news.mlab.sh

news.mlab.sh is a service of the mlab.sh platform. The mlab.sh Terms of Use and Privacy Policy apply to this site. This page adds what is specific to it.

An aggregator of public information

news.mlab.sh collects cyber security news that is already public, from news outlets, vendor blogs and government advisories, and redistributes it in a searchable form. We do not own the articles we list. Each article belongs to its author and publisher; names, logos and trademarks belong to their owners. Listing an article does not mean that its publisher endorses or is affiliated with mlab.sh.

What we publish about an article

  • its title, its publication date, the name of its source and a link to the original;
  • a short summary written in our own words, and structured data we extract from it (CVEs, vendors, products, threat actors, countries, category, severity);
  • until that summary is ready, the short excerpt the source publishes in its own RSS feed.

The full text of an article is read only to write the summary. It is not republished. Every article page links to the original, which remains the reference: read it for the full story.

Automatically generated summaries

Summaries and the daily and weekly digests are written by a language model, then checked automatically against the source articles. Checks reduce errors but cannot rule them out: a summary can still be incomplete or wrong. Where a summary and its source disagree, the source is right. Nothing on this site is legal, security or investment advice, and it is provided as is, without any warranty, for information and defensive purposes.

Corrections

Every article and digest has a Report an error form. Reports are reviewed by a person, and corrections are listed publicly on the corrections page. You can also write to [email protected].

Third-party data

  • CISA Known Exploited Vulnerabilities, the EU vulnerability database and NVD (CVSS scores), via vuln.mlab.sh;
  • EPSS exploit prediction scores, published by FIRST;
  • threat actor names and aliases from actors.mlab.sh;
  • ransomware leak-site claims from ransomware.live;
  • French breach alerts from FrenchBreaches, linked, never copied.

Ransomware claims

Ransomware sections list what criminal groups claim on their leak sites. These are allegations, not established facts: a claim can be false, exaggerated or about an old incident. We never link to leak sites or to stolen data. A named organisation can ask for the mention to be removed at [email protected].

What we keep, and for how long

We do not keep everything. Data is deleted automatically:

  • articles: after 365 days;
  • articles we filter out as not being security news: after 30 days;
  • daily and weekly digests: after 365 days;
  • sign-in sessions: after 7 days, even when still in use;
  • error reports: one year after they are handled.

Publishers and removal requests

A publisher can ask us to remove an article, to correct how it is summarised, or to stop listing its site altogether. A person named in an article can ask for the mention to be corrected or removed, and exercise the rights described in the mlab.sh Privacy Policy. Write to [email protected] with the link to the page concerned.

Reusing our content

news.mlab.sh formally prohibits the redistribution of its data. Our summaries, digests, classifications and structured data may not be republished, mirrored, scraped into, or fed to another news platform, aggregator or search product, in whole or in part, whether they are taken from the site, the RSS feeds, the API or the MCP server.

What is allowed:

  • citing news.mlab.sh, with a link back to it;
  • sharing or sending a link to an article, a digest or a page;
  • quoting a short extract, with attribution and a link;
  • personal and internal use of the feeds, the API and the MCP server, such as reading, alerting or research.

The articles we list belong to their publishers: to reuse one, go to the original. For any other use, ask first at [email protected].

Right of reply

Any person or organisation named or referred to on news.mlab.sh can exercise a right of reply by writing to [email protected] with the link to the page concerned and the text of the reply.

Accounts

Sign-in uses your mlab.sh account; account data is handled under the mlab.sh Privacy Policy.