← Back to all sparks
F

Feedly

ANALYTICS
Velocity5.0

Feedly has become a threat-intel platform where AI agents, not feeds, do the reading.

threat-intelligenceai-agentscve-triagesoc-integrationscitation-verifiability
Current state
Feedly now ships on a two-week cadence almost entirely against its Threat Intelligence product. The surface is a family of AI agents — Custom Intel Agents, Cyberattack Agent, Vulnerability Agent, plus tuned models for insider threats and threat-actor campaigns — wrapped in Insight Cards that carry CVE, IoC and detection-rule context. Report Builder and newsletters are the output layer; the RSS reader heritage barely appears in the changelog anymore.
Where it's heading
Two threads run through every release. First, agents are being fleshed out into complete workflow objects: they gained Ask AI Analyze and Research actions, then table controls, then alerting. Second, Feedly is closing the trust gap that AI-generated intel opens — MITRE ATT&CK tagging accuracy, exploit confidence and evidence on CVE cards, and Report Builder citations that resolve to the source passage. The integrations (Censys, GreyNoise, VirusTotal, Analyst1, SPL alongside KQL) point at fitting into SOC tooling rather than replacing it.
Prediction
Expect the alerting added to Custom Intel Agents to spread to the other agents, and continued query-language and enrichment coverage aimed at existing SIEM workflows. Whether the Ask AI Research Playground becomes a real self-serve entry point or stays an evaluation demo is not readable from these entries.

Recent moves

  1. 28d ago

    Stay on top of every Custom Intel Agent update

    Custom Intel Agents get alerting, adding a push channel to what was already continuous monitoring delivered through feeds and newsletters. It rounds out the agent as a workflow object rather than changing what it can watch.

  2. 1mo ago

    Custom Intel Agents gain Ask AI actions; Censys lookups on IP cards

    Custom Intel Agents can now invoke Ask AI Analyze and Research actions directly, and IP Insight Cards gain a Censys lookup. Both fit the pattern of pushing analysis into the agent surface instead of making analysts jump between tools.

  3. 1mo ago

    Hunt threat actor campaigns and run SPL queries alongside KQL

    SPL joins KQL as a supported hunting query language and a model tuned for threat-actor campaign detection lands alongside it. This is Feedly meeting SOC teams in whatever query dialect they already use rather than asking them to switch.

  4. 2mo ago

    Faster exploit triage, smarter Org Profiles, and more transparency across your Report Builder

    Exploit type, confidence and evidence move onto the CVE card itself, Org Profiles become @-mentionable across every surface, and Report Builder citations resolve to the source passage. The citation work is the notable part — it makes AI-written intel auditable by an analyst who has to defend it.

  5. 2mo ago

    Suricata detection rules, Ask AI Research Playground, and more

    Suricata detection rules can be pulled straight from Insight Cards, removing a manual hunt through article text, and an Ask AI Research Playground opens the product to evaluation without a sales call. The playground is a distribution experiment on an otherwise sales-led product.

  6. 3mo ago

    Track exploit types, Oracle and Atlassian advisories, and more

    A coverage release: sharper exploit signal plus Oracle and Atlassian advisories, with improvements to credential monitoring and Ask AI. The body is a teaser, so the direction is clear — widening vulnerability sources — even if the scope is not.