Security News Search
https://api.deepinfo.com/v1/cti/news/searchSearches curated cybersecurity news.
Authentication
Send your API key in the apikey request header.
Query Parameters
| Parameter | Required | Description |
|---|---|---|
page_ | Optional | Min 25, max 100. Default 100.Example 25 |
page | Optional | Min 1, max 800. Default 1.Example 1 |
Request Body
| Parameter | Type | Required | Description |
|---|---|---|---|
filters | object | Optional | See Filtering below |
sort | array | Optional | List of {field, order} |
{}
Filtering
Example body:
{
"filters": {
"must": [
{
"name": "title",
"type": "eq",
"value": "<value>"
}
]
},
"sort": [
{
"field": "title",
"order": "desc"
}
]
}
See Getting Started → Search & Filters for the operators.
The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.
Searchable Fields
Grouped by the operators they accept (measured against the API; sending another operator returns 400).
Operators eq in startswith endswith contains_ contains_ exists
| Field | Description |
|---|---|
title | The article's headline; the platform's news search box matches words in it. |
source | The publisher of the article, such as Bleeping Computer, The Hacker News or Security Affairs; a few records hold the article's address instead. |
tags | Topic tags of the article, in lower case with hyphens, such as zero-day, active-exploitation or cisa; they are the tag chips on the article cards. |
country | Countries the article names as targets (TARGET COUNTRY), as English country names such as Germany rather than codes. |
industry | Industries the article names as targets (TARGET INDUSTRY), as sector names such as Education or Financial and Insurance Activities. |
organization | Organizations the article names as targets (TARGET ORGANIZATION). |
cve_ | Vendor names linked to the CVEs in the article (VENDOR), in lower case with underscores, such as microsoft or fortinet. |
cve_ | Product names linked to the CVEs in the article (PRODUCT), usually in lower case with underscores, such as chrome or linux_kernel. |
cve_ | CVE IDs mentioned in the article, such as CVE-2025-59718 (CVE in the article's side panel). |
threat_ | Threat actors the article names (THREAT ACTOR), such as ShinyHunters. |
related_ | Issue types the article is linked to, as a list of strings; empty on every article in the samples. |
Operators eq exists
| Field | Description |
|---|---|
featured | Boolean flag for featured articles; false on every article in the samples. |
Operators eq in gte lte exists
| Field | Description |
|---|---|
publish_ | When the article was published (UTC date-time); the news menu groups articles by it under TODAY and LAST 7 DAYS. |
Sortable Fields
| Field | Description |
|---|---|
title | The article's headline; the platform's news search box matches words in it. |
source | The publisher of the article, such as Bleeping Computer, The Hacker News or Security Affairs; a few records hold the article's address instead. |
publish_ | When the article was published (UTC date-time); the news menu groups articles by it under TODAY and LAST 7 DAYS. |
tags | Topic tags of the article, in lower case with hyphens, such as zero-day, active-exploitation or cisa; they are the tag chips on the article cards. |
country | Countries the article names as targets (TARGET COUNTRY), as English country names such as Germany rather than codes. |
industry | Industries the article names as targets (TARGET INDUSTRY), as sector names such as Education or Financial and Insurance Activities. |
organization | Organizations the article names as targets (TARGET ORGANIZATION). |
cve_ | Vendor names linked to the CVEs in the article (VENDOR), in lower case with underscores, such as microsoft or fortinet. |
cve_ | Product names linked to the CVEs in the article (PRODUCT), usually in lower case with underscores, such as chrome or linux_kernel. |
cve_ | CVE IDs mentioned in the article, such as CVE-2025-59718 (CVE in the article's side panel). |
featured | Boolean flag for featured articles; false on every article in the samples. |
threat_ | Threat actors the article names (THREAT ACTOR), such as ShinyHunters. |
related_ | Issue types the article is linked to, as a list of strings; empty on every article in the samples. |
Response Fields
| Field | Type | Description |
|---|---|---|
page | integer | |
page_ | integer | |
result_ | integer | |
results | array of object | |
results[]. | string | |
results[]. | string | |
results[]. | string | |
results[]. | string | |
results[]. | string | |
results[]. | string | date-time |
results[]. | array of string | |
results[]. | array of string | |
results[]. | array of string | |
results[]. | array of string | |
results[]. | array of string | |
results[]. | array of string | |
results[]. | array of string | |
results[]. | boolean | |
results[]. | array of string | |
results[]. | array of string |
Paginated. See Getting Started → Pagination.
Response Schema
Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.
| Field | Type | Example |
|---|---|---|
page | number | 1 |
page_size | number | 25 |
result_count | number | 21 |
results | array< | |
results[]. | string | "000000000000000ecf240001" |
results[]. | string | "Phishing campaign targets online re…" |
results[]. | string | "https://platform-storage.example/im…" |
results[]. | string | "Kestrel Security Blog" |
results[]. | string | "https://www.acme.example/" |
results[]. | string | "2025-06-01T08:00:00Z" |
results[]. | array< | "production" |
results[]. | array | |
results[]. | array< | "Manufacturing" |
results[]. | array | |
results[]. | array< | "acme" |
results[]. | array< | "acme-portal" |
results[]. | array< | "CVE-0000-0001" |
results[]. | boolean | true |
results[]. | array< | "Phishing crew" |
results[]. | array |
Examples
Selecting one loads it into the request and response panels.