Live · Monitoring 32/32 feeds
Auto-refresh every 5 min|--:--:-- UTC
Breaking
Real-time cyber threat intelligence

Live Threat Intelligence Feed

The top cyber threats from the last 24 hours — aggregated from 32 authoritative sources, deduplicated, ranked by priority, and refreshed every 5 minutes.

0Stories · 24h
0Critical
0High severity
0Sources online
Overall threat level · 24h
0/ 100
High

2 critical and 1 high-severity threats active now.

Threat Level · 24h
High

2 critical and 1 high-severity threats active now.

Trending CVEs
Trending Topics
Auto-refresh · next sync 5:00

Top Threats

Ranked by priority
#1
79
CriticalExploited in the WildUnauthenticatedRCECVE-2026-58138

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote…

The Hacker News
#2
71
CriticalUnauthenticatedRCEVulnerabilityCVE-2026-28326

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is…

The Hacker News
#3
60
HighExploited in the WildVulnerability

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below…

The Hacker News
#5
42
ElevatedExploitVulnerability

AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum

AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely…

Security Affairs
#7
39
ElevatedExploit

BragJack attacks hijack AI browser agents through malicious extensions

BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in bounties…

BleepingComputer
#8
39
ElevatedBreach

Google Gemini also Broke Out of Its Test Environment

Google Gemini escaped a cyber test environment, reached three real companies, and exposed why AI security tests need strict isolation. Google has confirmed that one of its Gemini models broke into the systems of three real companies during a cybersecurity…

Security Affairs
#9
39
ElevatedBreach

Identity Visibility in 2026: The Foundation of Identity Security

Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This…

The Hacker News
#10
37
ElevatedSupply ChainMalware

Brevo Supply-Chain Attack Infected Over 100,000 Websites

A Brevo supply-chain attack used compromised Cloudflare access to inject malware into websites, potentially affecting over 100,000 sites. Brevo, formerly known as Sendinblue, is a French cloud-based marketing and customer communication platform whose clients…

Security Affairs
#12
34
InfoPatch

North Korean WaterPlum hackers infected 30,000 devices worldwide

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]

BleepingComputer
#13
27
Info

TigerByte Cyber Emerges From Stealth With $3 Million in Funding

The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA. The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.

SecurityWeek

Latest Intel

Live · newest first

Real-Time Threat Intel & Cyber Threat Intelligence, Ranked by Priority

TI News Feed is a live threat intel news feed — a single dashboard that aggregates the world's most authoritative cyber threat intelligence (TI) sources. Track zero-day vulnerabilities, critical CVEs, ransomware campaigns, data breaches and advanced persistent threat (APT) activity from the last 24 hours — automatically deduplicated and ranked by priority, refreshed every 5 minutes. It is the fastest way to stay on top of breaking threat intel without checking dozens of sources by hand.

Priority-ranked

Severity, recency and source authority combine into a single 0–100 priority score so the most urgent threats rise to the top automatically.

Deduplicated

Near-duplicate coverage of the same CVE or breach is collapsed to one representative story — no noise, no repeats.

Live · 24h window

Only threat activity from the last 24 hours, refreshed every 5 minutes, so the board always reflects the current state of play.

Authoritative sources

Government CERTs, vendor threat-research teams and the most trusted security newsrooms — all in one console.

Why a priority-ranked threat feed matters

Security teams are flooded with cyber threat intelligence from hundreds of sources. The challenge is not access to information — it is signal. TI News Feed solves the noise problem by scoring every story against the signals that drive real-world risk: is the vulnerability being actively exploited in the wild, does it allow unauthenticated remote code execution, is it tied to a known ransomware operator or nation-state actor, and how recently was it disclosed. The result is a clear, continuously updated view of the threats that actually demand attention right now.

Built for analysts, SOC teams and threat hunters

Whether you run a security operations center, hunt threats, manage vulnerabilities, or simply want to stay ahead of breaking cybersecurity news, TI News Feed gives you a single pane of glass. The Top Threats column ranks the highest-priority intelligence, while the Latest Intel column delivers a live chronological stream — both filtered to the last 24 hours and free of duplicate reporting. Every item links straight to the original source for full context and verification.

Threat Intel & Threat Intelligence — Frequently Asked Questions

What is threat intel?

Threat intel — short for threat intelligence (TI) — is curated, evidence-based information about current and emerging cyber threats: newly disclosed vulnerabilities (CVEs), zero-day exploits, ransomware campaigns, data breaches, malware and nation-state (APT) activity. TI News Feed turns that raw threat intel into a single, live, priority-ranked news feed so you can see what matters at a glance.

What does “TI” mean in TI News Feed?

TI stands for Threat Intelligence. TI News Feed is a free threat intel news feed that aggregates the most authoritative cyber threat intelligence sources, removes duplicate reporting, and ranks every story by priority — refreshed every 5 minutes.

What is a threat intelligence feed?

A threat intelligence feed is a continuously updated stream of information about emerging cyber threats — newly disclosed vulnerabilities (CVEs), zero-day exploits, ransomware campaigns, data breaches, malware, and nation-state (APT) activity. TI News Feed aggregates dozens of the most authoritative threat intelligence feeds into a single real-time dashboard so security teams can see what matters without checking every source individually.

How does TI News Feed rank threats by priority?

Every story is scored from 0 to 100 by blending three signals: severity (weighted keywords such as zero-day, actively exploited, remote code execution, critical, ransomware and supply chain), recency within the last 24 hours, and the authority of the publishing source (CERTs and vendor research teams rank highest). The highest-scoring stories surface in the Top Threats column.

How often is the threat feed updated?

TI News Feed refreshes automatically every 5 minutes. The server re-aggregates all sources on a 5-minute cache, and the dashboard polls for fresh intelligence in the background so you always see threat activity from the last 24 hours without reloading the page.

Are duplicate stories removed?

Yes. The same breach or CVE is often reported by many outlets within minutes. TI News Feed detects near-duplicate stories using canonical-URL matching, shared CVE identifiers and title-similarity analysis, then keeps only the single highest-priority copy so the feed stays clean and signal-dense.

Which threat intelligence sources does TI News Feed aggregate?

TI News Feed pulls from government CERTs (CISA, NCSC), incident responders (SANS ISC), vendor threat-research teams (Cisco Talos, Palo Alto Unit 42, Microsoft MSRC, Google Project Zero, Check Point, SentinelLabs, ESET) and leading security newsrooms (Krebs on Security, BleepingComputer, The Record, Dark Reading and more).

Is TI News Feed free to use?

Yes. TI News Feed is a free, open threat-intelligence dashboard. It links directly to each original source so you can read the full report and verify details first-hand.

Threat Intelligence Sources

32 authoritative cyber threat intelligence feeds — government CERTs, vendor threat-research teams and trusted security newsrooms — aggregated in real time.