The top cyber threats from the last 24 hours — aggregated from 32 authoritative sources, deduplicated, ranked by priority, and refreshed every 5 minutes.
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated flaw in Veeam's console that hands over a managed agent's…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows -…
OVSwrap is a 13-year-old Linux kernel flaw that lets local users gain root privileges on most distributions using Open vSwitch. Security researcher Asim Manizada disclosed OVSwrap (CVE-2026-64531, CVSS score of 7.8), a local privilege escalation vulnerability…
An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw…
The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited. [...]
Tuskira has launched its Agentic Control Plane for Exposure Management, a new capability within the Tuskira platform that governs AI-discovered vulnerabilities from scan to verified closure. The capability extends Tuskira’s existing zero-day and…
Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users. According to Fortinet FortiGuard Labs,…
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek.
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability. We…
The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass. The post CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities appeared first on SecurityWeek.
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). [...]
Hackers stole personal information, medical records, and financial information from the organization’s server. The post 311,000 Impacted by Brown Health Medical Group-MA Data Breach appeared first on SecurityWeek.
Real-Time Threat Intel & Cyber Threat Intelligence, Ranked by Priority
TI News Feed is a live threat intel news feed — a single dashboard that aggregates the world's most authoritative cyber threat intelligence (TI) sources. Track zero-day vulnerabilities, critical CVEs, ransomware campaigns, data breaches and advanced persistent threat (APT) activity from the last 24 hours — automatically deduplicated and ranked by priority, refreshed every 5 minutes. It is the fastest way to stay on top of breaking threat intel without checking dozens of sources by hand.
Priority-ranked
Severity, recency and source authority combine into a single 0–100 priority score so the most urgent threats rise to the top automatically.
Deduplicated
Near-duplicate coverage of the same CVE or breach is collapsed to one representative story — no noise, no repeats.
Live · 24h window
Only threat activity from the last 24 hours, refreshed every 5 minutes, so the board always reflects the current state of play.
Authoritative sources
Government CERTs, vendor threat-research teams and the most trusted security newsrooms — all in one console.
Why a priority-ranked threat feed matters
Security teams are flooded with cyber threat intelligence from hundreds of sources. The challenge is not access to information — it is signal. TI News Feed solves the noise problem by scoring every story against the signals that drive real-world risk: is the vulnerability being actively exploited in the wild, does it allow unauthenticated remote code execution, is it tied to a known ransomware operator or nation-state actor, and how recently was it disclosed. The result is a clear, continuously updated view of the threats that actually demand attention right now.
Built for analysts, SOC teams and threat hunters
Whether you run a security operations center, hunt threats, manage vulnerabilities, or simply want to stay ahead of breaking cybersecurity news, TI News Feed gives you a single pane of glass. The Top Threats column ranks the highest-priority intelligence, while the Latest Intel column delivers a live chronological stream — both filtered to the last 24 hours and free of duplicate reporting. Every item links straight to the original source for full context and verification.
Threat intel — short for threat intelligence (TI) — is curated, evidence-based information about current and emerging cyber threats: newly disclosed vulnerabilities (CVEs), zero-day exploits, ransomware campaigns, data breaches, malware and nation-state (APT) activity. TI News Feed turns that raw threat intel into a single, live, priority-ranked news feed so you can see what matters at a glance.
What does “TI” mean in TI News Feed?
TI stands for Threat Intelligence. TI News Feed is a free threat intel news feed that aggregates the most authoritative cyber threat intelligence sources, removes duplicate reporting, and ranks every story by priority — refreshed every 5 minutes.
What is a threat intelligence feed?
A threat intelligence feed is a continuously updated stream of information about emerging cyber threats — newly disclosed vulnerabilities (CVEs), zero-day exploits, ransomware campaigns, data breaches, malware, and nation-state (APT) activity. TI News Feed aggregates dozens of the most authoritative threat intelligence feeds into a single real-time dashboard so security teams can see what matters without checking every source individually.
How does TI News Feed rank threats by priority?
Every story is scored from 0 to 100 by blending three signals: severity (weighted keywords such as zero-day, actively exploited, remote code execution, critical, ransomware and supply chain), recency within the last 24 hours, and the authority of the publishing source (CERTs and vendor research teams rank highest). The highest-scoring stories surface in the Top Threats column.
How often is the threat feed updated?
TI News Feed refreshes automatically every 5 minutes. The server re-aggregates all sources on a 5-minute cache, and the dashboard polls for fresh intelligence in the background so you always see threat activity from the last 24 hours without reloading the page.
Are duplicate stories removed?
Yes. The same breach or CVE is often reported by many outlets within minutes. TI News Feed detects near-duplicate stories using canonical-URL matching, shared CVE identifiers and title-similarity analysis, then keeps only the single highest-priority copy so the feed stays clean and signal-dense.
Which threat intelligence sources does TI News Feed aggregate?
TI News Feed pulls from government CERTs (CISA, NCSC), incident responders (SANS ISC), vendor threat-research teams (Cisco Talos, Palo Alto Unit 42, Microsoft MSRC, Google Project Zero, Check Point, SentinelLabs, ESET) and leading security newsrooms (Krebs on Security, BleepingComputer, The Record, Dark Reading and more).
Is TI News Feed free to use?
Yes. TI News Feed is a free, open threat-intelligence dashboard. It links directly to each original source so you can read the full report and verify details first-hand.
Threat Intelligence Sources
32 authoritative cyber threat intelligence feeds — government CERTs, vendor threat-research teams and trusted security newsrooms — aggregated in real time.