A self-hosted threat intelligence desk
See what changed. Decide what needs attention.
BlueTeam.News helps security analysts prioritize public threat reporting, compare source changes, and prepare briefings with evidence they can review.
Wire and Wall work without an API key. Add your own Anthropic or OpenAI key for AI-generated briefings.

Prioritize reporting and inspect the evidence.
View Wire screenshot- Open source
- MIT-licensed
- Self-hosted
- Run on your own infrastructure
- Product telemetry
- None
The daily workflow
Follow the story. Keep the evidence in view.
A desk for the analyst or security lead who needs to understand the reporting and explain their assessment.
- 01
Find what deserves a closer look.
Filter Wire by urgency, known exploited vulnerabilities, or unread reports. See why a report was scored and how it matches the technologies and topics you watch.
- 02
See the source. Compare what changed.
Read saved source excerpts and compare earlier observations. Record your assessment, owner, and next review date in this browser.
- 03
Prepare a briefing you can review.
Generate an assessment with proposed actions and cited sources. Inspect its saved evidence inputs, review the claims, and print the same edition.
Compare saved source excerpts.
Compare saved observations of an advisory, with added and removed passages highlighted for review.
How matching and briefing inputs work
Watch-profile matches highlight reporting to investigate; they do not confirm exposure in your environment. Wire filters do not select generation inputs. Briefings use the latest collection selection and save the supplied evidence for review. Read the evidence and generation guide.
Highlighted source excerpt. Open the full comparison to inspect both observations.
View source-comparison screenshotBriefing
An assessment with sources you can review.
Scan the headlines in Overview, read the complete assessment in Full report, and carry the same edition into print.
Overview and Full report
Scan the featured story and supporting headlines in Overview. Open Full report for the complete assessment, response actions, qualifications, and citations.
View full-report screenshot
Print Edition
Print preview detail. Take the same saved assessment to paper or PDF, rendered locally without another AI request.
View Print Edition screenshotAI-generated. Reviewed by you. Check the claims against their cited reporting before acting. Each new Briefing saves the evidence used to generate it; automated checks do not verify every claim or confirm your exposure.
Read a sample briefing or download the Print Edition PDF. The sample uses a fictional scenario to show the assessment and its source trail.
About these screenshots
Overview and Full report were captured October 9, 2026 at 1440 × 900; the other screenshots were captured September 6, 2026. Wire and source evidence show collected public reporting. Briefing, Print, and Wall show the saved, editorially corrected September 6 edition 2. Some previews focus on a detail; open a screenshot to see the complete capture and its review status. These captures illustrate the interface, not a current security assessment; the fictional sample is separate.
Wall
Keep the room informed.
Put reporting and saved briefings on an operations display. Wall rotates through topics with their sources and publication times, in your light or dark theme.
Keep current reporting and saved briefings in view.
View Wall screenshotQuick start
Run BlueTeam.News locally.
Requirements: Node.js + npm. Node.js 24 is recommended. Anthropic or OpenAI API key for Briefing generation.
git clone --branch v1.3.2 --single-branch https://github.com/ryanshrier/blueteam.git blueteam
cd blueteam
npm install
npm start
Copy all four commands, or scroll horizontally to read each line.
Open http://127.0.0.1:3000. Collection starts automatically, and Wire fills as sources respond. Explore reports and source comparisons without an API key.
Add AI-generated briefings
In Settings, choose Anthropic or OpenAI, enter your API key, and select a model available to your account. Save your settings and use Verify to check access. Verification and generation use billable provider requests. Then open Briefing → Edition tools → Generate briefing. Automatic generation stays off until you enable it. Advanced users can also try an experimental Custom provider through a trusted local module; its contract may change, and credentials come only from the environment. Read the configuration guide.
Data and security
Run it yourself. See what leaves your host.
BlueTeam.News sends no product telemetry or analytics and requires no BlueTeam.News account. Review what stays on your host and which configured services receive requests.
Storage and access details
The server listens on 127.0.0.1 by default. Stored data and saved API keys are not encrypted by the application; protect the host and backups. Remote access requires authentication and TLS. There is no license check or runtime CDN. Read the deployment guidance.
- Stored on your host
- collected data · briefings · settings
- Configured sources
- news feeds · source articles · vulnerability data
- Configured AI provider
- Built-in key verification or optional Custom health checks; selected source evidence and configured organization context for generation
- Configured webhook
- selected alert or Briefing fields, if enabled
Your provider may charge for verification and generation. Experimental Custom modules define their own health checks, destinations, and billing.
Your daily intelligence desk
Bring the reporting into focus.
Run BlueTeam.News locally and start exploring the evidence behind the headlines.