Cybersecurity RSS feeds: news, CVEs and threat intel

Updated September 29, 2026 6 min read

The most useful cybersecurity RSS feeds come from three kinds of sources: government agencies such as CISA for alerts and exploited vulnerabilities, vendors for advisories about their own products, and researchers and news sites for threat intelligence. All 66 feeds below had new posts when we checked them on September 27, 2026. Click a feed's name to add it to Feeder, or copy its URL into any RSS reader.

CISA RSS feeds

CISA, the US Cybersecurity and Infrastructure Security Agency, lists its main feeds on its subscribe page. If you follow one, make it Alerts: it announces every addition to the Known Exploited Vulnerabilities (KEV) catalog.

FeedWhat you getFeed URL
All CISA advisoriesEvery alert, advisory and bulletin in one feedhttps://www.cisa.gov/cybersecurity-advisories/all.xml
AlertsNew entries in the Known Exploited Vulnerabilities catalog, plus urgent alertshttps://www.cisa.gov/cybersecurity-advisories/alerts.xml
Cybersecurity advisoriesIn-depth advisories on threat actors and campaigns, such as #StopRansomwarehttps://www.cisa.gov/cybersecurity-advisories/cybersecurity-advisories.xml
ICS advisoriesVulnerabilities in industrial control systems and deviceshttps://www.cisa.gov/cybersecurity-advisories/ics-advisories.xml
ICS medical advisoriesVulnerabilities in medical deviceshttps://www.cisa.gov/cybersecurity-advisories/ics-medical-advisories.xml
Vulnerability bulletinsA weekly summary of new vulnerabilities, sorted by severityhttps://www.cisa.gov/cybersecurity-advisories/bulletins.xml
CISA NewsPress releases and newshttps://www.cisa.gov/news.xml

Still following an old us-cert.cisa.gov or cisa.gov/uscert feed? Those addresses redirect to the new ones above, so they keep working.

Is there an RSS feed for new CVEs?

Not from NVD anymore. The National Vulnerability Database's old RSS addresses answer "not found" today, and Feeder last saw a new item in them on November 7, 2023. NVD now shares CVE data through its API, as JSON, which RSS readers can't follow.

For new vulnerabilities in your reader, follow CISA's weekly Vulnerability bulletins above, which CISA describes as "a summary of new vulnerabilities that have been recorded in the past week", or one of these:

FeedWhat you getFeed URL
cvefeed.io: latest vulnerabilitiesNew CVEs as they're published, from an independent CVE monitoring sitehttps://cvefeed.io/rssfeed/latest.xml
cvefeed.io: high and criticalOnly CVEs rated high or criticalhttps://cvefeed.io/rssfeed/severity/high.xml
CERT/CC vulnerability notesVulnerability notes from the CERT Coordination Centerhttps://www.kb.cert.org/vuls/atomfeed/
Zero Day Initiative: published advisoriesAdvisories the Zero Day Initiative has publishedhttps://www.zerodayinitiative.com/rss/published/
Zero Day Initiative: upcoming advisoriesAdvisories the Zero Day Initiative will publishhttps://www.zerodayinitiative.com/rss/upcoming/
Exploit DatabaseNew entries in the Exploit Databasehttps://www.exploit-db.com/rss.xml

Vendor security advisory feeds

Follow the vendors whose products you run, and you hear about their patches from the source. For open-source software, GitHub has a releases feed for every project: add /releases.atom to the project's address, as in the OpenSSL example.

VendorFeed URL
Microsoft Security Update Guidehttps://api.msrc.microsoft.com/update-guide/rss
Cisco security advisorieshttps://sec.cloudapps.cisco.com/security/center/psirtrss20/CiscoSecurityAdvisory.xml
Palo Alto Networks security advisorieshttps://security.paloaltonetworks.com/rss.xml
Fortinet PSIRT advisorieshttps://filestore.fortinet.com/fortiguard/rss/ir.xml
Fortinet outbreak alertshttps://filestore.fortinet.com/fortiguard/rss/outbreakalert.xml
Ubuntu security noticeshttps://ubuntu.com/security/notices/rss.xml
Debian security advisorieshttps://www.debian.org/security/dsa
Google Chrome Releaseshttps://chromereleases.googleblog.com/feeds/posts/default
AWS security bulletinshttps://aws.amazon.com/security/security-bulletins/rss/feed/
Splunk security advisorieshttps://advisory.splunk.com/feed.xml
SonicWall security advisorieshttps://psirtapi.global.sonicwall.com/api/v1/feed/rss.xml
Tenable product security advisorieshttps://www.tenable.com/security/feed
OpenSSL releases on GitHubhttps://github.com/openssl/openssl/releases.atom

Other government and CERT feeds

FeedFeed URL
UK National Cyber Security Centrehttps://www.ncsc.gov.uk/api/1/services/v1/all-rss-feed.xml
Canadian Centre for Cyber Security: alerts and advisorieshttps://www.cyber.gc.ca/api/cccs/atom/v1/get?feed=alerts_advisories&lang=en
Australian Cyber Security Centre: alertshttps://www.cyber.gov.au/rss/alerts
CERT-EU security advisorieshttps://cert.europa.eu/publications/security-advisories-rss
MS-ISAC advisories (Center for Internet Security)https://www.cisecurity.org/feed/advisories

Threat intelligence and research feeds

Security companies' research teams publish their analysis of malware, threat actors and vulnerabilities on their blogs:

FeedFeed URL
Cisco Taloshttps://blog.talosintelligence.com/rss/
Unit 42 (Palo Alto Networks)https://unit42.paloaltonetworks.com/feed/
Google Cloud: Threat Intelligencehttps://cloudblog.withgoogle.com/topics/threat-intelligence/rss/
Microsoft Security Bloghttps://www.microsoft.com/en-us/security/blog/feed/
Securelist (Kaspersky)https://securelist.com/feed/
WeLiveSecurity (ESET)https://www.welivesecurity.com/en/rss/feed/
Check Point Researchhttps://research.checkpoint.com/feed/
Sophos: Threat Researchhttps://www.sophos.com/en-us/category/threat-research/feed
SentinelLabshttps://www.sentinelone.com/labs/feed/
CrowdStrike bloghttps://www.crowdstrike.com/en-us/blog/feed
Project Zero (Google)https://projectzero.google/feed.xml
The DFIR Reporthttps://thedfirreport.com/feed/
SANS Internet Storm Centerhttps://isc.sans.edu/rssfeed.xml
Malwarebytes Labshttps://www.malwarebytes.com/blog/feed/index.xml
AWS Security Bloghttps://aws.amazon.com/blogs/security/feed/

Cybersecurity news feeds

FeedFeed URL
Krebs on Securityhttps://krebsonsecurity.com/feed/
BleepingComputerhttps://www.bleepingcomputer.com/feed/
The Hacker Newshttps://feeds.feedburner.com/TheHackersNews
Dark Readinghttps://www.darkreading.com/rss.xml
SecurityWeekhttps://www.securityweek.com/feed/
The Recordhttps://therecord.media/feed
CyberScoophttps://cyberscoop.com/feed/
Wired: Securityhttps://www.wired.com/feed/category/security/latest/rss
Ars Technica: Securityhttps://arstechnica.com/security/feed/
The Register: Securityhttps://www.theregister.com/security/headlines.atom
Help Net Securityhttps://www.helpnetsecurity.com/feed/
Security Affairshttps://securityaffairs.com/feed
Infosecurity Magazinehttps://www.infosecurity-magazine.com/rss/news/
Schneier on Securityhttps://www.schneier.com/feed/atom/
Troy Hunthttps://www.troyhunt.com/rss/
Graham Cluleyhttps://grahamcluley.com/feed/

Cybersecurity podcasts and Reddit feeds

Podcast feeds work in any RSS reader, and every subreddit has a feed at its address plus .rss:

FeedFeed URL
Risky Business (podcast)https://risky.biz/feeds/risky-business/
SANS Internet Storm Center: daily podcasthttps://isc.sans.edu/dailypodcast.xml
r/netsechttps://www.reddit.com/r/netsec/.rss
r/cybersecurityhttps://www.reddit.com/r/cybersecurity/.rss

Which security feeds have stopped updating?

Feeder still sees people following these feeds, but they've gone quiet. Threatpost alone has more than 700 subscriptions in Feeder. If you follow one of them, switch to a live feed:

Old feedWhat happenedFollow instead
Threatpost
https://threatpost.com/feed/
Last post on August 31, 2022SecurityWeek or The Record
Naked Security (Sophos)
https://nakedsecurity.sophos.com/feed/
Now opens the Sophos blog, not a feed. Last post in September 2023Sophos: Threat Research
National Vulnerability Database
https://nvd.nist.gov/feeds/xml/cve/misc/nvd-rss.xml
Answers "not found". Last item on November 7, 2023CISA Vulnerability bulletins or cvefeed.io
Microsoft TechNet security advisories
https://technet.microsoft.com/en-us/security/rss/advisory
Its newest item is from January 2018Microsoft Security Update Guide
Dark Reading (old address)
https://www.darkreading.com/rss_simple.asp
No longer loads as a feed. Last post in November 2023Dark Reading at https://www.darkreading.com/rss.xml

How do I keep up without drowning in alerts?

  • Sort feeds by type. Put advisories, research and news in separate folders, so a busy news day doesn't bury a CISA alert.
  • Get notified about what's urgent. Turn on notifications for CISA Alerts and your vendors' advisories. Push and desktop notifications work on every plan.
  • Filter by the products you run. On Plus, at $7.99 a month billed yearly, a Filter posts rule on the cvefeed.io or CISA feeds can keep only the posts that mention your vendors, such as Fortinet, Ivanti or Citrix. See How to filter an RSS feed by keyword.
  • Share with your team. On Professional, at $14.99 per user a month billed yearly, rules can post matching advisories to Slack or Microsoft Teams. Filter duplicates hides a post when an earlier one had the same link or title, which helps when you follow both CISA's All feed and its Alerts feed.
  • Check often. Plus updates feeds as often as every 5 minutes, and Professional as often as every minute.

Common questions

Does CISA have RSS feeds?

Yes. CISA publishes feeds for all advisories, alerts, cybersecurity advisories, ICS and ICS medical advisories, weekly vulnerability bulletins and news. The addresses are in the CISA table above.

How do I get the CISA KEV catalog as an RSS feed?

Follow CISA's Alerts feed. The catalog itself is a JSON or CSV file, with 1,726 vulnerabilities on September 25, 2026, but each addition is announced in the Alerts feed with a post such as "CISA Adds Two Known Exploited Vulnerabilities to Catalog".

Are there cybersecurity RSS feeds on Reddit?

Yes. Every subreddit has one: https://www.reddit.com/r/netsec/.rss for r/netsec, for example. Reddit RSS feeds shows how to follow searches and users too.

How do I follow a security blog that isn't on this list?

Paste the blog's address into Add feed in Feeder, and Feeder finds its feed. For a site with no feed, Feeder can make one from the page: see How to get notified when a website changes.

Try Feeder

Follow CISA alerts, vendor advisories and security news in one place, with notifications for what's urgent.

Feeder is an RSS reader for the web, iOS and Android, with extensions for Chrome, Firefox and Edge. The free plan follows up to 200 feeds, updated as often as every 30 minutes, with no ads. Plus is $7.99 a month, billed yearly, for 2,500 feeds, updates as often as every 5 minutes and e-mail summaries.

Get started with Feeder for free

Read next

Still need help?

Our support team reads every message. Tell us what's going on and we'll help you out.

Contact support