I've started experimenting with a broader collection concerning "Breach Events". The idea is to selectively monitor News sources for signs of organizations having suffered some sort of cyber incidents.
Would anyone be interested in having this sort of feed added to ORLYSEC?
Basically something like this:
- Monitor sources tagged 'news'
- Determine if breach related
- Extract victim entity
- Extract origin source
Toot:
Alleged breach involving <entity> originally reported by <origin_source>, and first reported by <news_source>
The idea is to slowly build a set of sources covering global, and eventually also begin to do 'national' events monitoring and reporting.
Yes, no? Pointless?