Category Archives: All

Don’t miss out on your competitors and partners’ product launches

Market Intelligence
Easily track the latest product launches in your industry with Feedly’s AI engine

Keeping up with your competitor’s latest product announcements in real-time is close to impossible.

We’ve added Product Launches to the list of strategic moves Feedly’s AI Engine understands.

This new machine learning model will help you:

  • Analyze how to differentiate yourself from your competitors
  • Spot new partnership opportunities
  • Monitor the latest releases of portfolio companies

Curious how it works? Here is a quick tour:

Example: Product Launches related to Autonomous Vehicles
A machine learning model that flags mentions of product launches
Popular product launch use cases
Fewer false positives than basic keyword searches
Quickly identify key product launch sentences
Customer Feedback

Speed up your market intelligence research

Product Launches is one of the machine learning models included in Feedly for Market Intelligence. Start a free 30-day trial to see how Feedly can help you speed up your market intelligence.

Start 30-day free trial

Don’t miss out on your competitors and partners’ product launches

Market Intelligence
Easily track the latest product launches in your industry with Feedly’s AI engine

Keeping up with your competitor’s latest product announcements in real-time is close to impossible.

We’ve added Product Launches to the list of strategic moves Feedly’s AI Engine understands.

This new machine learning model will help you:

  • Analyze how to differentiate yourself from your competitors
  • Spot new partnership opportunities
  • Monitor the latest releases of portfolio companies

Curious how it works? Here is a quick tour:

Example: Product Launches related to Autonomous Vehicles
A machine learning model that flags mentions of product launches
Popular product launch use cases
Fewer false positives than basic keyword searches
Quickly identify key product launch sentences
Customer Feedback

Speed up your market intelligence research

Product Launches is one of the machine learning models included in Feedly for Market Intelligence. Start a free 30-day trial to see how Feedly can help you speed up your market intelligence.

Start 30-day free trial

Research critical vulnerabilities with the new CVE Intelligence Card

Threat Intelligence
Use Feedly’s AI Engine to get the full picture you need to quickly prioritize critical vulnerabilities and minimize exposure

Exploited and critical CVEs need to be prioritized as soon as possible to limit exposure.

But manually gathering the full picture needed to make smart prioritization decisions is tedious.

We are excited to announce the new Leo CVE Intelligence Card.

It’s a machine learning model that aggregates, analyzes, and synthesizes vulnerability information from across the web in real-time so that CTI teams can easily:

  • Get a 360-degree view of a CVE without having to open a multitude of tabs
  • Discover critical, exploited, and trending vulnerabilities early
  • Easily link vulnerabilities to threat actors, malware families, and TTPs
  • Predict the CVSS severity, CWE, and popularity of zero-days

Curious how it works? Here is a quick tour

Introducing the new Leo CVE Intelligence Card
Feedly’s AI Engine aggregates, analyzes, and synthesizes millions of articles

Leo aggregates CVE information from NVD, 25+ vendor advisories, Github, and 10 trusted exploit sources to offer you in one place all the information you need to prioritize an emerging vulnerability.

Leo also predicts the CVSS severity and CWE when it is not yet available on NVD.

You can use the cut and paste action to capture the information you need to create a ticket for your team to review this vulnerability.

Get a 360-degree view of a CVE to easily prioritize critical vulnerabilities

Leo identifies links between the CVE, threat actors, and malware families by analyzing news articles, threat intelligence reports, and social media posts.

Quickly research adversary activity and awareness level

This graph also captures how many sources and social media accounts are mentioning the CVE and compares it to the number of mentions of other CVEs of the same vendor, allowing you to detect trending vulnerabilities early.

Leo organizes all the information he aggregated and analyzed into 3 buckets: vendor advisories, references (trusted and highly curated cybersecurity sources), and social media chatter.

Skim through advisories, trusted reference articles, and social media chatter in one place

As soon as Leo discovers a mention of a vulnerability on news sites, research blogs, vendor advisories, or social media posts, he will create a CVE intelligence card. You can access the CVE intelligence card of any CVE using the https://feedly.com/i/cve/$cve-id URL format.

Some interesting CVEs to research

Here are some examples of CVE intelligence cards you can explore: CVE-2021-44228, CVE-2022-22965, CVE-2022-1388, and CVE-2022-26134.

Speed up your cyber threat intelligence

The CVE intelligence card is one of the machine learning models included in Feedly for Threat Intelligence. Start a free 30-day trial to see how Feedly can help you speed up your threat intelligence.

START 30-day FREE TRIAL

Track funding events effortlessly

Market Intelligence
Quickly discover the latest funding rounds in your sector with Feedly’s AI Engine

Do you track the growth strategies of your competitors, customers, or partners?

We have added Funding Events to the list of strategic moves Leo understands.

This new machine learning model will help you:

  • Track your competitors’ growth
  • Identify potential partners
  • Discover investment opportunities

Curious how it works? Here is a tour

Example: Funding Events related to Web 3
A machine learning model that flags mentions of funding events in your industry
Popular funding events use cases
Fewer false positives than basic keyword searches
Quickly identify key funding events sentences
Customer Feedback

Speed up your market intelligence research

Funding Events is one of the machine learning models included in Feedly for Market Intelligence. Start a free 30-day trial to see how Feedly can help you speed up your market intelligence.

Start 30-day free trial

Discover proof of exploits early

Threat Intelligence
Track emerging exploits across the Web with Feedly’s AI Engine

Does your team track emerging exploits across cybersecurity websites, code repositories, and social media sites?

We just released a new Proof of Exploit Leo Concept that I think you will find valuable.

This new machine learning model allows you to:

  • Discover proof of exploits early
  • Research how vulnerabilities are being exploited
  • Link exploited CVEs to adversary behavior

Curious how it works? Here is a tour

Example: Proof of Exploits related to Google Chrome
A machine learning model that flags mentions of exploits
Fewer false positives than basic keyword searches
Quickly identify key exploit sentences
Popular exploit use cases

Speed up your cyber threat intelligence

Proof of exploit is one of the machine learning models included in Feedly for Threat Intelligence. Start a free 30-day trial to see how Feedly can help you speed up your threat intelligence.

START 30-DAY FREE TRIAL

Track competitors and emerging trends with Leo, Feedly’s AI Engine

Market Intelligence
Speed up your market intelligence by 70% with Leo Web Alerts

The core of Feedly for Market Intelligence is an AI engine, called Leo, that automatically gathers, analyzes, and prioritizes intelligence from millions of sources in real-time.

In this article, we’ll show you how to use Leo to:

  • Track your competitors and their strategic moves
  • Stay ahead of consumer trends and insights
  • Scout technical innovation
  • Identify business development opportunities

Before we look at those four examples, let’s start with a short overview of how Leo works.

Meet Leo, Feedly’s AI Engine

Leo reads millions of articles, reports, and social media posts to determine if they are relevant to the topics you want to track.

Feedly’s AI Engine (Leo) automatically tags key market intelligence concepts

All this information is at your fingertips in near real-time via a powerful search and tracking interface called Leo Web Alerts.

To understand how this works, let’s review a Leo Web Alert designed to track Amazon’s recent product launches:

Leo Web Alerts: A powerful and intuitive search and tracking interface

Creating a Leo Web Alert is a three-step process:

  1. Use Leo Concepts to define the information you want to gather. In our example, we use a Company and Strategic Move Leo Concept to track all information about Amazon’s product launches.
  2. Use AND, OR, NOT operators to combine multiple Leo Concepts and refine your focus. In our example, we use AND to only track articles that reference both Amazon and product launches.
  3. If needed, refine sources with your own trusted sources. By default, Leo Web Alerts will search across the Market Intelligence Bundle, which is a collection of top tier B2B sources including strategy magazines, tech blogs, business magazines, research journals, and trade publications. You can control the sources your Web Alert pulls from using the “Refine Sources” feature.

Leo Web Alerts are Feeds you can add to a team or personal Folder. New articles, reports, or social media posts that match the specified Leo Concepts will appear in the Leo Web Alert feed.

Leo Concepts are easier to use, more comprehensive, and less noisy than traditional keyword searches

The power of Leo Web Alerts is that Amazon and Product Launches are not simple keyword matches. These Leo Concepts are machine learning models that encapsulate a broader understanding of each concept.

  • ‘Amazon’ is a Company Leo Concept that tracks mentions of Amazon or any known alias, like amazon.com. A disambiguation model will be used to remove false positives for “amazon”, and only return relevant mentions of the company.
  • ‘Product Launches’ is a Strategic Move Leo Concept that intelligently scans for new product announcements. This Concept will be able to find relevant updates even if the term “product launch” isn’t explicitly used.

Without Leo Concepts, finding the right information would require manually updating a long list of keywords, leaving room for human error and irrelevant results.

Feedly for Market Intelligence comes with a wide range of pre-trained Leo Concepts so that you can easily translate your intelligence needs into Leo Web Alerts. Leo Concepts can be identified by their unique icons, and you can review a full legend of each icon and the Leo Concept they correspond to here.

Feedly includes AI models for key market intelligence concepts

Let’s examine how to combine these Leo Concepts to build a strong market intelligence engine.

Track your competitors and their strategic moves

Tracking the strategic moves of your competitors can be tedious and overwhelming. That’s why Feedly has created Company Leo Concepts, which tracks competitor decisions and actions using Artificial Intelligence, saving your team hundreds of hours.

Let’s take a look at a Leo Web Alert designed to track all the latest updates about Apple:

Use Company Leo Concepts to track mentions and updates from specific companies
  • ‘Apple’ is a Company Leo Concept that tracks all mentions of Apple and its aliases (such as Apple, Inc. and apple.com). A disambiguation model will be used to remove false positives for “apple”, and only return relevant mentions of the company.

You can use Strategic Move Leo Concepts to refine your competitive research to only the most relevant updates, such as Product Launches, New Patents, and Partnerships.

Let’s take a look at a Leo Web Alert designed to track Apple’s newest patents and tech innovations:

Use Strategic Moves Leo Concepts to track specific news about competitors, like New Patents or Innovations
  • ‘Apple’ is a Company Leo Concept that tracks all mentions of Apple and its common aliases.
  • ‘New Patents’ is a Strategic Move Leo Concept that tracks newly published patents.
  • ‘Tech & Scientific Innovation’ is a Leo Concept that tracks breakthroughs and innovations by companies, startups, and research teams.

Here are some additional Leo Concepts you can use to refine your competitive research:

Use Strategic Move Leo Concepts to refine competitive research

Discover emerging trends

Manually tracking consumer behaviors often feels like searching for a needle in a haystack. That’s why we built the Consumer Insights Leo Concept, which surfaces articles that mention behavioral statistics and consumer data most relevant to you.

Let’s take a look at a Leo Web Alert designed to track Consumer Insights related to Sustainability:

The Consumer Insights Leo Concept detects articles that mention behavioral statistics related to customers and consumers
  • ‘Consumer Insights’ is a Leo Concept that tracks consumer statistics related to emerging societal, technological, economic, ecological, and political trends.
  • ‘Sustainability’ is a Leo Concept that intelligently scans for mention of Environmental Sustainability and everything related to this topic.

Scout technical innovation

Market Intelligence teams leverage Feedly’s powerful AI Engine to make their tech innovation research 70% faster. Technology Leo Concepts intelligently scan for a range of new technologies, such as Augmented Reality, Crypto, and Quantum Computing.

Let’s take a look at a Leo Web Alert designed to track updates about Crypto and Digital Wallets:

Track relevant new technologies like Crypto with Technology Leo Concepts
  • ‘Crypto’ is a Technology Leo Concept that recognizes numerous terms for Crypto. The Leo Concept will continuously learn and include new terms, keeping pace with ever-changing technologies.
  • ‘Digital Wallet’ is a Leo Concept that intelligently scans for mentions of digital wallets and continuously updates to account for new aliases.

Identify new partnership opportunities

Keeping up with business development opportunities helps your company stay competitive in your industry. Leo Web Alerts allow you to identify and act on key market opportunities as they arise.

Let’s take a look at a Leo Web Alert designed to gather intelligence about companies that have recently raised funds in the finance industry:

Tracking Funding Events in your industry allows your team to stay ahead of partnerships opportunities for specific or broad industries
  • Finance Industry’ is an Industry Leo Concept that classifies articles related to the finance industry based on company mentions and terminology.
  • Funding Events’ is a Strategic Move Leo Concept that detects any capital-raising events, from seed funding to late-stage rounds or exits.

Getting smarter every day

The world’s leading Market Intelligence teams use Feedly to stay competitive, so the product constantly improves based on their feedback.

Here is the roadmap for some new Leo Concepts we are researching for our Market Intelligence customers:

2022 Leo Concepts Roadmap – Market Intelligence

Feedly for Market Intelligence customers can reach out to enterprise@feedly.com to share feedback on existing Leo Concepts or suggestions for new Leo Concepts. We value our community’s input, as this ensures Feedly is working at full capacity to serve your Market Intelligence needs.

Try Feedly for Market Intelligence

All of these features, plus many more, are available as a part of Feedly for Market Intelligence. To learn more or to start a free 30-day trial, click the link below.

Try Feedly for Market Intelligence

Track emerging threats with Leo, Feedly’s AI Engine

Cybersecurity
Speed up your open-source threat intelligence by 70% with Leo Web Alerts

The core of Feedly for Threat Intelligence is an AI engine, called Leo, that automatically gathers, analyzes, and prioritizes intelligence from millions of sources in real-time.

In this article, we’ll show you how to use Leo to:

  • Monitor critical vulnerabilities and zero-days
  • Research the behavior of specific threat actors and malware families
  • Understand the threat landscape around your industry
  • Track niche cybersecurity topics

Before we look at those four use cases, let’s start with a short overview of how Leo works.

Meet Leo, Feedly’s AI Engine

Leo reads millions of articles, reports, and social media posts every day and automatically tags key threat intelligence concepts: critical vulnerabilities, malware families, threat actors, indicators of compromise, ATT&CK techniques, companies, vendors, industries, etc.

Feedly’s AI Engine (Leo) automatically tags key threat intelligence concepts

All this information is at your fingertips in near real-time via a powerful and intuitive search and tracking interface called Leo Web Alerts.

Curious how it works? Let’s take a look at a Leo Web Alert designed to track critical vulnerabilities and zero-days related to Cisco Systems:

Leo Web Alerts: A powerful and intuitive search and tracking interface

Creating a Leo Web Alert is a three-step process:

  1. Use Leo Concepts to define the intelligence you want to gather. In our example, we use the ‘High Vulnerability’ and ‘Cisco Systems’ Leo Concepts to discover new critical vulnerabilities related to Cisco Systems.
  2. Use AND, OR, NOT operators to combine multiple Leo Concepts and refine your focus. In our example, we use AND to track articles and reports that reference both ‘High Vulnerabilities’ and ‘Cisco Systems’.
  3. If needed, refine sources with your own trusted sources. By default, Leo Web Alerts will search across the Cybersecurity Bundle (a collection of 50,000+ security news sources, threat research blogs, newsletters, vendor advisories, government agencies, vulnerability databases, CISO magazines, and Reddit communities curated collectively by 200,000 cyber professionals using Feedly and partitioned by Leo into three tiers based on popularity and authority).

Leo Web Alerts are feeds you can add to a team or personal folder. New articles, reports, or social media posts matching the specified Leo Concepts will appear in the Leo Web Alert feed.

Leo Concepts are easier to use, more comprehensive and less noisy than traditional keyword searches

The power of Leo Web Alerts is that ‘High Vulnerability’ and ‘Cisco Systems’ are not simple keyword matches. These Leo Concepts are machine learning models that encapsulate a broader understanding of each concept:

  • ‘High Vulnerability’ is a Leo Concept that tracks vulnerabilities with a CVSS score above 8 or a CVSS score above 5 that includes a known exploit. If the vulnerability does not have a CVSS score yet, a machine learning model is used to forecast the CVSS score based on the descriptions of the vulnerability. Learn more
  • ‘Cisco Systems’ is a ‘Company’ Leo Concept that tracks for mentions of Cisco by its name or any known aliases. When the company name is ambiguous, a disambiguation model is used to remove false positives.

Without Leo Concepts, gathering intelligence would require a tedious effort of trying to find a long list of the right keywords, leaving room for blind spots and lots of irrelevant results.

Feedly for Threat Intelligence comes with a wide range of pre-trained Leo Concepts so that you can easily translate your intelligence needs into Leo Web Alerts.

Feedly includes models for key threat intelligence concepts.

Let’s see how we can combine these Leo Concepts to proactively track specific threats and stay one step ahead of your adversaries.

Research the behavior of specific threat actors and malware families

Tracking the behavior of threat actors and malware families can be tedious and overwhelming, taking up valuable time that could be spent hunting for malicious activity in your environment.

That’s why Feedly has created a set of Leo Concepts that automatically tag threat actors, malware families, TTPs, and IoCs.

Let’s take a look at a Leo Web Alert designed to track the latest IoCs and TTPs related to Lazarus Group across threat intelligence reports published on the web:

Gather IoCs and TTPs related to Lazarus Groups from intelligence reports
  • ‘Lazarus Group’ is a ‘Threat Actor’ Leo Concept powered by Malpedia that tracks mentions of the threat actor by name or its many aliases. Learn more
  • ‘Indicators of Compromise’ is a Leo Concept that tracks malicious URLs, IPs, email addresses, domains, and hashes. Learn more
  • ‘Tactics & Techniques’ is a Leo Concept powered by the Mitre ATT&CK v10 framework that tracks tactics, techniques, and sub-techniques and their relationships. Learn more
  • ‘Threat Intelligence Report’ is a Leo Concept that flags intel reports containing in-depth technical details about IoCs, TTPs, threat actors, and malware. Learn more

Here are some additional Leo Concepts you can use to broaden or narrow your threat profiling:

Understand the threat landscape around your industry

Staying up to date with the latest attacks against your industry can help you be better prepared when putting defenses in place, as well as help you learn about which threat actors to look out for so you can be more targeted when gathering intelligence.

Let’s take a look at a Leo Web Alert designed to gather intelligence about cyber attacks in the finance industry:

Track cyber attacks around the finance industry
  • ‘Cyber Attacks’ is a Leo Concept that tracks instances of cyber attacks and tries to determine who or what the target of the attack is. Learn more
  • ‘Finance Industry’ is an ‘Industry’ Leo Concept that classifies articles related to the finance industry based on company mentions and terminology. Learn more

You can also easily narrow your focus on a specific type of attack:

Track credit card data breaches

Monitor critical vulnerabilities and zero-days

Manually keeping ahead of new vulnerabilities and zero-days is an impossible task, but you can set up Leo Web Alerts to help you stay up to date on new vulnerabilities that come across the radar of the global cybersecurity community.

Feedly aggregates vulnerability information from NVD and over 20 vendor advisory sites — as well as monitoring many sources to find exploits for each CVE — in near real-time.

Let’s take a look at a Leo Web Alert designed to surface critical vulnerabilities and zero-days related to a vendor deployed in your environment:

Track high vulnerabilities related to Zoom

When you discover a new CVE, you can use the CVE intelligence card to get a 360 degree view of that vulnerability and decide if you should create a ticket for your response team.

A CVE intelligence card – a 360 degree view of CVE-2021-44228

Track niche cybersecurity topics

You can also use Leo Web Alerts to track niche cybersecurity topics.

Let’s take a look at a Leo Web Alert designed to gather intelligence about malicious, compromised, or hijacked packages:

Here are some additional Leo Concepts you can use to track niche cybersecurity topics:

Getting smarter every day

The world’s leading cybersecurity teams use Feedly for their OSINT, so the product constantly improves based on their feedback.

Here is a roadmap of some of the new Leo Concepts we are researching:

2022 Leo Concepts Roadmap – Threat Intelligence

Feedly for Threat Intelligence customers can reach out to us at enterprise@feedly.com to give feedback on improving existing Leo Concepts or creating new ones to ensure that Feedly is working at full capacity to serve your Threat Intelligence needs.

Try Feedly for Threat Intelligence

All of these features, plus many more, are available as a part of Feedly for Threat Intelligence. To learn more about any of these features, or start a free 30-day trial, click the link below.

TRY FEEDLY FOR THREAT INTELLIGENCE

New: Track specific CVEs in Feedly

What’s New
Leo now autocompletes specific CVE IDs so you can monitor for exploits or attacks, or track threat intelligence reports mentioning the CVE

Looking to monitor a specific CVE ID? Previously, you had to type in the exact CVE ID and be sure it was the right number. Now, Leo autocompletes the CVE ID and shows you the description of the vulnerability, so you can be sure you’re tracking the right one.

Just start typing the CVE ID and choose the correct ID from the menu. Then, refine your Leo Web Alert and add it to a Folder.

This is a small improvement to the UI that makes it much easier for you to quickly track a CVE (instead of entering the ID manually) and to make sure you’re tracking the right CVE.

Create a Leo Web Alert to track a CVE and get updates as it develops

The more high profile a CVE becomes, the more likely threat actors will develop exploits for it. You can keep an eye on a trending vulnerability by simply creating a Leo Web Alert and adding it to your “Trending vulnerabilities” Folder, for example.

When it’s taking a while to apply a security patch, you want to keep an eye on the tactics used to exploit the vulnerability. Create a Leo Web Alert for the CVE ID and the concept “Cyber Attacks” and Leo will look for attacks or exploitation attempts related to the specific CVE.

Then, you and your team can use this information about available exploits to prioritize which vulnerabilities to patch. You can also update the Leo Web Alert to add more CVEs if needed, like when a vulnerability has multiple IDs associated with it.

Tracking, gathering and ingesting indicators of compromise is a great way to proactively hunt for signs of an attack on your environment. Since Leo allows you to gather and export IoCs from multiple sources (including articles, Twitter, Reddit, and emails), you can create a Web Alert to track a specific CVE ID and the “Indicators of Compromise” Leo Concept.

Once you create a Leo Web Alert for IoCs related to the specific CVE you’re tracking you can easily export the resulting IoCs with context and add them to your own security environment.

Track threat intelligence reports published about the CVE

Gather intelligence others have curated by adding the “Threat Intelligence Report” Leo Concept to your Web Alert. When you combine the CVE ID with the Threat Intelligence Report Leo Concept, you’ll get Threat Intel Reports mentioning the CVE.

Bundle these concepts together into a single Web Alert to keep an eye on a specific CVE

And if you want to get all angles of a CVE, you can combine all of these concepts into a single Leo Web Alert. Just track the specific CVE ID and add other Leo Concepts like Indicators of Compromise, Threat Intelligence Reports, and Cyber Attacks.

And don’t forget — to get a complete overview of a specific CVE in the moment, you can also click on the CVE ID and open up the CVE Intelligence Card. You’ll find an at-a-glance overview of exploits, malware families, and related threat actors in a single view.

Try tracking a specific CVE in Feedly

Not a member of the Feedly for Threat Intelligence community yet? Try a free 30 day trial and speed up your discovery and research of emerging threats.

START FREE 30-DAY TRIAL

You might also be interested in

Blueprint of a highly functional Feedly for Threat Intelligence Account

Cybersecurity
How to structure your Feedly for Threat Intelligence account to optimize your open source threat intelligence

Many of the leading cyber security teams use Feedly to organize and automate their open-source threat intelligence and stay ahead of emerging threats. We have had the chance to research 100 of them and review their open-source threat intelligence best practices.

In this article, we will share how they translate their intelligence needs into various types of feeds and how they structure those feeds into a highly functional Feedly account.

Structure of a highly functional threat intelligence account

Most cybersecurity professionals start their day in the Threat Intelligence Dashboard. It offers a broad overview of the emerging threat landscape: trending cybersecurity articles and attacks, new critical vulnerabilities, active attackers, new behaviors, and malware families, so it’s easy to get a sense of what’s going on in just a few minutes.

Start your day with a general overview of the threat landscape with the Threat Intelligence Dashboard

Here’s a brief overview of each section:

  • Trending News: Stay ahead of attacks by seeing which threats are trending in the cybersecurity community.
  • Vulnerabilities: Improve reaction time and respond quickly to new vulnerabilities as they arise, allowing cybersecurity teams and their clients to stay informed of oncoming risks faster.
  • Attackers: Identify at a glance which Threat Actors are trending and quickly create Web Alerts to track their actions and behaviors.
  • Tactics & Techniques: Keep track of which TTPs are proving to be the most prevalent among Threat Actors, map data to the Mitre ATT&CK Navigator to compare with other Threat Actor Profiles, or to identify gaps in your defensive capability.
  • New Malware: Research what New Malware is affecting systems and be vigilant against emerging threats.

Discover critical vulnerabilities

The most effective way to track critical vulnerabilities and zero-days across the web is with Leo, Feedly’s AI research assistant. Leo has been pre-trained to understand vulnerabilities and assess their severity. He reads millions of articles every day, looking for critical security threats.

Track critical vulnerabilities for products deployed in your environment

When Leo finds a CVE, he automatically searches for its CVSS score, related exploits and malware families, links to threat actors, CWE information, and patches. He then organizes all this information into a rich CVE intelligence card.

If the CVE doesn’t have a CVSS score yet, Leo uses machine learning to predict the CVSS score, keeping you one step ahead of the latest emerging threats.

Discover critical vulnerabilities and get a 360-degree view with the CVE intelligence card

Creating a broad Leo Web Alert targeting all critical vulnerabilities gives you a big picture view of what is happening across the threat landscape, while adding specific vendors to the search narrows the focus into more precise and manageable feeds.

Cybersecurity teams often create a Leo Web Alert for each of the main products deployed in their environment and group them into a Vulnerabilities folder.

Track adversary behaviors

One way cybersecurity teams track and visualize the behaviors of specific Threat Actors and Malware Families is by using Feedly’s integration with the Mitre ATT&CK framework. Leo has been pre-trained to understand threat actors (integration with Malpedia), Mitre ATT&CK (version 10), and the concept of threat intelligence reports. These three concepts can be easily combined to track the behavior of selected adversaries.

Here is an example of a Leo Web Alert surfacing all the threat intelligence reports mentioning the Lazarus Group threat actor:

Track threat intelligence reports mentioning the Lazarus Group

Cybersecurity teams often create a Leo Web Alert for each of the threat actors and malware families defined on their threat profiling list and group them into a “Threat Intel” folder.

When Leo finds an article in which he has identified TTPs, he can map the content of that article to the ATT&CK navigator so that cybersecurity teams can easily analyze the adversary behavior and compare it with their existing defenses.

Automatically open TTPs mentioned in an article to the MITRE ATT&CK Navigator

Leo also automatically flags all the malicious IPs, hashes, domains, and URLs (IoCs) he identifies in articles so that they can easily be exported with links to threat actors, malware families, and vulnerabilities using STIX 2.1 and imported into Threat Intelligence Platforms (TIP).

Export IoCs with links to threat actors and malware using STIX 2.1

Track cyber attacks

Security teams can efficiently track cyber attacks targeting their industry or supply chain. Leo has been pre-trained to understand the concept of a cyber attack and who the target of the attack is. Here is an example of how a cybersecurity professional might ask Leo to track all the cyber attacks targeted at the finance industry.

Track cyber-attacks across the finance industry

The focus can also be narrowed down to more specific threats like “data breaches impacting credit cards” or “cyber attacks using multi-factor authentication”

Follow trusted security feeds

Feedly allows cybersecurity teams to follow a wide variety of trusted feeds all in one place, including websites and blogs, newsletters, Reddit communities, and Twitter accounts, searches, and hashtags. The teams that get the most out of Feedly turn it into their one-stop intelligence center so they can share common sources in one place. They end up saving hours each week because they’re no longer sharing articles ad-hoc across email, Slack, and other messaging platforms.

Follow your trusted security websites, blogs, newsletters, Twitter and Reddit in one place

Collect and share threat intelligence with Boards

When an article of importance surfaces, Feedly provides the tools to annotate, highlight, add notes, and save the article to a Board for review later. When an article is saved to a Team Board, Feedly for Threat Intelligence users have additional options to auto-generate Newsletters, share with Slack or Microsoft Teams, or use Feedly’s Rest API to integrate into an existing workflow.

Save and organize selected articles into Boards and share them with your teams

Here are a few examples of Team Boards that have helped cybersecurity teams stay organized:

  • Critical Vulnerabilities Board: Save articles about exploitable vulnerabilities and zero-days that a cybersecurity team will want to research and patch as soon as possible.
  • IoC Report Board: Save articles referencing IoCs that should be pushed to a threat intelligence platform.
  • Threat Intelligence Brief Board: Save articles to share with an executive team.
  • Threat Actors Board: Save articles describing behaviors of specific threat actors active in the industry that should be imported into the TIP for the rest of the team to research.
  • Emerging Malware Board: Save articles about techniques used by emerging malware families.
  • Supply Chain Attacks Board: Save instances of attacks and data breaches reference supply chain or third-party partners.

Try Feedly for Threat Intelligence

All of these features, plus many more, are available as a part of Feedly for Threat Intelligence. To learn more about any of these features, or start a free 30-day trial, click the link below.

Try Feedly for threat intelligence

You might also be interested in

Feeds and Folders

If you’ve popped into Feedly today, you might notice something’s…different.

We’ve introduced a new naming convention: RSS feeds and all the other streams of content you follow in Feedly (Twitter, Reddit, Newsletters) are feeds and the place you use to organize and group your feeds is a Folder.

Add the TechCrunch feed to one of your Folders

This doesn’t change anything about how Feedly works, it just makes it a little easier to talk about how to organize everything you follow and read. Happy reading!