Data API · v1

Cybersecurity intelligence, as data

The same structured intelligence behind CybersecurityNews.us, over a simple REST API: news, vulnerabilities, CISA KEV, incidents, vendors and products, and an append-only event feed you can sync from. Every record keeps its sources.

No credit card. Nothing is charged automatically: when the trial ends, access simply pauses.

What the Data API offers

  • News

    Published stories with severity, recommended action, exploitation status, audiences, and every source we cite.

  • Vulnerabilities

    CVEs with CVSS, affected vendors and products, exploitation evidence and a full event history.

  • CISA KEV

    The Known Exploited Vulnerabilities catalog, filterable by vendor, product, ransomware use and date added.

  • Incidents

    Developing incidents and their current status, from first report to resolution.

  • Vendors & products

    A normalized catalog, so you can match intelligence against the technology you run.

  • Intelligence events

    An append-only feed of what changed and when. Sync it with a cursor and never miss an update.

  • Threat status

    The Cyber Threat Status, calculated from countable signals, with the evidence behind each point.

Free 30-day trial

  • No credit card, no automatic charge. The trial simply ends after 30 days.
  • We email you 7, 3 and 1 day before it ends, and again when it has ended.
  • Nothing is deleted when it ends. Your account, keys and settings are kept. Calls return HTTP 402 until you move to a paid plan.
  • The API is a separate product from the website subscription. A website subscription does not include API access, and the reverse.
  • Anti-abuse is proportionate: a verified email address, one trial per person, and rate limits. We do not fingerprint your device.

When a trial has ended, every call returns:

HTTP/1.1 402 Payment Required
Content-Type: application/json

{"error":"subscription_required","message":"Your CybersecurityNews.us API trial has expired."}

Plans

API trial

Free for 30 days

30-day evaluation of the Data API. No credit card; access stops at the end unless you subscribe.

Requests per day
1,000
Requests per minute
30
History
90 days
API keys
2
Webhooks
Not included
Start free trial

API Developer

Pricing coming soon

For products and integrations.

Requests per day
10,000
Requests per minute
60
History
365 days
API keys
5
Webhooks
Not included

API Business

Pricing coming soon

High volume, full history and webhooks.

Requests per day
100,000
Requests per minute
300
History
3,650 days
API keys
20
Webhooks
Included (coming soon)

Paid plans are coming soon. Until then, trials can be extended on request for evaluations.

Authentication and base URL

Create a key in the developer dashboard. Keys start with csn_live_ and are shown once. Send yours on every request in either header:

Authorization: Bearer csn_live_...
X-API-Key: csn_live_...
Base URL
https://api.cybersecuritynews.us/v1
Format
JSON over HTTPS. Timestamps are ISO 8601 UTC.

Keep keys server-side. Never put a key in browser code or a mobile app bundle. If one leaks, rotate it from the dashboard.

Code examples

Authenticate with the X-API-Key header and list unpatched critical and high severity CVEs. Read the key from an environment variable or secret manager. You can also try any endpoint from the API test console in your dashboard.

export CSN_API_KEY="csn_live_..."   # keep keys out of source control

curl -H "X-API-Key: $CSN_API_KEY" \
  "https://api.cybersecuritynews.us/v1/cves?severity=critical,high&patched=false&pageSize=20"

Rate limits and quotas

Every response carries your quota status:

Rate-limit response headers
HeaderMeaning
X-RateLimit-Limit-DayRequests allowed per day on your plan.
X-RateLimit-Remaining-DayRequests left today (resets 00:00 UTC).
X-Trial-EndsWhen your trial ends (trial accounts only).
Retry-AfterOn a 429, the number of seconds to wait before retrying.

History is limited to your plan’s history window (api.history_days). Older records are not returned.

Errors

Errors are JSON with a stable machine-readable error code and a human-readable message:

{"error":"rate_limited","message":"..."}
API error codes
HTTPerrorWhen
401missing_api_keyNo key was sent.
401invalid_api_keyThe key is not recognised.
401key_revokedThe key was revoked from the dashboard.
401key_expiredThe key passed its expiry date (including the 24-hour grace period after a rotation).
402subscription_requiredYour trial or plan has ended. Your account, keys and settings are kept.
403account_suspendedThe account was suspended. Contact support@cybersecuritynews.us.
404not_foundThe resource does not exist, or is outside your plan's history window.
429rate_limitedToo many requests this minute. Wait for Retry-After seconds.
429quota_exceededThe daily request quota is used up. It resets at 00:00 UTC.

Endpoint reference

List endpoints return { data, page, pageSize, total }. Enum values are kebab-case strings, for example kev-added, proof-of-concept and severity critical.

GET /v1/status

Your account, plan, limits and usage today. Use it to check a key works.

curl -H "Authorization: Bearer $CSN_API_KEY" \
  "https://api.cybersecuritynews.us/v1/status"

GET /v1/news

Published stories, newest first.

category
Category slug, e.g. vulnerabilities
vendor / product
Vendor or product slug
cve
A CVE id the story covers
minSeverity
informational, elevated, high or critical
exploited
true for stories with confirmed or widespread exploitation
since
ISO 8601 timestamp
page / pageSize
Paging; pageSize is at most 100
curl -H "Authorization: Bearer $CSN_API_KEY" \
  "https://api.cybersecuritynews.us/v1/news?vendor=microsoft&minSeverity=high&pageSize=20"

GET /v1/news/{slug}

One story with its sources, updates and the intelligence events it produced.

curl -H "Authorization: Bearer $CSN_API_KEY" \
  "https://api.cybersecuritynews.us/v1/news/{slug}"

GET /v1/vulnerabilities, GET /v1/cves

CVEs we track, with CVSS, severity band, exploitation status, KEV listing and patch availability. /v1/cves is an alias that returns exactly the same data.

vendor / product
Vendor or product slug
severity
Comma-separated CVSS bands: critical (9.0+), high (7.0–8.9), medium (4.0–6.9), low (below 4.0)
patched
true for CVEs with a known fix, false for CVEs still waiting for one
kev
true for CISA KEV-listed CVEs only
exploited
true for confirmed or widespread exploitation
minCvss
Minimum CVSS base score, e.g. 9.0
ransomware
true for CVEs known to be used in ransomware campaigns
since
ISO 8601 timestamp (last updated)
page / pageSize
Paging; pageSize is at most 100
curl -H "Authorization: Bearer $CSN_API_KEY" \
  "https://api.cybersecuritynews.us/v1/cves?severity=critical,high&patched=false"

GET /v1/vulnerabilities/{CVE-ID}, GET /v1/cves/{CVE-ID}

One vulnerability with affected products, related stories and its event history timeline. Each products[] entry carries affectedVersions, fixedVersions and the basis for them (kev, nvd or editor).

curl -H "Authorization: Bearer $CSN_API_KEY" \
  "https://api.cybersecuritynews.us/v1/cves/CVE-2026-65660"

GET /v1/threats

Active threats in one call: the current threat status, CVEs being actively exploited, developing incidents and the most recent intelligence events in the window.

vendor
Vendor slug, to focus on the technology you run
days
Look-back window in days, 1 to 90 (default 14)
curl -H "Authorization: Bearer $CSN_API_KEY" \
  "https://api.cybersecuritynews.us/v1/threats?vendor=microsoft&days=14"

GET /v1/kev

The CISA Known Exploited Vulnerabilities catalog as we track it.

vendor / product
Vendor or product slug
ransomware
true for known ransomware use
addedSince
Date the CVE was added to KEV, YYYY-MM-DD
curl -H "Authorization: Bearer $CSN_API_KEY" \
  "https://api.cybersecuritynews.us/v1/kev?addedSince=2026-09-01"

GET /v1/incidents

Developing incidents and their status.

active
true for incidents that are still developing
curl -H "Authorization: Bearer $CSN_API_KEY" \
  "https://api.cybersecuritynews.us/v1/incidents?active=true"

GET /v1/vendors, GET /v1/vendors/{slug}

The vendor catalog, searchable by name; a single vendor with its products.

q
Name search
curl -H "Authorization: Bearer $CSN_API_KEY" \
  "https://api.cybersecuritynews.us/v1/vendors?q=micro"

GET /v1/products

Products, optionally for one vendor.

vendor
Vendor slug
q
Name search
curl -H "Authorization: Bearer $CSN_API_KEY" \
  "https://api.cybersecuritynews.us/v1/products?vendor=microsoft"

The same search as the website: understands CVE ids, vendor and product names and phrases like "exploited this week". Returns stories and CVEs, each with a link; `understood` explains how the query was read.

q
2 to 200 characters
page
Page of stories, 1 to 20
curl -H "Authorization: Bearer $CSN_API_KEY" \
  "https://api.cybersecuritynews.us/v1/search?q=critical%20Microsoft%20vulnerabilities%20exploited%20this%20week"

GET /v1/intelligence

The append-only intelligence event feed: every disclosure, exploitation change, KEV addition, severity change, patch release and incident update, in order. Poll it with a cursor to stay in sync.

after
The last event id you processed (cursor). The response includes `next`.
type
Comma-separated event types, e.g. kev-added,exploitation-confirmed,patch-released
vendor / product / cve
Filter to a subject
kev
true for KEV-related events
profile
me: only events that match the vendors, products, topics and CVEs your account follows, using your alert thresholds. Each result adds `tier`, `reasons` (why it matched) and a `link`; `next` advances past skipped events too.
since
ISO 8601 timestamp
limit
Events per call, at most 500
curl -H "Authorization: Bearer $CSN_API_KEY" \
  "https://api.cybersecuritynews.us/v1/intelligence?profile=me&after=150"

GET /v1/threat-status

The current Cyber Threat Status, its audience indicators and the evidence behind it.

curl -H "Authorization: Bearer $CSN_API_KEY" \
  "https://api.cybersecuritynews.us/v1/threat-status"

Severity bands and patch status

Every vulnerability carries a severity band derived from its CVSS base score (null until a score is published), plus patchAvailable and the vendor patchUrls we have verified. Filter on both with severity and patched.

Severity bands by CVSS base score
severityCVSS base score
critical9.0 – 10.0
high7.0 – 8.9
medium4.0 – 6.9
lowBelow 4.0
{
  "id": "CVE-2026-65660",
  "title": "Microsoft SharePoint remote code execution",
  "cvssScore": 9.8,
  "severity": "critical",
  "exploitation": "confirmed",
  "kev": true,
  "patchAvailable": true,
  "patchUrls": ["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660"],
  ...
}

GET /v1/threats gathers what is active right now, optionally for one vendor:

{
  "threatStatus": { ... },
  "windowDays": 14,
  "activelyExploited": [ { "id": "CVE-2026-65660", "severity": "critical", ... } ],
  "activeIncidents": [ { "slug": "...", "title": "...", ... } ],
  "recentEvents": [ { "id": 158, "type": "patch-released", ... } ]
}

The intelligence event feed

Events are append-only: a change never rewrites history, it adds a new event (with isUpdate: true when it revises an earlier one). To stay in sync, store the highest id you have processed and pass it as after. Keep calling with the returned next cursor until it stops advancing.

{
  "id": 158,
  "type": "kev-added",
  "subject": "cve:CVE-2026-65660",
  "cveId": "CVE-2026-65660",
  "storyId": null,
  "title": "CVE-2026-65660 added to CISA KEV: Microsoft SharePoint...",
  "summary": "...",
  "severity": "high",
  "exploitation": "confirmed",
  "kev": true,
  "isUpdate": false,
  "basis": "CISA Known Exploited Vulnerabilities catalog",
  "vendorIds": [1],
  "productIds": [4],
  "occurredAt": "2026-09-25T17:17:30Z"
}
Intelligence event types
typeMeaning
vulnerability-disclosedA new CVE was published or first reported.
cvss-scoredA CVSS base score was published for the CVE.
severity-raisedOur severity assessment went up.
proof-of-concept-releasedPublic proof-of-concept exploit code appeared.
exploitation-suspectedCredible reports of exploitation, not yet confirmed.
exploitation-confirmedExploitation confirmed by the vendor, CISA or a named responder.
kev-addedAdded to the CISA Known Exploited Vulnerabilities catalog.
patch-releasedThe vendor released a fix or update; patchUrls lists where to get it.
advisory-publishedA vendor or government advisory was published.
incident-createdA new incident is being tracked.
incident-updatedAn incident's status or details changed.
news-publishedA story was published.

New event types may be added over time; ignore types your client does not recognise.

Versioning

v1 is stable. We may add endpoints, fields and enum values; your client should ignore what it does not know. Breaking changes (removing or renaming fields, changing meanings) only ship in a new major version, such as /v2, with at least 12 months of overlap and advance notice by email and Deprecation / Sunset response headers. See the API changelog and version policy.

Webhooks

Coming soon: push delivery of intelligence events to your endpoint, signed and retried. Until then, poll /v1/intelligence with a cursor.

Try it on your own data

Sign in with your email, start the trial, and make your first call in about a minute.

Start free 30-day trial