OpenCTI
Open cyber threat intelligence platform
OpenCTI adopts a FIPS 140-3 validated base image — a quiet signal the platform is targeting federal and defense buyers.
◆Recent moves
- 22h ago
Version 7.260917.0
Version 7.260917.0 lands multi-OpenAEV security coverage results, SSVC risk-based vulnerability prioritization metrics behind a feature flag, and the first user merge RBAC rights merge with a union/strict option — infrastructure for organization-level consolidation. The Fintel direct-to-PDF export simplification and several investigation graph stability fixes round out the release.
View source ↗ - 4d ago
Version 7.260914.0
Version 7.260914.0 fixes a meaningful data segregation bug — stream objects whose STIX IDs appeared in container references even when they didn't meet the stream filter, which could leak intelligence scope to unintended subscribers. Configurable keep-alive and header timeouts for ALB/ECS deployments address a real operational pain point for cloud-hosted instances.
View source ↗ - 7d ago
Version 7.260910.0
Version 7.260910.0 integrates Filigran Design System v1 and replaces the external map tile server with local PMTiles rendering — eliminating an outbound dependency in air-gapped or restricted deployments. Ingestion logs for RSS, JSON, and stream feeds add long-overdue operational visibility to data pipeline health.
View source ↗ - 11d ago
Version 7.260907.0
⚡ SPARKFIPS 140-3 validated base image is the single most consequential change in this release. Combined with workflow status sync across all entities and CSV ingestion logs, version 7.260907.0 is the release that opens OpenCTI's door to federal and classified-environment deployments.
View source ↗ - 14d ago
Version 7.260904.0
Version 7.260904.0 derives the session signature key from the application encryption key rather than a static or separately managed secret. A quiet security hardening measure that reduces the attack surface on session tokens without requiring any user-facing change.
View source ↗ - 15d ago
Version 7.260902.0
Version 7.260902.0 fixes a range intersection bug in the backend, search query processing, and Arabic character encoding in CSV export. The user merge API surface lands behind a feature flag — no user-visible effect yet.
View source ↗