API trial
Free for 30 days
30-day evaluation of the Data API. No credit card; access stops at the end unless you subscribe.
- Requests per day
- 1,000
- Requests per minute
- 30
- History
- 90 days
- API keys
- 2
- Webhooks
- Not included
The same structured intelligence behind CybersecurityNews.us, over a simple REST API: news, vulnerabilities, CISA KEV, incidents, vendors and products, and an append-only event feed you can sync from. Every record keeps its sources.
No credit card. Nothing is charged automatically: when the trial ends, access simply pauses.
Published stories with severity, recommended action, exploitation status, audiences, and every source we cite.
CVEs with CVSS, affected vendors and products, exploitation evidence and a full event history.
The Known Exploited Vulnerabilities catalog, filterable by vendor, product, ransomware use and date added.
Developing incidents and their current status, from first report to resolution.
A normalized catalog, so you can match intelligence against the technology you run.
An append-only feed of what changed and when. Sync it with a cursor and never miss an update.
The Cyber Threat Status, calculated from countable signals, with the evidence behind each point.
When a trial has ended, every call returns:
HTTP/1.1 402 Payment Required
Content-Type: application/json
{"error":"subscription_required","message":"Your CybersecurityNews.us API trial has expired."}Free for 30 days
30-day evaluation of the Data API. No credit card; access stops at the end unless you subscribe.
Pricing coming soon
For products and integrations.
Pricing coming soon
High volume, full history and webhooks.
Paid plans are coming soon. Until then, trials can be extended on request for evaluations.
Create a key in the developer dashboard. Keys start with csn_live_ and are shown once. Send yours on every request in either header:
Authorization: Bearer csn_live_...
X-API-Key: csn_live_...https://api.cybersecuritynews.us/v1Keep keys server-side. Never put a key in browser code or a mobile app bundle. If one leaks, rotate it from the dashboard.
Authenticate with the X-API-Key header and list unpatched critical and high severity CVEs. Read the key from an environment variable or secret manager. You can also try any endpoint from the API test console in your dashboard.
export CSN_API_KEY="csn_live_..." # keep keys out of source control
curl -H "X-API-Key: $CSN_API_KEY" \
"https://api.cybersecuritynews.us/v1/cves?severity=critical,high&patched=false&pageSize=20"// Node 18+ or any server-side runtime with fetch. Never ship a key to the browser.
const res = await fetch("https://api.cybersecuritynews.us/v1/cves?severity=critical,high&patched=false&pageSize=20", {
headers: { "X-API-Key": process.env.CSN_API_KEY },
});
if (!res.ok) {
const err = await res.json(); // { error, message }
throw new Error(`${res.status} ${err.error}: ${err.message}`);
}
const { data, total } = await res.json();
console.log(`${total} unpatched critical/high CVEs`);
for (const v of data) console.log(v.id, v.severity, v.cvssScore);import os
import requests
resp = requests.get(
"https://api.cybersecuritynews.us/v1/cves",
headers={"X-API-Key": os.environ["CSN_API_KEY"]},
params={"severity": "critical,high", "patched": "false", "pageSize": 20},
timeout=30,
)
resp.raise_for_status()
body = resp.json()
print(body["total"], "unpatched critical/high CVEs")
for v in body["data"]:
print(v["id"], v["severity"], v["cvssScore"])using System.Net.Http.Json;
using System.Text.Json;
using var http = new HttpClient { BaseAddress = new Uri("https://api.cybersecuritynews.us/v1/") };
http.DefaultRequestHeaders.Add("X-API-Key", Environment.GetEnvironmentVariable("CSN_API_KEY"));
using var res = await http.GetAsync("cves?severity=critical,high&patched=false&pageSize=20");
res.EnsureSuccessStatusCode();
var body = await res.Content.ReadFromJsonAsync<JsonElement>();
Console.WriteLine($"{body.GetProperty("total")} unpatched critical/high CVEs");
foreach (var v in body.GetProperty("data").EnumerateArray())
Console.WriteLine($"{v.GetProperty("id")} {v.GetProperty("severity")}");Every response carries your quota status:
| Header | Meaning |
|---|---|
| X-RateLimit-Limit-Day | Requests allowed per day on your plan. |
| X-RateLimit-Remaining-Day | Requests left today (resets 00:00 UTC). |
| X-Trial-Ends | When your trial ends (trial accounts only). |
| Retry-After | On a 429, the number of seconds to wait before retrying. |
History is limited to your plan’s history window (api.history_days). Older records are not returned.
Errors are JSON with a stable machine-readable error code and a human-readable message:
{"error":"rate_limited","message":"..."}| HTTP | error | When |
|---|---|---|
| 401 | missing_api_key | No key was sent. |
| 401 | invalid_api_key | The key is not recognised. |
| 401 | key_revoked | The key was revoked from the dashboard. |
| 401 | key_expired | The key passed its expiry date (including the 24-hour grace period after a rotation). |
| 402 | subscription_required | Your trial or plan has ended. Your account, keys and settings are kept. |
| 403 | account_suspended | The account was suspended. Contact support@cybersecuritynews.us. |
| 404 | not_found | The resource does not exist, or is outside your plan's history window. |
| 429 | rate_limited | Too many requests this minute. Wait for Retry-After seconds. |
| 429 | quota_exceeded | The daily request quota is used up. It resets at 00:00 UTC. |
List endpoints return { data, page, pageSize, total }. Enum values are kebab-case strings, for example kev-added, proof-of-concept and severity critical.
Your account, plan, limits and usage today. Use it to check a key works.
curl -H "Authorization: Bearer $CSN_API_KEY" \
"https://api.cybersecuritynews.us/v1/status"Published stories, newest first.
curl -H "Authorization: Bearer $CSN_API_KEY" \
"https://api.cybersecuritynews.us/v1/news?vendor=microsoft&minSeverity=high&pageSize=20"One story with its sources, updates and the intelligence events it produced.
curl -H "Authorization: Bearer $CSN_API_KEY" \
"https://api.cybersecuritynews.us/v1/news/{slug}"CVEs we track, with CVSS, severity band, exploitation status, KEV listing and patch availability. /v1/cves is an alias that returns exactly the same data.
curl -H "Authorization: Bearer $CSN_API_KEY" \
"https://api.cybersecuritynews.us/v1/cves?severity=critical,high&patched=false"One vulnerability with affected products, related stories and its event history timeline. Each products[] entry carries affectedVersions, fixedVersions and the basis for them (kev, nvd or editor).
curl -H "Authorization: Bearer $CSN_API_KEY" \
"https://api.cybersecuritynews.us/v1/cves/CVE-2026-65660"Active threats in one call: the current threat status, CVEs being actively exploited, developing incidents and the most recent intelligence events in the window.
curl -H "Authorization: Bearer $CSN_API_KEY" \
"https://api.cybersecuritynews.us/v1/threats?vendor=microsoft&days=14"The CISA Known Exploited Vulnerabilities catalog as we track it.
curl -H "Authorization: Bearer $CSN_API_KEY" \
"https://api.cybersecuritynews.us/v1/kev?addedSince=2026-09-01"Developing incidents and their status.
curl -H "Authorization: Bearer $CSN_API_KEY" \
"https://api.cybersecuritynews.us/v1/incidents?active=true"The vendor catalog, searchable by name; a single vendor with its products.
curl -H "Authorization: Bearer $CSN_API_KEY" \
"https://api.cybersecuritynews.us/v1/vendors?q=micro"Products, optionally for one vendor.
curl -H "Authorization: Bearer $CSN_API_KEY" \
"https://api.cybersecuritynews.us/v1/products?vendor=microsoft"The same search as the website: understands CVE ids, vendor and product names and phrases like "exploited this week". Returns stories and CVEs, each with a link; `understood` explains how the query was read.
curl -H "Authorization: Bearer $CSN_API_KEY" \
"https://api.cybersecuritynews.us/v1/search?q=critical%20Microsoft%20vulnerabilities%20exploited%20this%20week"The append-only intelligence event feed: every disclosure, exploitation change, KEV addition, severity change, patch release and incident update, in order. Poll it with a cursor to stay in sync.
curl -H "Authorization: Bearer $CSN_API_KEY" \
"https://api.cybersecuritynews.us/v1/intelligence?profile=me&after=150"The current Cyber Threat Status, its audience indicators and the evidence behind it.
curl -H "Authorization: Bearer $CSN_API_KEY" \
"https://api.cybersecuritynews.us/v1/threat-status"Every vulnerability carries a severity band derived from its CVSS base score (null until a score is published), plus patchAvailable and the vendor patchUrls we have verified. Filter on both with severity and patched.
| severity | CVSS base score |
|---|---|
| critical | 9.0 – 10.0 |
| high | 7.0 – 8.9 |
| medium | 4.0 – 6.9 |
| low | Below 4.0 |
{
"id": "CVE-2026-65660",
"title": "Microsoft SharePoint remote code execution",
"cvssScore": 9.8,
"severity": "critical",
"exploitation": "confirmed",
"kev": true,
"patchAvailable": true,
"patchUrls": ["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660"],
...
}GET /v1/threats gathers what is active right now, optionally for one vendor:
{
"threatStatus": { ... },
"windowDays": 14,
"activelyExploited": [ { "id": "CVE-2026-65660", "severity": "critical", ... } ],
"activeIncidents": [ { "slug": "...", "title": "...", ... } ],
"recentEvents": [ { "id": 158, "type": "patch-released", ... } ]
}Events are append-only: a change never rewrites history, it adds a new event (with isUpdate: true when it revises an earlier one). To stay in sync, store the highest id you have processed and pass it as after. Keep calling with the returned next cursor until it stops advancing.
{
"id": 158,
"type": "kev-added",
"subject": "cve:CVE-2026-65660",
"cveId": "CVE-2026-65660",
"storyId": null,
"title": "CVE-2026-65660 added to CISA KEV: Microsoft SharePoint...",
"summary": "...",
"severity": "high",
"exploitation": "confirmed",
"kev": true,
"isUpdate": false,
"basis": "CISA Known Exploited Vulnerabilities catalog",
"vendorIds": [1],
"productIds": [4],
"occurredAt": "2026-09-25T17:17:30Z"
}| type | Meaning |
|---|---|
| vulnerability-disclosed | A new CVE was published or first reported. |
| cvss-scored | A CVSS base score was published for the CVE. |
| severity-raised | Our severity assessment went up. |
| proof-of-concept-released | Public proof-of-concept exploit code appeared. |
| exploitation-suspected | Credible reports of exploitation, not yet confirmed. |
| exploitation-confirmed | Exploitation confirmed by the vendor, CISA or a named responder. |
| kev-added | Added to the CISA Known Exploited Vulnerabilities catalog. |
| patch-released | The vendor released a fix or update; patchUrls lists where to get it. |
| advisory-published | A vendor or government advisory was published. |
| incident-created | A new incident is being tracked. |
| incident-updated | An incident's status or details changed. |
| news-published | A story was published. |
New event types may be added over time; ignore types your client does not recognise.
v1 is stable. We may add endpoints, fields and enum values; your client should ignore what it does not know. Breaking changes (removing or renaming fields, changing meanings) only ship in a new major version, such as /v2, with at least 12 months of overlap and advance notice by email and Deprecation / Sunset response headers. See the API changelog and version policy.
Coming soon: push delivery of intelligence events to your endpoint, signed and retried. Until then, poll /v1/intelligence with a cursor.
Sign in with your email, start the trial, and make your first call in about a minute.
Start free 30-day trial