Source watchlist
Where labsec intel comes from, and how often to check. URLs were checked on 2026-09-28.
The "Machine-readable" column is what the Phase 3 nightly job should poll.
Cadence key: daily = nightly job, weekly = Sunday review, event = only when something breaks.
CVEs and advisories
| Source |
Human page |
Machine-readable |
Cadence |
| CISA KEV |
https://www.cisa.gov/known-exploited-vulnerabilities-catalog |
https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json |
daily |
| NVD |
https://nvd.nist.gov/vuln/search |
NVD CVE API 2.0 (filter by keyword per TAGS.md) |
daily |
| GitHub Advisory DB |
https://github.com/advisories |
GitHub GraphQL securityAdvisories |
daily |
| SANS ISC |
https://isc.sans.edu/ |
https://isc.sans.edu/rssfeed_full.xml |
daily |
| Shadowserver reports |
https://www.shadowserver.org/what-we-do/network-reporting/ |
— |
weekly |
Vendor advisories (home stack)
| Stack |
Where |
| Grafana |
https://grafana.com/security/security-advisories/ |
| Prometheus |
https://github.com/prometheus/prometheus/security |
| Docker |
https://docs.docker.com/security/security-announcements/ |
| Proxmox |
https://forum.proxmox.com/forums/announcements.7/ |
| TrueNAS |
https://www.truenas.com/security/ |
| Nextcloud |
https://github.com/nextcloud/security-advisories/security/advisories |
| Home Assistant |
https://www.home-assistant.io/security/ |
| Traefik |
https://github.com/traefik/traefik/security |
| Vaultwarden |
https://github.com/dani-garcia/vaultwarden/security |
| Immich |
https://github.com/immich-app/immich/security |
All GitHub-hosted ones are also covered by the Advisory DB poll. Check the page directly when a card
needs the vendor's own fixed-version wording.
AI stack (first-class)
| Stack |
Where |
| Ollama |
https://github.com/ollama/ollama/security · releases: https://github.com/ollama/ollama/releases.atom |
| vLLM |
https://github.com/vllm-project/vllm/security |
| LiteLLM |
https://github.com/BerriAI/litellm/security |
| Open WebUI |
https://github.com/open-webui/open-webui/security |
| MCP reference servers |
https://github.com/modelcontextprotocol/servers/security |
Cloudflare
| Source |
Machine-readable |
Cadence |
| Blog |
https://blog.cloudflare.com/rss/ |
daily |
| Developer changelog (Tunnel, Access, WAF) |
https://developers.cloudflare.com/changelog/ |
weekly |
| Status |
https://www.cloudflarestatus.com/ |
event |
News (filtered: only when small-scale relevant)
| Source |
Feed |
| BleepingComputer |
https://www.bleepingcomputer.com/feed/ |
| The Hacker News |
https://feeds.feedburner.com/TheHackersNews |
| Krebs on Security |
https://krebsonsecurity.com/feed/ |
Community chatter
| Source |
Feed |
Notes |
| r/selfhosted |
https://www.reddit.com/r/selfhosted/new/.rss |
Reddit returns 429 on rapid requests. Space polls a few seconds apart and send a descriptive User-Agent. |
| r/homelab |
https://www.reddit.com/r/homelab/new/.rss |
Same rate limit. |
| r/LocalLLaMA |
https://www.reddit.com/r/LocalLLaMA/new/.rss |
AI-stack chatter. Same rate limit. |
| Lemmy selfhosted |
https://lemmy.world/feeds/c/selfhosted.xml |
|
| Hacker News |
https://news.ycombinator.com/ (hnrss.org search feeds) |
hnrss returned 502 during the check; treat as flaky. |
| Discord |
Self-hosted / Proxmox / Cloudflare servers the operator is in |
Manual only. No scraping. |
Rules
- A card needs at least one primary source: a vendor advisory, CVE record, KEV entry, or original research write-up. News and social posts are signals, not sources.
- Social chatter can raise a topic for triage but never sets severity on its own.