RSS & Atom Feeds

Free public feeds for your reader, SIEM, or downstream automation. Refreshed hourly.

Subscribe in Feedly, Inoreader, NewsBlur, or any RSS-capable tool. All feeds are public and require no authentication. We rate-limit at 60 requests/minute per IP and cache responses for 1 hour, so polling every 5 minutes is fine — but a WebSub hub is also advertised on the main threat feed for push notifications.

Import all feeds in one click

Download our OPML bundle and import it into your reader (Feedly: Organize → Import OPML · Inoreader: Preferences → Import/Export).

Download OPML

Threat Feed

Public RSS 2.0 50 items · 1h refresh

The top 50 trending threat clusters from the last 7 days. Same content as the home page. Each item links to a cluster page with summary, timeline, source articles, and related entities.

Open feed · also at: /rss /feed
https://threatcluster.io/feed.xml [copy]

Vulnerabilities Feed

Public RSS 2.0 50 items · 1h refresh

Latest CVEs from the last 7 days, enriched with severity, CISA KEV status, and public PoC availability. Each item links to the full CVE page with article mentions and timeline. Ideal for tracking what's hitting the news cycle this week, not the firehose of all NVD entries.

Sample item title: CVE-2026-28318 [KEV] [Exploit]
https://threatcluster.io/vulnerabilities/feed.xml [copy]

Exploits Feed

Public RSS 2.0 50 items · 1h refresh

CVEs with publicly available proof-of-concept exploit code, from the last 30 days. Sorted by exploit availability then CVSS. Same content as /exploits. Useful for prioritising patch cycles by weaponisation, not just severity.

https://threatcluster.io/exploits/feed.xml [copy]

Dark Web Victims Feed

Public RSS 2.0 50 items · 1h refresh

Newly observed victims on ransomware leak sites, from the last 14 days. Item title is “Victim — claimed by [Group]” with description fields for country, sector, and the group's public post text. Aggregated from /dark-web.

https://threatcluster.io/dark-web/feed.xml [copy]

IOC Blocklist Feed

Public TXT JSON CSV 1h refresh

High-confidence malicious domains and IP addresses, last 30 days. Ready to paste into pfSense, Pi-hole, or your firewall's blocklist. Available in plain text, JSON (with sources), or CSV. See the IOC landing page for integration examples.

https://threatcluster.io/api/iocs/public/feed.txt [copy] https://threatcluster.io/api/iocs/public/feed.json [copy] https://threatcluster.io/api/iocs/public/feed.csv [copy]

MISP Feed

Public MISP 1h refresh

MISP-compatible feed for direct ingestion into your MISP instance. Manifest at /misp/manifest.json, per-event JSON at /misp/{uuid}.json, optional hashes index at /misp/hashes.csv. Add as a remote feed in your MISP UI under Sync Actions → List Feeds.

https://threatcluster.io/misp/manifest.json [copy]

My Interests & Custom Feeds

Business tier RSS 2.0

Personalised feeds filtered by the entities and keywords you track. Set up in Settings → Interests, or create a saved Custom Feed from a filter combination. Authenticated via session cookie (no API token needed for the signed-in browser session).

https://threatcluster.io/api/feed/interests.xml https://threatcluster.io/api/feed/custom/{feed-uuid}.xml

Tips

  • All feeds are RSS 2.0 with an atom:link rel="self"; the main threat feed also advertises a WebSub hub for push.
  • Cache TTL on our side is 1 hour. Polling more often than that won't get you fresher items.
  • Rate limit is 60 requests/minute per IP. Plenty for any normal reader.
  • Need a STIX / TAXII or full-fidelity firehose? See /formats.
  • Want to share findings back to ThreatCluster? Get in touch about ingestion partnerships.