CISA Cybersecurity Advisories
active Ingestion health: delivering Executive · Tier 2 · RSS feed · Department of Homeland Security (CISA)
Official site (opens in a new tab) · All sources
What this source is
The Cybersecurity and Infrastructure Security Agency publishes cybersecurity advisories, alerts, and the Known Exploited Vulnerabilities (KEV) catalog — federal directives and warnings that constitute an action category the pipeline does not cover at all.
The Cybersecurity and Infrastructure Security Agency publishes cybersecurity advisories, alerts, and known exploited vulnerabilities that inform federal and public security practices.
The Cybersecurity and Infrastructure Security Agency (CISA), part of the Department of Homeland Security, is the federal government's civilian cybersecurity authority. CISA publishes official advisories and alerts on cybersecurity threats and vulnerabilities, serving as actionable guidance for federal agencies, critical infrastructure operators, and the broader public.
CISA advisories address specific cybersecurity vulnerabilities and threats: detailed technical information on security flaws in software and systems, recommendations for remediation, and guidance on defensive practices. Advisories may accompany warnings about active exploitation of particular vulnerabilities or newly discovered threats.
The Known Exploited Vulnerabilities (KEV) catalog is CISA's authoritative list of security flaws that have been observed in active use by malicious actors. This catalog serves as a reference for organizations prioritizing remediation efforts—CISA has issued guidance that federal agencies address vulnerabilities on this list by specified deadlines.
These publications represent a category of federal action not covered by other sources in the digest: direct security guidance and threat notification. Unlike analysis or commentary, CISA advisories are technical directives intended to inform security decisions across the government and critical infrastructure.
For readers concerned with cybersecurity policy, federal security posture, and threat awareness, CISA advisories represent the government's official guidance on current and emerging security challenges.
Model-written orientation, generated 2026-08-05 by haiku, prompt version 1. It may draw on general knowledge of public institutions and is not official-record content.
Identity and registry record
- Registry id
cisa-advisories- Agency / parent organization
- Department of Homeland Security (CISA)
- Branch
- executive
- Type
- RSS feed
- Status
- active
- Tier
- 2
- URL (feed)
- https://www.cisa.gov/cybersecurity-advisories/all.xml (opens in a new tab)
- URL (home)
- https://www.cisa.gov/news-events/cybersecurity-advisories (opens in a new tab)
- URL (index)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog (opens in a new tab)
- Registered
- 2026-07-28
- Registry notes
- Research flagged the 2025-05 RSS retirement announcement, but the probe (2026-07-28) found all.xml alive and rich: HTTP 200, 2.0 MB feed, 30 recent advisories whose descriptions embed the full advisory text (~55,000 chars each); sample advisory page also extracts (9,317 chars). Content evaluation: descriptions carry the substance — article fetches add layout, not content — but pages fetch cleanly, so full mode is kept for capture/provenance value. First ingest brings ~30 substantial items. Activated 2026-07-28.
How we ingest it
- Channel
- RSS feed
- Method
- Polls the advisories RSS feed via AgencyClient; KEV JSON is a later extension.
- Poll cadence
- about every 60 minutes while the collector runs
- Request budget
- the agency class: at most 3,000 requests per day shared across every agency web source, counted from the fetch log (failed requests count too)
- Politeness
- robots.txt is honored as observed — including each host's crawl-delay, exactly — and every request identifies itself as fapd/0.1 (Free Agentic Publication Digester; +https://fapd.info/bot.html; contact: hustleyourcity@gmail.com); a refusal is recorded, never evaded
- Capture and hash
- captured raw content is hashed (SHA-256) into the day's committed provenance manifest, hash-chained day to day (PROVENANCE.md)
Ingestion health
Ingestion health: delivering 31 item(s) in the last 14 days; most recent 2026-09-27; 0 of 381 request(s) to www.cisa.gov returned no content.
This label has held since 2026-08-03T18:46:01Z (UTC) and was last re-checked 2026-09-29T09:47:01Z (UTC).
Counts are of our own requests, retries included. A 4xx or 5xx is the server declining to return content — that may be load, maintenance, on-demand generation, or a limit the publisher sets, and we cannot tell which from outside. Nothing here is a measurement of the publisher.
Ingestion statistics
These figures describe this project's ingestion of this source — items we recorded and requests we made — and nothing else. They are not a measurement of the publisher.
Last 24 hours
Last 24 hours: 26 request(s) (26 answered, 0 returned no content) · no items ingested
Last 14 days
Items ingested: 31 in 14 days (2.21 per day) · most recent 2026-09-27
Content length: 9,457 characters average, 8,143 median (shortest 4,392, longest 30,127)
Delivery mode: full — full article text, fetched from the item's own page
Our requests to www.cisa.gov: 381 request(s) · 381 answered · 0 declined (4xx) · 0 server declined (5xx) · 0 no response — 0.0% returned no content
last answered request 2026-09-29T09:27:44.352+00:00 UTC.
31 item(s) in the last 14 days; most recent 2026-09-27; 0 of 381 request(s) to www.cisa.gov returned no content.
All time
Our requests to www.cisa.gov, all time (since 2026-07-30): 1,904 request(s) · 1,900 answered · 4 returned no content
Request counts begin 2026-07-30, the day this service went into production; earlier development-machine traffic is excluded. Counts before 2026-08-03 include unmarked source-probe traffic; probes are labeled and excluded thereafter.
Last 30 days, day by day
Each day runs midnight to midnight on Eastern time (Washington, D.C.), the publication day the digests use; the stored request stamps remain UTC.
| Day | requests |
|---|---|
| 2026-08-31 | 27 |
| 2026-09-01 | 32 |
| 2026-09-02 | 27 |
| 2026-09-03 | 38 |
| 2026-09-04 | 27 |
| 2026-09-05 | 34 |
| 2026-09-06 | 27 |
| 2026-09-07 | 26 |
| 2026-09-08 | 29 |
| 2026-09-09 | 27 |
| 2026-09-10 | 32 |
| 2026-09-11 | 27 |
| 2026-09-12 | 29 |
| 2026-09-13 | 26 |
| 2026-09-14 | 30 |
| 2026-09-15 | 36 |
| 2026-09-16 | 29 |
| 2026-09-17 | 33 |
| 2026-09-18 | 28 |
| 2026-09-19 | 26 |
| 2026-09-20 | 26 |
| 2026-09-21 | 30 |
| 2026-09-22 | 35 |
| 2026-09-23 | 26 |
| 2026-09-24 | 29 |
| 2026-09-25 | 29 |
| 2026-09-26 | 27 |
| 2026-09-27 | 29 |
| 2026-09-28 | 26 |
| 2026-09-29 | 8 |
| Day | items |
|---|---|
| 2026-08-31 | 1 |
| 2026-09-01 | 6 |
| 2026-09-02 | 2 |
| 2026-09-03 | 10 |
| 2026-09-04 | 1 |
| 2026-09-05 | 0 |
| 2026-09-06 | 0 |
| 2026-09-07 | 0 |
| 2026-09-08 | 3 |
| 2026-09-09 | 1 |
| 2026-09-10 | 5 |
| 2026-09-11 | 2 |
| 2026-09-12 | 0 |
| 2026-09-13 | 0 |
| 2026-09-14 | 1 |
| 2026-09-15 | 9 |
| 2026-09-16 | 3 |
| 2026-09-17 | 7 |
| 2026-09-18 | 2 |
| 2026-09-19 | 0 |
| 2026-09-20 | 0 |
| 2026-09-21 | 1 |
| 2026-09-22 | 10 |
| 2026-09-23 | 1 |
| 2026-09-24 | 3 |
| 2026-09-25 | 2 |
| 2026-09-26 | 0 |
| 2026-09-27 | 2 |
| 2026-09-28 | 0 |
| 2026-09-29 | 0 |
| Day | ms |
|---|---|
| 2026-08-31 | 142 |
| 2026-09-01 | 119 |
| 2026-09-02 | 193 |
| 2026-09-03 | 654 |
| 2026-09-04 | 195 |
| 2026-09-05 | 287 |
| 2026-09-06 | 172 |
| 2026-09-07 | 140 |
| 2026-09-08 | 149 |
| 2026-09-09 | 141 |
| 2026-09-10 | 113 |
| 2026-09-11 | 134 |
| 2026-09-12 | 235 |
| 2026-09-13 | 179 |
| 2026-09-14 | 345 |
| 2026-09-15 | 109 |
| 2026-09-16 | 134 |
| 2026-09-17 | 106 |
| 2026-09-18 | 200 |
| 2026-09-19 | 165 |
| 2026-09-20 | 155 |
| 2026-09-21 | 220 |
| 2026-09-22 | 105 |
| 2026-09-23 | 129 |
| 2026-09-24 | 190 |
| 2026-09-25 | 164 |
| 2026-09-26 | 233 |
| 2026-09-27 | 170 |
| 2026-09-28 | 216 |
| 2026-09-29 | 120 |
Our ingestion assessment
The CISA cybersecurity-advisories RSS feed delivered 40 items over 14 days at 2.86 per day, down from 3.5 per day in the prior assessment. The most recent item arrived 2026-09-04. Extracted article descriptions average 10,711 characters, with individual advisories ranging up to 56,634 characters. Request success was 383 of 387 answered (1.0% no-response), with four requests returning no content. The prior assessment reported zero failures over 272 attempts; this window shows four failures scattered across the measurement period. The feed remains a reliable source of cybersecurity advisories; article page fetches add layout and formatting context but do not introduce new content beyond the feed's embedded full-text descriptions.
Model-written assessment of our own ingestion, generated 2026-09-05 by haiku, prompt version 1, trigger: age-30d. It restates our measured figures and is not official-record content.