{
  "id": 12497808,
  "title": "Federated Threat Intelligence: Sharing IOCs Without Sharing Content",
  "url": "https://urgent.news/2026/10/06/federated-threat-intelligence-sharing-iocs-without-sharing-content",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-06T23:37:15.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/aegisgate/federated-threat-intelligence-sharing-iocs-without-sharing-content-bpk"
  },
  "original_language": "en",
  "account": "Traditional threat intelligence suffers from significant delays before organizations can respond to emerging attacks. AegisGate, an open-source AI security platform, introduces a federated threat intelligence system to close this latency window. The solution tackles three key issues: raw content sharing concerns, slow signature feeds, and binary trust in threat intelligence sources.\n\nAegisGate creates privacy-safe Indicators of Compromise (IOCs) by generating SHA-256 fingerprints of detection structs, containing technique information without any original attack payloads. These IOCs are shared through a pull-based gossip protocol, where instances communicate via HTTP and exchange signed bundles. Each bundle is signed with ECDSA P-256, and peers discover each other's public keys through a bootstrap peer list, creating a trust mesh architecture.\n\nPeer reputation is established using an Exponentially Weighted Moving Average (EWMA) with a 7-day half-life, allowing trusted peers to enhance response capabilities while untrustworthy peers' contributions are filtered. Corroboration escalation enables an attack detected by one organization to automatically trigger blocking actions in other organizations, fostering a collaborative defense mechanism. Additionally, TAXII 2.1 feeds integrate existing TI platforms, providing flexibility for incorporating legacy threat intelligence sources.",
  "summary": "The fundamental problem in threat intelligence is latency. Organization A detects a novel prompt injection. Organizations B, C, and D won't see it until someone writes a blog post, a vendor updates a signature, and a SIEM rule gets deployed. In AI security, that latency window is measured in hours — and attacks iterate faster than that. I've been building AegisGate — an open-source AI security…",
  "key_points": [
    "AegisGate platform enables federated threat intelligence without raw content sharing.",
    "Privacy-safe IOCs created using SHA-256 fingerprints of detection structs.",
    "Trust mesh architecture establishes peer reputation via EWMA for collaborative defense."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}