (Kaspersky) · 24 September 2026, 10:00 GMT
    0.62 Medium

    We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.

    Finance Technology

Intelligence sources

71 sources were queried for today’s briefing. Sources are weighted by credibility (0–100) when ranking threats.

NCSC UK 95

UK government's National Cyber Security Centre. Advisories are based on classified threat intelligence and vetted by a national authority mandated to protect UK critical infrastructure. Scoring reflects direct government backing and the rigorous publication process.

advisory uk government
CISA Advisories 95

US Cybersecurity and Infrastructure Security Agency — the primary US government authority on cyber threats. Advisories undergo inter-agency review and are operationally actionable; the Known Exploited Vulnerabilities (KEV) catalogue reflects confirmed in-the-wild exploitation.

advisory us government
CISA Current Activity 93

CISA's near-real-time alert channel for active threats. Typically published within hours of confirmed exploitation; slightly lower than the main advisory feed because posts are shorter and less fully attributed, but timeliness is very high.

advisory us government
Canadian Centre for Cyber Security 92

Canada's national cyber authority and a member of the Five Eyes intelligence partnership. Advisories benefit from shared intelligence and are thoroughly vetted before publication, giving strong reliability for both North American and cross-allied threats.

advisory ca government
Microsoft MSRC 92

Microsoft Security Response Center — the authoritative source for Microsoft Patch Tuesday advisories and out-of-band security updates. Covers CVEs across Windows, Office, Azure, and Exchange. Essential for tracking actively exploited Microsoft vulnerabilities; high credibility as first-party disclosure from the world's most widely deployed enterprise software vendor.

advisory vendor vulnerability patch
CERT-FR (ANSSI) 91

French national CERT operated by ANSSI (Agence nationale de la sécurité des systèmes d'information). Rigorous editorial and technical review process; strong coverage of European and francophone threat actors, and early disclosure on threats affecting French critical infrastructure.

advisory fr government
BSI Germany 91

Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik). Well-resourced national authority with strong European industrial threat coverage; publications are technically thorough and benefit from EU-wide information sharing.

advisory de government
JPCERT/CC 90

Japan's Computer Emergency Response Team. Primary national CERT for Japan and highly reliable for APT campaigns affecting Asia-Pacific organisations. Frequently publishes early technical analysis of threats targeting Japanese critical infrastructure and supply chains.

advisory jp government
NCSC Netherlands 90

Dutch National Cyber Security Centre — consistently one of Europe's most active and technically detailed national CERTs. Publishes thorough advisories with clear risk classification and is frequently first among European authorities to address newly disclosed vulnerabilities. Strong track record on state-sponsored threat attribution.

advisory nl government eu
Google Project Zero 90

Elite vulnerability research team credited with discovering some of the most significant zero-days in recent years across browsers, operating systems, and hardware. Responsible disclosure process is rigorous; publications include deep technical analysis. Score reflects research quality and historical impact.

research vulnerability
CIRCL (Luxembourg CERT) 88

Computer Incident Response Center Luxembourg — a respected European CERT and the maintainer of MISP (Malware Information Sharing Platform). Publishes high- quality technical advisories and is a significant contributor to EU threat intelligence sharing. Strong credibility from open-source tool stewardship.

advisory lu government eu
Cisco Talos Blog 88

One of the world's largest commercial threat intelligence teams, backed by telemetry from hundreds of millions of Cisco devices globally. Research is technically rigorous, peer-reviewed internally, and frequently cited by national CERTs. Strong across network, email, and endpoint threats.

research vendor threat-intel
Mandiant Blog 88

Leading incident response firm with deep expertise in nation-state actor attribution. Reports are grounded in real intrusion data from hundreds of breach investigations annually. Widely considered the industry authority on APT tracking and campaign attribution.

research vendor threat-intel
Krebs on Security 88

Brian Krebs's independent investigative security journalism. Many of the most consequential breach disclosures and cybercrime investigations of the last decade first surfaced here. Known for meticulous sourcing, direct engagement with threat actors, and consistent accuracy.

news journalism blog
CERT-IN (India) 87

Indian Computer Emergency Response Team, the national nodal agency for cybersecurity incident response. Covers threats to Indian critical infrastructure and publishes advisories on vulnerabilities actively exploited in the region. Increasingly relevant given India's scale and growing threat surface.

advisory in government
Singapore CSA 87

Cyber Security Agency of Singapore — the national authority for cybersecurity. Covers threats to Southeast Asian critical infrastructure and issues advisories that often reflect APAC-specific threat actor activity ahead of wider reporting. Singapore's tech-forward posture makes it an important regional intelligence source.

advisory sg government
Palo Alto Unit 42 87

Threat intelligence and incident response arm of Palo Alto Networks. Large research team with broad telemetry across cloud, network, and endpoint. Consistent track record on ransomware attribution, nation-state campaigns, and cloud threat analysis.

research vendor threat-intel
CrowdStrike Blog 87

Endpoint telemetry across tens of thousands of organisations worldwide. Industry leader in adversary naming and tracking (e.g. FANCY BEAR, COZY BEAR). Technical depth is consistently high; particularly authoritative on nation-state intrusion sets and big-game-hunting ransomware.

research vendor threat-intel
Check Point Research 86

Long-established vendor research team with strong output on malware reverse engineering, campaign tracking, and mobile threats. Publications are technically thorough and frequently reference novel attack techniques; strong coverage of Middle Eastern and financially motivated threat actors.

research vendor threat-intel
Microsoft Security Blog 86

Microsoft Threat Intelligence (MSTIC) has visibility across over one billion devices and a large volume of enterprise email and cloud infrastructure. Regularly uncovers nation-state APT activity and zero-days. Authoritative for Windows, Azure, and identity-based threats.

research vendor
Troy Hunt (Have I Been Pwned) 86

Troy Hunt is the creator of Have I Been Pwned and a leading independent researcher on data breaches. Frequently publishes the first public analysis of major credential leaks and breach datasets. Direct access to breach data gives his posts authoritative, first-hand insight not available elsewhere. Strong mainstream crossover for high-profile leaks.

research blog breach expert
Schneier on Security 85

Bruce Schneier's independent analysis blog. Highly credible expert commentary from one of the most cited security practitioners of the last 30 years. Valuable for contextualising geopolitical cyber threats, policy developments, and cryptographic issues. Lower volume but consistently high signal.

blog expert
SANS Internet Storm Center 85

Community-driven internet threat monitoring run by SANS Institute. Daily handler diaries provide ground-level analysis of emerging threats and exploitation attempts observed across distributed sensors. Strong 20-year track record; particularly reliable for early warning on novel attack techniques.

advisory research
Red Canary Blog 85

Managed detection and response provider with strong depth in MITRE ATT&CK-mapped threat analysis. Publishes the annual Threat Detection Report — one of the most widely cited practical threat summaries in the industry. Consistently strong on initial access, persistence, and lateral movement techniques.

research threat-intel
Trend Micro Research 85

Trend Micro's dedicated research portal. Strong global telemetry covering cloud, email, and endpoint threats across Asia-Pacific, Europe, and the Americas. Particularly authoritative on APT groups targeting manufacturing, healthcare, and government sectors; consistently publishes technically detailed malware analysis and campaign attribution.

research vendor threat-intel
TeamCymru Blog 85

Specialist internet infrastructure and threat intelligence firm with unique visibility into BGP routing, IP reputation, and malicious infrastructure at a global scale. Research focuses on threat actor infrastructure mapping, botnet C2 tracking, and network-level threat analysis not available from endpoint- centric vendors.

research threat-intel network
NCC Group Research 85

NCC Group is one of the UK's largest independent cybersecurity consultancies. Research covers vulnerability disclosure, penetration testing findings, reverse engineering, and cryptographic analysis. Known for high-quality original vulnerability research and responsible disclosure; particularly strong on hardware and embedded system security.

research vendor vulnerability
Abuse.ch Blog 85

Abuse.ch operates MalwareBazaar, URLhaus, ThreatFox, and other widely used open-source malware intelligence platforms. Blog covers new malware families, campaign tracking, and threat indicator releases. Uniquely positioned at the intersection of academic research and practitioner tooling; data is community- validated and freely shared with the security community.

research malware threat-intel open-source
Secureworks Blog 85

Secureworks Counter Threat Unit (CTU) produces in-depth threat intelligence on ransomware groups, nation-state actors, and crimeware campaigns backed by extensive telemetry from managed security customers worldwide. Consistent track record on identifying and attributing novel malware families and intrusion sets.

research vendor threat-intel
Elastic Security Labs 84

Elastic's security research team produces detailed malware analysis and detection engineering content grounded in Elastic's broad telemetry. Known for thorough reverse engineering write-ups and YARA/EQL rule publications. Technically rigorous and increasingly prominent.

research vendor
ESET WeLiveSecurity 84

ESET's research arm has historically produced some of the most technically detailed analysis of Eastern European APT activity (e.g. Turla, Sandworm, Sednit). Strong malware reverse engineering output; publications are peer-reviewed and include novel findings rather than rehashing public reports.

research vendor
Sophos X-Ops 84

Combined research unit merging Sophos Labs, SophosAI, and managed detection telemetry. Well-regarded for detailed ransomware playbooks and attacker behaviour analysis drawn from active incident response cases. Good cross-sector visibility with particular strength on SMB-targeted threats.

research vendor
Proofpoint Threat Intelligence 84

Leading email security vendor with unparalleled phishing, BEC (business email compromise), and email-borne malware telemetry. Threat actor tracking is especially strong for financially motivated groups. Consistently among the first to document new phishing campaigns and initial access brokers.

research vendor threat-intel
IBM Security Intelligence 84

IBM X-Force's research publication. One of the longest-established commercial threat intelligence teams with visibility across IBM's global managed security customer base. Strong on ransomware economics, dark web monitoring, and incident response insights. IBM Threat Intelligence Index is an industry- standard annual reference.

research vendor threat-intel
Bitdefender Labs 84

Bitdefender's dedicated security research arm. Well-regarded for original malware reverse engineering and APT research, particularly threats targeting European and Eastern European organisations. Technically thorough with consistent output on novel malware families and evasion techniques.

research vendor
Sekoia.io Blog 84

French threat intelligence firm with strong coverage of European threat actors and cybercriminal ecosystems. Publishes detailed technical analyses of malware families, phishing infrastructure, and information-stealer campaigns. Fills a gap for French-language and European-origin threat actor tracking not well covered by US-centric vendors.

research vendor threat-intel
SentinelOne Blog 83

Endpoint security vendor with growing research output. Good technical malware analysis and coverage of novel EDR evasion techniques; SentinelLabs team publishes detailed nation-state and ransomware research. Slightly lower score reflects a shorter research track record than some peers.

research vendor
Huntress Labs Blog 83

Managed security provider focused on SMB and mid-market organisations. Particularly valuable for tracking threats that bypass enterprise-focused intelligence — commodity ransomware, opportunistic attackers, and techniques targeting under-resourced IT environments. Research is grounded in active incident response.

research vendor threat-intel
Trellix Threat Research 83

Trellix (formerly McAfee/FireEye) threat research team. Long heritage in APT tracking and malware analysis; particularly strong on financially motivated and nation-state campaigns. Merged intelligence from the legacy FireEye and McAfee research teams gives it broad coverage across network, endpoint, and email vectors.

research vendor threat-intel
The Washington Post Technology 83

The Washington Post's technology coverage consistently breaks significant cyber and privacy stories, particularly those intersecting with policy, government, and US national security. Its investigative capacity gives it strong credibility for major breach reporting.

news mainstream us broadsheet
Graham Cluley 82

Well-established independent security journalist and former Sophos researcher. Known for accurate, clearly sourced reporting and a long track record of responsible disclosure coverage. Lower volume than trade publications but consistently well-verified before publishing.

news journalism blog expert
BleepingComputer 82

Fast-moving news outlet specialising in practical Windows security, ransomware, and malware. Frequently first to break incident news with direct communication from threat actors and victims. Strong community-driven verification; editorial standards are good for breaking news, though depth of analysis varies.

news journalism
Recorded Future News 82

Threat intelligence vendor with a large data aggregation platform covering open, dark web, and technical sources. Strong geopolitical cyber context and ransomware tracking. Score reflects editorial quality of the blog arm rather than the platform itself.

news threat-intel
Tenable Blog 82

Market leader in vulnerability management. Authoritative on CVE scoring, patch urgency, and exposure prioritisation. Tenable Research is consistently reliable for assessing the real-world exploitability of newly disclosed vulnerabilities and their severity in cloud and enterprise contexts.

research vendor vulnerability
BBC News Technology 82

BBC's technology news feed. The UK's most-trusted public broadcaster; covers major cyber incidents, data breaches, and digital policy at a level accessible to a general audience. High editorial standards and broad readership make it a strong signal for stories that have reached mainstream public awareness.

news mainstream uk
WIRED Security 82

WIRED's dedicated security section. Sits at the intersection of mainstream journalism and informed tech analysis — readable by a general tech-interested audience while still covering incidents with some depth. Strong track record on breach investigations, surveillance, and cyberwarfare stories.

news mainstream journalism
The New York Times Technology 82

New York Times technology section. One of the world's most widely read news outlets; covers major cyber incidents, data breaches, and digital privacy stories for a mass audience. Articles are written for general readers with no assumed technical knowledge, making them a strong signal for stories that have reached true mainstream awareness.

news mainstream us journalism
SecurityWeek 80

Long-running independent security industry publication. Good breadth across vulnerability disclosures, breaches, and geopolitical incidents. Respected for balanced reporting; slightly lower credibility weight than specialist research blogs because articles are news-led rather than deeply analytical.

news journalism
Qualys Security Blog 80

Vulnerability management vendor with broad scan telemetry across cloud and enterprise environments. Research team focuses on patch analysis and CVE impact assessment. Useful for understanding real-world exposure to newly disclosed vulnerabilities at population scale.

research vendor vulnerability
Securelist (Kaspersky) 80

Kaspersky's threat research portal. Technically high-quality malware analysis and APT research, particularly strong on Russian-speaking threat actors. Credibility score reflects research quality; note that some organisations apply their own weighting adjustments based on vendor geopolitical considerations.

research vendor
Malwarebytes Labs 80

Consumer and SMB-focused security research. Useful for tracking commodity malware campaigns, widespread phishing, and opportunistic attacks affecting a broad user base. Lower score than enterprise threat intel teams reflects narrower analytical scope, not a reliability concern.

research vendor
The Record (Recorded Future) 80

Investigative security journalism outlet backed by Recorded Future's intelligence platform. Strong on ransomware, government cyber operations, and policy. Good editorial independence from its parent; credibility reflects solid journalism standards with some dependence on vendor context.

news journalism
AttackIQ Blog 80

AttackIQ specialises in automated security control validation aligned to MITRE ATT&CK. Blog content covers ATT&CK technique analysis, adversary emulation, and practical guidance for defenders — complementing the more news-oriented threat intel sources with actionable defensive context.

research threat-intel attck defence
The Guardian Technology 80

The Guardian's technology section. Combines investigative journalism with accessible tech coverage; known for breaking data privacy and surveillance stories. Good for incidents affecting consumers, businesses, or government that have crossed into public awareness.

news mainstream uk
Politico Cybersecurity 80

Politico's dedicated cybersecurity policy vertical. Covers US government cyber policy, legislation, and high-profile incidents from a political and public policy angle. Accessible to policy-minded readers; strong for stories where cyber incidents intersect with government, regulation, or national security debate.

news mainstream us policy
The Telegraph Technology 79

The Daily Telegraph's technology section. Mainstream UK national newspaper covering major cyber incidents and data breaches from a consumer and business perspective. Good for stories affecting UK companies and government — written for a general audience rather than security professionals.

news mainstream uk journalism
TechCrunch 79

Technology news publication with broad consumer and business readership. Covers data breaches, hacks, and privacy incidents in accessible language. Particularly good at translating security incidents into business and consumer impact terms. Wider audience than specialist security blogs.

news mainstream journalism
NBC News Technology 79

Major US broadcast network with a sizeable digital newsroom. Covers consumer- facing cyber stories — breaches affecting millions, scam warnings, privacy controversies — at a level accessible to a general audience. Good for US- centric incidents that reach primetime TV news.

news mainstream us broadcast
The Hacker News 78

High-traffic cybersecurity news aggregator. Good breadth of coverage and fast publication. Score is moderate because a proportion of content is vendor-sponsored or PR-driven, which requires context when assessing significance. Useful for breadth signal rather than deep analytical weight.

news journalism
Cyber Scoop 78

US-focused publication covering cyber policy, government cyber operations, and regulatory developments. Strong on CISA, NSA, and FBI-adjacent stories; a good source for policy-informed threat context. Slightly lower analytical depth than specialist research blogs.

news journalism
Dark Reading 78

Established B2B security trade publication with broad threat coverage. Useful for tracking industry-wide awareness of emerging threats and vendor perspectives. Moderate credibility weight reflects variable analytical depth and a high volume of sponsored content alongside editorial articles.

news journalism
Security Affairs 78

Pierluigi Paganini's independent security blog and news outlet. One of the most widely read European cybersecurity publications; covers APT campaigns, data breaches, and malware with a strong international perspective. Faster than trade publications on breaking threat news; credibility reflects independent journalism standards with thorough source attribution.

news journalism threat-intel
ZDNet Security 78

ZDNet's security section bridges technical and business audiences. While some articles are technical in detail, the majority are written for IT managers and business decision-makers rather than security researchers. Good for high-profile breach and ransomware stories that affect enterprises broadly.

news mainstream journalism
Sky News Technology 77

Sky News technology feed. Reliable UK broadcast journalism; covers high-profile cyber incidents and data breaches as they affect the general public. Slightly lower than BBC/Guardian due to less depth of investigative tech coverage, but strong breadth and fast publication.

news mainstream uk
ABC News Technology 77

ABC News US technology headlines. Mainstream broadcast news outlet covering technology stories at a level accessible to the widest possible audience. Particularly good for stories about consumer data breaches, high-profile arrests, and government cyber-related announcements.

news mainstream us journalism
Infosecurity Magazine 76

UK-based trade publication with global coverage. Solid editorial process and useful for European threat context. Lower credibility weight reflects that the publication is primarily news-led with limited original technical research.

news journalism
Help Net Security 76

Industry news aggregator with a mix of original analysis and vendor-submitted content. Good volume and consistent editorial standards. Scored at the lower end of the journalism tier because a significant portion of content is contributed by vendors rather than independently researched.

news journalism
The Independent Technology 76

UK-based digital broadsheet with a broad technology section. Covers consumer cyber incidents, privacy stories, and scam warnings. Provides useful UK and European perspective alongside the US-heavy sources in this tier. Accessible writing style suited to a general audience.

news mainstream uk broadsheet
Exploit Database 75

Offensive Security's public archive of proof-of-concept exploit code. Essential for tracking weaponised vulnerabilities — the presence of a working exploit significantly increases the operational risk of a CVE. Lower credibility score reflects its role as a repository rather than an editorial source; content is not reviewed for accuracy of attribution or impact claims.

vulnerability exploit research
Engadget 75

Consumer technology news outlet. Covers security and privacy incidents that directly affect everyday technology users — phone vulnerabilities, smart home security, platform data breaches. Written entirely for a non-technical audience.

news mainstream consumer
Mashable Tech 72

Consumer-oriented tech publication with a younger audience. Covers scam alerts, privacy tool recommendations, and major breach stories in plain language. Lower credibility than broadsheets due to lighter editorial standards, but useful for consumer-facing security warnings that reach non-technical readers.

news mainstream us digital
Using the data feeds

All three services expose machine-readable JSON feeds that update daily.

⚠ Cyber Threats Feed

Daily top-10 cyber threat intelligence briefing.

latest.json
curl -s https://bcheevers123.github.io/threat-landscape/latest.json \
  | python3 -m json.tool

🤖 AI/ML Feed

Daily top-10 AI and machine learning developments.

aiml/latest.json
curl -s https://bcheevers123.github.io/threat-landscape/aiml/latest.json \
  | python3 -m json.tool

📅 Conferences Feed

Upcoming cybersecurity events for the next 12 months.

conferences/latest.json
curl -s https://bcheevers123.github.io/threat-landscape/conferences/latest.json \
  | python3 -m json.tool

Python example — today’s top threats

import requests
url = "https://bcheevers123.github.io/threat-landscape/latest.json"
data = requests.get(url, timeout=10).json()
for threat in data["threats"][:3]:
    print(f"[{threat['score']:.2f}] {threat['title']}")

How this page is generated

Collection

Items are gathered daily from a curated list of government advisories, vendor research blogs, and established security journalism sources. All sources are fetched via RSS/Atom feeds.

Deduplication

Near-identical stories reported by multiple sources are merged into a single entry. The primary source shown is the most credible outlet that covered the story.

Ranking

Each item is scored across six dimensions: recency, source credibility, corroboration, severity signals, breadth of impact, and actionability. Weights are configurable and fully transparent.

Enrichment

CVE identifiers, MITRE ATT&CK techniques, affected countries, sectors, malware families, and threat actors are extracted using rule-based analysis of the source text.

Disclaimer & Limitations

This page is generated automatically from publicly available sources and is intended for informational purposes only. It does not constitute professional security advice.

ATT&CK technique mappings, threat actor attribution, and affected country/sector classifications are best-effort analytical outputs derived from keyword matching. They may be incomplete, incorrect, or out of date. Always refer to the original source and consult qualified security professionals before taking action.

No classified, proprietary, or non-public information is used. All sources are publicly available. Source terms of service and attribution requirements apply.