安全从业者通常已经在 Feedly 订阅了十个以上的信息源。我们的价值不在于比他们更快发布,而在于把所有信息读完、剔除噪声、筛出真正值得关注的内容。本页公开我们每日阅读的全部来源,您可以据此独立判断我们的筛选质量。
我们目前追踪 47 个信息源:31 个在用、8 个审查中、8 个已主动排除。
每季度复审一次。最近复审:2026-04-22。
当前驱动我们日常报道的信息源。权威独立媒体在编辑判断中权重最高;常规来源用于扩展覆盖面与多方交叉验证。
Official U.S. CISA cybersecurity alerts and advisories — authoritative primary source.
CISA's KEV catalog — the authoritative list of actively exploited vulnerabilities requiring immediate remediation.
Official Fortinet PSIRT advisory feed for vulnerability disclosures and remediation guidance.
Elite vulnerability research team publishing deep technical zero-day write-ups.
Official Ivanti security advisory feed with vulnerability disclosures and mitigation guidance.
Kaspersky GReAT team's APT and crimeware research — widely cited primary source.
Brian Krebs' original investigative security reporting — the gold standard for attribution and follow-the-money analysis.
UK National Cyber Security Centre all-content RSS feed; the threat-report-only feed currently returns zero items.
NIST NVD 2.0 CVE API queried over a rolling 48-hour publication window — authoritative source-of-truth for the vulnerabilities category's CVE hard-gate.
OpenAI Daybreak is OpenAI's cybersecurity accelerator for security startups building the next generation of cybersecurity tools.
Official OpenAI news feed filtered at ingest to cybersecurity, security, provenance, supply-chain, and AI-safety items.
Official Palo Alto Networks security advisory RSS feed for PAN-OS, Prisma, Cortex, and related product vulnerability disclosures.
In-depth APT, ransomware, cloud, and IoT research — one of the most cited vendor research outlets.
Daily SANS ISC Stormcast feed with topic links and summaries; replaces the handler diary RSS where Stormcast entries carried boilerplate-only descriptions.
Bruce Schneier's long-running blog on cryptography, security policy, and privacy — essential for big-picture analysis.
Independent cybersecurity journalism covering nation-state operations, ransomware, and policy — staffed by career security reporters.
Small independent research shop with a consistent track record of zero-day discoveries (Ivanti, Atlassian, Exchange).
Trend Micro's ZDI advisories from their bug-bounty program — primary-source vulnerability disclosures.
Practitioner-level pentest, threat hunting, and active defense content from the BHIS team.
Breaking breach news, ransomware leaks, and malware analysis — fast wire coverage.
Internet-scan-based research on exposed infrastructure, IOC enrichment, and attack-surface trends.
Vendor research arm publishing malware analysis and campaign reports.
Enterprise-focused security analysis aimed at CISOs and SOC leaders.
Malware analysis, detection engineering, and threat hunting techniques.
Threat intelligence on malware, scams, and enterprise threats.
Emergent threat analysis and Metasploit-adjacent vulnerability research.
Nation-state threat research and geopolitical cyber risk analysis.
Major independent cybersecurity outlet covering breaches, vulnerabilities, and policy.
SentinelLabs research on malware families, threat actors, and exploitation.
High-volume daily security news aggregator covering CVEs, breaches, and disclosures.
ESET research on APT campaigns and Eastern European threats.
试用期内。在确认长期纳入或排除前,我们会持续评估其信息源稳定性、编辑信号强度以及与其他来源的重合度。
Strong threat research, paused pending vendor-heavy-coverage review against independent sources.
Official MyF5 security advisory surface for BIG-IP, BIG-IQ, NGINX, and related F5 product vulnerability disclosures.
排除原因: F5 advisories require MyF5/custom RSS handling; keep under review until we confirm a stable machine-readable feed that does not produce empty or dirty results.
Chinese-language security community — first native ZH source added to the pool; enters as ingest-only per the contract spec for a 30-day audit before promotion.
排除原因: Feed returns HTTP 405 to Node-based ingestion clients as of 2026-05-05; keep under review until a reliable machine-readable endpoint is available.
Google's TAG on government-backed attacks and zero-day tracking — authoritative primary research, but the configured category RSS URL now returns 404.
World-class APT attribution research; paused pending feed-reliability verification.
Authoritative Microsoft security disclosures; paused pending feed-format stability confirmation.
Official Progress community advisories for MOVEit Transfer, MOVEit Cloud, and MOVEit Automation vulnerability bulletins.
排除原因: No stable public RSS endpoint confirmed yet; keep visible for transparency while coverage is cross-checked through NVD, CISA KEV, and vendor bulletin URLs.
Strong X-Ops research; paused pending feed noise review (product posts interleaved with research).
我们主动不纳入的来源。在此列出,以便您核实我们究竟阅读什么、不阅读什么。
Vendor blog mixing threat research with sales and product marketing at roughly a 1:4 ratio.
排除原因: Signal-to-noise threshold — majority of items are commercial/sales content rather than research. Revisit via whitelist on /blog/threat-research/ if the ratio improves.
Low-authority aggregator that re-writes content from BleepingComputer and The Hacker News.
排除原因: Signal-to-noise threshold — duplicates higher-authority primary sources.
Vendor patch summaries that typically lack CVE detail and independent analysis.
排除原因: Signal-to-noise threshold — contributed to the April 2026 CVE-hedging ship quality issue; patch advisories without identifiers downstream.
General tech community feed — off-topic for a security-focused newsroom.
排除原因: Signal-to-noise threshold — majority of items are general tech, not security.
Predominantly vendor surveys, product roundups, and press releases.
排除原因: Signal-to-noise threshold — product/survey content outweighed incident reporting.
Primarily product marketing interleaved with research.
排除原因: Signal-to-noise threshold — marketing content outweighed standalone research value.
Mix of threat research with webinar and analyst-report promotions.
排除原因: Signal-to-noise threshold — promotional content interleaved with research reduced the usable yield.
Patch Tuesday analysis and cloud posture findings that largely duplicate ZDI, Rapid7, and The Hacker News.
排除原因: Signal redundancy — patch coverage already provided by higher-authority sources in our pool.
请通过邮件发给我们:名称、URL,以及一句话说明为什么值得纳入。我们会逐封阅读,并在每季度复审时一并评估。我们刻意使用邮件而非网页表单——没有表单、没有提交队列、没有可以被公开刷榜的建议入口。
推荐一个来源通常会在几个工作日内回复。我们不使用自动回复。