Every feed, one page.
Looking for saved, per-entity custom feeds inside the product? That is custom feeds. This page is the public, no-key catalogue. Threat clusters, CVEs, weaponised exploits, ransomware victims and a blocklist, as RSS, JSON, CSV and MISP. All public, no key, no login. Refreshed hourly.
No authentication on any feed below. Point a reader, a SIEM or a cron job at it.
Start here
Download the OPML bundle and import it once, your reader picks up every public feed on this page.
Feedly: Organize → Import OPML. Inoreader: Preferences → Import/Export. NewsBlur, Reeder and any other RSS-capable tool will take the same file.
https://threatcluster.io/feeds.opml
Cache TTL is one hour on our side, so polling more often than that returns the same items. The main threat feed also advertises a WebSub hub if you would rather be pushed to than poll.
Threat intelligence
Threat Feed Public RSS 2.0
The top 50 trending threat clusters from the last 7 days, the same content as the home page. Each item links to a cluster page with the summary, timeline, source articles and related entities.
https://threatcluster.io/feed.xml
Vulnerabilities Feed Public RSS 2.0
Latest CVEs from the last 7 days, enriched with severity, CISA KEV status and public
PoC availability. Built for tracking what is hitting the news cycle this week,
not the firehose of every NVD entry. Item titles look like
CVE-2026-28318 [KEV] [Exploit].
https://threatcluster.io/vulnerabilities/feed.xml
Exploits Feed Public RSS 2.0
CVEs with publicly available proof-of-concept code, from the last 30 days, sorted by exploit availability then CVSS, the same content as /exploits. Use it to prioritise patch cycles by weaponisation instead of raw severity.
https://threatcluster.io/exploits/feed.xml
Dark Web Victims Feed Public RSS 2.0
Newly observed victims on ransomware leak sites, from the last 14 days. Titles read “Victim, claimed by [Group]”, with description fields for country, sector and the group's public post text. Aggregated from /dark-web.
https://threatcluster.io/dark-web/feed.xml
Dark Web Data, CSV & JSON Public CSV / JSON
The same corpus behind the RSS feed, as structured data. Victims carry group, country, sector and the leak-site post URL; the onion list covers extortion leak-site addresses with their operator and current status.
These are claims published by the groups themselves. A listing is not confirmation that a breach occurred, or that the group's claim is accurate.
Site rows carry the page title, claimed operator, language, login/captcha gate and a link to our own watermarked screenshot where we have one.
https://threatcluster.io/api/darkweb/public/victims.csv
https://threatcluster.io/api/darkweb/public/onions.csv
https://threatcluster.io/api/darkweb/public/groups.csv
https://threatcluster.io/api/darkweb/public/victims.json
Victim feeds default to a 90-day window (CSV) and 30 days (JSON); add
?days=365 for more. The JSON carries company enrichment, legal name, headquarters, data size, where the leak post included it.
Snapshotted daily to GitHub with history: Jam0k/Ransomware-Intel , victims (90d / 365d / first-party only), groups and onion addresses.
For tooling
IOC Blocklist Public TXT JSON CSV
High-confidence malicious domains and IP addresses from the last 30 days, ready to paste into pfSense, Pi-hole or a firewall blocklist. Plain text for drop-in use, JSON when you want the source attribution, CSV for spreadsheets. The IOC page has integration examples.
https://threatcluster.io/api/iocs/public/feed.txt
https://threatcluster.io/api/iocs/public/feed.json
https://threatcluster.io/api/iocs/public/feed.csv
MISP Feed Public MISP
MISP-compatible feed for direct ingestion, no key or token required. Manifest at
/misp/manifest.json, per-event JSON at /misp/{uuid}.json,
optional hashes index at /misp/hashes.csv. Add it in your MISP UI under
Sync Actions → List Feeds.
https://threatcluster.io/misp/manifest.json
AlienVault OTX Pulses Public OTX
ThreatCluster clusters published as pulses on
AlienVault OTX.
Subscribe to the projectargus account in OTX and the indicators flow
straight into any tool already wired to the Open Threat Exchange, no extra integration on your side.
https://otx.alienvault.com/user/projectargus/pulses
SmartNews Feed Public SmartFormat 2.2
SmartFormat-compliant RSS for the
SmartNews
publisher platform, with full content:encoded bodies,
media:thumbnail, snf:logo and Dublin Core attribution.
Only needed if you are submitting to an aggregator that requires SmartFormat, everyone else should use the Threat Feed.
https://threatcluster.io/feed/smartnews.xml
Your own feed
My Interests & Custom Feeds Researcher and above RSS 2.0
Feeds filtered to the entities and keywords you track, your vendors, your sector, your suppliers. Set them up in Settings → Interests, or save a Custom Feed from any filter combination. Authenticated by session cookie, so a signed-in browser needs no API token.
https://threatcluster.io/api/feed/interests.xmlhttps://threatcluster.io/api/feed/custom/{feed-uuid}.xmlNotes
- Every feed is RSS 2.0 with an
atom:link rel="self"; the main threat feed also advertises a WebSub hub for push delivery. - Cache TTL is one hour. Polling faster will not return fresher items.
- Rate limit is 60 requests per minute per IP, ample for any normal reader.
- Need STIX / TAXII or a full-fidelity firehose? That is on /formats.
- Want to contribute findings back? Get in touch about ingestion partnerships.
Take the whole set.
One OPML import wires every RSS feed into your reader. The CSV and JSON feeds aren't reader formats, grab those above. Nothing to sign up for.