POSThttps://api.deepinfo.com/v1/cti/news/search

Searches curated cybersecurity news.

Authentication

Send your API key in the apikey request header.

Query Parameters

ParameterRequiredDescription
page_sizeOptional
Min 25, max 100. Default 100.
Example25
pageOptional
Min 1, max 800. Default 1.
Example1

Request Body

ParameterTypeRequiredDescription
filtersobjectOptional
See Filtering below
sortarrayOptional
List of {field, order}
application/json
{}

Filtering

Example body:

JSON
{
  "filters": {
    "must": [
      {
        "name": "title",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "title",
      "order": "desc"
    }
  ]
}

See Getting Started → Search & Filters for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators eq in startswith endswith contains_any contains_all exists

FieldDescription
titleThe article's headline; the platform's news search box matches words in it.
sourceThe publisher of the article, such as Bleeping Computer, The Hacker News or Security Affairs; a few records hold the article's address instead.
tagsTopic tags of the article, in lower case with hyphens, such as zero-day, active-exploitation or cisa; they are the tag chips on the article cards.
countryCountries the article names as targets (TARGET COUNTRY), as English country names such as Germany rather than codes.
industryIndustries the article names as targets (TARGET INDUSTRY), as sector names such as Education or Financial and Insurance Activities.
organizationOrganizations the article names as targets (TARGET ORGANIZATION).
cve_vendorVendor names linked to the CVEs in the article (VENDOR), in lower case with underscores, such as microsoft or fortinet.
cve_productProduct names linked to the CVEs in the article (PRODUCT), usually in lower case with underscores, such as chrome or linux_kernel.
cve_idCVE IDs mentioned in the article, such as CVE-2025-59718 (CVE in the article's side panel).
threat_actorThreat actors the article names (THREAT ACTOR), such as ShinyHunters.
related_issue_typesIssue types the article is linked to, as a list of strings; empty on every article in the samples.

Operators eq exists

FieldDescription
featuredBoolean flag for featured articles; false on every article in the samples.

Operators eq in gte lte exists

FieldDescription
publish_dateWhen the article was published (UTC date-time); the news menu groups articles by it under TODAY and LAST 7 DAYS.

Sortable Fields

FieldDescription
titleThe article's headline; the platform's news search box matches words in it.
sourceThe publisher of the article, such as Bleeping Computer, The Hacker News or Security Affairs; a few records hold the article's address instead.
publish_dateWhen the article was published (UTC date-time); the news menu groups articles by it under TODAY and LAST 7 DAYS.
tagsTopic tags of the article, in lower case with hyphens, such as zero-day, active-exploitation or cisa; they are the tag chips on the article cards.
countryCountries the article names as targets (TARGET COUNTRY), as English country names such as Germany rather than codes.
industryIndustries the article names as targets (TARGET INDUSTRY), as sector names such as Education or Financial and Insurance Activities.
organizationOrganizations the article names as targets (TARGET ORGANIZATION).
cve_vendorVendor names linked to the CVEs in the article (VENDOR), in lower case with underscores, such as microsoft or fortinet.
cve_productProduct names linked to the CVEs in the article (PRODUCT), usually in lower case with underscores, such as chrome or linux_kernel.
cve_idCVE IDs mentioned in the article, such as CVE-2025-59718 (CVE in the article's side panel).
featuredBoolean flag for featured articles; false on every article in the samples.
threat_actorThreat actors the article names (THREAT ACTOR), such as ShinyHunters.
related_issue_typesIssue types the article is linked to, as a list of strings; empty on every article in the samples.

Response Fields

FieldTypeDescription
pageinteger
page_sizeinteger
result_countinteger
resultsarray of object
results[].idstring
results[].titlestring
results[].imagestring
results[].sourcestring
results[].source_urlstring
results[].publish_datestring
date-time
results[].tagsarray of string
results[].countryarray of string
results[].industryarray of string
results[].organizationarray of string
results[].cve_vendorarray of string
results[].cve_productarray of string
results[].cve_idarray of string
results[].featuredboolean
results[].threat_actorarray of string
results[].related_issue_typesarray of string

Paginated. See Getting Started → Pagination.

Response Schema

Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

FieldTypeExample
pagenumber1
page_sizenumber25
result_countnumber21
resultsarray<object>
results[].idstring"000000000000000ecf240001"
results[].titlestring"Phishing campaign targets online re…"
results[].imagestring"https://platform-storage.example/im…"
results[].sourcestring"Kestrel Security Blog"
results[].source_urlstring"https://www.acme.example/"
results[].publish_datestring"2025-06-01T08:00:00Z"
results[].tagsarray<string>"production"
results[].countryarray
results[].industryarray<string>"Manufacturing"
results[].organizationarray
results[].cve_vendorarray<string>"acme"
results[].cve_productarray<string>"acme-portal"
results[].cve_idarray<string>"CVE-0000-0001"
results[].featuredbooleantrue
results[].threat_actorarray<string>"Phishing crew"
results[].related_issue_typesarray

Examples

Selecting one loads it into the request and response panels.

Reference updated