Overview
The CAL™ 3.15 release, scheduled for late March 2026, will deliver a major upgrade for ThreatConnect® and Polarity customers leveraging CAL Automated Threat Library (ATL). In addition to bringing in data from new blogs and report sources and improving the frequency and reliability of data retrieval, this release includes changes that streamline and update blog metadata and remove blogs that no longer exist or provide relevant data:
- Tag names for some CAL ATL blogs were changed to ensure consistency and correctness.
- Some CAL ATL blogs were consolidated under a single Tag.
- Retired blogs that were re-activated were added back to CAL ATL.
- Blogs that stopped publishing relevant data were retired.
- URLs for CAL ATL blogs were updated as needed.
CAL ATL Updates for CAL 3.15
The CAL Automated Threat Library Source includes the following features under the CAL 3.15 release:
- 125 of the best blog and report sources—including CERTs, government agencies, security research organizations, industry vendors, and security news—to help power CTI workflows, orchestration, and decision making. These sources include the following:
- 46 new blog and report sources
- Reactivated blog and report sources:
- 360 Netlab Blog
- Check Point Research
- CrowdStrike (formerly CrowdStrike Blog)
- Dark Reading
- Flashpoint
- Internet Crime Complaint Center (IC3)
- RedPacket Security (formerly Red Packet Security Pikabot C2, Red Packet Security Ransomware Feed, and Red Packet Security Posh C2)
- Security Week
- Splunk (formerly Splunk Threat Research Team)
- The DFIR Report
- The Digest (Crypto-Ransomware) (formerly ID Ransomware)
- VIPRE Labs (formerly VIPRE Labs Blog)
- Hourly updates for all blog and report sources
- Improved reliability of retrieved information
- Reduced false positives from links identified as indicators of compromise (IoCs) in blogs and reports
What Do I Need to Do?
The CAL 3.15 release is scheduled for late March 2026. You do not need to make any changes, as automatic Tag normalization rules will make all necessary adjustments to account for changed Tags. If you think you may not want automated Tag normalization to occur on your ThreatConnect instance, please reach out to your Customer Support Manager to be excluded.
Table 1 lists the updated blogs, including changes to their corresponding Tag and a description of the change.
| Blog Name | Source URL | Old ThreatConnect Tag | Current ThreatConnect Tag | What Changed? |
|---|---|---|---|---|
| 360 Netlab Blog | https://blog.netlab.360.com/ | N/A | Blog: 360 Netlab Blog | Blog reactivated in CAL ATL |
| Bitdefender | https://www.bitdefender.com/en-us | Blog: Bitdefender Labs | Blog: Bitdefender | Tag change |
| Bleeping Computer | https://www.bleepingcomputer.com | Blog: BleepingComputer | Blog: Bleeping Computer | Tag change |
| Canadian Centre for Cyber Security | https://www.cyber.gc.ca | Blog: Government of Canada Alerts and Advisories | Blog: Canadian Centre for Cyber Security | Tag change |
| Center for Internet Security | https://www.cisecurity.org |
| Blog: Center for Internet Security | Multiple Tags consolidated into a single Tag |
| Centre gouvernemental de veille | https://www.cert.ssi.gouv.fr |
| Blog: Centre gouvernemental de veille | Multiple Tags consolidated into a single Tag |
| CERT-UA | https://cert.gov.ua/ | Blog: CERT-UA News | Blog: CERT-UA | Tag change |
| Check Point Research | https://research.checkpoint.com | N/A | Blog: Check Point Research | Blog reactivated in CAL ATL |
| CISA | https://cisa.gov/ | Blog: CISA Cybersecurity Alerts & Advisories | Blog: CISA | Tag change |
| CrowdStrike | https://www.crowdstrike.com | Blog: CrowdStrike Blog | Blog: CrowdStrike | Blog reactivated in CAL ATL; Tag change |
| Cyber Security News | https://cybersecuritynews.com | Blog: Cybersecurity News | Blog: Cyber Security News | Tag change |
| Cyberscoop - Attacks | https://www.cshub.com/rss/categories/attacks | Blog: CyberScoop Attacks | N/A | Blog retired from CAL ATL - stopped publishing data in April 2025 |
| Cyberscoop - Security Strategy | https://www.cshub.com/rss/categories/security-strategy | Blog: Cyber Security Hub | N/A | Blog retired from CAL ATL - stopped publishing data in August 2025 |
| Cyberscoop - Threat Defense | https://www.cshub.com/rss/categories/threat-defense | Blog: CyberScoop | N/A | Blog retired from CAL ATL - stopped publishing data in June 2025 |
| Dark Reading | https://www.darkreading.com/ | N/A | Blog: Dark Reading | Blog reactivated in CAL ATL |
| DataBreaches | https://databreaches.net/ | Blog: Data Breach Today | Blog: DataBreaches | Tag change |
| Flashpoint | https://www.flashpoint-intel.com | Blog: flashpoint | Blog: Flashpoint | Blog reactivated in CAL ATL; Tag change |
| Fox-IT | https://blog.fox-it.com | Blog: Fox IT | Blog: Fox-IT | Tag change |
| GreyNoise Labs | https://www.greynoise.io | Blog: GreyNoise | Blog: GreyNoise Labs | Tag change |
| Heimdal Security Blog | https://heimdalsecurity.com/blog/ | Blog: Heimdal Security | Blog: Heimdal Security Blog | Tag change |
| Internet Crime Complaint Center (IC3) | https://www.ic3.gov | N/A | Blog: IC3 | Blog reactivated in CAL ATL |
| JPCERT コーディネーションセンター | https://blogs.jpcert.or.jp/en |
| Blog: JPCERT コーディネーションセンター | Multiple Tags consolidated into a single Tag |
| Malwarebytes | https://www.malwarebytes.com/ | BLOG: Malware Bytes Threat AnalysisVIPRE Labs Blog | Blog: Malwarebytes | Tag change |
| Mandiant | https://www.mandiant.com/resources/blog/rss.xml | Blog: Mandiant | Blog: Think With Google | Mandiant no longer publishes threat intelligence information, but redirects to Google Cloud Threat Intelligence Blog, which is now added to CAL ATL |
| Microsoft Enterprise | https://www.microsoft.com/en-us/security/blog/ | Blog: Microsoft Secure | Blog: Microsoft Enterprise | Tag change |
| NCSC UK | https://www.ncsc.gov.uk | Blog: NCSC Reports, Guidance and Blog-post | Blog: NCSC UK | Tag change |
| Nextron Systems | https://nextron-systems.com/ | Blog: Nextron | Blog: Nextron Systems | Tag change |
| Palo Alto Networks | https://security.paloaltonetworks.com | Blog: Palo Alto Daily Post | Blog: Palo Alto Networks | Tag change |
| Project Zero | https://projectzero.google | Blog: Google Project Zero | Blog: Project Zero | Tag change |
| Proofpoint | https://www.proofpoint.com | Blog: Proof Point | Blog: Proofpoint | Tag change |
| RedPacket Security | https://www.redpacketsecurity.com |
| Blog: RedPacket Security | Blog reactivated in CAL ATL; multiple Tags consolidated into a single Tag |
| SANS Internet Storm Center | https://isc.sans.edu | Blog: SANS | Blog: SANS Internet Storm Center | Tag change |
| Security Week | https://www.securityweek.com | N/A | Blog: Security Week | Blog reactivated in CAL ATL |
| Sekoia | http://blog.sekoia.io | Blog: Sekoia.io | Blog: Sekoia | Tag change |
| Sentinel One | https://www.sentinelone.com | Blog: SentinelOne | Blog: Sentinel One | Tag change |
| Sophos | https://www.sophos.com |
| Blog: Sophos | Multiple Tags consolidated into a single Tag |
| Splunk | https://www.splunk.com/en_us/blog/author/secmrkt-research.html | Blog: Splunk Threat Research Team | Blog: Splunk | Blog reactivated in CAL ATL; Tag change |
| Sucuri Blog | https://blog.sucuri.net | Blog: Sucuri | Blog: Sucuri Blog | Tag change |
| Talos Blog | https://blog.talosintelligence.com | Blog: Cisco Talos Blog | Blog: Talos Blog | Tag change |
| Tech Xplore | https://techxplore.com | Blog: TechXplore | Blog: Tech Xplore | Tag change |
| TG Soft | https://tgsoft.it/ | Blog: VirIT | Blog: TG Soft | Tag change |
| The Citizen Lab | https://citizenlab.ca | Blog: Citizen Lab | Blog: The Citizen Lab | Tag change |
| The Cyber Express | https://thecyberexpress.com | Blog: The Cyber Express Daily Firewall | Blog: The Cyber Express | Tag change |
| The DFIR Report | https://thedfirreport.com/ | N/A | Blog: The DFIR Report | Blog reactivated in CAL ATL |
| The Digest (Crypto-Ransomware) | https://id-ransomware.blogspot.com/ | BLOG: ID Ransomware | Blog: The Digest (Crypto-Ransomware) | Blog reactivated in CAL ATL; Tag change |
| The Register Security | https://www.theregister.com/security/headlines.atom | Blog: The Register Security | N/A | Blog retired from CAL ATL due to copyright licensing changes; licensed content from this blog may be added to CAL ATL in the future |
| Traficomin Kyberturvallisuuskeskus | https://www.kyberturvallisuuskeskus.fi |
| Blog: Traficomin Kyberturvallisuuskeskus | Multiple Tags consolidated into a single Tag |
| Trend Micro Blog | https://blog.trendmicro.com | Blog: TrendMicro | Blog: Trend Micro Blog | Tag change |
| Unit 42 | https://unit42.paloaltonetworks.com | Blog: Unit42 | Blog: Unit 42 | Tag change |
| VIPRE Labs | https://vipre.com/ | BLOG: VIPRE Labs Blog | Blog: VIPRE Labs | Blog reactivated in CAL ATL; Tag change |
ThreatConnect® is a registered trademark, and CAL™ is a trademark, of ThreatConnect, Inc.
20183-01 v.03.A