RSS and other feeds

Here are solid RSS feeds focused on zero-day (0-day) and actively exploitable vulnerabilities. True 0-days (unpatched, actively exploited or publicly disclosed with no fix yet) are rare and often appear first via coordinated disclosure programs, exploit databases, or known-exploited lists rather than generic CVE feeds.

zerodayinitiative.comTop recommendations for 0-day / exploitable issues

  • Zero Day Initiative (ZDI) – Upcoming Advisories
    https://www.zerodayinitiative.com/rss/upcoming/
    Excellent for early heads-up. Vulnerabilities appear here once the vendor is notified and the public-disclosure countdown starts (often before a patch or full advisory).
  • Zero Day Initiative (ZDI) – Published Advisories
    https://www.zerodayinitiative.com/rss/published/
    Released advisories (many involve high-impact bugs that started as 0-days).
  • ZDI Blog
    https://www.zerodayinitiative.com/blog?format=rss (or https://www.thezdi.com/blog?format=rss)
    Research write-ups, Pwn2Own results, and deeper analysis.
  • Exploit-DB
    https://www.exploit-db.com/rss.xml
    Public exploits, PoCs, and many 0-day / remote/local/webapp issues as they are published. Very practical for “exploitable right now.” community.emergingthreats.net
  • Full Disclosure mailing list
    https://seclists.org/rss/fulldisclosure.rss
    Raw researcher disclosures; frequently includes new or unpatched issues.

Known Exploited / high-priority (often recent 0-days that hit the wild)CISA’s official KEV RSS was discontinued, so use these maintained alternatives:

  • https://cisa.kevintel.com/rss.xml (community-maintained, updates frequently)
  • https://vulnerability.circl.lu/known-exploited-vulnerabilities.rss (or .atom)
  • CVEDatabase KEV additions: https://cvedatabase.com/feed/cve/kev

Other useful high-signal feeds

  • Talos Vulnerability Reports: https://www.talosintelligence.com/vulnerability_reports/feed
  • watchTowr Labs: https://labs.watchtowr.com/feed (or /rss/)
  • Critical/high CVEs (broader but useful filter):
    • https://cvedatabase.com/feed/cve/critical
    • https://cvedatabase.com/feed/cve/high
    • Recent CVEs: https://cvedatabase.com/feed/cve/recent

Quick tips

  • Subscribe to the ZDI upcoming + Exploit-DB + a KEV feed combination for the best coverage of true 0-days and actively exploited issues.
  • Use a good RSS reader (Feedly, Inoreader, NewsBlur, or a self-hosted option like FreshRSS/Tiny Tiny RSS) and apply keyword filters (e.g., “0-day”, “zero-day”, “RCE”, “unauthenticated”, high CVSS) if the volume is high.
  • Pair with X/Twitter lists of vulnerability researchers or Project Zero for the absolute earliest chatter, then cross-check the RSS items.
  • HITCON ZeroDay has some community RSS generators on GitHub if you want additional regional coverage, but the ones above are the most reliable mainstream sources.

These should keep you current without drowning in every low-severity CVE. Start with the ZDI upcoming and Exploit-DB feeds.

Claude Is Hiding Watermarks in Your AI Text (What It Actually Means)

Sometimes it’s good to look to some smaller channels to get a street level view of a current topic, and this is a HOT topic. Thanks to Kyle for this,

Anthropic says new Claude models launched in the EU must support machine-readable marking. That means embedded watermarks for generated text and signed provenance metadata for supported files…but the viral claim that every Claude response is already publicly detectable is too broad. There’s a lot of bad info going around.

I break down what Anthropic has actually committed to, how text watermarking differs from C2PA metadata, why a detected mark does not prove Claude authored the work, and why no mark does not prove a human wrote it. The technical documentation and public detection tools are still coming, so anyone claiming certainty about the exact implementation is getting ahead of the evidence.

Cassini’s Grand Finale

One of my favorite missions, EVER! We learned so much. The only way to make sure we didn’t hit one of the moons and ruin any future science, we flew her INTO Saturn.

This has been the most freeing experience I have every had.

To some, this would be a sad event. For me, it has been liberating.

I spent years in various sportbike groups, enjoying riding, and events, and lunches out. Long story, short…I was involved in a really bad wreck, hit by another rider. Hung it all up.

For a couple years I’d get some of the group together and we’d have lunch, etc. But…one day I realized that I was the only reason it was happening. What I thought was a bunch of 2-way relationships was WRONG. Sooo, how to test this.

I stopped. I mean literally stopped contacting them. I wanted to see which of them would reach out to setup the next lunch, etc. No one did, not a single time. At first I was offended, but then I realized that I didn’t need any of that. Being offended is a choice, and I chose not to be. I took the energy that I used to spend on thinking about them, and contacting them, and getting them to agree on where to meet…blah, blah, blah, and applied it to ME.

Wow, talk about freedom. I realized that I don’t give a fuck about any of that. I don’t care what they may think. I don’t care if they don’t like me, or ever did. It’s really cool.

If you wonder/worry about what your “friends” think about you, you’d be very surprised just how little they actually think about you at all.

How should OpenAI address the competition from cheaper open-source alternatives?

This is from Brian Roemmele – Founder + Editor at Read Multiplex.

There is only one way.

Meet the competition on that level.
Do what they set out to do: make the AI open source.

Why?
Because the market will be moved by them at the lowest entry levels—and grasped by them at the highest. Ecosystems will form at kitchen tables, in garages, and in campus rooms around free access to performative models. That access creates a stickiness to the brand that can last a lifetime.

Instead, they cling to the idea that revenue must be extracted from the lowest entry point into their system.
This is short-term thinking.

It is lazy thinking.

It comes from people with naïve business experience and even thinner life experience.

Since the opening of the iPhone App Store, a generation of founders and venture capitalists has lived to replay the same tired success story: renting server time.

Exactly like the mainframe era of the 1970s.
That era is long dead.

OpenAI and Anthropic never got the memo.

There are dozens of far more substantial monetization systems that can be built around this new epoch of AI access.

I will not list them here (hire me and I’ll tell you).

They exist.

The tragedy is that the talent stack at both companies almost guarantees they will never see them—even when they ask their own models for solutions.

There is no moat that uniquely protects the base models we currently call LLMs.

A simple reality: every AI model will become good enough for 99% of use cases and collapse into low commodity access and pricing.

I predict this with clarity:

If they refuse to open-source the full weights for the entry-level market, they will be forced to subsidize usage below the cost of the electricity just to keep people on the platform—hoping someone buys the fries and the shake with the hamburger.

Let me make it so simple even an AI executive can understand it:

It makes better sense for the user to burn their own RAM, their own processor, their own GPU, and—most importantly—their own electricity running your model.

Read that again.
Read that again.
And now think.

I am not guessing.

This is the way it is going to be.

The only question is how fast the world catches up.

The magic of this period I call the Interregnum will belong to the new companies that form abstraction layers on top of what is now the electricity of computing: AI.

AI is electricity.

What we connect to electricity today is not just the lightbulb Edison imagined.

It is hundreds of trillions of motors—large and small—that power hundreds of trillions of systems, that also power hundreds of trillions of transistors we call computers… and yes, also lightbulbs.

I have had these conversations with people in the upper echelon of these companies.

They can’t understand the concept.

Yet they still grasp at a $20-a-month subscription from the common person, hoping that drop in the bucket will somehow monetize multi-billion-dollar investments.

It never will.

Hire the right people—people with real experience.
Encourage creativity instead of “yes, sir” to the CEOs.

Do that, and their names might still be known by their grandkids.

10,000 Galaxies Were Hiding in a Patch of ‘Nothing’

I’m new to “Astro Kirsten”. *Subscribed*

Anyway, this is an old story told in a new video, but the story is worth retelling.

In 1995, a scientist gambled ten days of the world’s most in-demand telescope on a patch of sky that looked completely empty. What came back changed astronomy forever.

This is the story of the Hubble Deep Field — one of the most important images ever taken, and the astronomers who bet everything to get it. We cover the Director’s Discretionary Time gamble, the colleague who tried to talk him out of it, and how that single image led to the Hubble Ultra Deep Field, the Extreme Deep Field, and eventually Webb’s First Deep Field — each one staring longer and deeper into the universe’s past.

I love this guy! I love his mission, and his message.

From AI Copium: NVIDIA reportedly just invested $5 billion into Ilya Sutskever’s secret AI company, Safe Superintelligence (SSI), after receiving rare access to its research.

So… what did they see?

In this video, we break down everything we know about SSI, Ilya’s recent interview with Dwarkesh Patel, the clues he gave about the future of AI, and why this could be one of the biggest AI stories of the year.