Sources we trust

We don't rewrite press releases. Every advisory we publish has a traceable origin — an NVD record, a KEV entry, a vendor bulletin, a CERT note, or a researcher's write-up. If a source disappears, the link breaks honestly instead of silently decaying into hearsay.

The list below is the current registry of what feeds this desk. It updates automatically when we add or retire a source, so what you see here is what we're actually reading today — not a marketing checklist.

Vulnerability feeds

Canonical CVE data — NVD and equivalent national registries.

NameTypeRegionDescription
NVD — Recent CVEs ↗CVE feedusNIST National Vulnerability Database recent CVEs

Threat intelligence

Exploitation signal — CISA KEV and other actively-exploited-vulnerability catalogs.

NameTypeRegionDescription
CISA — Known Exploited Vulnerabilities ↗KEVusCISA Known Exploited Vulnerabilities catalog (JSON)

National CERTs

Government response teams publishing coordinated advisories.

NameTypeRegionDescription
BSI — CERT-Bund WID ↗CERTdeBSI CERT-Bund Warn- und Informationsdienst
CISA — Cybersecurity Advisories ↗CERTusCISA cybersecurity advisories (broader than KEV)
JPCERT/CC Alert ↗CERTjpJapan CERT — broad APAC visibility

Vendor advisories

First-party security bulletins from software and hardware vendors.

NameTypeRegionDescription
Google Project Zero ↗Vendor advisoryglobalGoogle Project Zero original 0-day research drops
MSRC — Security Update Guide ↗Vendor advisoryglobalMicrosoft Security Response Center advisory feed