About the project

NEOSEC Intel

The German-language vulnerability and threat intelligence platform. Built by NEOSEC GmbH for mid-market and KRITIS operators under NIS2.

Mission

We consolidate publicly available security data sources — NVD, CVE.org, CISA, BSI, GHSA, OSV, MSRC, abuse.ch, vendor PSIRTs — into a single, German-language situational view. Instead of keeping five tabs open, security teams see at a glance what's new, what's critical, what affects their own stack, and what made the CISA KEV list. We address both operators (NIS2, mandatory since 2024) and manufacturers (Cyber Resilience Act / EU 2024/2847, mandatory from December 2027 for products with digital elements — including Coordinated Vulnerability Disclosure, SBOM creation and security updates across the lifecycle).

Sources & licenses

Every source NEOSEC Intel ingests — grouped by purpose, with origin, license and our usage discipline. BSI content is never mirrored 1:1; commercial tech news runs strictly as RSS teaser with a backlink to the origin.

Vulnerability advisories (structured)

SourceLicenseNote
NIST NVDUS Government Open Data (effectively CC0)
CVE.org / MITRE CVE ServicesCVE Record Format — CC0 1.0
CISA Known Exploited Vulnerabilities (KEV)US Government Open Data — Public Domain
BSI CERT-Bund WID (RSS + CSAF 2.0)BSI EigenurheberrechtLinked-only. Wir spiegeln keine Inhalte 1:1; Original-Quelle wird verlinkt + eigen-angereichert.
GitHub Security Advisories (GHSA)CC-BY-4.0
OSV.dev (Open Source Vulnerabilities)Pro Ökosystem unterschiedlich — überwiegend CC-BY-4.0 / CC0 1.0 / Apache-2.0 / MITWir ziehen alle 44 Ökosysteme: PyPI, npm, Go, crates.io, Maven, RubyGems, NuGet, Packagist, Hex, Pub, Debian, Ubuntu, Red Hat, AlmaLinux, Rocky Linux, SUSE, Alpine, Echo u. a.
Microsoft Security Response Center (MSRC) CVRFMicrosoft Permitted Use — Public Vendor ContentLinked-only zum offiziellen Update-Guide-Eintrag.
ENISA EUVD (European Vulnerability Database)EU Public Sector Information — free reuse with attributionSeit Mai 2025 das EU-Pendant zur NVD. JSON-API mit CVSS v3/v4, EPSS und Aliase auf CVE-IDs.
Debian Security Advisories (DSA)salsa-Tracker: GPL-3.0-or-later
Ubuntu Security Notices (USN)CC-BY-SA-4.0 (Share-Alike)Wir spiegeln nicht den Volltext, nur Metadaten + Backlink — kein Share-Alike-Trigger.

Threat intel / Indicators of Compromise

SourceLicenseNote
abuse.ch URLhausCC0 1.0 Public Domain
abuse.ch MalwareBazaarCC0 1.0 Public Domain
abuse.ch ThreatFoxCC0 1.0 Public Domain
abuse.ch Feodo TrackerCC0 1.0 Public Domain
AlienVault OTX (subscribed pulses)Pro Pulse unterschiedlich — wir filtern strikt auf TLP:WHITETLP:GREEN/AMBER/RED-Pulses werden vor dem Persist verworfen, damit sie nicht in der anonymen Sicht landen.
Tor Exit Node List (onionoo.torproject.org)Public — BSD-style

Enrichment

SourceLicenseNote
CrowdSec CTI (community signal)Free Tier mit AccountTag-only — wir hängen crowdsec:* Tags an IPs, kein Bulk-Re-Export der CrowdSec-Blocklist.
VirusTotal v3 (Free Public API)Free-Tier ToS — keine Bulk-RedistributionOn-demand-Lookup mit 24h Redis-Cache, ≤500 Requests/Tag. Wir speichern nur detection_count + reputation + permalink.
EPSS (FIRST.org Exploit Prediction Scoring System)CC0 1.0 Public Domain
CISA Cybersecurity Advisories RSSUS Government Open DataFallback über web.archive.org wenn die Hetzner-IP von Akamai blockiert wird.

News & editorial RSS

SourceLicenseNote
Cisco PSIRTVendor Permitted Use — linked-only
Fortinet PSIRTVendor Permitted Use — linked-only
VMware (Broadcom) Security BlogVendor Permitted Use — linked-only
NCSC-NL Security AdvisoriesNational CERT (Niederlande) — Public Domain
ANSSI / CERT-FRNational CERT (Frankreich) — staatliche Open Data
MITRE ATT&CK Release BlogMITRE ATT&CK Framework — Apache 2.0 (Daten) / Medium (Blog)
SANS Internet Storm Center DiaryTLP:WHITE Community Content
Krebs on SecurityEditorial © Brian Krebs — RSS Teaser + Backlink
The Hacker NewsEditorial — RSS Teaser + Backlink
BleepingComputerEditorial — RSS Teaser + Backlink
DarkReadingEditorial — RSS Teaser + Backlink
Schneier on SecurityCC-BY-NC-SA — RSS Teaser + Backlink
Heise SecurityEditorial — RSS Teaser + Backlink
Golem SecurityEditorial — RSS Teaser + Backlink
ZDNet SecurityEditorial — RSS Teaser + Backlink
CSO Online (Foundry)Editorial — RSS Teaser + Backlink
The Register (Security)Editorial — Atom Teaser + Backlink
Ars Technica SecurityEditorial — RSS Teaser + Backlink
SecurityWeekEditorial — RSS Teaser + Backlink
SANS NewsBites (Mail-Subscription)TLP:WHITE — Subscription via NEOSEC-PostfachKein öffentlicher RSS-Feed — Distribution ausschließlich über die Mailingliste.
BSI Allianz für Cyber-Sicherheit (ACS) — RSS-FeedBSI Eigenurheberrecht — linked-onlyInklusive Cybersicherheitswarnungen (Backlink auf das PDF unter /SharedDocs/Cybersicherheitswarnungen/DE/…). Partnerangebote werden im Classify-Pass automatisch gefiltert.

Enrichment

English-language advisories are translated into German via a curated glossary — including industry-relevance mapping (which sectors are affected?) and NIS2 / ISO-27001 context. Translations run exclusively through our LiteLLM proxy with full audit trail. Subscriber data never enters LLM prompts.

Priority score

Every vulnerability gets a score combining CISA-KEV flag, EPSS probability, CVSS severity, recency, and Germany-relevance of the vendor. That's how 80,000 entries collapse into two screens of what actually warrants attention this week.

Operator

Operated by NEOSEC GmbH, Mönchengladbach. Founded and led by J. Benjamin Espagné, Managing Director. This platform is part of our XIEM® stack (Radar / Sonar / Orchestrate / Central). Anonymous research is freely available; in-depth analysis, alert subscriptions and estate correlation against your own inventory are part of our customer offering.

Public Beta

This platform is not yet feature-complete. Sign-in, newsletter delivery, MISP export and the LLM enrichment pipeline are in progress. Feedback to support@neosec.eu — we read every email.

Interfaces

NEOSEC Intel — NEOSEC Intel