The most useful cybersecurity RSS feeds come from three kinds of sources: government agencies such as CISA for alerts and exploited vulnerabilities, vendors for advisories about their own products, and researchers and news sites for threat intelligence. All 66 feeds below had new posts when we checked them on September 27, 2026. Click a feed's name to add it to Feeder, or copy its URL into any RSS reader.
CISA RSS feeds
CISA, the US Cybersecurity and Infrastructure Security Agency, lists its main feeds on its subscribe page. If you follow one, make it Alerts: it announces every addition to the Known Exploited Vulnerabilities (KEV) catalog.
| Feed | What you get | Feed URL |
|---|---|---|
| All CISA advisories | Every alert, advisory and bulletin in one feed | https://www.cisa.gov/cybersecurity-advisories/all.xml |
| Alerts | New entries in the Known Exploited Vulnerabilities catalog, plus urgent alerts | https://www.cisa.gov/cybersecurity-advisories/alerts.xml |
| Cybersecurity advisories | In-depth advisories on threat actors and campaigns, such as #StopRansomware | https://www.cisa.gov/cybersecurity-advisories/cybersecurity-advisories.xml |
| ICS advisories | Vulnerabilities in industrial control systems and devices | https://www.cisa.gov/cybersecurity-advisories/ics-advisories.xml |
| ICS medical advisories | Vulnerabilities in medical devices | https://www.cisa.gov/cybersecurity-advisories/ics-medical-advisories.xml |
| Vulnerability bulletins | A weekly summary of new vulnerabilities, sorted by severity | https://www.cisa.gov/cybersecurity-advisories/bulletins.xml |
| CISA News | Press releases and news | https://www.cisa.gov/news.xml |
Still following an old us-cert.cisa.gov or cisa.gov/uscert feed? Those addresses redirect to the new ones above, so they keep working.
Is there an RSS feed for new CVEs?
Not from NVD anymore. The National Vulnerability Database's old RSS addresses answer "not found" today, and Feeder last saw a new item in them on November 7, 2023. NVD now shares CVE data through its API, as JSON, which RSS readers can't follow.
For new vulnerabilities in your reader, follow CISA's weekly Vulnerability bulletins above, which CISA describes as "a summary of new vulnerabilities that have been recorded in the past week", or one of these:
| Feed | What you get | Feed URL |
|---|---|---|
| cvefeed.io: latest vulnerabilities | New CVEs as they're published, from an independent CVE monitoring site | https://cvefeed.io/rssfeed/latest.xml |
| cvefeed.io: high and critical | Only CVEs rated high or critical | https://cvefeed.io/rssfeed/severity/high.xml |
| CERT/CC vulnerability notes | Vulnerability notes from the CERT Coordination Center | https://www.kb.cert.org/vuls/atomfeed/ |
| Zero Day Initiative: published advisories | Advisories the Zero Day Initiative has published | https://www.zerodayinitiative.com/rss/published/ |
| Zero Day Initiative: upcoming advisories | Advisories the Zero Day Initiative will publish | https://www.zerodayinitiative.com/rss/upcoming/ |
| Exploit Database | New entries in the Exploit Database | https://www.exploit-db.com/rss.xml |
Vendor security advisory feeds
Follow the vendors whose products you run, and you hear about their patches from the source. For open-source software, GitHub has a releases feed for every project: add /releases.atom to the project's address, as in the OpenSSL example.
| Vendor | Feed URL |
|---|---|
| Microsoft Security Update Guide | https://api.msrc.microsoft.com/update-guide/rss |
| Cisco security advisories | https://sec.cloudapps.cisco.com/security/center/psirtrss20/CiscoSecurityAdvisory.xml |
| Palo Alto Networks security advisories | https://security.paloaltonetworks.com/rss.xml |
| Fortinet PSIRT advisories | https://filestore.fortinet.com/fortiguard/rss/ir.xml |
| Fortinet outbreak alerts | https://filestore.fortinet.com/fortiguard/rss/outbreakalert.xml |
| Ubuntu security notices | https://ubuntu.com/security/notices/rss.xml |
| Debian security advisories | https://www.debian.org/security/dsa |
| Google Chrome Releases | https://chromereleases.googleblog.com/feeds/posts/default |
| AWS security bulletins | https://aws.amazon.com/security/security-bulletins/rss/feed/ |
| Splunk security advisories | https://advisory.splunk.com/feed.xml |
| SonicWall security advisories | https://psirtapi.global.sonicwall.com/api/v1/feed/rss.xml |
| Tenable product security advisories | https://www.tenable.com/security/feed |
| OpenSSL releases on GitHub | https://github.com/openssl/openssl/releases.atom |
Other government and CERT feeds
| Feed | Feed URL |
|---|---|
| UK National Cyber Security Centre | https://www.ncsc.gov.uk/api/1/services/v1/all-rss-feed.xml |
| Canadian Centre for Cyber Security: alerts and advisories | https://www.cyber.gc.ca/api/cccs/atom/v1/get?feed=alerts_advisories&lang=en |
| Australian Cyber Security Centre: alerts | https://www.cyber.gov.au/rss/alerts |
| CERT-EU security advisories | https://cert.europa.eu/publications/security-advisories-rss |
| MS-ISAC advisories (Center for Internet Security) | https://www.cisecurity.org/feed/advisories |
Threat intelligence and research feeds
Security companies' research teams publish their analysis of malware, threat actors and vulnerabilities on their blogs:
| Feed | Feed URL |
|---|---|
| Cisco Talos | https://blog.talosintelligence.com/rss/ |
| Unit 42 (Palo Alto Networks) | https://unit42.paloaltonetworks.com/feed/ |
| Google Cloud: Threat Intelligence | https://cloudblog.withgoogle.com/topics/threat-intelligence/rss/ |
| Microsoft Security Blog | https://www.microsoft.com/en-us/security/blog/feed/ |
| Securelist (Kaspersky) | https://securelist.com/feed/ |
| WeLiveSecurity (ESET) | https://www.welivesecurity.com/en/rss/feed/ |
| Check Point Research | https://research.checkpoint.com/feed/ |
| Sophos: Threat Research | https://www.sophos.com/en-us/category/threat-research/feed |
| SentinelLabs | https://www.sentinelone.com/labs/feed/ |
| CrowdStrike blog | https://www.crowdstrike.com/en-us/blog/feed |
| Project Zero (Google) | https://projectzero.google/feed.xml |
| The DFIR Report | https://thedfirreport.com/feed/ |
| SANS Internet Storm Center | https://isc.sans.edu/rssfeed.xml |
| Malwarebytes Labs | https://www.malwarebytes.com/blog/feed/index.xml |
| AWS Security Blog | https://aws.amazon.com/blogs/security/feed/ |
Cybersecurity news feeds
| Feed | Feed URL |
|---|---|
| Krebs on Security | https://krebsonsecurity.com/feed/ |
| BleepingComputer | https://www.bleepingcomputer.com/feed/ |
| The Hacker News | https://feeds.feedburner.com/TheHackersNews |
| Dark Reading | https://www.darkreading.com/rss.xml |
| SecurityWeek | https://www.securityweek.com/feed/ |
| The Record | https://therecord.media/feed |
| CyberScoop | https://cyberscoop.com/feed/ |
| Wired: Security | https://www.wired.com/feed/category/security/latest/rss |
| Ars Technica: Security | https://arstechnica.com/security/feed/ |
| The Register: Security | https://www.theregister.com/security/headlines.atom |
| Help Net Security | https://www.helpnetsecurity.com/feed/ |
| Security Affairs | https://securityaffairs.com/feed |
| Infosecurity Magazine | https://www.infosecurity-magazine.com/rss/news/ |
| Schneier on Security | https://www.schneier.com/feed/atom/ |
| Troy Hunt | https://www.troyhunt.com/rss/ |
| Graham Cluley | https://grahamcluley.com/feed/ |
Cybersecurity podcasts and Reddit feeds
Podcast feeds work in any RSS reader, and every subreddit has a feed at its address plus .rss:
| Feed | Feed URL |
|---|---|
| Risky Business (podcast) | https://risky.biz/feeds/risky-business/ |
| SANS Internet Storm Center: daily podcast | https://isc.sans.edu/dailypodcast.xml |
| r/netsec | https://www.reddit.com/r/netsec/.rss |
| r/cybersecurity | https://www.reddit.com/r/cybersecurity/.rss |
Which security feeds have stopped updating?
Feeder still sees people following these feeds, but they've gone quiet. Threatpost alone has more than 700 subscriptions in Feeder. If you follow one of them, switch to a live feed:
| Old feed | What happened | Follow instead |
|---|---|---|
Threatposthttps://threatpost.com/feed/ | Last post on August 31, 2022 | SecurityWeek or The Record |
Naked Security (Sophos)https://nakedsecurity.sophos.com/feed/ | Now opens the Sophos blog, not a feed. Last post in September 2023 | Sophos: Threat Research |
National Vulnerability Databasehttps://nvd.nist.gov/feeds/xml/cve/misc/nvd-rss.xml | Answers "not found". Last item on November 7, 2023 | CISA Vulnerability bulletins or cvefeed.io |
Microsoft TechNet security advisorieshttps://technet.microsoft.com/en-us/security/rss/advisory | Its newest item is from January 2018 | Microsoft Security Update Guide |
Dark Reading (old address)https://www.darkreading.com/rss_simple.asp | No longer loads as a feed. Last post in November 2023 | Dark Reading at https://www.darkreading.com/rss.xml |
How do I keep up without drowning in alerts?
- Sort feeds by type. Put advisories, research and news in separate folders, so a busy news day doesn't bury a CISA alert.
- Get notified about what's urgent. Turn on notifications for CISA Alerts and your vendors' advisories. Push and desktop notifications work on every plan.
- Filter by the products you run. On Plus, at $7.99 a month billed yearly, a Filter posts rule on the cvefeed.io or CISA feeds can keep only the posts that mention your vendors, such as Fortinet, Ivanti or Citrix. See How to filter an RSS feed by keyword.
- Share with your team. On Professional, at $14.99 per user a month billed yearly, rules can post matching advisories to Slack or Microsoft Teams. Filter duplicates hides a post when an earlier one had the same link or title, which helps when you follow both CISA's All feed and its Alerts feed.
- Check often. Plus updates feeds as often as every 5 minutes, and Professional as often as every minute.
Common questions
Does CISA have RSS feeds?
Yes. CISA publishes feeds for all advisories, alerts, cybersecurity advisories, ICS and ICS medical advisories, weekly vulnerability bulletins and news. The addresses are in the CISA table above.
How do I get the CISA KEV catalog as an RSS feed?
Follow CISA's Alerts feed. The catalog itself is a JSON or CSV file, with 1,726 vulnerabilities on September 25, 2026, but each addition is announced in the Alerts feed with a post such as "CISA Adds Two Known Exploited Vulnerabilities to Catalog".
Are there cybersecurity RSS feeds on Reddit?
Yes. Every subreddit has one: https://www.reddit.com/r/netsec/.rss for r/netsec, for example. Reddit RSS feeds shows how to follow searches and users too.
How do I follow a security blog that isn't on this list?
Paste the blog's address into Add feed in Feeder, and Feeder finds its feed. For a site with no feed, Feeder can make one from the page: see How to get notified when a website changes.
Try Feeder
Follow CISA alerts, vendor advisories and security news in one place, with notifications for what's urgent.
Feeder is an RSS reader for the web, iOS and Android, with extensions for Chrome, Firefox and Edge. The free plan follows up to 200 feeds, updated as often as every 30 minutes, with no ads. Plus is $7.99 a month, billed yearly, for 2,500 feeds, updates as often as every 5 minutes and e-mail summaries.
Get started with Feeder for free