# Security News Search

POST /cti/news/search: Searches curated cybersecurity news.

Source: https://docs.deepinfo.com/reference/cti/security-news-search/

Last updated: 2026-09-27

---
`POST https://api.deepinfo.com/v1/cti/news/search`

Searches curated cybersecurity news.

## Authentication

Send your API key in the `apikey` request header.

## Query Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `page_size` | Optional | Min `25`, max `100`. Default `100`. | `25` |
| `page` | Optional | Min `1`, max `800`. Default `1`. | `1` |

## Request Body

| Parameter | Type | Required | Description |
|---|---|---|---|
| `filters` | object | Optional | See [Filtering](#ref-filtering) below |
| `sort` | array | Optional | List of `{field, order}` |

```json
{}
```

## Filtering

Example body:

```json
{
  "filters": {
    "must": [
      {
        "name": "title",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "title",
      "order": "desc"
    }
  ]
}
```

See [Getting Started → Search & Filters](/getting-started/search-and-filters/) for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

### Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators: `eq`, `in`, `startswith`, `endswith`, `contains_any`, `contains_all`, `exists`

| Field | Description |
|---|---|
| `title` | The article's headline; the platform's news search box matches words in it. |
| `source` | The publisher of the article, such as `Bleeping Computer`, `The Hacker News` or `Security Affairs`; a few records hold the article's address instead. |
| `tags` | Topic tags of the article, in lower case with hyphens, such as `zero-day`, `active-exploitation` or `cisa`; they are the tag chips on the article cards. |
| `country` | Countries the article names as targets (TARGET COUNTRY), as English country names such as `Germany` rather than codes. |
| `industry` | Industries the article names as targets (TARGET INDUSTRY), as sector names such as `Education` or `Financial and Insurance Activities`. |
| `organization` | Organizations the article names as targets (TARGET ORGANIZATION). |
| `cve_vendor` | Vendor names linked to the CVEs in the article (VENDOR), in lower case with underscores, such as `microsoft` or `fortinet`. |
| `cve_product` | Product names linked to the CVEs in the article (PRODUCT), usually in lower case with underscores, such as `chrome` or `linux_kernel`. |
| `cve_id` | CVE IDs mentioned in the article, such as `CVE-2025-59718` (CVE in the article's side panel). |
| `threat_actor` | Threat actors the article names (THREAT ACTOR), such as `ShinyHunters`. |
| `related_issue_types` | Issue types the article is linked to, as a list of strings; empty on every article in the samples. |

Operators: `eq`, `exists`

| Field | Description |
|---|---|
| `featured` | Boolean flag for featured articles; `false` on every article in the samples. |

Operators: `eq`, `in`, `gte`, `lte`, `exists`

| Field | Description |
|---|---|
| `publish_date` | When the article was published (UTC date-time); the news menu groups articles by it under TODAY and LAST 7 DAYS. |

### Sortable Fields

| Field | Description |
|---|---|
| `title` | The article's headline; the platform's news search box matches words in it. |
| `source` | The publisher of the article, such as `Bleeping Computer`, `The Hacker News` or `Security Affairs`; a few records hold the article's address instead. |
| `publish_date` | When the article was published (UTC date-time); the news menu groups articles by it under TODAY and LAST 7 DAYS. |
| `tags` | Topic tags of the article, in lower case with hyphens, such as `zero-day`, `active-exploitation` or `cisa`; they are the tag chips on the article cards. |
| `country` | Countries the article names as targets (TARGET COUNTRY), as English country names such as `Germany` rather than codes. |
| `industry` | Industries the article names as targets (TARGET INDUSTRY), as sector names such as `Education` or `Financial and Insurance Activities`. |
| `organization` | Organizations the article names as targets (TARGET ORGANIZATION). |
| `cve_vendor` | Vendor names linked to the CVEs in the article (VENDOR), in lower case with underscores, such as `microsoft` or `fortinet`. |
| `cve_product` | Product names linked to the CVEs in the article (PRODUCT), usually in lower case with underscores, such as `chrome` or `linux_kernel`. |
| `cve_id` | CVE IDs mentioned in the article, such as `CVE-2025-59718` (CVE in the article's side panel). |
| `featured` | Boolean flag for featured articles; `false` on every article in the samples. |
| `threat_actor` | Threat actors the article names (THREAT ACTOR), such as `ShinyHunters`. |
| `related_issue_types` | Issue types the article is linked to, as a list of strings; empty on every article in the samples. |

## Response Fields

| Field | Type | Description |
|---|---|---|
| `page` | integer |  |
| `page_size` | integer |  |
| `result_count` | integer |  |
| `results` | array of object |  |
| `results[].id` | string |  |
| `results[].title` | string |  |
| `results[].image` | string |  |
| `results[].source` | string |  |
| `results[].source_url` | string |  |
| `results[].publish_date` | string | date-time |
| `results[].tags` | array of string |  |
| `results[].country` | array of string |  |
| `results[].industry` | array of string |  |
| `results[].organization` | array of string |  |
| `results[].cve_vendor` | array of string |  |
| `results[].cve_product` | array of string |  |
| `results[].cve_id` | array of string |  |
| `results[].featured` | boolean |  |
| `results[].threat_actor` | array of string |  |
| `results[].related_issue_types` | array of string |  |

Paginated. See [Getting Started → Pagination](/getting-started/pagination/).

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `page` | number |
| `page_size` | number |
| `result_count` | number |
| `results` | array<object> |
| `results[].id` | string |
| `results[].title` | string |
| `results[].image` | string |
| `results[].source` | string |
| `results[].source_url` | string |
| `results[].publish_date` | string |
| `results[].tags` | array<string> |
| `results[].country` | array |
| `results[].industry` | array<string> |
| `results[].organization` | array |
| `results[].cve_vendor` | array<string> |
| `results[].cve_product` | array<string> |
| `results[].cve_id` | array<string> |
| `results[].featured` | boolean |
| `results[].threat_actor` | array<string> |
| `results[].related_issue_types` | array |

## Examples

### 200 · OK

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/news/search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 21,
  "results": [
    {
      "id": "000000000000000ecf240001",
      "title": "Phishing campaign targets online retailers",
      "image": "https://platform-storage.example/images/acme.png",
      "source": "Kestrel Security Blog",
      "source_url": "https://www.acme.example/",
      "publish_date": "2025-06-01T08:00:00Z",
      "tags": [
        "production",
        "staging"
      ],
      "country": [],
      "industry": [],
      "organization": [],
      "cve_vendor": [
        "acme"
      ],
      "cve_product": [
        "acme-portal"
      ],
      "cve_id": [
        "CVE-0000-0001",
        "CVE-0000-0002"
      ],
      "featured": true,
      "threat_actor": [],
      "related_issue_types": []
    },
    {
      "id": "000000000000000ecf240002",
      "title": "Ransomware group claims attack on logistics firm",
      "image": "https://platform-storage.example/images/acme-2.png",
      "source": "Fernhill Threat Report",
      "source_url": "https://app.fernhill.example/",
      "publish_date": "2025-05-25T08:00:00Z",
      "tags": [
        "production-2",
        "staging-2"
      ],
      "country": [],
      "industry": [
        "Manufacturing"
      ],
      "organization": [],
      "cve_vendor": [],
      "cve_product": [],
      "cve_id": [],
      "featured": true,
      "threat_actor": [
        "Phishing crew"
      ],
      "related_issue_types": []
    }
  ]
}
```

### 400 · Invalid Parameter (invalid page=0)

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/news/search?page=0' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 10400,
  "parameters": [
    {
      "param": "page",
      "details": [
        "Ensure this value is greater than or equal to 1."
      ]
    }
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```

### Request Template

The request only: a request template has no response.

```bash
curl -X POST 'https://api.deepinfo.com/v1/cti/news/search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "title",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "source",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "tags",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "country",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "industry",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "organization",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve_vendor",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve_product",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "cve_id",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "threat_actor",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "related_issue_types",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "featured",
        "type": "eq",
        "value": true
      },
      {
        "name": "publish_date",
        "type": "eq",
        "value": "<date-time>"
      }
    ]
  },
  "sort": [
    {
      "field": "title",
      "order": "desc"
    }
  ]
}'
```
