Provenance
Sources
Every signal published on thrunt.me originates with one of the feeds below. License terms and attribution are tracked per source. Last-success and last-check timestamps are read from the live pipeline state; when a feed has not succeeded in 48 hours its status flips to stale and the next brief carries a visible notice.
| Source | Status | Last success | License |
|---|---|---|---|
| abuse.ch URLhaus (malicious URL IOCs) | healthy | 2026-07-14 09:33:20 UTC | CC0 with attribution requested |
| circl-misp | healthy | 2026-07-14 09:33:23 UTC | Unknown |
| CISA Known Exploited Vulnerabilities Catalog | healthy | 2026-07-14 09:30:03 UTC | Public domain (U.S. Government) |
| FIRST.org Exploit Prediction Scoring System (EPSS) | healthy | 2026-07-14 09:30:04 UTC | Per FIRST.org Terms of Use |
| GitHub Security Advisories (reviewed) | healthy | 2026-07-14 09:33:22 UTC | Per GitHub Terms of Use |
| MITRE ATT&CK Enterprise | healthy | 2026-07-14 09:33:22 UTC | CC BY 4.0 |
| MITRE CTID KEV→ATT&CK Mappings | healthy | 2026-07-14 09:33:24 UTC | Apache 2.0 (Center for Threat-Informed Defense) |
| NIST National Vulnerability Database (CVEs) | healthy | 2026-07-14 09:32:50 UTC | Public domain (NIST) |
| ransomware.live (victim postings) | healthy | 2026-07-14 09:30:03 UTC | Per ransomware.live Terms of Use |
| SEC EDGAR — Form 8-K Item 1.05 (Material Cybersecurity Incidents) | healthy | 2026-07-14 09:30:01 UTC | Public domain (U.S. Government) |
| SigmaHQ Community Detection Rules (coverage index) | healthy | 2026-07-14 09:33:25 UTC | Detection Rule License (DRL) 1.1 |