Source watchlist

Where labsec intel comes from, and how often to check. URLs were checked on 2026-09-28. The "Machine-readable" column is what the Phase 3 nightly job should poll.

Cadence key: daily = nightly job, weekly = Sunday review, event = only when something breaks.

CVEs and advisories

Source Human page Machine-readable Cadence
CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json daily
NVD https://nvd.nist.gov/vuln/search NVD CVE API 2.0 (filter by keyword per TAGS.md) daily
GitHub Advisory DB https://github.com/advisories GitHub GraphQL securityAdvisories daily
SANS ISC https://isc.sans.edu/ https://isc.sans.edu/rssfeed_full.xml daily
Shadowserver reports https://www.shadowserver.org/what-we-do/network-reporting/ — weekly

Vendor advisories (home stack)

Stack Where
Grafana https://grafana.com/security/security-advisories/
Prometheus https://github.com/prometheus/prometheus/security
Docker https://docs.docker.com/security/security-announcements/
Proxmox https://forum.proxmox.com/forums/announcements.7/
TrueNAS https://www.truenas.com/security/
Nextcloud https://github.com/nextcloud/security-advisories/security/advisories
Home Assistant https://www.home-assistant.io/security/
Traefik https://github.com/traefik/traefik/security
Vaultwarden https://github.com/dani-garcia/vaultwarden/security
Immich https://github.com/immich-app/immich/security

All GitHub-hosted ones are also covered by the Advisory DB poll. Check the page directly when a card needs the vendor's own fixed-version wording.

AI stack (first-class)

Stack Where
Ollama https://github.com/ollama/ollama/security · releases: https://github.com/ollama/ollama/releases.atom
vLLM https://github.com/vllm-project/vllm/security
LiteLLM https://github.com/BerriAI/litellm/security
Open WebUI https://github.com/open-webui/open-webui/security
MCP reference servers https://github.com/modelcontextprotocol/servers/security

Cloudflare

Source Machine-readable Cadence
Blog https://blog.cloudflare.com/rss/ daily
Developer changelog (Tunnel, Access, WAF) https://developers.cloudflare.com/changelog/ weekly
Status https://www.cloudflarestatus.com/ event

News (filtered: only when small-scale relevant)

Source Feed
BleepingComputer https://www.bleepingcomputer.com/feed/
The Hacker News https://feeds.feedburner.com/TheHackersNews
Krebs on Security https://krebsonsecurity.com/feed/

Community chatter

Source Feed Notes
r/selfhosted https://www.reddit.com/r/selfhosted/new/.rss Reddit returns 429 on rapid requests. Space polls a few seconds apart and send a descriptive User-Agent.
r/homelab https://www.reddit.com/r/homelab/new/.rss Same rate limit.
r/LocalLLaMA https://www.reddit.com/r/LocalLLaMA/new/.rss AI-stack chatter. Same rate limit.
Lemmy selfhosted https://lemmy.world/feeds/c/selfhosted.xml
Hacker News https://news.ycombinator.com/ (hnrss.org search feeds) hnrss returned 502 during the check; treat as flaky.
Discord Self-hosted / Proxmox / Cloudflare servers the operator is in Manual only. No scraping.

Rules

  • A card needs at least one primary source: a vendor advisory, CVE record, KEV entry, or original research write-up. News and social posts are signals, not sources.
  • Social chatter can raise a topic for triage but never sets severity on its own.