Every feed, one page.

Looking for saved, per-entity custom feeds inside the product? That is custom feeds. This page is the public, no-key catalogue. Threat clusters, CVEs, weaponised exploits, ransomware victims and a blocklist, as RSS, JSON, CSV and MISP. All public, no key, no login. Refreshed hourly.

8
public feeds
1h
refresh interval
60/min
rate limit per IP
20,000+
sources monitored

No authentication on any feed below. Point a reader, a SIEM or a cron job at it.

Start here

One import, all feeds

Download the OPML bundle and import it once, your reader picks up every public feed on this page.

Feedly: Organize → Import OPML. Inoreader: Preferences → Import/Export. NewsBlur, Reeder and any other RSS-capable tool will take the same file.

https://threatcluster.io/feeds.opml

Cache TTL is one hour on our side, so polling more often than that returns the same items. The main threat feed also advertises a WebSub hub if you would rather be pushed to than poll.

Threat intelligence

4 RSS feeds

Threat Feed Public RSS 2.0 50 items · 1h refresh

The top 50 trending threat clusters from the last 7 days, the same content as the home page. Each item links to a cluster page with the summary, timeline, source articles and related entities.

https://threatcluster.io/feed.xml

Vulnerabilities Feed Public RSS 2.0 50 items · 1h refresh

Latest CVEs from the last 7 days, enriched with severity, CISA KEV status and public PoC availability. Built for tracking what is hitting the news cycle this week, not the firehose of every NVD entry. Item titles look like CVE-2026-28318 [KEV] [Exploit].

https://threatcluster.io/vulnerabilities/feed.xml

Exploits Feed Public RSS 2.0 50 items · 1h refresh

CVEs with publicly available proof-of-concept code, from the last 30 days, sorted by exploit availability then CVSS, the same content as /exploits. Use it to prioritise patch cycles by weaponisation instead of raw severity.

https://threatcluster.io/exploits/feed.xml

Dark Web Victims Feed Public RSS 2.0 50 items · 1h refresh

Newly observed victims on ransomware leak sites, from the last 14 days. Titles read “Victim, claimed by [Group]”, with description fields for country, sector and the group's public post text. Aggregated from /dark-web.

https://threatcluster.io/dark-web/feed.xml

Dark Web Data, CSV & JSON Public CSV / JSON 1h refresh

The same corpus behind the RSS feed, as structured data. Victims carry group, country, sector and the leak-site post URL; the onion list covers extortion leak-site addresses with their operator and current status.

These are claims published by the groups themselves. A listing is not confirmation that a breach occurred, or that the group's claim is accurate.

Site rows carry the page title, claimed operator, language, login/captcha gate and a link to our own watermarked screenshot where we have one.

https://threatcluster.io/api/darkweb/public/victims.csv
https://threatcluster.io/api/darkweb/public/onions.csv
https://threatcluster.io/api/darkweb/public/groups.csv
https://threatcluster.io/api/darkweb/public/victims.json

Victim feeds default to a 90-day window (CSV) and 30 days (JSON); add ?days=365 for more. The JSON carries company enrichment, legal name, headquarters, data size, where the leak post included it.

Snapshotted daily to GitHub with history: Jam0k/Ransomware-Intel , victims (90d / 365d / first-party only), groups and onion addresses.

For tooling

Blocklist, MISP

IOC Blocklist Public TXT JSON CSV 1h refresh

High-confidence malicious domains and IP addresses from the last 30 days, ready to paste into pfSense, Pi-hole or a firewall blocklist. Plain text for drop-in use, JSON when you want the source attribution, CSV for spreadsheets. The IOC page has integration examples.

https://threatcluster.io/api/iocs/public/feed.txt
https://threatcluster.io/api/iocs/public/feed.json
https://threatcluster.io/api/iocs/public/feed.csv

MISP Feed Public MISP 1h refresh

MISP-compatible feed for direct ingestion, no key or token required. Manifest at /misp/manifest.json, per-event JSON at /misp/{uuid}.json, optional hashes index at /misp/hashes.csv. Add it in your MISP UI under Sync Actions → List Feeds.

https://threatcluster.io/misp/manifest.json

AlienVault OTX Pulses Public OTX

ThreatCluster clusters published as pulses on AlienVault OTX. Subscribe to the projectargus account in OTX and the indicators flow straight into any tool already wired to the Open Threat Exchange, no extra integration on your side.

https://otx.alienvault.com/user/projectargus/pulses

SmartNews Feed Public SmartFormat 2.2 50 items · 30min refresh

SmartFormat-compliant RSS for the SmartNews publisher platform, with full content:encoded bodies, media:thumbnail, snf:logo and Dublin Core attribution. Only needed if you are submitting to an aggregator that requires SmartFormat, everyone else should use the Threat Feed.

https://threatcluster.io/feed/smartnews.xml

Your own feed

Business tier

My Interests & Custom Feeds Researcher and above RSS 2.0

Feeds filtered to the entities and keywords you track, your vendors, your sector, your suppliers. Set them up in Settings → Interests, or save a Custom Feed from any filter combination. Authenticated by session cookie, so a signed-in browser needs no API token.

https://threatcluster.io/api/feed/interests.xml
https://threatcluster.io/api/feed/custom/{feed-uuid}.xml

Notes

Limits and formats
  • Every feed is RSS 2.0 with an atom:link rel="self"; the main threat feed also advertises a WebSub hub for push delivery.
  • Cache TTL is one hour. Polling faster will not return fresher items.
  • Rate limit is 60 requests per minute per IP, ample for any normal reader.
  • Need STIX / TAXII or a full-fidelity firehose? That is on /formats.
  • Want to contribute findings back? Get in touch about ingestion partnerships.

Take the whole set.

One OPML import wires every RSS feed into your reader. The CSV and JSON feeds aren't reader formats, grab those above. Nothing to sign up for.