r/threatintel

18k members
r/threatintel is a subreddit with 18k members. The most common kinds of discussions are news and advice requests, and the community frequently discusses cve, network, commix, oast, and telegram fraud.
Sharing of information about threats, vulnerabilities, tools and trends across the security industry.

Popular Themes in r/threatintel

#1
News
: "DoppelCart: 119,000 Domains in What May Be the Largest Documented Fake-Shop Network"
6 posts
#2
Advice Requests
: "What AI-assisted workflows, models, or agents do you genuinely find helpful?"
5 posts
#3
Pain & Anger
: "Anyone else struggling to keep detection coverage aligned with changing threats?"
2 posts
#4
Solution Requests
: "Best vulnerability threat intel solution you have actually used?"
1 post
#5
Self-Promotion
: "Landed my first CVE !! (in a plugin with 600k+ installs) after months of mostly dead ends. Sharing the actual process, not just the win."
1 post

Popular Topics in r/threatintel

#1

Cve

: "2 Citrix NetScaler zero-days (Cve-2026-88771, Cve-2026-88772) are under active exploitation and listed in CISA KEV"
6 posts
#2

Network

: "DoppelCart: 119,000 Domains in What May Be the Largest Documented Fake-Shop Network"
4 posts
#3

Commix

: "Commix now does out-of-band (OAST) detection and exploitation."
2 posts
#4

Oast

: "Commix now does out-of-band (Oast) detection and exploitation."
2 posts
#5

Telegram Fraud

: "The Malware Watched Back: Inside a Telegram Fraud Operation"
2 posts
#6

Telegram

: "The Malware Watched Back: Inside a Telegram Fraud Operation"
2 posts
#7

Motion

: "⚠️ Security Warning: Alleged Malware / Botnet Activity Linked to "Motion" / "Deadeye""
2 posts
#8

Deadeye

: "⚠️ Security Warning: Alleged Malware / Botnet Activity Linked to "Motion" / "Deadeye""
2 posts
#9

Mapping

: "Mapping all 343 million china ip addresses to study there reliance on US software."
2 posts
#10

Software

: "Mapping all 343 million china ip addresses to study there reliance on US Software."
2 posts

Flair Used in r/threatintel

#1
APT/Threat Actor
: "Underrated CTI account worth following for infrastructure hunting"
20 posts
#2
Help/Question
: "How lucrative is this field still? Is it too late?"
16 posts
#3
CVE Discussion
: "CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT"
7 posts
#4
OSINT
: "List of keyless (zero-auth) public CTI and infostealer API endpoints for rapid triage + open-source Python script to query them"
5 posts

Member Growth in r/threatintel

Yearly
+7k members(68.8%)

Similar Subreddits to r/threatintel

/r/blueteamsec

r/blueteamsec

73k members
25.3% / yr
/r/CTI

r/CTI

1k members
41.0% / yr
/r/CyberAdvice

r/CyberAdvice

22k members
37.6% / yr
/r/cybersecurity_

r/cybersecurity_

681 members
96.8% / yr
/r/Cybersecurity101

r/Cybersecurity101

70k members
190.1% / yr

r/cybersecurity_help

89k members
69.7% / yr
/r/cybersecurity_news

r/cybersecurity_news

16k members
17.0% / yr
/r/cybersecurityUK

r/cybersecurityUK

2k members
168.6% / yr
/r/purpleteamsec

r/purpleteamsec

9k members
17.9% / yr
/r/SecOpsDaily

r/SecOpsDaily

16k members
508.5% / yr

About

GummySearch helps people research Reddit communities by organizing activity, growth, themes, and post-level signals into one place.

This page gives a focused view of r/threatintel, including current member size, discussion patterns, product reviews, and related communities to explore.

This data is synced periodically so insights stay current and useful for ongoing research.

Last updated: October 1, 2026