- 03 Mar 2026
- 4 Minutes to read
-
Print
-
DarkLight
-
PDF
Prepare for CAL ATL Changes in CAL 3.15 Release
- Updated on 03 Mar 2026
- 4 Minutes to read
-
Print
-
DarkLight
-
PDF
Overview
The CAL™ 3.15 release, scheduled for early April 2026, will deliver a major upgrade for ThreatConnect® and Polarity customers leveraging CAL Automated Threat Library (ATL). In addition to bringing in data from new blogs and report sources and improving the frequency and reliability of data retrieval, this release includes changes that streamline and update blog metadata and remove blogs that no longer exist or provide relevant data:
- Tag names for some CAL ATL blogs were changed to ensure consistency and correctness.
- Some CAL ATL blogs were consolidated under a single Tag.
- Retired blogs that were re-activated were added back to CAL ATL.
- Blogs that stopped publishing relevant data were retired.
- URLs for CAL ATL blogs were updated as needed.
CAL ATL Updates for CAL 3.15
The CAL Automated Threat Library Source includes the following features under the CAL 3.15 release:
- 125 of the best blog and report sources—including CERTs, government agencies, security research organizations, industry vendors, and security news—to help power CTI workflows, orchestration, and decision making. These sources include the following:
- 46 new blog and report sources
- Reactivated blog and report sources:
- 360 Netlab Blog
- Check Point Research
- CrowdStrike (formerly CrowdStrike Blog)
- Dark Reading (formerly Darkreading)
- Flashpoint
- Internet Crime Complaint Center Industry Alerts (IC3)
- labs.vipre.com (formerly VIPRE Labs Blog)
- Red Packet Security (formerly Red Packet Security Pikabot C2, Red Packet Security Ransomware Feed, and Red Packet Security Posh C2)
- Security Week
- Splunk (formerly Splunk Threat Research Team)
- The DFIR Report
- The Digest (Crypto-Ransomware) (formerly ID Ransomware)
- Hourly updates for ALL blog and report sources
- Improved reliability of retrieved information
- Reduced false positives from links identified as indicators of compromise (IoCs) in blogs and reports
What Do I Need to Do?
The CAL 3.15 release is scheduled for early April 2026. You do not need to make any changes, as automatic Tag normalization rules will make all necessary adjustments to account for changed Tags. If you think you may not want automated Tag normalization to occur on your ThreatConnect instance, please reach out to your Customer Support Manager to be excluded.
Table 1 lists the updated blogs, including changes to their corresponding Tag and a description of the change.
| Blog Name | Source URL | Old ThreatConnect Tag | Current ThreatConnect Tag | What Changed? |
|---|---|---|---|---|
| 360 Netlab Blog | https://blog.netlab.360.com/ | N/A | Blog: 360 Netlab Blog | Blog reactivated in CAL ATL |
| Bitdefender | https://www.bitdefender.com/en-us | Blog: Bitdefender Labs | Blog: Bitdefender | Tag change |
| Bleeping Computer | https://www.bleepingcomputer.com | Blog: BleepingComputer | Blog: Bleeping Computer | Tag change |
| Canadian Centre for Cyber Security | https://www.cyber.gc.ca | Blog: Government of Canada Alerts and Advisories | Blog: Canadian Centre for Cyber Security | Tag change |
| Center for Internet Security | https://www.cisecurity.org |
| Blog: Center for Internet Security | Multiple Tags consolidated into a single Tag |
| CERT-UA | http://cert.gov.ua | Blog: CERT-UA News | Blog: CERT-UA | Tag change |
| Check Point Research | https://research.checkpoint.com | N/A | Blog: Check Point Research | Blog reactivated in CAL ATL |
| CISA | http://cisa.gov | Blog: CISA Cybersecurity Alerts & Advisories | Blog: CISA | Tag change |
| CrowdStrike | https://www.crowdstrike.com | N/A | Blog: CrowdStrike | Blog reactivated in CAL ATL |
| Cyber Security News | https://cybersecuritynews.com | Blog: Cybersecurity News | Blog: Cyber Security News | Tag change |
| Cyberscoop - Attacks | https://www.cshub.com/rss/categories/attacks | Blog: CyberScoop Attacks | N/A | Blog retired from CAL ATL - stopped publishing data in April 2025 |
| Cyberscoop - Security Strategy | https://www.cshub.com/rss/categories/security-strategy | Blog: Cyber Security Hub | N/A | Blog retired from CAL ATL - stopped publishing data in August 2025 |
| Cyberscoop - Threat Defense | https://www.cshub.com/rss/categories/threat-defense | Blog: CyberScoop | N/A | Blog retired from CAL ATL - stopped publishing data in June 2025 |
| Dark Reading | http://www.darkreading.com | N/A | Blog: Dark Reading | Blog reactivated in CAL ATL |
| DataBreaches | http://databreaches.net | Blog: Data Breach Today | Blog: DataBreaches | Tag change |
| Endpoint Threat Protection | https://www.sentinelone.com | Blog: SentinelOne | Blog: Endpoint Threat Protection | Tag change |
| Flashpoint | https://www.flashpoint-intel.com | Blog: flashpoint | Blog: Flashpoint | Blog reactivated in CAL ATL; Tag change |
| Fox-IT | https://blog.fox-it.com | Blog: Fox IT | Blog: Fox-IT | Tag change |
| Google Online Security Blog | https://security.googleblog.com | Blog: Google Security Blog | Blog: Google Online Security Blog | Tag change |
| Government Centre for Monitoring, Alerting and Responding to Computer Attacks | https://www.cert.ssi.gouv.fr/cti/feed/ |
| Blog: Centre gouvernemental de veille | Multiple Tags consolidated to a single Tag |
| Greynoise Labs | https://www.greynoise.io | Blog: GreyNoise | Blog: Greynoise Labs | Tag change |
| Hack Read | https://www.hackread.com | Blog: HackRead | Blog: Hack Read | Tag change |
| Heimdal Security Blog | https://heimdalsecurity.com/blog/ | Blog: Heimdal Security | Blog: Heimdal Security Blog | Tag change |
| Hipaajournal | https://www.hipaajournal.com | Blog: Hipaa Journal | Blog: Hipaajournal | Tag change |
| Internet Crime Complaint Center Industry Alerts (IC3) | https://www.ic3.gov | N/A | Blog: Federal Bureau of Investigation | Blog reactivated in CAL ATL |
| JPCERT コーディネーションセンター | https://blogs.jpcert.or.jp/en |
| Blog: JPCERT コーディネーションセンター | Multiple Tags consolidated into a single Tag |
| labs.vipre.com | https://vipre.com/ | BLOG: VIPRE Labs Blog | Blog: labs.vipre.com | Blog reactivated in CAL ATL; Tag change |
| Mandiant | https://www.mandiant.com/resources/blog/rss.xml | Blog: Mandiant | Blog: Think With Google | Mandiant no longer publishes threat intelligence information, but redirects to Google Cloud Threat Intelligence Blog, which is now added to CAL ATL |
| Microsoft Enterprise | https://www.microsoft.com/en-us | Blog: Microsoft Secure | Blog: Microsoft Enterprise | Tag change |
| Ncsc.gov.uk | https://www.ncsc.gov.uk | Blog: NCSC Reports, Guidance and Blog-post | Blog: Ncsc.gov.uk | Tag change |
| Nextron systems | http://nextron-systems.com | Blog: Nextron | Blog: Nextron systems | Tag change |
| Palo Alto Networks | https://security.paloaltonetworks.com | Blog: Palo Alto Daily Post | Blog: Palo Alto Networks | Tag change |
| Project Zero | https://projectzero.google | Blog: Google Project Zero | Blog: Project Zero | Tag change |
| Proofpoint UK | https://www.proofpoint.com | Blog: Proof Point | Blog: Proofpoint UK | Tag change |
| Recordedfuture | https://www.recordedfuture.com/blog | Blog: Recorded Future | Blog: Recordedfuture | Tag change |
| Red Packet Security | https://www.redpacketsecurity.com |
| Blog: RedPacket Security | Blog reactivated in CAL ATL; multiple Tags consolidated into a single Tag |
| Reversing Labs | http://www.reversinglabs.com | Blog: ReversingLabs | Blog: Reversing Labs | Tag change |
| SANS Internet Storm Center | https://isc.sans.edu | Blog: SANS | Blog: SANS Internet Storm Center | Tag change |
| Securelist.com | https://securelist.com | Blog: Securelist | Blog: Securelist.com | Tag change |
| Security Week | https://www.securityweek.com | N/A | Blog: Security Week | Blog reactivated in CAL ATL |
| Sekoia | http://blog.sekoia.io | Blog: Sekoia.io | Blog: Sekoia | Tag change |
| Sophos security | https://www.sophos.com |
| Blog: Sophos security | Multiple Tags consolidated into a single Tag |
| Splunk | https://www.splunk.com/en_us/blog | Blog: Splunk Threat Research Team | Blog: Splunk | Blog reactivated in CAL ATL; Tag change |
| Sucuri Blog | https://blog.sucuri.net | Blog: Sucuri | Blog: Sucuri Blog | Tag change |
| Talos Blog | https://blog.talosintelligence.com | Blog: Cisco Talos Blog | Blog: Talos Blog | Tag change |
| Tech Xplore | https://techxplore.com | Blog: TechXplore | Blog: Tech Xplore | Tag change |
| Tgsoft | http://tgsoft.it | Blog: VirIT | Blog: Tgsoft | Tag change |
| The Citizen Lab | https://citizenlab.ca | Blog: Citizen Lab | Blog: The Citizen Lab | Tag change |
| The Cyber Express | https://thecyberexpress.com | Blog: The Cyber Express Daily Firewall | Blog: The Cyber Express | Tag change |
| The DFIR Report | http://thedfirreport.com | N/A | Blog: The DFIR Report | Blog reactivated in CAL ATL |
| The Digest (Crypto-Ransomware) | http://id-ransomware.blogspot.com | BLOG: ID Ransomware | Blog: The Digest (Crypto-Ransomware) | Blog reactivated in CAL ATL; Tag change |
| The Record Media | https://therecord.media | Blog: The Record | Blog: The Record Media | Tag change |
| The Register Security | https://www.theregister.com/security/headlines.atom | Blog: The Register Security | N/A | Blog retired from CAL ATL due to copyright licensing changes; licensed content from this blog may be added to CAL ATL in the future |
| Traficomin Kyberturvallisuuskeskus | https://www.kyberturvallisuuskeskus.fi |
| Blog: Traficomin Kyberturvallisuuskeskus | Multiple Tags consolidated into a single Tag |
| Trend Micro Blog | https://blog.trendmicro.com | Blog: TrendMicro | Blog: Trend Micro Blog | Tag change |
| Unit 42 | https://unit42.paloaltonetworks.com | Blog: Unit42 | Blog: Unit 42 | Tag change |
ThreatConnect® is a registered trademark, and CAL™ is a trademark, of ThreatConnect, Inc.
20183-01 v.01.A