About the project
NEOSEC Intel
The German-language vulnerability and threat intelligence platform. Built by NEOSEC GmbH for mid-market and KRITIS operators under NIS2.
Mission
We consolidate publicly available security data sources — NVD, CVE.org, CISA, BSI, GHSA, OSV, MSRC, abuse.ch, vendor PSIRTs — into a single, German-language situational view. Instead of keeping five tabs open, security teams see at a glance what's new, what's critical, what affects their own stack, and what made the CISA KEV list. We address both operators (NIS2, mandatory since 2024) and manufacturers (Cyber Resilience Act / EU 2024/2847, mandatory from December 2027 for products with digital elements — including Coordinated Vulnerability Disclosure, SBOM creation and security updates across the lifecycle).
Sources & licenses
Every source NEOSEC Intel ingests — grouped by purpose, with origin, license and our usage discipline. BSI content is never mirrored 1:1; commercial tech news runs strictly as RSS teaser with a backlink to the origin.
Vulnerability advisories (structured)
| Source | License | Note |
|---|---|---|
| NIST NVD ↗ | US Government Open Data (effectively CC0) | — |
| CVE.org / MITRE CVE Services ↗ | CVE Record Format — CC0 1.0 | — |
| CISA Known Exploited Vulnerabilities (KEV) ↗ | US Government Open Data — Public Domain | — |
| BSI CERT-Bund WID (RSS + CSAF 2.0) ↗ | BSI Eigenurheberrecht | Linked-only. Wir spiegeln keine Inhalte 1:1; Original-Quelle wird verlinkt + eigen-angereichert. |
| GitHub Security Advisories (GHSA) ↗ | CC-BY-4.0 | — |
| OSV.dev (Open Source Vulnerabilities) ↗ | Pro Ökosystem unterschiedlich — überwiegend CC-BY-4.0 / CC0 1.0 / Apache-2.0 / MIT | Wir ziehen alle 44 Ökosysteme: PyPI, npm, Go, crates.io, Maven, RubyGems, NuGet, Packagist, Hex, Pub, Debian, Ubuntu, Red Hat, AlmaLinux, Rocky Linux, SUSE, Alpine, Echo u. a. |
| Microsoft Security Response Center (MSRC) CVRF ↗ | Microsoft Permitted Use — Public Vendor Content | Linked-only zum offiziellen Update-Guide-Eintrag. |
| ENISA EUVD (European Vulnerability Database) ↗ | EU Public Sector Information — free reuse with attribution | Seit Mai 2025 das EU-Pendant zur NVD. JSON-API mit CVSS v3/v4, EPSS und Aliase auf CVE-IDs. |
| Debian Security Advisories (DSA) ↗ | salsa-Tracker: GPL-3.0-or-later | — |
| Ubuntu Security Notices (USN) ↗ | CC-BY-SA-4.0 (Share-Alike) | Wir spiegeln nicht den Volltext, nur Metadaten + Backlink — kein Share-Alike-Trigger. |
Threat intel / Indicators of Compromise
| Source | License | Note |
|---|---|---|
| abuse.ch URLhaus ↗ | CC0 1.0 Public Domain | — |
| abuse.ch MalwareBazaar ↗ | CC0 1.0 Public Domain | — |
| abuse.ch ThreatFox ↗ | CC0 1.0 Public Domain | — |
| abuse.ch Feodo Tracker ↗ | CC0 1.0 Public Domain | — |
| AlienVault OTX (subscribed pulses) ↗ | Pro Pulse unterschiedlich — wir filtern strikt auf TLP:WHITE | TLP:GREEN/AMBER/RED-Pulses werden vor dem Persist verworfen, damit sie nicht in der anonymen Sicht landen. |
| Tor Exit Node List (onionoo.torproject.org) ↗ | Public — BSD-style | — |
Enrichment
| Source | License | Note |
|---|---|---|
| CrowdSec CTI (community signal) ↗ | Free Tier mit Account | Tag-only — wir hängen crowdsec:* Tags an IPs, kein Bulk-Re-Export der CrowdSec-Blocklist. |
| VirusTotal v3 (Free Public API) ↗ | Free-Tier ToS — keine Bulk-Redistribution | On-demand-Lookup mit 24h Redis-Cache, ≤500 Requests/Tag. Wir speichern nur detection_count + reputation + permalink. |
| EPSS (FIRST.org Exploit Prediction Scoring System) ↗ | CC0 1.0 Public Domain | — |
| CISA Cybersecurity Advisories RSS ↗ | US Government Open Data | Fallback über web.archive.org wenn die Hetzner-IP von Akamai blockiert wird. |
News & editorial RSS
| Source | License | Note |
|---|---|---|
| Cisco PSIRT ↗ | Vendor Permitted Use — linked-only | — |
| Fortinet PSIRT ↗ | Vendor Permitted Use — linked-only | — |
| VMware (Broadcom) Security Blog ↗ | Vendor Permitted Use — linked-only | — |
| NCSC-NL Security Advisories ↗ | National CERT (Niederlande) — Public Domain | — |
| ANSSI / CERT-FR ↗ | National CERT (Frankreich) — staatliche Open Data | — |
| MITRE ATT&CK Release Blog ↗ | MITRE ATT&CK Framework — Apache 2.0 (Daten) / Medium (Blog) | — |
| SANS Internet Storm Center Diary ↗ | TLP:WHITE Community Content | — |
| Krebs on Security ↗ | Editorial © Brian Krebs — RSS Teaser + Backlink | — |
| The Hacker News ↗ | Editorial — RSS Teaser + Backlink | — |
| BleepingComputer ↗ | Editorial — RSS Teaser + Backlink | — |
| DarkReading ↗ | Editorial — RSS Teaser + Backlink | — |
| Schneier on Security ↗ | CC-BY-NC-SA — RSS Teaser + Backlink | — |
| Heise Security ↗ | Editorial — RSS Teaser + Backlink | — |
| Golem Security ↗ | Editorial — RSS Teaser + Backlink | — |
| ZDNet Security ↗ | Editorial — RSS Teaser + Backlink | — |
| CSO Online (Foundry) ↗ | Editorial — RSS Teaser + Backlink | — |
| The Register (Security) ↗ | Editorial — Atom Teaser + Backlink | — |
| Ars Technica Security ↗ | Editorial — RSS Teaser + Backlink | — |
| SecurityWeek ↗ | Editorial — RSS Teaser + Backlink | — |
| SANS NewsBites (Mail-Subscription) ↗ | TLP:WHITE — Subscription via NEOSEC-Postfach | Kein öffentlicher RSS-Feed — Distribution ausschließlich über die Mailingliste. |
| BSI Allianz für Cyber-Sicherheit (ACS) — RSS-Feed ↗ | BSI Eigenurheberrecht — linked-only | Inklusive Cybersicherheitswarnungen (Backlink auf das PDF unter /SharedDocs/Cybersicherheitswarnungen/DE/…). Partnerangebote werden im Classify-Pass automatisch gefiltert. |
Enrichment
English-language advisories are translated into German via a curated glossary — including industry-relevance mapping (which sectors are affected?) and NIS2 / ISO-27001 context. Translations run exclusively through our LiteLLM proxy with full audit trail. Subscriber data never enters LLM prompts.
Priority score
Every vulnerability gets a score combining CISA-KEV flag, EPSS probability, CVSS severity, recency, and Germany-relevance of the vendor. That's how 80,000 entries collapse into two screens of what actually warrants attention this week.
Operator
Operated by NEOSEC GmbH, Mönchengladbach. Founded and led by J. Benjamin Espagné, Managing Director. This platform is part of our XIEM® stack (Radar / Sonar / Orchestrate / Central). Anonymous research is freely available; in-depth analysis, alert subscriptions and estate correlation against your own inventory are part of our customer offering.
Public Beta
This platform is not yet feature-complete. Sign-in, newsletter delivery, MISP export and the LLM enrichment pipeline are in progress. Feedback to support@neosec.eu — we read every email.