← Back to all sparks
F

Feedly

ANALYTICS
Velocity5.0

Feedly's reader roots recede as threat-intel agents take over the changelog

threat-intelligenceai-agentsvulnerability-managementdetection-rulessoc-workflow
Current state
Feedly's changelog is now almost entirely a cyber threat intelligence product log. The last three months added models tuned for insider threats and threat actor campaigns, Suricata rule extraction, SPL queries alongside KQL, GreyNoise and VirusTotal enrichment, and a Vulnerability Agent. The August release extends Custom Intel Agents with Analyze and Research actions and adds a Censys lookup to IP cards.
Where it's heading
The arc runs from retrieval toward analysis: earlier releases broadened what Feedly could collect, recent ones give analysts agents that reason over it and emit artifacts their existing tools accept. Report Builder citations that trace a claim to its source passage target the trust problem gating generated intelligence in a SOC. Coverage has become table stakes; the contest is over whether analysts accept the machine's conclusions.
Prediction
Expect the agent surface to keep gaining verbs rather than new data sources, with more export formats aimed at the SIEM and detection tooling analysts already run.

Recent moves

  1. 6d ago

    Custom Intel Agents gain Analyze and Research actions

    Custom Intel Agents pick up Ask AI's Analyze and Research actions, continuing the pattern of adding verbs to an existing agent rather than new data sources. A Censys lookup on IP cards and a Report Builder progress indicator round out a maintenance-weighted release.

  2. 20d ago

    Hunt threat actor campaigns and run SPL queries alongside KQL

    A model tuned for threat actor campaign detection plus SPL output alongside KQL widens both the reasoning and the export side of the same workflow. Supporting Splunk's query language is the more consequential half: it lets Feedly's output land in SOCs it previously could not address.

  3. 1mo ago

    Faster exploit triage, smarter Org Profiles, and more transparency across your Report Builder

    Exploit type, confidence, and evidence move onto the CVE card, cutting a step out of triage. Report Builder citations that resolve to the source passage address verification directly, which is what makes generated intelligence usable in a report someone signs.

  4. 1mo ago

    Suricata detection rules, Ask AI Research Playground, and more

    Pulling Suricata rules straight from Insight Cards turns reading into something a detection engineer can deploy. The Ask AI Research Playground is a go-to-market move as much as a feature, letting evaluators test the AI on real actors and CVEs without a sales conversation.

  5. 2mo ago

    Track exploit types, Oracle and Atlassian advisories, and more

    Broader vendor advisory coverage and sharper exploit signal are the collection-side work the agent features depend on. Routine for Feedly at this cadence, which makes releases like this the baseline rather than the news.

  6. 2mo ago

    Smarter insider threat detection, broader search coverage, and more

    An improved insider threat model and wider language coverage in search extend the same two axes: a tuned model, plus more to run it over. It is an early instance of the purpose-built-model pattern the July threat actor campaign release repeats.