Some form of curation of reports seems like it would be an achievable (partial) solution. It seems like it would be less than perfect, but perhaps better than the status quo.
A lot of internal threat teams generate these kinds of reports, usually scoped on the organization(s) they support. Making these publicly available is a tricky proposition as a lot of companies sources are secret sauce kind of deals and they're most valuable when scoped explicitly on the software being used by the organization.
Some form of curation of reports seems like it would be an achievable (partial) solution. It seems like it would be less than perfect, but perhaps better than the status quo.