๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Security & IT news ticker

The security news that matters, where your team already works.

Nobody has time to watch a dozen advisory feeds. Lavawall® brings the ones that matter straight into your console: a live ticker of critical security and IT advisories across the top of every page, and a full threat-news reader behind it. When a vendor you run ships a critical fix or CISA adds a vulnerability to its exploited list, you see it where you are already working, not three days later in a newsletter.

Start free, no credit cardSee the sources

Included at every tier · national CERTs, vendor and news sources · CVE links to NVD

The Lavawall console with a critical-advisory ticker across the top and a Threat news dropdown open over the dashboard

A ticker up top, a full reader behind it

The most urgent advisories scroll across the top of the console so they are impossible to miss. Open the reader and you get the whole feed: search it, filter by severity, switch between your subscribed sources and everything available, and mark items read. Every CVE links straight to its entry on the National Vulnerability Database.

The Lavawall Threat News reader showing critical advisories from IBM, N-able and CISA with a severity filter, source toggles, and a source list on the right

Impossible to miss

Critical items ride a ticker across the top of every page, so the advisory that matters is in front of you, not buried in an inbox.

Read on your terms

Search, filter by minimum severity, flip between your sources and all sources, and mark all read when you have triaged the queue.

Straight to the CVE

Advisories carry their CVE identifiers, each linking directly to the NVD entry, so you go from headline to detail in one click.

Set it once for every client

An MSP should not have to configure a news feed tenant by tenant. Company-wide subscription defaults let you choose which sources are subscribed for everyone, mark a source Required so it stays on and locked, raise console notifications for a source, and set a minimum severity, all per company. Set your baseline once and it applies across the book, while individual users can still tune what they personally see unless you have locked it.

The Canadian Centre for Cyber Security alerts and the CISA Known Exploited Vulnerabilities catalogue come subscribed by default, because those are the two every organization should be watching.

Company-wide advisory subscription defaults in Lavawall: per-source toggles for subscribed-for-everyone, required, console notifications, and minimum severity

Notifications that fit each person

Alert fatigue is its own security risk, so everyone picks the level that keeps them informed without drowning them. Turn the desktop ticker on or off, choose an email digest cadence and the severity it includes, set in-console notifications, and opt into browser push, per device. A tech who wants critical-only in the console and a weekly email gets exactly that, while the person who wants everything can have it.

The result is a whole team that hears about the advisory that affects them, in the way that actually reaches them.

Per-user notification options in Lavawall: desktop ticker toggle, email digest cadence and severity, console notifications, and browser push

Curated sources, not a firehose

Lavawall® pulls from authoritative national cyber centres, vendor security advisories, and the security news that professionals actually read, then lets you choose which appear. You get signal without babysitting a stack of RSS readers.

The source list grows all the time. Samples of current sources include:

  • Canadian Centre for Cyber Security - Alerts and Advisories
  • Canadian Centre for Cyber Security - Guidance, News and Events
  • CISA Alerts and Advisories
  • CISA Known Exploited Vulnerabilities
  • NCSC UK - News and Advisories
  • Australian Cyber Security Centre - Alerts
  • NVD - Recently analysed CVEs
  • Tenable Research Advisories
  • Tenable Product Security Advisories
  • Tenable Blog
  • Nessus - Newest Plugins
  • Zero Day Initiative - Published Advisories
  • Zero Day Initiative - Upcoming Advisories
  • Microsoft Security Blog
  • Microsoft Security Update Guide
  • Google Project Zero
  • Rapid7 Blog
  • Qualys Security Blog
  • LevelBlue Labs (AlienVault OTX)
  • Cisco Talos Intelligence
  • Palo Alto Unit 42
  • Google Cloud Threat Intelligence (Mandiant)
  • Securelist
  • SANS Internet Storm Center
  • Huntress Blog
  • Sophos News
  • ESET WeLiveSecurity
  • CrowdStrike Blog
  • watchTowr Labs
  • Sekoia.io Blog
  • Malwarebytes Labs
  • BleepingComputer
  • The Hacker News
  • Krebs on Security
  • The Record
  • Dark Reading
  • Schneier on Security
  • AWS Security Bulletins
  • Ubuntu Security Notices

Why it lives in Lavawall®, and why it is free

Awareness is the cheapest control there is, so we do not charge for it. The security and IT news ticker is included at every tier, from the free Scout plan through Complete. It sits in the same console as your patching, your Microsoft 365 and Google Workspace breach detection, and your vulnerability findings, so a headline about an actively exploited vulnerability is one step from the fleet of machines you need to check. News you can act on beats news you merely read.

Start free, no credit cardSee everything Lavawall® includes

Common questions

Is the news ticker an extra cost?
No. The ticker and the threat-news reader are included at every tier, from the free Scout plan through Complete. There is nothing to add to your bill.
Where do the advisories come from?
Curated, authoritative sources: national cyber centres like the Canadian Centre for Cyber Security, CISA including its Known Exploited Vulnerabilities catalogue, NCSC UK and ACSC, vendor advisories from Microsoft, Dell, IBM, Tenable, N-able and others, and security news such as SANS Internet Storm Center and The Hacker News. CVEs link straight to their NVD entry.
Can an MSP set this up once for every client?
Yes. Company-wide defaults choose which sources are on for everyone, mark a source Required so it cannot be turned off, set console notifications, and set a minimum severity, per company, so you roll it out across your book without touching each user.
How do people get notified?
Each person picks what fits: a desktop ticker, an email digest at a chosen cadence and severity, in-console notifications, and browser push. The owner sets defaults and users tune from there.

Start my free trial →