Free public feeds for your reader, SIEM, or downstream automation. Refreshed hourly.
Subscribe in Feedly, Inoreader, NewsBlur, or any RSS-capable tool. All feeds are public and require no authentication. We rate-limit at 60 requests/minute per IP and cache responses for 1 hour, so polling every 5 minutes is fine — but a WebSub hub is also advertised on the main threat feed for push notifications.
Import all feeds in one click
Download our OPML bundle and import it into your reader (Feedly: Organize → Import OPML · Inoreader: Preferences → Import/Export).
The top 50 trending threat clusters from the last 7 days. Same content as the home page. Each item links to a cluster page with summary, timeline, source articles, and related entities.
https://threatcluster.io/feed.xml [copy]
Latest CVEs from the last 7 days, enriched with severity, CISA KEV status, and public PoC availability. Each item links to the full CVE page with article mentions and timeline. Ideal for tracking what's hitting the news cycle this week, not the firehose of all NVD entries.
CVE-2026-28318 [KEV] [Exploit]https://threatcluster.io/vulnerabilities/feed.xml [copy]
CVEs with publicly available proof-of-concept exploit code, from the last 30 days. Sorted by exploit availability then CVSS. Same content as /exploits. Useful for prioritising patch cycles by weaponisation, not just severity.
https://threatcluster.io/exploits/feed.xml [copy]
Newly observed victims on ransomware leak sites, from the last 14 days. Item title is “Victim — claimed by [Group]” with description fields for country, sector, and the group's public post text. Aggregated from /dark-web.
https://threatcluster.io/dark-web/feed.xml [copy]
High-confidence malicious domains and IP addresses, last 30 days. Ready to paste into pfSense, Pi-hole, or your firewall's blocklist. Available in plain text, JSON (with sources), or CSV. See the IOC landing page for integration examples.
https://threatcluster.io/api/iocs/public/feed.txt [copy]
https://threatcluster.io/api/iocs/public/feed.json [copy]
https://threatcluster.io/api/iocs/public/feed.csv [copy]
MISP-compatible feed for direct ingestion into your MISP instance. Manifest at
/misp/manifest.json, per-event JSON at
/misp/{uuid}.json, optional hashes index at
/misp/hashes.csv. Add as a remote feed in your MISP UI under
Sync Actions → List Feeds.
https://threatcluster.io/misp/manifest.json [copy]
Personalised feeds filtered by the entities and keywords you track. Set up in Settings → Interests, or create a saved Custom Feed from a filter combination. Authenticated via session cookie (no API token needed for the signed-in browser session).
https://threatcluster.io/api/feed/interests.xml
https://threatcluster.io/api/feed/custom/{feed-uuid}.xml
atom:link rel="self"; the main threat feed also advertises a WebSub hub for push.