{
  "$schema": "https://redlens.liminallayers.com/schemas/redlens.agents/3/site.json",
  "schema_version": "redlens.agents/3",
  "license": {
    "name": "CC BY 4.0",
    "url": "https://creativecommons.org/licenses/by/4.0/",
    "attribution": "The Red Lens, https://redlens.liminallayers.com/",
    "terms": "Use it for anything, commercial or not, with no permission needed; credit The Red Lens with a link. Covers what this site wrote (editions, summaries, labels, incident records, data files); linked articles belong to their publishers."
  },
  "generated_at": "2026-10-09T17:27:29Z",
  "generatedAt": "2026-10-09T17:27:29Z",
  "site": {
    "name": "The Red Lens",
    "url": "https://redlens.liminallayers.com",
    "parent": "Spin Signal",
    "parent_url": "https://spinsignal.liminallayers.com",
    "parentUrl": "https://spinsignal.liminallayers.com"
  },
  "figures": {
    "sources": 52,
    "active_sources": 48,
    "activeSources": 48,
    "parked_sources": 4,
    "parkedSources": 4,
    "documents_on_file": 2452,
    "documentsOnFile": 2452,
    "archive_since": "2026-09-12",
    "archiveSince": "2026-09-12",
    "last_collection_at": "2026-10-09T17:26:07Z",
    "lastCollectionAt": "2026-10-09T17:26:07Z",
    "standing_searches": 25,
    "standingSearches": 25,
    "cadences": {
      "fast": "1h",
      "standard": "6h",
      "slow": "24h"
    }
  },
  "evidence_classes": [
    {
      "id": "reproducible_result",
      "definition": "Artefacts published; anyone can check it."
    },
    {
      "id": "independent_confirmation",
      "definition": "A second party confirmed it, without published artefacts."
    },
    {
      "id": "threat_intel_report",
      "definition": "First-hand telemetry or casework from the party that observed it; not reproducible by a reader. The classifier also gives this class to an article relaying such a report (the class of what is reported); for those, standing_class is secondary_report."
    },
    {
      "id": "vendor_claim",
      "definition": "Asserted by an interested party, nothing offered."
    },
    {
      "id": "analyst_assessment",
      "definition": "A judgement from someone who did not observe it."
    },
    {
      "id": "commentary",
      "definition": "Discussion of the above."
    }
  ],
  "evidenceClasses": [
    {
      "id": "reproducible_result",
      "definition": "Artefacts published; anyone can check it."
    },
    {
      "id": "independent_confirmation",
      "definition": "A second party confirmed it, without published artefacts."
    },
    {
      "id": "threat_intel_report",
      "definition": "First-hand telemetry or casework from the party that observed it; not reproducible by a reader. The classifier also gives this class to an article relaying such a report (the class of what is reported); for those, standing_class is secondary_report."
    },
    {
      "id": "vendor_claim",
      "definition": "Asserted by an interested party, nothing offered."
    },
    {
      "id": "analyst_assessment",
      "definition": "A judgement from someone who did not observe it."
    },
    {
      "id": "commentary",
      "definition": "Discussion of the above."
    }
  ],
  "standing_classes": [
    {
      "id": "secondary_report",
      "definition": "A publisher that did not see it first-hand relaying a report of threat_intel_report or stronger (reports_on has the relayed class). Weaker than the report it relays; stronger than a bare vendor claim."
    }
  ],
  "ai_roles": [
    {
      "id": "instrument",
      "definition": "AI used to attack.",
      "in_brief": true,
      "inBrief": true
    },
    {
      "id": "target",
      "definition": "An AI system attacked.",
      "in_brief": true,
      "inBrief": true
    },
    {
      "id": "defender",
      "definition": "AI used to defend.",
      "in_brief": true,
      "inBrief": true
    },
    {
      "id": "subject",
      "definition": "Capability research or an evaluation.",
      "in_brief": true,
      "inBrief": true
    },
    {
      "id": "incidental",
      "definition": "Mentioned, not involved. Archived, not briefed.",
      "in_brief": false,
      "inBrief": false
    }
  ],
  "aiRoles": [
    {
      "id": "instrument",
      "definition": "AI used to attack.",
      "in_brief": true,
      "inBrief": true
    },
    {
      "id": "target",
      "definition": "An AI system attacked.",
      "in_brief": true,
      "inBrief": true
    },
    {
      "id": "defender",
      "definition": "AI used to defend.",
      "in_brief": true,
      "inBrief": true
    },
    {
      "id": "subject",
      "definition": "Capability research or an evaluation.",
      "in_brief": true,
      "inBrief": true
    },
    {
      "id": "incidental",
      "definition": "Mentioned, not involved. Archived, not briefed.",
      "in_brief": false,
      "inBrief": false
    }
  ],
  "pipeline": [
    {
      "id": "discover",
      "label": "the listing",
      "status": "live"
    },
    {
      "id": "screen",
      "label": "free gates, no request",
      "status": "live"
    },
    {
      "id": "acquire",
      "label": "the only body request",
      "status": "live"
    },
    {
      "id": "decide",
      "label": "one row, one verdict",
      "status": "live"
    },
    {
      "id": "store",
      "label": "ClickHouse",
      "status": "live"
    },
    {
      "id": "classify",
      "label": "local model, fixed schema",
      "status": "planned"
    }
  ],
  "models": {
    "classifier": {
      "profile": "gemma4_12b",
      "model": "gemma4-12b",
      "name": "Gemma 4 12B",
      "version": "gemma4-12b@v5"
    },
    "second_opinion": {
      "profile": "qwen38_27b",
      "model": "qwen3.8-27b-q5-nothink",
      "name": "Qwen3.8 27B"
    },
    "edition_writer": {
      "profile": "qwen38_27b",
      "model": "qwen3.8-27b-q5-nothink",
      "name": "Qwen3.8 27B"
    },
    "edition_checker": {
      "profile": "qwen38_27b",
      "model": "qwen3.8-27b-q5-nothink",
      "name": "Qwen3.8 27B"
    },
    "feature_writer": {
      "profile": "gemma4_26b_moe",
      "model": "gemma4-26b-a4b",
      "name": "Gemma 4 26B-A4B"
    },
    "feature_checker": {
      "profile": "qwen38_27b",
      "model": "qwen3.8-27b-q5-nothink",
      "name": "Qwen3.8 27B"
    }
  },
  "engagement": {
    "user_agent": "RedLensMonitor/0.1 (+https://github.com/spinsignal/redlens; AI and cyber security research; contact via repo issues)",
    "userAgent": "RedLensMonitor/0.1 (+https://github.com/spinsignal/redlens; AI and cyber security research; contact via repo issues)",
    "in_force_since": "2026-09-11",
    "inForceSince": "2026-09-11"
  },
  "sources_by_category": [
    {
      "category": "lab_threat_intel",
      "label": "Lab threat intelligence",
      "active": 7,
      "total": 8,
      "sources": [
        {
          "id": "openai_blog",
          "name": "OpenAI",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://openai.com/blog/"
        },
        {
          "id": "anthropic_news",
          "name": "Anthropic",
          "tier": "standard",
          "adapter": "html",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.anthropic.com/news"
        },
        {
          "id": "openai_misalignment_reports",
          "name": "OpenAI — misalignment reports",
          "tier": "standard",
          "adapter": "html",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://alignment.openai.com/misalignment-reports/"
        },
        {
          "id": "deepmind_blog",
          "name": "Google DeepMind",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://deepmind.google/blog/"
        },
        {
          "id": "google_threat_intel",
          "name": "Google Threat Intelligence (Mandiant)",
          "tier": "fast",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence"
        },
        {
          "id": "google_security_blog",
          "name": "Google Security Blog",
          "tier": "standard",
          "adapter": "rss",
          "enabled": false,
          "jurisdiction": "US",
          "parked_reason": "Big Sleep announcements land here as well as on Project Zero.",
          "parkedReason": "Big Sleep announcements land here as well as on Project Zero.",
          "url": "https://security.googleblog.com/"
        },
        {
          "id": "microsoft_security_blog",
          "name": "Microsoft Security Blog",
          "tier": "fast",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.microsoft.com/en-us/security/blog/"
        },
        {
          "id": "meta_security",
          "name": "Meta — security and integrity",
          "tier": "slow",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://about.fb.com/news/category/technology-and-innovation/"
        }
      ]
    },
    {
      "category": "autonomous_security",
      "label": "Autonomous offence and defence",
      "active": 7,
      "total": 7,
      "sources": [
        {
          "id": "anthropic_frontier_red_team",
          "name": "Anthropic — Frontier Red Team",
          "tier": "standard",
          "adapter": "html",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.anthropic.com/research/team/frontier-red-team"
        },
        {
          "id": "project_zero",
          "name": "Google Project Zero",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://googleprojectzero.blogspot.com/"
        },
        {
          "id": "aixcc",
          "name": "DARPA AI Cyber Challenge",
          "tier": "slow",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://aicyberchallenge.com/news/"
        },
        {
          "id": "xbow_blog",
          "name": "XBOW",
          "tier": "standard",
          "adapter": "html",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://xbow.com/blog"
        },
        {
          "id": "trail_of_bits",
          "name": "Trail of Bits",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://blog.trailofbits.com/"
        },
        {
          "id": "hackerone_blog",
          "name": "HackerOne",
          "tier": "standard",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.hackerone.com/blog"
        },
        {
          "id": "huggingface_blog",
          "name": "Hugging Face",
          "tier": "slow",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "INT",
          "url": "https://huggingface.co/blog"
        }
      ]
    },
    {
      "category": "eval_institute",
      "label": "Evaluations and safety institutes",
      "active": 3,
      "total": 3,
      "sources": [
        {
          "id": "metr",
          "name": "METR",
          "tier": "slow",
          "adapter": "html",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://metr.org/blog/"
        },
        {
          "id": "uk_aisi",
          "name": "UK AI Security Institute",
          "tier": "slow",
          "adapter": "html",
          "enabled": true,
          "jurisdiction": "GB",
          "url": "https://www.aisi.gov.uk/work"
        },
        {
          "id": "apollo_research",
          "name": "Apollo Research",
          "tier": "slow",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "GB",
          "url": "https://www.apolloresearch.ai/research"
        }
      ]
    },
    {
      "category": "gov_advisory",
      "label": "Government and regulators",
      "active": 6,
      "total": 7,
      "sources": [
        {
          "id": "acsc_advisories",
          "name": "ACSC — advisories",
          "tier": "fast",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "AU",
          "url": "https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories"
        },
        {
          "id": "acsc_news",
          "name": "ACSC — news and media",
          "tier": "standard",
          "adapter": "firecrawl",
          "enabled": false,
          "jurisdiction": "AU",
          "parked_reason": "Disabled 2026-09-11 — this path 404s (confirmed through Firecrawl, which reaches the rest of the domain fine), so the URL is wrong rather than blocked. The advisories source covers the same material meanwhile. Find the real news index and re-enable; do not delete, the id has history.",
          "parkedReason": "Disabled 2026-09-11 — this path 404s (confirmed through Firecrawl, which reaches the rest of the domain fine), so the URL is wrong rather than blocked. The advisories source covers the same material meanwhile. Find the real news index and re-enable; do not delete, the id has history.",
          "url": "https://www.cyber.gov.au/about-us/news-and-media"
        },
        {
          "id": "cisa_advisories",
          "name": "CISA — cybersecurity advisories",
          "tier": "fast",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories"
        },
        {
          "id": "ncsc_uk",
          "name": "NCSC UK",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "GB",
          "url": "https://www.ncsc.gov.uk/"
        },
        {
          "id": "nist_news",
          "name": "NIST",
          "tier": "slow",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.nist.gov/news-events/news"
        },
        {
          "id": "enisa",
          "name": "ENISA",
          "tier": "slow",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "EU",
          "url": "https://www.enisa.europa.eu/news"
        },
        {
          "id": "cisa_kev_page",
          "name": "CISA — Known Exploited Vulnerabilities catalog",
          "tier": "fast",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ]
    },
    {
      "category": "vendor_research",
      "label": "Security vendors and research",
      "active": 11,
      "total": 11,
      "sources": [
        {
          "id": "unit42",
          "name": "Palo Alto Unit 42",
          "tier": "fast",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://unit42.paloaltonetworks.com/"
        },
        {
          "id": "talos",
          "name": "Cisco Talos",
          "tier": "fast",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://blog.talosintelligence.com/"
        },
        {
          "id": "crowdstrike",
          "name": "CrowdStrike",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.crowdstrike.com/blog/"
        },
        {
          "id": "welivesecurity",
          "name": "ESET WeLiveSecurity",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "SK",
          "url": "https://www.welivesecurity.com/en/"
        },
        {
          "id": "reversinglabs",
          "name": "ReversingLabs",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.reversinglabs.com/blog/"
        },
        {
          "id": "snyk",
          "name": "Snyk",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "GB",
          "url": "https://snyk.io/blog/"
        },
        {
          "id": "endor_labs",
          "name": "Endor Labs",
          "tier": "slow",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.endorlabs.com/blog/"
        },
        {
          "id": "sentinelone",
          "name": "SentinelOne",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.sentinelone.com/blog/"
        },
        {
          "id": "trendmicro",
          "name": "Trend Micro Research",
          "tier": "standard",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "JP",
          "url": "https://www.trendmicro.com/en_us/research.html"
        },
        {
          "id": "checkpoint",
          "name": "Check Point Research",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "IL",
          "url": "https://research.checkpoint.com/"
        },
        {
          "id": "schneier",
          "name": "Schneier on Security",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.schneier.com/"
        }
      ]
    },
    {
      "category": "research",
      "label": "Research",
      "active": 2,
      "total": 2,
      "sources": [
        {
          "id": "arxiv_cs_cr",
          "name": "arXiv cs.CR",
          "tier": "slow",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "INT",
          "url": "https://arxiv.org/list/cs.CR/recent"
        },
        {
          "id": "arxiv_cs_ai_sec",
          "name": "arXiv cs.AI",
          "tier": "slow",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "INT",
          "url": "https://arxiv.org/list/cs.AI/recent"
        }
      ]
    },
    {
      "category": "trade_press",
      "label": "Trade press",
      "active": 12,
      "total": 14,
      "sources": [
        {
          "id": "the_record",
          "name": "The Record",
          "tier": "fast",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://therecord.media/"
        },
        {
          "id": "bleepingcomputer",
          "name": "BleepingComputer",
          "tier": "fast",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.bleepingcomputer.com/"
        },
        {
          "id": "thehackernews",
          "name": "The Hacker News",
          "tier": "fast",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "INT",
          "url": "https://thehackernews.com/"
        },
        {
          "id": "helpnetsecurity",
          "name": "Help Net Security",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "INT",
          "url": "https://www.helpnetsecurity.com/"
        },
        {
          "id": "krebs",
          "name": "KrebsOnSecurity",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://krebsonsecurity.com/"
        },
        {
          "id": "darkreading",
          "name": "Dark Reading",
          "tier": "fast",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.darkreading.com/"
        },
        {
          "id": "securityweek",
          "name": "SecurityWeek",
          "tier": "fast",
          "adapter": "rss",
          "enabled": false,
          "jurisdiction": "US",
          "parked_reason": "Disabled 2026-09-11 — persistent 403. Every feed path (/feed, /rss, feedburner) refuses an honest User-Agent, and Firecrawl gets the same 403 from the origin, so this is the site refusing non-browser clients rather than a scraper limitation. No bypass attempted. Re-check periodically; the id is kept so history survives if it comes back.",
          "parkedReason": "Disabled 2026-09-11 — persistent 403. Every feed path (/feed, /rss, feedburner) refuses an honest User-Agent, and Firecrawl gets the same 403 from the origin, so this is the site refusing non-browser clients rather than a scraper limitation. No bypass attempted. Re-check periodically; the id is kept so history survives if it comes back.",
          "url": "https://www.securityweek.com/"
        },
        {
          "id": "cyberscoop",
          "name": "CyberScoop",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://cyberscoop.com/"
        },
        {
          "id": "theregister_security",
          "name": "The Register — security",
          "tier": "fast",
          "adapter": "rss",
          "enabled": false,
          "jurisdiction": "GB",
          "parked_reason": "Disabled 2026-09-11 — robots.txt (updated 18 June 2026) is default-deny: it allows named search engines and blocks every other agent, including this one, and directs AI companies to a content-licensing contact instead. That is a clear statement of policy, not a misconfiguration, so it is honoured rather than worked around. Re-enable only under a licence.",
          "parkedReason": "Disabled 2026-09-11 — robots.txt (updated 18 June 2026) is default-deny: it allows named search engines and blocks every other agent, including this one, and directs AI companies to a content-licensing contact instead. That is a clear statement of policy, not a misconfiguration, so it is honoured rather than worked around. Re-enable only under a licence.",
          "url": "https://www.theregister.com/security/"
        },
        {
          "id": "arstechnica_security",
          "name": "Ars Technica — security",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://arstechnica.com/security/"
        },
        {
          "id": "four04media",
          "name": "404 Media",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.404media.co/"
        },
        {
          "id": "riskybiz",
          "name": "Risky Business",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "AU",
          "url": "https://risky.biz/"
        },
        {
          "id": "itnews_security",
          "name": "iTnews — security",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "AU",
          "url": "https://www.itnews.com.au/news/security"
        },
        {
          "id": "cyberdaily_au",
          "name": "Cyber Daily",
          "tier": "standard",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "AU",
          "url": "https://www.cyberdaily.au/security"
        }
      ]
    }
  ],
  "sourcesByCategory": [
    {
      "category": "lab_threat_intel",
      "label": "Lab threat intelligence",
      "active": 7,
      "total": 8,
      "sources": [
        {
          "id": "openai_blog",
          "name": "OpenAI",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://openai.com/blog/"
        },
        {
          "id": "anthropic_news",
          "name": "Anthropic",
          "tier": "standard",
          "adapter": "html",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.anthropic.com/news"
        },
        {
          "id": "openai_misalignment_reports",
          "name": "OpenAI — misalignment reports",
          "tier": "standard",
          "adapter": "html",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://alignment.openai.com/misalignment-reports/"
        },
        {
          "id": "deepmind_blog",
          "name": "Google DeepMind",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://deepmind.google/blog/"
        },
        {
          "id": "google_threat_intel",
          "name": "Google Threat Intelligence (Mandiant)",
          "tier": "fast",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence"
        },
        {
          "id": "google_security_blog",
          "name": "Google Security Blog",
          "tier": "standard",
          "adapter": "rss",
          "enabled": false,
          "jurisdiction": "US",
          "parked_reason": "Big Sleep announcements land here as well as on Project Zero.",
          "parkedReason": "Big Sleep announcements land here as well as on Project Zero.",
          "url": "https://security.googleblog.com/"
        },
        {
          "id": "microsoft_security_blog",
          "name": "Microsoft Security Blog",
          "tier": "fast",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.microsoft.com/en-us/security/blog/"
        },
        {
          "id": "meta_security",
          "name": "Meta — security and integrity",
          "tier": "slow",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://about.fb.com/news/category/technology-and-innovation/"
        }
      ]
    },
    {
      "category": "autonomous_security",
      "label": "Autonomous offence and defence",
      "active": 7,
      "total": 7,
      "sources": [
        {
          "id": "anthropic_frontier_red_team",
          "name": "Anthropic — Frontier Red Team",
          "tier": "standard",
          "adapter": "html",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.anthropic.com/research/team/frontier-red-team"
        },
        {
          "id": "project_zero",
          "name": "Google Project Zero",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://googleprojectzero.blogspot.com/"
        },
        {
          "id": "aixcc",
          "name": "DARPA AI Cyber Challenge",
          "tier": "slow",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://aicyberchallenge.com/news/"
        },
        {
          "id": "xbow_blog",
          "name": "XBOW",
          "tier": "standard",
          "adapter": "html",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://xbow.com/blog"
        },
        {
          "id": "trail_of_bits",
          "name": "Trail of Bits",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://blog.trailofbits.com/"
        },
        {
          "id": "hackerone_blog",
          "name": "HackerOne",
          "tier": "standard",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.hackerone.com/blog"
        },
        {
          "id": "huggingface_blog",
          "name": "Hugging Face",
          "tier": "slow",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "INT",
          "url": "https://huggingface.co/blog"
        }
      ]
    },
    {
      "category": "eval_institute",
      "label": "Evaluations and safety institutes",
      "active": 3,
      "total": 3,
      "sources": [
        {
          "id": "metr",
          "name": "METR",
          "tier": "slow",
          "adapter": "html",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://metr.org/blog/"
        },
        {
          "id": "uk_aisi",
          "name": "UK AI Security Institute",
          "tier": "slow",
          "adapter": "html",
          "enabled": true,
          "jurisdiction": "GB",
          "url": "https://www.aisi.gov.uk/work"
        },
        {
          "id": "apollo_research",
          "name": "Apollo Research",
          "tier": "slow",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "GB",
          "url": "https://www.apolloresearch.ai/research"
        }
      ]
    },
    {
      "category": "gov_advisory",
      "label": "Government and regulators",
      "active": 6,
      "total": 7,
      "sources": [
        {
          "id": "acsc_advisories",
          "name": "ACSC — advisories",
          "tier": "fast",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "AU",
          "url": "https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories"
        },
        {
          "id": "acsc_news",
          "name": "ACSC — news and media",
          "tier": "standard",
          "adapter": "firecrawl",
          "enabled": false,
          "jurisdiction": "AU",
          "parked_reason": "Disabled 2026-09-11 — this path 404s (confirmed through Firecrawl, which reaches the rest of the domain fine), so the URL is wrong rather than blocked. The advisories source covers the same material meanwhile. Find the real news index and re-enable; do not delete, the id has history.",
          "parkedReason": "Disabled 2026-09-11 — this path 404s (confirmed through Firecrawl, which reaches the rest of the domain fine), so the URL is wrong rather than blocked. The advisories source covers the same material meanwhile. Find the real news index and re-enable; do not delete, the id has history.",
          "url": "https://www.cyber.gov.au/about-us/news-and-media"
        },
        {
          "id": "cisa_advisories",
          "name": "CISA — cybersecurity advisories",
          "tier": "fast",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories"
        },
        {
          "id": "ncsc_uk",
          "name": "NCSC UK",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "GB",
          "url": "https://www.ncsc.gov.uk/"
        },
        {
          "id": "nist_news",
          "name": "NIST",
          "tier": "slow",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.nist.gov/news-events/news"
        },
        {
          "id": "enisa",
          "name": "ENISA",
          "tier": "slow",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "EU",
          "url": "https://www.enisa.europa.eu/news"
        },
        {
          "id": "cisa_kev_page",
          "name": "CISA — Known Exploited Vulnerabilities catalog",
          "tier": "fast",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ]
    },
    {
      "category": "vendor_research",
      "label": "Security vendors and research",
      "active": 11,
      "total": 11,
      "sources": [
        {
          "id": "unit42",
          "name": "Palo Alto Unit 42",
          "tier": "fast",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://unit42.paloaltonetworks.com/"
        },
        {
          "id": "talos",
          "name": "Cisco Talos",
          "tier": "fast",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://blog.talosintelligence.com/"
        },
        {
          "id": "crowdstrike",
          "name": "CrowdStrike",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.crowdstrike.com/blog/"
        },
        {
          "id": "welivesecurity",
          "name": "ESET WeLiveSecurity",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "SK",
          "url": "https://www.welivesecurity.com/en/"
        },
        {
          "id": "reversinglabs",
          "name": "ReversingLabs",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.reversinglabs.com/blog/"
        },
        {
          "id": "snyk",
          "name": "Snyk",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "GB",
          "url": "https://snyk.io/blog/"
        },
        {
          "id": "endor_labs",
          "name": "Endor Labs",
          "tier": "slow",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.endorlabs.com/blog/"
        },
        {
          "id": "sentinelone",
          "name": "SentinelOne",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.sentinelone.com/blog/"
        },
        {
          "id": "trendmicro",
          "name": "Trend Micro Research",
          "tier": "standard",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "JP",
          "url": "https://www.trendmicro.com/en_us/research.html"
        },
        {
          "id": "checkpoint",
          "name": "Check Point Research",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "IL",
          "url": "https://research.checkpoint.com/"
        },
        {
          "id": "schneier",
          "name": "Schneier on Security",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.schneier.com/"
        }
      ]
    },
    {
      "category": "research",
      "label": "Research",
      "active": 2,
      "total": 2,
      "sources": [
        {
          "id": "arxiv_cs_cr",
          "name": "arXiv cs.CR",
          "tier": "slow",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "INT",
          "url": "https://arxiv.org/list/cs.CR/recent"
        },
        {
          "id": "arxiv_cs_ai_sec",
          "name": "arXiv cs.AI",
          "tier": "slow",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "INT",
          "url": "https://arxiv.org/list/cs.AI/recent"
        }
      ]
    },
    {
      "category": "trade_press",
      "label": "Trade press",
      "active": 12,
      "total": 14,
      "sources": [
        {
          "id": "the_record",
          "name": "The Record",
          "tier": "fast",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://therecord.media/"
        },
        {
          "id": "bleepingcomputer",
          "name": "BleepingComputer",
          "tier": "fast",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.bleepingcomputer.com/"
        },
        {
          "id": "thehackernews",
          "name": "The Hacker News",
          "tier": "fast",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "INT",
          "url": "https://thehackernews.com/"
        },
        {
          "id": "helpnetsecurity",
          "name": "Help Net Security",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "INT",
          "url": "https://www.helpnetsecurity.com/"
        },
        {
          "id": "krebs",
          "name": "KrebsOnSecurity",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://krebsonsecurity.com/"
        },
        {
          "id": "darkreading",
          "name": "Dark Reading",
          "tier": "fast",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.darkreading.com/"
        },
        {
          "id": "securityweek",
          "name": "SecurityWeek",
          "tier": "fast",
          "adapter": "rss",
          "enabled": false,
          "jurisdiction": "US",
          "parked_reason": "Disabled 2026-09-11 — persistent 403. Every feed path (/feed, /rss, feedburner) refuses an honest User-Agent, and Firecrawl gets the same 403 from the origin, so this is the site refusing non-browser clients rather than a scraper limitation. No bypass attempted. Re-check periodically; the id is kept so history survives if it comes back.",
          "parkedReason": "Disabled 2026-09-11 — persistent 403. Every feed path (/feed, /rss, feedburner) refuses an honest User-Agent, and Firecrawl gets the same 403 from the origin, so this is the site refusing non-browser clients rather than a scraper limitation. No bypass attempted. Re-check periodically; the id is kept so history survives if it comes back.",
          "url": "https://www.securityweek.com/"
        },
        {
          "id": "cyberscoop",
          "name": "CyberScoop",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://cyberscoop.com/"
        },
        {
          "id": "theregister_security",
          "name": "The Register — security",
          "tier": "fast",
          "adapter": "rss",
          "enabled": false,
          "jurisdiction": "GB",
          "parked_reason": "Disabled 2026-09-11 — robots.txt (updated 18 June 2026) is default-deny: it allows named search engines and blocks every other agent, including this one, and directs AI companies to a content-licensing contact instead. That is a clear statement of policy, not a misconfiguration, so it is honoured rather than worked around. Re-enable only under a licence.",
          "parkedReason": "Disabled 2026-09-11 — robots.txt (updated 18 June 2026) is default-deny: it allows named search engines and blocks every other agent, including this one, and directs AI companies to a content-licensing contact instead. That is a clear statement of policy, not a misconfiguration, so it is honoured rather than worked around. Re-enable only under a licence.",
          "url": "https://www.theregister.com/security/"
        },
        {
          "id": "arstechnica_security",
          "name": "Ars Technica — security",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://arstechnica.com/security/"
        },
        {
          "id": "four04media",
          "name": "404 Media",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "US",
          "url": "https://www.404media.co/"
        },
        {
          "id": "riskybiz",
          "name": "Risky Business",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "AU",
          "url": "https://risky.biz/"
        },
        {
          "id": "itnews_security",
          "name": "iTnews — security",
          "tier": "standard",
          "adapter": "rss",
          "enabled": true,
          "jurisdiction": "AU",
          "url": "https://www.itnews.com.au/news/security"
        },
        {
          "id": "cyberdaily_au",
          "name": "Cyber Daily",
          "tier": "standard",
          "adapter": "firecrawl",
          "enabled": true,
          "jurisdiction": "AU",
          "url": "https://www.cyberdaily.au/security"
        }
      ]
    }
  ],
  "standing_searches": [
    "AI orchestrated cyberattack",
    "LLM assisted malware",
    "AI generated malware campaign",
    "autonomous vulnerability discovery",
    "AI agent exploited vulnerability",
    "agentic AI penetration testing",
    "AI discovered zero-day",
    "AIxCC AI Cyber Challenge results",
    "Google Big Sleep vulnerability",
    "XBOW HackerOne autonomous",
    "OpenAI threat report malicious use",
    "Anthropic threat intelligence report",
    "state actor using AI cyber operations",
    "North Korea AI cyber",
    "China AI cyber espionage",
    "AI security operations center deployment",
    "AI automated patching production",
    "machine learning threat detection efficacy",
    "deepfake CEO fraud",
    "voice cloning scam losses",
    "AI phishing campaign",
    "frontier model cyber capability evaluation",
    "AI cyber threat assessment government",
    "ASD artificial intelligence cyber threat",
    "Australia AI cyber security policy"
  ],
  "standingSearches": [
    "AI orchestrated cyberattack",
    "LLM assisted malware",
    "AI generated malware campaign",
    "autonomous vulnerability discovery",
    "AI agent exploited vulnerability",
    "agentic AI penetration testing",
    "AI discovered zero-day",
    "AIxCC AI Cyber Challenge results",
    "Google Big Sleep vulnerability",
    "XBOW HackerOne autonomous",
    "OpenAI threat report malicious use",
    "Anthropic threat intelligence report",
    "state actor using AI cyber operations",
    "North Korea AI cyber",
    "China AI cyber espionage",
    "AI security operations center deployment",
    "AI automated patching production",
    "machine learning threat detection efficacy",
    "deepfake CEO fraud",
    "voice cloning scam losses",
    "AI phishing campaign",
    "frontier model cyber capability evaluation",
    "AI cyber threat assessment government",
    "ASD artificial intelligence cyber threat",
    "Australia AI cyber security policy"
  ],
  "schema": "redlens.site/2"
}
