Global Threats Insights
Global Threats Insights is a real-time cybersecurity intelligence ticker device — a purpose-built "Cyber Ticker" running on the LilyGO T-Display-S3...
Global Threats Insights
Category: Embedded Systems / Cybersecurity / Real-Time Intelligence Display
Platform: LilyGO T-Display-S3 (ESP32-S3)
Framework: Arduino via PlatformIO | C++
Status: Active — Production Ready
Project Overview
Global Threats Insights is a real-time cybersecurity intelligence ticker device — a purpose-built "Cyber Ticker" running on the LilyGO T-Display-S3. It continuously aggregates live threat data from three premier cybersecurity intelligence APIs and displays it in a richly formatted, colour-coded, on-screen dashboard. The device also runs a companion web server accessible via browser over the local network, providing a live HTML dashboard mirroring the on-screen display.
The project is aimed at security analysts, researchers, SOC operators, and cybersecurity enthusiasts who want always-on, at-a-glance situational awareness of the global threat landscape — delivered on a compact, portable ESP32-powered display.
Data Sources
The device cycles through three authoritative cybersecurity intelligence feeds, auto-refreshing every 60 seconds:
1. NIST National Vulnerability Database (NVD)
- Queries the official NIST NVD REST API v2.0 for the most recent CVEs published in the last 7 days
- Displays:
- CVE identifier (e.g., CVE-2026-12345)
- CVSS base score (v3.1, v3.0, or v2.0 — auto-selected in order of preference)
- Full vulnerability description (paginated if longer than display capacity)
- Visual feature: Colour-coded circular CVSS score badge rendered directly on the TFT
- Green: Low severity (0.0–3.9)
- Orange: Medium/High severity (4.0–8.9)
- Red: Critical severity (9.0–10.0)
- NTP time-synced date range queries — always fetches the most recent 7-day window
2. MalwareBazaar (abuse.ch)
- Queries the MalwareBazaar API for the most recently submitted malware sample
- Displays:
- Malware signature (family/variant name)
- Classification tags (e.g., ransomware, trojan, loader)
- Original filename of the submitted malware sample
- Visual feature: Dangerous extension highlighting — if the filename ends in .exe, .js, or .vbs, a red bounding box is drawn around the filename entry
3. AlienVault OTX (Open Threat Exchange)
- Queries the AlienVault OTX API for the most recently published threat intelligence pulse from subscribed feeds
- Displays:
- Campaign/pulse name
- Author/researcher who published the pulse
- Targeted country (if available)
- Visual feature: Country tag badge — a filled green pill/tag renders the targeted country name directly on screen
Display Features
Styled UI Border System
- Every screen features a custom multi-layer glowing cyan border with rounded corners and accent corner dots
- Creates a professional "security terminal" aesthetic on the small display
Real-Time Battery Indicator
- Battery voltage is read from GPIO 4 via ADC on every screen render
- Percentage is calculated from LiPo voltage curve (3.2V = 0%, 4.2V = 100%)
- Displayed in the top-right corner of every screen
Paginated Content Display
- Long vulnerability descriptions and malware data are automatically paginated
- Users can navigate forward and backward through content pages using the hardware buttons
- Each page is displayed for 8 seconds before auto-advancing
Deep Sleep Power Management
- Holding the left hardware button for 2 seconds initiates a graceful power-off sequence
- Device enters ESP32 deep sleep with GPIO 14 configured as the wake-up trigger
- Proper RTC GPIO pull-up configuration prevents false wake events
Hardware Button Controls
| Button | Short Press | Long Press (2s+) |
|---|---|---|
| Right (GPIO 14) | Advance to next data feed immediately | Wake from deep sleep |
| Left (GPIO 0) | Jump backward / shift feed state | Enter deep sleep |
Web Dashboard
The device runs an ESPAsyncWebServer on port 80, hosting:
- Root page (/) — Full HTML dashboard with styled panels for each of the three data sources (NVD, MalwareBazaar, AlienVault OTX)
- /api/data — JSON REST endpoint returning the latest fetched data for all three sources:
{ "nvd": "CVE-2026-XXXXX\nCVSS Score: 9.1\n...", "malware": "Sig: RedLine\nTag: stealer\n...", "alienvault": "Campaign: Operation Shadow\nAuthor: ..." }
The web dashboard is accessible from any browser on the same local network as the device.
Technical Architecture
| Component | Detail |
|---|---|
| MCU | ESP32-S3 @ 240 MHz |
| Display | ST7789 IPS TFT — 320x170 pixels (landscape) |
| Display Library | TFT_eSPI with viewport system |
| WiFi | WiFiManager — captive portal for first-run setup |
| HTTPS | WiFiClientSecure (setInsecure — no cert pinning) |
| JSON | ArduinoJson 7.x with streaming filter deserialization |
| Time | NTP via pool.ntp.org and time.nist.gov |
| Web Server | ESPAsyncWebServer + AsyncTCP |
| Power | ESP32 deep sleep with ext0 wakeup on GPIO 14 |
API Credentials Required
| Service | API Key Location |
|---|---|
| AlienVault OTX | ALIENVAULT_API_KEY constant in source |
| MalwareBazaar | MALWARE_BAZAAR_API_KEY constant in source |
| NIST NVD | No API key required (public endpoint) |
Deployment
- Install PlatformIO in VS Code
- Configure API keys in source (AlienVault OTX key, MalwareBazaar key)
- Build and flash to LilyGO T-Display-S3
- On first boot, connect to CyberTicker_AP WiFi hotspot and enter home network credentials
- Device auto-connects, syncs NTP time, and begins cycling threat feeds immediately
- Access web dashboard via device IP address on your local network
Use Cases
- Security Operations Centre (SOC) ambient awareness display
- Personal threat intelligence monitoring station
- Conference and event security awareness display
- Home lab real-time vulnerability monitoring
- Educational cybersecurity demonstration device