A free watch floor for security practitioners
Cybersecurity Tracker aggregates security news and vulnerability intelligence into one ranked, filterable feed. It runs autonomously, costs nothing, and asks for no account.
Built and operated by Gary Bowen

I am a cybersecurity leader, and I built Cybersecurity Tracker to solve a problem I have on my own watch floor: too many sources, too little time, and no free tool that ranks what actually matters. It runs autonomously and stays free because the security community it serves should not have to pay to keep up.
Feedback makes it better. You can connect with me on LinkedIn or send feedback directly.
Send feedback
A bug, a source we should add, or anything else. No account needed. Leave contact details only if you want a reply.
How it works
A pipeline crawls 43 high-fidelity news sources plus structured feeds: CISA (Known Exploited Vulnerabilities, its advisories, and industrial control system advisories), the National Vulnerability Database (NVD), the Exploit Prediction Scoring System (EPSS), Microsoft, GitHub, Exploit-DB, and SigmaHQ detection rules. Breach data comes from Securities and Exchange Commission (SEC) 8-K filings, the Department of Health and Human Services Office for Civil Rights (HHS OCR), the California Attorney General portal, and the Have I Been Pwned breach directory; leak-site claims come from RansomLook and ransomware.live, always labeled unverified. Stories are de-duplicated and clustered across outlets, classified by category, and summarized in our own words; vulnerabilities are enriched and ranked into priority tiers. The full source list, with each licence, is on theattributions page.
Editorial policy
- Summaries are two to three sentences in our own words. We never reproduce article text beyond a short phrase.
- Every item links to and names its sources.
- Leak-site entries are always labeled "Claimed by [group]. Unverified." We do not present a claim as a confirmed breach.
- We respect robots.txt on any page fetch and use the syndicated feed when full text is disallowed.
How priority works
A vulnerability's priority is a tier, not a raw sum. Confirmed exploitation and internet-facing exposure set the tier first, then a Stakeholder Specific Vulnerability Categorization (SSVC) style decision this tracker computes, founded on the CISA Vulnrichment program's published judgments wherever they have been ingested for a Common Vulnerabilities and Exposures (CVE) identifier, and on inputs we derive from the Common Vulnerability Scoring System (CVSS) where none is stored, then Exploit Prediction Scoring System (EPSS) likelihood. Our exploitation, exposure, and End of Life signals only ever raise the tier above what that decision implies, never lower it. The rank within a tier draws on those same signals plus how much attention the CVE identifier is getting across our sources. It is a triage signal, not a substitute for your own risk assessment.
What it costs
Nothing, to you. No account, no paywall, no tracking. See the attributions and licences page for how every source is credited, and the API if you want the raw data.