ForumsResourcesFree threat intelligence feeds worth subscribing to

Free threat intelligence feeds worth subscribing to

PatchTuesday_Sam 9/16/2025 USER

Compiled a list of free threat intelligence feeds and sources:

IP/Domain Reputation

  • AbuseIPDB — Community-reported malicious IPs
  • URLhaus (abuse.ch) — Malware URLs
  • PhishTank — Community-verified phishing URLs
  • AlienVault OTX — Open threat exchange

Vulnerability Intel

  • CISA KEV (Known Exploited Vulnerabilities) — The "must patch" list
  • NVD — National Vulnerability Database
  • VulnCheck — Exploit intelligence

Malware/IOC

  • MalwareBazaar — Malware sample sharing
  • Feodo Tracker — Botnet C2 tracking
  • ThreatFox — IOC sharing platform

RSS/Newsletters

  • SANS ISC — Daily security diary
  • The Hacker News — Breaking security news
  • Krebs on Security — Investigative journalism
  • TLDR Sec — Weekly security newsletter

All free. No excuses for not having threat intel.

AP
AppSec_Jordan9/16/2025

CISA KEV is the single most actionable feed. If a CVE is on the KEV list, it means it's actively being exploited in the wild. We prioritize KEV entries above CVSS scores in our patching.

MD
MDR_Analyst_Chris9/17/2025

Add GreyNoise — they show what's being mass-scanned on the internet. Helps distinguish "this IP probed us" vs "this IP probes everyone." Free community tier is solid.

HO
HoneyPot_Hacker_Zara9/19/2025

For MSPs: AlertMonitor's SOC-powered intelligence basically aggregates and contextualizes these feeds for you. The daily brief saves me from checking 10 different sources every morning.

Verified Access Required

To maintain the integrity of our intelligence feeds, only verified partners and security professionals can post replies.

Request Access

Thread Stats

Created9/16/2025
Last Active9/18/2025
Replies3
Views3,638