Beat · Cybersecurity

Cybersecurity: the podcasts, blogs and shows worth following

Threat intelligence, breach reporting, and the advisories that drive enterprise security spend. These are the public sources Briefwire reads to cover it — the podcasts, blogs and shows — each fetched and checked before it is listed, and each with a note on what it is good for.

What is in it

Podcasts, blogs and shows.

Keywords it starts with

breach · vulnerability · ransomware · advisory

Library as of

19 September 2026. Every source is English-language and public: nothing behind a paywall or a login is read.

Podcasts

Where operators and investors reason out loud at length. The receipt for a line from one of these is a timestamp.

  1. Narrative incident retellings; ships transcripts, so episodes are extractable once wired.

  2. Security Now

    Long-running deep-dive show on protocol and crypto weaknesses; carries transcripts.

  3. Security Cryptography Whatever

    Deirdre Connolly, Thomas Ptacek and David Adrian arguing about real protocol decisions; ships transcripts.

  4. Weekly analyst-grade discussion of the security news cycle with vendor-market context.

  5. Cloud Security Podcast by Google

    Anton Chuvakin interviewing detection and cloud-security leads; candid on what SOC automation does not solve.

  6. Open Source Security

    Josh Bressers on open-source supply chain, CVE process and CRA compliance; ships transcripts.

Blogs and newsletters

Company engineering blogs, analyst newsletters and practitioner posts. The receipt is the paragraph.

Just the Cybersecurity blogs and newsletters

  1. Original investigative reporting; frequently the first public account of a major breach.

  2. Policy and cryptography commentary; the standard citation for security-economics arguments.

  3. Fastest breach and ransomware reporting; high volume, high timeliness.

  4. Vendor funding, M&A and product coverage — the commercial layer of the security market.

  5. Authoritative US government advisories; the compliance-relevant primary source.

  6. Palo Alto's threat intelligence; detailed campaign write-ups with IOCs and timelines.

  7. Independent-leaning malware research; good technical depth on nation-state tooling.

  8. Breach-data analysis from the operator of Have I Been Pwned; authoritative on exposure scale.

  9. Vulnerability analysis and exploitation-likelihood assessments for prioritisation decisions.

  10. Cloud-security research; the reference source for multi-tenant cloud vulnerability classes.

  11. Curated daily security briefing; unusually good signal-to-noise for executive reading.

  12. Recorded Future's newsroom; strong on state-sponsored activity and policy.

  13. Large-telemetry threat research; quantified campaign scale from Cisco's install base.

  14. Federal cyber policy, budget and procurement moves; dates government demand shifts.

  15. Microsoft MSRC Update Guide

    Structured CVE and patch stream; the baseline for enterprise exposure every month.

  16. Cloud-provider vulnerability disclosures affecting customer workloads directly.

  17. Google Chrome Releases
  18. MSTIC threat-actor naming and campaign write-ups — the narrative stream, distinct from the MSRC CVE feed already tracked.

  19. Kaspersky's research team on APT tooling; often the only public account of campaigns in non-Western telemetry.

  20. Vulnerability and malware research with exploitation detail; publishes disclosure timelines vendors can be held to.

  21. Cloud-proxy telemetry on phishing and encrypted-channel abuse; quantified from a large SASE install base.

  22. Incident write-ups from the SMB and MSP estate — the segment enterprise-focused vendors do not see.

  23. Detection engineering and the annual Threat Detection Report; the reference ranking of observed ATT&CK techniques.

  24. Firmware and UEFI supply-chain research; the layer endpoint vendors structurally cannot inspect.

  25. Hardware and device supply-chain integrity research; names affected OEMs and models.

  26. Vulnerability triage with exploitation-likelihood calls; the prioritisation input for patch decisions.

  27. Canonical's per-package advisories; the patch-availability signal for the most common server distro.

  28. RHEL and OpenShift hardening and post-quantum migration positions from the vendor enterprises inherit defaults from.

  29. Audit firm publishing its own findings on cryptography and TEE assumptions; full posts ship in the feed.

  30. Aggressive n-day analysis of enterprise edge appliances, usually with a working reproduction.

  31. Where new web attack classes get named; request smuggling and cache poisoning both originated here.

  32. Thirty-year practitioner writing under his own name; blunt where vendor blogs hedge.

  33. Independent analyst on AI-security convergence and where the practitioner role is heading; one reputation on the line.

  34. Johns Hopkins cryptographer on encryption policy and protocol weaknesses; the standard technical rebuttal source.

  35. Investigative reporter working sources directly on election security and nation-state operations; long-form originals.

  36. Practitioner newsletter tracking new detection tooling and rules week by week; a named author's picks.

  37. Daily practitioner diaries on exploitation activity seen in the wild; the full-text feed, after isc.sans.edu/rssfeed.xml started serving the site's HTML under a text/xml content type.

  38. Malicious-package counts from the largest Maven and npm proxy; the volume series behind supply-chain claims.

  39. Threat-actor attribution and annual-report data from the largest endpoint vendor.

  40. The UK national authority's advisories and guidance; the non-US mandate source beside CISA.

  41. ESET's researchers on European and LATAM campaigns; strong on the espionage tooling US vendors under-cover.

  42. Software supply-chain and package-registry attacks; covered the npm worm arrests with named packages.

YouTube shows

Interviews, conference talks and explainers, read from their published captions.

Just the Cybersecurity YouTube channels

  1. Malware and incident walkthroughs; fast technical read on live campaigns.

  2. Vulnerability-research explainers; useful for translating CVEs into business risk.

  3. Offensive-technique demonstrations; grounds red-team capability claims in evidence.

  4. Enterprise-facing security research briefings; the vendor-facing half of the conference circuit.

  5. US government briefings on active campaigns and binding directives; the mandate source.

  6. Long unedited practitioner interviews; candid on tooling choices and career signal.

  7. Instructor webcasts and threat briefings carrying named detection detail.

  8. Weekly unscripted infosec news and live webcasts by working testers; opinionated on tooling that fails in practice.

  9. Bug-bounty hunter demonstrating live exploitation, including AI-assistant prompt-injection chains.

What Briefwire does with them

  1. 01Reads

    Every source above is fetched through the day. Spoken sources are read from their published transcript or captions; written ones from the post itself.

  2. 02Extracts and matches

    Discrete claims are pulled out, typed — a product move, a data point, a prediction, an opinion — and matched against the same claim from other publishers.

  3. 03Ranks and sends

    The 12 lines that rank highest go out as a brief, daily or weekly at the hour you choose. A claim several independent sources made ranks higher; that counts agreement, not accuracy, and every line links to where it was said.

More on the method: how a line earns its place, what industry intelligence is, and how this differs from page monitors, podcast summarisers, industry newsletters, and the other tools you may already run.

Run one of the sources above, or think one is missing? How sources are attributed, and how to reach us.

The other industries Briefwire reads

Cybersecurity in 12 lines a brief, each with a receipt.

14 days of Desk, every seat, card on file — cancel before day 14 and it is never charged. Or take three lines free by email every Monday, no account.