CISA Cybersecurity Advisories

active Ingestion health: delivering Executive · Tier 2 · RSS feed · Department of Homeland Security (CISA)

What this source is

The Cybersecurity and Infrastructure Security Agency publishes cybersecurity advisories, alerts, and the Known Exploited Vulnerabilities (KEV) catalog — federal directives and warnings that constitute an action category the pipeline does not cover at all.

Model-written orientation

The Cybersecurity and Infrastructure Security Agency publishes cybersecurity advisories, alerts, and known exploited vulnerabilities that inform federal and public security practices.

The Cybersecurity and Infrastructure Security Agency (CISA), part of the Department of Homeland Security, is the federal government's civilian cybersecurity authority. CISA publishes official advisories and alerts on cybersecurity threats and vulnerabilities, serving as actionable guidance for federal agencies, critical infrastructure operators, and the broader public.

CISA advisories address specific cybersecurity vulnerabilities and threats: detailed technical information on security flaws in software and systems, recommendations for remediation, and guidance on defensive practices. Advisories may accompany warnings about active exploitation of particular vulnerabilities or newly discovered threats.

The Known Exploited Vulnerabilities (KEV) catalog is CISA's authoritative list of security flaws that have been observed in active use by malicious actors. This catalog serves as a reference for organizations prioritizing remediation efforts—CISA has issued guidance that federal agencies address vulnerabilities on this list by specified deadlines.

These publications represent a category of federal action not covered by other sources in the digest: direct security guidance and threat notification. Unlike analysis or commentary, CISA advisories are technical directives intended to inform security decisions across the government and critical infrastructure.

For readers concerned with cybersecurity policy, federal security posture, and threat awareness, CISA advisories represent the government's official guidance on current and emerging security challenges.

Model-written orientation, generated 2026-08-05 by haiku, prompt version 1. It may draw on general knowledge of public institutions and is not official-record content.

Identity and registry record

Registry id
cisa-advisories
Agency / parent organization
Department of Homeland Security (CISA)
Branch
executive
Type
RSS feed
Status
active
Tier
2
URL (feed)
https://www.cisa.gov/cybersecurity-advisories/all.xml (opens in a new tab)
URL (home)
https://www.cisa.gov/news-events/cybersecurity-advisories (opens in a new tab)
URL (index)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog (opens in a new tab)
Registered
2026-07-28
Registry notes
Research flagged the 2025-05 RSS retirement announcement, but the probe (2026-07-28) found all.xml alive and rich: HTTP 200, 2.0 MB feed, 30 recent advisories whose descriptions embed the full advisory text (~55,000 chars each); sample advisory page also extracts (9,317 chars). Content evaluation: descriptions carry the substance — article fetches add layout, not content — but pages fetch cleanly, so full mode is kept for capture/provenance value. First ingest brings ~30 substantial items. Activated 2026-07-28.

How we ingest it

Channel
RSS feed
Method
Polls the advisories RSS feed via AgencyClient; KEV JSON is a later extension.
Poll cadence
about every 60 minutes while the collector runs
Request budget
the agency class: at most 3,000 requests per day shared across every agency web source, counted from the fetch log (failed requests count too)
Politeness
robots.txt is honored as observed — including each host's crawl-delay, exactly — and every request identifies itself as fapd/0.1 (Free Agentic Publication Digester; +https://fapd.info/bot.html; contact: hustleyourcity@gmail.com); a refusal is recorded, never evaded
Capture and hash
captured raw content is hashed (SHA-256) into the day's committed provenance manifest, hash-chained day to day (PROVENANCE.md)

Ingestion health

Ingestion health: delivering 31 item(s) in the last 14 days; most recent 2026-09-27; 0 of 382 request(s) to www.cisa.gov returned no content.

This label has held since 2026-08-03T18:46:01Z (UTC) and was last re-checked 2026-09-29T10:51:00Z (UTC).

Counts are of our own requests, retries included. A 4xx or 5xx is the server declining to return content — that may be load, maintenance, on-demand generation, or a limit the publisher sets, and we cannot tell which from outside. Nothing here is a measurement of the publisher.

Ingestion statistics

These figures describe this project's ingestion of this source — items we recorded and requests we made — and nothing else. They are not a measurement of the publisher.

Last 24 hours

Last 24 hours: 26 request(s) (26 answered, 0 returned no content) · no items ingested

Last 14 days

Items ingested: 31 in 14 days (2.21 per day) · most recent 2026-09-27

Content length: 9,457 characters average, 8,143 median (shortest 4,392, longest 30,127)

Delivery mode: full — full article text, fetched from the item's own page

Our requests to www.cisa.gov: 382 request(s) · 382 answered · 0 declined (4xx) · 0 server declined (5xx) · 0 no response — 0.0% returned no content

last answered request 2026-09-29T10:30:46.241+00:00 UTC.

31 item(s) in the last 14 days; most recent 2026-09-27; 0 of 382 request(s) to www.cisa.gov returned no content.

All time

Our requests to www.cisa.gov, all time (since 2026-07-30): 1,905 request(s) · 1,901 answered · 4 returned no content

Request counts begin 2026-07-30, the day this service went into production; earlier development-machine traffic is excluded. Counts before 2026-08-03 include unmarked source-probe traffic; probes are labeled and excluded thereafter.

Last 30 days, day by day

Each day runs midnight to midnight on Eastern time (Washington, D.C.), the publication day the digests use; the stored request stamps remain UTC.

Requests per day to www.cisa.gov: 856 requests over the last 30 days (peak 38 on 2026-09-03).
Requests per day to www.cisa.gov: 856 requests over the last 30 days (peak 38 on 2026-09-03).
Dayrequests
2026-08-3127
2026-09-0132
2026-09-0227
2026-09-0338
2026-09-0427
2026-09-0534
2026-09-0627
2026-09-0726
2026-09-0829
2026-09-0927
2026-09-1032
2026-09-1127
2026-09-1229
2026-09-1326
2026-09-1430
2026-09-1536
2026-09-1629
2026-09-1733
2026-09-1828
2026-09-1926
2026-09-2026
2026-09-2130
2026-09-2235
2026-09-2326
2026-09-2429
2026-09-2529
2026-09-2627
2026-09-2729
2026-09-2826
2026-09-299
Items ingested per day: 72 items over the last 30 days (peak 10 on 2026-09-03).
Items ingested per day: 72 items over the last 30 days (peak 10 on 2026-09-03).
Dayitems
2026-08-311
2026-09-016
2026-09-022
2026-09-0310
2026-09-041
2026-09-050
2026-09-060
2026-09-070
2026-09-083
2026-09-091
2026-09-105
2026-09-112
2026-09-120
2026-09-130
2026-09-141
2026-09-159
2026-09-163
2026-09-177
2026-09-182
2026-09-190
2026-09-200
2026-09-211
2026-09-2210
2026-09-231
2026-09-243
2026-09-252
2026-09-260
2026-09-272
2026-09-280
2026-09-290
Daily mean response time of www.cisa.gov: between 105 and 654 ms across the last 30 days (days without a timed request are gaps, not zeroes).
Daily mean response time of www.cisa.gov: between 105 and 654 ms across the last 30 days (days without a timed request are gaps, not zeroes).
Dayms
2026-08-31142
2026-09-01119
2026-09-02193
2026-09-03654
2026-09-04195
2026-09-05287
2026-09-06172
2026-09-07140
2026-09-08149
2026-09-09141
2026-09-10113
2026-09-11134
2026-09-12235
2026-09-13179
2026-09-14345
2026-09-15109
2026-09-16134
2026-09-17106
2026-09-18200
2026-09-19165
2026-09-20155
2026-09-21220
2026-09-22105
2026-09-23129
2026-09-24190
2026-09-25164
2026-09-26233
2026-09-27170
2026-09-28216
2026-09-29119

Our ingestion assessment

Model-written ingestion assessment

The CISA cybersecurity-advisories RSS feed delivered 40 items over 14 days at 2.86 per day, down from 3.5 per day in the prior assessment. The most recent item arrived 2026-09-04. Extracted article descriptions average 10,711 characters, with individual advisories ranging up to 56,634 characters. Request success was 383 of 387 answered (1.0% no-response), with four requests returning no content. The prior assessment reported zero failures over 272 attempts; this window shows four failures scattered across the measurement period. The feed remains a reliable source of cybersecurity advisories; article page fetches add layout and formatting context but do not introduce new content beyond the feed's embedded full-text descriptions.

Model-written assessment of our own ingestion, generated 2026-09-05 by haiku, prompt version 1, trigger: age-30d. It restates our measured figures and is not official-record content.