Cybersecurity · Blogs and newsletters

Cybersecurity blogs and newsletters worth following, and what each is good for

These are the blogs and newsletters Briefwire reads to cover Cybersecurity, each one fetched and checked before it is listed. Company engineering blogs, analyst newsletters and practitioner posts. The receipt is the paragraph.

The list

In no ranked order. The note beside each says what it is good for, which is a different thing from how big it is.

  1. Original investigative reporting; frequently the first public account of a major breach.

  2. Policy and cryptography commentary; the standard citation for security-economics arguments.

  3. Fastest breach and ransomware reporting; high volume, high timeliness.

  4. Vendor funding, M&A and product coverage — the commercial layer of the security market.

  5. Authoritative US government advisories; the compliance-relevant primary source.

  6. Palo Alto's threat intelligence; detailed campaign write-ups with IOCs and timelines.

  7. Independent-leaning malware research; good technical depth on nation-state tooling.

  8. Breach-data analysis from the operator of Have I Been Pwned; authoritative on exposure scale.

  9. Vulnerability analysis and exploitation-likelihood assessments for prioritisation decisions.

  10. Cloud-security research; the reference source for multi-tenant cloud vulnerability classes.

  11. Curated daily security briefing; unusually good signal-to-noise for executive reading.

  12. Recorded Future's newsroom; strong on state-sponsored activity and policy.

  13. Large-telemetry threat research; quantified campaign scale from Cisco's install base.

  14. Federal cyber policy, budget and procurement moves; dates government demand shifts.

  15. Microsoft MSRC Update Guide

    Structured CVE and patch stream; the baseline for enterprise exposure every month.

  16. Cloud-provider vulnerability disclosures affecting customer workloads directly.

  17. Google Chrome Releases
  18. MSTIC threat-actor naming and campaign write-ups — the narrative stream, distinct from the MSRC CVE feed already tracked.

  19. Kaspersky's research team on APT tooling; often the only public account of campaigns in non-Western telemetry.

  20. Vulnerability and malware research with exploitation detail; publishes disclosure timelines vendors can be held to.

  21. Cloud-proxy telemetry on phishing and encrypted-channel abuse; quantified from a large SASE install base.

  22. Incident write-ups from the SMB and MSP estate — the segment enterprise-focused vendors do not see.

  23. Detection engineering and the annual Threat Detection Report; the reference ranking of observed ATT&CK techniques.

  24. Firmware and UEFI supply-chain research; the layer endpoint vendors structurally cannot inspect.

  25. Hardware and device supply-chain integrity research; names affected OEMs and models.

  26. Vulnerability triage with exploitation-likelihood calls; the prioritisation input for patch decisions.

  27. Canonical's per-package advisories; the patch-availability signal for the most common server distro.

  28. RHEL and OpenShift hardening and post-quantum migration positions from the vendor enterprises inherit defaults from.

  29. Audit firm publishing its own findings on cryptography and TEE assumptions; full posts ship in the feed.

  30. Aggressive n-day analysis of enterprise edge appliances, usually with a working reproduction.

  31. Where new web attack classes get named; request smuggling and cache poisoning both originated here.

  32. Thirty-year practitioner writing under his own name; blunt where vendor blogs hedge.

  33. Independent analyst on AI-security convergence and where the practitioner role is heading; one reputation on the line.

  34. Johns Hopkins cryptographer on encryption policy and protocol weaknesses; the standard technical rebuttal source.

  35. Investigative reporter working sources directly on election security and nation-state operations; long-form originals.

  36. Practitioner newsletter tracking new detection tooling and rules week by week; a named author's picks.

  37. Daily practitioner diaries on exploitation activity seen in the wild; the full-text feed, after isc.sans.edu/rssfeed.xml started serving the site's HTML under a text/xml content type.

  38. Malicious-package counts from the largest Maven and npm proxy; the volume series behind supply-chain claims.

  39. Threat-actor attribution and annual-report data from the largest endpoint vendor.

  40. The UK national authority's advisories and guidance; the non-US mandate source beside CISA.

  41. ESET's researchers on European and LATAM campaigns; strong on the espionage tooling US vendors under-cover.

  42. Software supply-chain and package-registry attacks; covered the npm worm arrests with named packages.

How the list was made, and what we do with it

Chosen by hand
Every source is here because people who work in Cybersecurity say substantive things on it, not because it is large. Enough of them to cover the field, few enough to audit.
Checked before listing
Each feed is fetched before it goes on the list, and a feed that answers but has stopped publishing is a fail, not a warning. Every source is English-language and public.
Read, so you need not
You do not have to read all of them. Each new post is read, and the claims worth keeping are pulled out with a link to the paragraph they came from.
Sent as a brief
The 12 lines that rank highest across the whole Cybersecurity beat go out daily or weekly. A claim several independent sources made ranks higher — that counts agreement, not accuracy.

The blogs and newsletters are one part of the beat. Every Cybersecurity source, all media — or just the YouTube channels.

Run one of these, or think one is missing? How sources are attributed, and how to reach us.

Blogs and newsletters in other industries

Cybersecurity in 12 lines a brief, each with a receipt.

14 days of Desk, every seat, card on file — cancel before day 14 and it is never charged. Or take three lines free by email every Monday, no account.