The Best Cybersecurity Newsletters, for Professionals and Everyone Else
Security reading splits sharply between people who do this for a living and people who just don't want to get breached. Here's what to read in each case.
The Subscribeam Team
The Subscribeam team builds tools for newsletter readers and creators — and writes about how to do both well.
Security is a field where reading the wrong newsletter is actively harmful. Not because the information is false, but because a daily feed of catastrophic breaches and unpatched zero-days produces a state of low-grade alarm that doesn't map onto anything you can do.
The useful split isn't by topic — it's by whether responding to this is your job. Those two audiences need almost entirely different reading.
It's also the field with the widest gap between what gets covered and what actually causes incidents. Coverage skews toward the novel and sophisticated, because that's what makes a good story. The incidents skew overwhelmingly toward reused passwords and unpatched software, which makes for terrible copy and is where nearly all the risk lives.
If security is your job
- Krebs on Security — Brian Krebs does original investigative reporting rather than aggregation, which in this field makes him close to unique. Particularly strong on the criminal economy: who is actually doing this, how the money moves, and why. Several times a week.
- Risky Business News — A concise daily rundown of what happened, with enough editorial judgement to indicate which items matter. The associated podcast covers the same ground if you prefer it. Daily, weekdays.
- tl;dr sec — Aimed squarely at people building security programmes: tooling, appsec, practical techniques. Dense with links and one of the better ways to keep up with the field's tooling churn. Weekly.
- CISA advisories and your vendors' bulletins — Not glamorous, and the actual job. If you are responsible for patching, the authoritative source beats a newsletter summarising it a day later. Subscribe to the ones covering software you actually run.
One note for professionals: resist subscribing to more than two general news sources. The overlap is enormous, and the marginal item you get from a third is almost never the one that mattered.
If security is not your job
Most people don't need breach coverage at all. What they need is the occasional prompt to do a specific thing, and almost nothing in the professional tier provides that.
Look for newsletters that are explicitly consumer-facing — the ones published by digital rights organisations and by a handful of writers who translate security news into “here is what to change in your settings.” The test is simple: does a typical issue end with an action you could take in ten minutes? If it ends with a CVE number, it isn't written for you.
The other genuinely useful subscription for a general reader is a breach notification service that tells you when an address of yours appears in a leak. That's a signal you can act on, arriving only when it applies to you, which is the opposite of how security news usually works.
The specialist tiers
Below the general news layer, security fragments into sub-fields that barely overlap, and this is where the reading gets genuinely valuable once you know which one is yours.
Application security. Newsletters covering vulnerability classes, secure coding and the tooling around it. If you write software, one of these does more for you than any amount of breach news, because it changes what you build rather than what you worry about.
Detection and response. Aimed at people running a SOC or on call for incidents. Heavy on detection engineering, log analysis and post-incident write-ups. The incident retrospectives are the valuable part — they're one of the few places anyone describes what actually went wrong in detail.
Cloud and infrastructure security. Fast-moving, because the platforms change constantly and a misconfiguration that was safe last year may not be now. This category ages faster than any other in security, which argues for reading it promptly.
Privacy and policy. Regulation, surveillance, cross-border data rules. Different intellectual territory from technical security, and increasingly the thing that determines what an organisation is allowed to do with the data it holds.
Pick the one matching your actual work and skip the others entirely. The breadth-first approach — subscribing across all four to be well-rounded — is how people end up with a security folder they stop opening.
What to be wary of
This category has more vendor-published content dressed as journalism than any other we've looked at, largely because security marketing budgets are enormous and fear converts well.
Newsletters that are lead generation. Plenty of excellent security writing is published by companies selling security products, and much of it is genuinely good. The thing to watch is whether the threat described is one their product happens to solve, in every single issue.
Anything with a countdown or a named apocalypse. Branded vulnerabilities with logos are marketing artefacts. Some are serious; the branding tells you nothing about which.
Aggregators with no triage. A list of every CVE published this week is a database dump. The value in security writing is entirely in someone telling you which three of the four hundred matter to you.
Breach coverage without remediation. An article telling you a company you use was breached, with no guidance on what to do, generates anxiety and nothing else.
Reading security news without dread
A real problem in this field, and worth treating as one. Two habits help.
Separate the interesting from the applicable. Most security news is interesting. Very little of it is applicable to you. Read with the question “does this touch something I run or use?” and let the rest pass as industry awareness rather than a task.
Batch it. Security news is the worst possible candidate for real-time consumption, because the incentive to publish immediately means early reports are frequently wrong. Reading a week's worth in one sitting gets you the corrected version and a fraction of the anxiety. The only exception is an actively exploited vulnerability in something you operate, and for that you want vendor alerts, not a newsletter.
Podcasts and the overlap problem
A large share of security newsletters have an accompanying podcast covering the same material, and people frequently subscribe to both without noticing the duplication.
Pick one. The podcast is generally better for context and the reasoning behind a story; the newsletter is better for scanning and for the links. If you commute, the podcast probably wins on time you weren't using anyway. If you need to act on specifics, the written version is the one you can search six months later.
A note for small businesses
If you run something small and have no security staff, the professional newsletters will mislead you by implication. They describe threat models belonging to organisations with dedicated teams, and reading them suggests your priorities should be similar. They shouldn't.
Almost everything that happens to small organisations comes through a short list: credential reuse, phishing, unpatched public-facing software, and no backups. One newsletter aimed at your sector, plus vendor advisories for what you run, covers more real risk than any amount of following the wider field.
Building the list
For professionals: one investigative source, one daily rundown, one practitioner newsletter for your specialism, plus vendor advisories. Four, and the fourth is the only one that's truly obligatory.
For everyone else: one consumer-facing newsletter and a breach notification service. That's genuinely it.
You can add several at once from the Subscribeam directory and cut back from one place once you see what the volume actually feels like — worth doing here, because security newsletters are frequent and it's easy to underestimate the load. And given the cadence, set up a filter first: our Gmail filters guide takes ten minutes and keeps a daily security digest from burying anything that needs a reply.
Subscribe to your favourites in one click
Browse the Subscribeam directory, pick the newsletters you want, and enter your email once. Manage or cancel any of them from a single place.
Browse newslettersKeep reading
The Best AI Newsletters in 2026, Sorted by How Technical You Want It
AI is the noisiest newsletter category there is. These are the ones worth reading — split by how much maths you want, and with a note on which hype signals to walk away from.
Should Your Side Project Have a Newsletter? A Straight Answer
Everyone tells you to build an audience. Here's when a newsletter genuinely helps a side project, when it's a distraction, and what a low-effort version looks like.