Operational Snapshot
Use this as a starting point for daily/weekly threat briefs. The live news feed searches cyber, espionage, disinformation, influence operations, information warfare, hack-and-leak, wiper, telecom, and critical-infrastructure terms for each state.
What Changed
The newest high-priority collection changes in the selected window. Scores explain why an item surfaced.
Standing collection priorities
China
Telecom backbone access, critical-infrastructure pre-positioning, strategic technology theft, diaspora and Taiwan-related influence activity.
Russia
Ukraine-war cyber effects, GRU-linked disruptive operations, NATO/defense targeting, election influence and hack-and-leak activity.
Iran
Regional espionage, destructive/wiper activity, hack-and-leak personas, ransomware enablement, Israeli and Gulf targets.
North Korea
Cryptocurrency theft, defense/aerospace espionage, supply-chain abuse, fake IT worker schemes, nuclear/missile program support.
Recent Cyber & Information Warfare News
Pick a Source, then click Refresh live news. Hourly feed (prebuilt) β the default β loads data/news.json, regenerated hourly by a GitHub Action that fetches all feeds server-side (no proxy, instant load). The live sources below fetch on demand from the browser. GDELT API queries the global news index directly. Google News runs the same per-country cyber query against Google News and aggregates thousands of outlets. Cyber news feeds reaches out to major cyber-security outlets (The Hacker News, BleepingComputer, Krebs, CyberScoop, The Register, WIRED, and more β see Sources tab) via their RSS feeds and keeps Big 4-relevant items. Results are deduplicated and ranked by likely operational relevance.
APT / Threat Actor Catalog
The catalog attempts to live-load all CN/RU/IR/KP country-tagged actors from MISP Galaxy Threat Actor and Microsoft Activity Group data. If live sources fail, it displays the built-in curated fallback list.
| Country | Actor / Group | Aliases / Vendor Names | Notes | Source |
|---|
Tip: click any actor row to open its name crosswalk β every vendor's name for that actor.
Threat Actor Name Crosswalk
Answer one question fast: "this vendor calls the actor X β what does everyone else call it?" Search a name or alias below; each row maps the actor across vendor naming schemes (derived from the loaded catalog + the provider conventions). Click a row for the full breakdown.
| Actor | Providers | Origin | Other names & aliases |
|---|
Provider naming conventions
Known Exploited Vulnerabilities (CISA KEV)
The most recently added entries from the CISA KEV catalog β vulnerabilities with reliable evidence of active in-the-wild exploitation. KEV is not nation-state attributed, so it is not filtered by country; use the search box to filter by CVE, vendor, or product. The π flag marks known ransomware-campaign use; EPSS is FIRSTβs modeled probability of exploitation in the next 30 days (refreshed daily).
| CVE | Vendor / Product | Vulnerability | Added | Due | EPSS | Ransomware | Linked actors |
|---|
Diamond Model Mapper
Map a news story onto the Diamond Model of Intrusion Analysis β Adversary, Capability, Infrastructure, Victim. Pick a story below (or click β Diamond on any card in Recent News). Vertices are auto-extracted from the headline as a starting point β confirm against the full article.
Activity Trends
Stories per country per day, from the rolling archive the hourly sync maintains (data/archive.json). Hover for exact counts; the table below has the raw data.
Data table
| Date | China | Russia | Iran | North Korea | Total | Feeds OK |
|---|
Analyst Workbench
Pins, notes, and watchlists live in this browser (localStorage) β nothing leaves your machine. Pin stories from Recent News with the π button; pinned items lead the π Copy brief export.
π Pinned stories
Nothing pinned yet β use the π button on any Recent News card.
π Keyword watchlist
Stories matching these terms get a highlighted WATCH badge in Recent News β your own sector, a malware family, a region.
π¦ Machine-readable exports
Export the current (filtered) news β detected actors and CVEs included β as a STIX 2.1 bundle for MISP / OpenCTI, or subscribe to the curated stream as RSS / consume data/news.json directly.
Browser backup
Download or restore your pinned stories, notes, and watch terms. The backup contains no feed data.
Sources, Feeds, and Caveats
Live data sources used by this dashboard
- MISP Galaxy Threat Actor JSON β country-tagged threat actor clusters.
- MISP Galaxy Microsoft Activity Group JSON β Microsoft weather-family activity groups and aliases.
- Microsoft threat actor naming taxonomy β Typhoon/Blizzard/Sandstorm/Sleet families.
- GDELT Doc API β public news article discovery.
- MITRE ATT&CK Groups β TTP profiles and group aliases.
- Malpedia Actors β actor-to-malware family mappings.
- CISA Cybersecurity Advisories β U.S. government advisories.
Hourly prebuilt feed
The default Hourly feed (prebuilt) source reads data/news.json, regenerated every hour by the Sync news feed GitHub Action (scripts/fetch-news.mjs). It fetches all feeds server-side β no CORS proxy, no rate limits, instant load β and publishes a cached data snapshot without adding hourly bot commits to the source branch. The live sources below remain available as an on-demand fallback.
Google News & cyber news feeds (RSS)
Google News runs the same per-country cyber query (see Overview) against the Google News RSS search endpoint, aggregating thousands of outlets with a when: recency window tied to the lookback selector. The Cyber news feeds source option reads RSS/Atom from cyber-security press (The Hacker News, BleepingComputer, Krebs on Security, CyberScoop, SecurityWeek, Dark Reading, The Record, Help Net Security, The Register, WIRED), vendor threat-research blogs (Microsoft, Cisco Talos, Palo Alto Unit 42, CrowdStrike, SentinelOne, ESET, Kaspersky Securelist, Check Point, Fortinet, Proofpoint), and government/community sources (SANS ISC, CISA), then keeps items mentioning China, Russia, Iran, or North Korea. Feeds are fetched with limited concurrency through the proxy. Because most outlets do not send CORS headers, feed requests are routed through a public CORS proxy (allorigins / corsproxy.io). If feeds fail to load, the proxy may be rate-limited or down β switch back to the GDELT source. Edit the feed list in data/sources.json (the single source of truth for the hourly collector and this page) to add or remove outlets.
Analytic caveats
- Attribution is probabilistic and often based on TTPs, infrastructure, malware, targeting, timing, language, and government/vendor reporting.
- Names are not one-to-one. APT37, ScarCruft, Reaper, Ricochet Chollima, and Group123 are treated differently by different vendors.
- Some MISP records are legacy, low-confidence, campaign-level, or cybercrime/state-aligned rather than formal state units.
- Information warfare reporting is broader than APT reporting; the news feed searches both cyber-technical and influence-operation terms.