Research Intelligence Feed

Curated intelligence stays manual, attributed, and fail-closed.

This feed remains intentionally constrained. No live ingestion, no hidden webhooks, no transcript scraping, and no automatic publication path are active.

Current safe state

  • Automatic ingestion: disabled
  • Inbound webhooks: disabled
  • AI summarization approval path: disabled
  • Publication automation: prohibited

Source discipline

  • Tier 1 official-source support is planned but not active
  • Tier 2 and Tier 3 source review is required before activation
  • Tier 4 sources never auto-publish
  • Attribution never substitutes for permission

Threat Video Wall

Click-to-load embeds only, with attribution and visible review states.

The wall is designed for consent-first loading. Cards stay blocked until source, publisher, date, and rights checks are complete, and every outbound source link remains explicit.

Supported options

  • YouTube Privacy-Enhanced Mode: Supported with click-to-load gate. Embed only from approved originals and only through youtube-nocookie.com. No autoplay, no transcript scraping, and no silent background player loads.
  • Vimeo Official Embeds: Supported with manual review. Use only official player embeds or publisher-approved pages. Attribution, original link, and publish-date verification are required before a card can be activated.
  • TikTok: Held pending additional review. Not enabled by default. Any future support requires a stricter trust review for redirects, account age, attribution, and moderation workflow.

Guardrails in force

  • Only official embed methods or APIs are allowed.
  • No transcript scraping or body reposting is enabled.
  • Descriptions remain defanged when indicators appear.
  • Third-party players stay off until a visitor clicks to load them.
VIDEO WALLYouTube privacy-enhancedApril 2, 2024

APPROVED

Summiting the Pyramid: An Interview with the Creator of ATT&CK

Source: Center for Threat-Informed Defense
Creator or publisher: MITRE / CTID

Approved because the source page is official, the embedded player is disclosed by the publisher, and the content stays squarely in threat-informed defense and research context.

  • Original MITRE-affiliated source page verified
  • Publisher-disclosed YouTube embed confirmed
  • Attribution includes source, creator, and date
  • Player remains click-to-load until the visitor opts in

Indicator handling

  • No malicious indicators are displayed in this record[.]
VIDEO WALLYouTube privacy-enhancedApril 16, 2025

APPROVED

Understanding Adversaries via Threat-Informed Defense

Source: Center for Threat-Informed Defense
Creator or publisher: MITRE / CTID

Approved as a research-fit interview that stays on adversary understanding, browser security, and practical defensive interpretation rather than offensive demonstration.

  • Original MITRE-affiliated source page verified
  • Publisher-disclosed YouTube embed confirmed
  • No transcript scraping or excerpt reposting enabled
  • Visitor consent required before player load

Indicator handling

  • No malicious indicators are displayed in this record[.]
VIDEO WALLYouTube privacy-enhancedMarch 19, 2025

APPROVED

RSAC Virtual Seminar: How to Create a Threat Modeling Process and use ATT&CK

Source: Center for Threat-Informed Defense
Creator or publisher: MITRE / CTID

Approved because the source page is official and the seminar supports the site's defensive research lane with practical ATT&CK-based threat modeling.

  • Original MITRE-affiliated source page verified
  • Publisher-disclosed YouTube embed confirmed
  • Attribution fields complete
  • Privacy-enhanced embed path enforced

Indicator handling

  • No malicious indicators are displayed in this record[.]
VIDEO WALLVimeoPublish date pending independent verification

PENDING DATE VERIFICATION

CISA Teamworkshop 2025

Source: CISA
Creator or publisher: CISA

Candidate item from an official CISA publisher page. Kept blocked until the original publish date is independently confirmed and logged.

  • Original source link captured
  • Publisher label matches the source page
  • Third-party player remains blocked until review is complete
  • Outbound navigation stays explicit and attributed

Indicator handling

  • No malicious indicators are displayed in this record[.]
VIDEO WALLTikTok pending reviewNot approved for publication

PENDING RIGHTS REVIEW

Short-form threat video path

Source: Not approved
Creator or publisher: Not approved

Short-form feeds need additional verification for redirects, impersonation risk, account freshness, and rights handling before they belong on a public research page.

  • Provider support intentionally disabled
  • No embed code stored
  • No creator has been approved for this lane
  • Manual legal and attribution review still required

Indicator handling

  • Example defanged profile path: tiktok[.]com/@review_pending
ORIGINAL RESEARCHHackerman Crew ServicesAugust 17, 2026

Agent Trust Boundaries in Security Workflows

CONFIRMED

Internal research priority remains AI security controls that fail closed before an agent quietly expands authority.

EXTERNAL RESEARCHMicrosoft SecurityJuly 12, 2026

Defending SaaS-based applications against ShinyHunters OAuth abuse

CONFIRMED

Useful current research for identity-first defenders: Microsoft ties overlapping ShinyHunters tradecraft to OAuth abuse, vishing, guest access misuse, and supply-chain pressure against SaaS environments.

APPROVED — OFFICIAL SOURCE

SECURITY ADVISORYMicrosoft SecurityMarch 3, 2026

Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale

CONFIRMED

Storm-1747 remains relevant because it shows how phishing-as-a-service normalizes MFA bypass at industrial scale. This is a strong fit for the research lane and the site's identity-attack coverage.

APPROVED — OFFICIAL SOURCE

EXTERNAL RESEARCHRapid7 LabsMarch 17, 2026

The Attack Cycle is Accelerating: Rapid7 2026 Global Threat Landscape Report

CONFIRMED

A strong anchor item for the page because it frames speed, identity abuse, ransomware economics, and AI as an accelerant instead of a separate category of magic.

APPROVED — OFFICIAL SOURCE

EXTERNAL RESEARCHRapid7 LabsMarch 25, 2026

BPFdoor in Telecom Networks: Sleeper Cells in the Backbone

CONFIRMED

This is one of the better examples of why the site should privilege verified research writeups over recycled takes. It is threat-intel heavy, high signal, and still defensively framed.

APPROVED — OFFICIAL SOURCE

SECURITY ADVISORYRapid7 LabsJune 17, 2026

Rapid7 Detection Coverage for Iran-Linked Cyber Activity

CONFIRMED

Useful when defenders need a compact, current reference point for monitoring, detection coverage, and campaign follow-through during regional conflict-driven activity.

APPROVED — OFFICIAL SOURCE

SECURITY ADVISORYBitdefenderAugust 11, 2026

Bitdefender Threat Debrief | August 2026

CORRELATED

A current ransomware snapshot with strong disclosure language about the limits of leak-site claims. Good fit for a research feed that wants to stay analytical instead of sensational.

APPROVED — OFFICIAL SOURCE

SECURITY ADVISORYBitdefender LabsAugust 2, 2026

Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums

CONFIRMED

This one belongs because it connects gamer-focused lures, Discord distribution, and hands-on-keyboard malware tradecraft without requiring us to republish the underlying technical body.

APPROVED — OFFICIAL SOURCE

CONFERENCE NOTEHalcyonAugust 5, 2026

Black Hat's AI Blind Spot

CORRELATED

A useful conference-side commentary item because it asks whether the industry is matching attacker use of AI with equally serious defensive analysis, rather than just expo-floor enthusiasm.

APPROVED — OFFICIAL SOURCE

EXTERNAL RESEARCHHalcyonAugust 11, 2026

When Ransomware Hits, Are Board Members Personally Liable?

CORRELATED

Included because governance belongs in the threat conversation. The piece is less about malware mechanics and more about accountability, proportional action, and board-level oversight.

APPROVED — OFFICIAL SOURCE