← Back to all sparks
O

OpenCTI

ANALYTICS
Velocity7.5

Open cyber threat intelligence platform

OpenCTI adopts a FIPS 140-3 validated base image — a quiet signal the platform is targeting federal and defense buyers.

threat-intelligencefips-complianceenterprise-securityvulnerability-managementai-assistantfederal-sector
Current state
OpenCTI is running a 2–3 release per week cadence with dense mixes of security hardening and incremental feature work. The most significant structural change in the past month is the adoption of a FIPS 140-3 validated base image, which is a hard prerequisite for US federal agencies, defense contractors, and a broad class of regulated enterprises. Alongside that, Filigran Design System v1 integrated, local PMTiles rendering replaced an external tile server dependency, and SSVC risk-based vulnerability prioritization landed behind a feature flag.
Where it's heading
OpenCTI is consolidating as an enterprise-grade threat intelligence platform with a compliance story. The FIPS move signals a deliberate push toward government and regulated-sector sales. Ask Ariane (the AI assistant) gaining human-in-the-loop tool approval in a recent release shows cautious AI integration — appropriate for security-sensitive contexts where auditability matters. The user merge framework (dry-run/run, RBAC rights merge) is infrastructure work that suggests multi-tenant and org-consolidation use cases are coming.
Prediction
SSVC risk-based prioritization will exit its feature flag in the next 1–2 releases; the user merge feature will reach the UI after the framework matures. Expect FIPS compliance to become a front-page sales message as OpenCTI pursues government procurement channels.

Recent moves

  1. 22h ago

    Version 7.260917.0

    Version 7.260917.0 lands multi-OpenAEV security coverage results, SSVC risk-based vulnerability prioritization metrics behind a feature flag, and the first user merge RBAC rights merge with a union/strict option — infrastructure for organization-level consolidation. The Fintel direct-to-PDF export simplification and several investigation graph stability fixes round out the release.

    View source ↗
  2. 4d ago

    Version 7.260914.0

    Version 7.260914.0 fixes a meaningful data segregation bug — stream objects whose STIX IDs appeared in container references even when they didn't meet the stream filter, which could leak intelligence scope to unintended subscribers. Configurable keep-alive and header timeouts for ALB/ECS deployments address a real operational pain point for cloud-hosted instances.

    View source ↗
  3. 7d ago

    Version 7.260910.0

    Version 7.260910.0 integrates Filigran Design System v1 and replaces the external map tile server with local PMTiles rendering — eliminating an outbound dependency in air-gapped or restricted deployments. Ingestion logs for RSS, JSON, and stream feeds add long-overdue operational visibility to data pipeline health.

    View source ↗
  4. 11d ago

    Version 7.260907.0

    ⚡ SPARK

    FIPS 140-3 validated base image is the single most consequential change in this release. Combined with workflow status sync across all entities and CSV ingestion logs, version 7.260907.0 is the release that opens OpenCTI's door to federal and classified-environment deployments.

    View source ↗
  5. 14d ago

    Version 7.260904.0

    Version 7.260904.0 derives the session signature key from the application encryption key rather than a static or separately managed secret. A quiet security hardening measure that reduces the attack surface on session tokens without requiring any user-facing change.

    View source ↗
  6. 15d ago

    Version 7.260902.0

    Version 7.260902.0 fixes a range intersection bug in the backend, search query processing, and Arabic character encoding in CSV export. The user merge API surface lands behind a feature flag — no user-visible effect yet.

    View source ↗