Quick Links

News in Hearth

Overview

The News page shows recent cybersecurity headlines, triaged against your stack. Hearth pulls stories from a small set of trusted public security-news feeds. Hearth then tags each story by how likely it is to touch your environment, which includes the vendors, cloud platforms, and tools that you run.

On most days, it is unlikely that a story on this page requires action from you. The value of the page is the tagging. When a headline matches something that you use, Hearth marks it, so that you do not have to read every story to find it.

How it works

Hearth aggregates recent headlines from four public security-news sources: Krebs on Security, BleepingComputer, The Hacker News, and Schneier on Security. Hearth merges the headlines into one list, newest first, and collapses duplicate stories into a single entry. A duplicate occurs when several sources syndicate the same story. Hearth shows only recent items, which covers approximately the last two days.

For each headline, Hearth compares the story text against a set of keywords that it builds from your workspace. These keywords come from your declared profile, the types of information that currently arrive in your workspace, and your connected integrations. Hearth expands each keyword to cover common vendor names and aliases. For example, "Microsoft 365" also matches "Entra," "Exchange," and "Outlook."

Hearth then applies one of the following verdict tags to each item:

TagMeaning
LOOKThe story mentions something in your stack. Apply a few minutes of judgment to it.
HANDLEDNothing in the story matched your stack. No action is required.

Items that match your stack sort to the top of the list. The remaining items follow in newest-first order. When an item matches, Hearth also shows a row of match chips that name the stack keywords that triggered the tag, so that you can see the reason for the match.

The feed refreshes automatically, approximately once an hour. If one source is unreachable, Hearth still shows the others. If every source is briefly unavailable, Hearth shows the last good set of headlines with a staleness note instead of an empty page.

Note: The News page is read-only. Each headline links to the original article, and nothing on the page runs an action or changes your workspace.

Reviewing the news

To review the news for your workspace, do the following:

  1. Navigate to More > News.
  2. Review the items that Hearth tagged LOOK.
  3. Click a card to open the full article in a new tab.
  4. Decide whether the story warrants a follow-up. For example, you can ask Hestia to investigate related activity in your own workspace.

Note: The feed refreshes approximately once an hour. To see the latest set, reload the page.

Troubleshooting common issues

IssueWhat to do
The page states that no news items are availableThe aggregator polls approximately once an hour and had no recent story to show, or a temporary fetch error returned an empty set. Try again shortly. This message does not indicate an error in your workspace.
The page states that it cannot load the newsA temporary problem prevented Hearth from reaching the news service. Reload the page to try again.
Every item is tagged HANDLEDHearth found nothing in the recent headlines that matches your stack, or Hearth does not yet know your stack. On a new workspace, complete onboarding (industry, cloud, EDR, SIEM, and compliance), connect your integrations, or allow information to flow in. These actions give Hearth the keywords that it needs. Tags can take a few minutes to reflect a change.
A story that you care about is tagged HANDLEDThe tags are keyword-based and deliberately conservative, so that Hearth does not raise unnecessary alarms. A story can be important to you without naming one of your specific vendors. HANDLED means that the story did not match your stack keywords. It does not mean that the story is safe to ignore.
The headlines look old, or a staleness note appearsIf every source is briefly unreachable, Hearth shows the last good set of headlines instead of an empty page, and marks the set as aging. Hearth corrects this on the next successful refresh.