Sources we summarize
Every syndicated item on this site comes from a publication an editor has explicitly approved. We publish a headline, a short original summary and a link to the original article; we never reproduce full articles or images without permission. Read the source attribution policy.
| Publication | Website | Items summarized | Notes |
|---|---|---|---|
| Adversa AI | adversa.ai | 2 | AI red-teaming news digests. |
| AI Incident Database | incidentdatabase.ai | 20 | Catalogue of real-world AI harms and security incidents. |
| Apple Developer | developer.apple.com | 0 | Apple software release announcements (pair with Apple security content pages). |
| Ars Technica | arstechnica.com | 4 | Technology press; careful technical security reporting. |
| arXiv cs.CR | arxiv.org | 0 | Academic preprints in cryptography and security (high volume). |
| Binarly | binarly.io | 0 | Firmware and UEFI supply-chain research. |
| Bishop Fox | bishopfox.com | 2 | Offensive security research and tooling. |
| BlackFog | blackfog.com | 0 | Monthly "State of Ransomware" reports counting disclosed and undisclosed attacks (vendor). |
| BleepingComputer | bleepingcomputer.com | 15 | Fast mainstream desk for ransomware, breach and malware news. |
| Canadian Centre for Cyber Security | cyber.gc.ca | 25 | Official Canadian alerts and advisories. |
| CERT-EU | cert.europa.eu | 0 | Computer Emergency Response Team for the EU institutions. |
| CERT/CC | kb.cert.org | 3 | Carnegie Mellon CERT Coordination Center vulnerability notes. |
| Check Point Research | research.checkpoint.com | 2 | Weekly threat intelligence bulletins and deep dives. |
| Chrome Releases | chromereleases.googleblog.com | 16 | Google Chrome stable channel updates incl. zero-day fixes. |
| CISA | cisa.gov | 0 | US Cybersecurity and Infrastructure Security Agency: alerts, KEV additions and advisories. Blocks some automated clients; test from the production server. |
| Cisco PSIRT | sec.cloudapps.cisco.com | 25 | Official Cisco security advisories. |
| Cisco Security | blogs.cisco.com | 0 | Cisco security blog incl. AI Defense / Robust Intelligence research. |
| Cisco Talos | blog.talosintelligence.com | 3 | Cisco Talos threat research: campaign write-ups with indicators. |
| Citizen Lab | citizenlab.ca | 0 | University of Toronto: spyware and civil-society targeting research. |
| Claroty Team82 | claroty.com | 0 | OT/ICS and IoT vulnerability research. |
| Cloud Security Alliance | cloudsecurityalliance.org | 0 | AI Safety Initiative guidance and frameworks. |
| Cloudflare | blog.cloudflare.com | 4 | Internet measurement, DDoS reports and incident post-mortems (filter for security). |
| Comparitech | comparitech.com | 0 | Monthly ransomware round-ups and studies. |
| Coveware | coveware.com | 0 | Quarterly ransomware payment and negotiation statistics. |
| CrowdStrike | crowdstrike.com | 0 | Adversary reports and Counter Adversary Operations. |
| CyberScoop | cyberscoop.com | 9 | US government, policy and law-enforcement cybersecurity news. |
| Cyble | cyble.com | 1 | Dark-web and ransomware monitoring; high volume. |
| Dark Reading | darkreading.com | 17 | Enterprise security news and analysis. |
| DataBreaches.net | databreaches.net | 10 | Independent breach and ransomware reporting with direct follow-up. |
| Datadog Security Labs | securitylabs.datadoghq.com | 2 | Cloud security research. |
| Debian Security | debian.org | 10 | Debian Security Advisories. |
| Doyensec | blog.doyensec.com | 1 | Application security research. |
| Eclypsium | eclypsium.com | 1 | Firmware and hardware security research. |
| Elastic Security Labs | elastic.co | 2 | Malware analysis and detection research. |
| Embrace The Red | embracethered.com | 0 | Johann Rehberger: AI red-team research and prompt-injection exploits against real products. |
| Emsisoft | emsisoft.com | 1 | Ransomware statistics and decryptor news. |
| ESET WeLiveSecurity | welivesecurity.com | 3 | ESET Research: APT activity reports and malware analysis with strong European coverage. |
| Europol | europol.europa.eu | 10 | Official newsroom: takedowns, arrests and operations against ransomware and cybercrime groups. |
| Exploit-DB | exploit-db.com | 0 | Public exploit availability (OffSec). |
| Flashpoint | flashpoint.io | 2 | Cybercrime, ransomware and vulnerability intelligence. |
| Fortinet PSIRT | fortiguard.com | 0 | Official Fortinet advisories. |
| Full Disclosure | seclists.org | 0 | Public disclosure mailing list: unvetted, verify before publishing. |
| GitHub Security Lab | securitylab.github.com | 0 | Open-source vulnerability research and CodeQL. |
| GitLab | about.gitlab.com | 0 | Official GitLab security releases. |
| Google Project Zero | projectzero.google | 0 | Vulnerability research by Google. Its feed carries full post bodies (about 13 MB); raise FEED_MAX_BYTES above 13000000 in .env before enabling. |
| Google Security Blog | security.googleblog.com | 0 | Google Online Security Blog incl. AI vulnerability discovery and agent security. |
| Google Threat Intelligence Group | cloud.google.com | 0 | Google / Mandiant threat intelligence: APT reporting and zero-day exploitation trends. |
| Graham Cluley | grahamcluley.com | 3 | Independent security news and commentary. |
| GreyNoise Labs | greynoise.io | 0 | Internet-wide scanning and exploitation telemetry. |
| Group-IB | group-ib.com | 4 | Cybercrime and APAC/EMEA threat research. |
| GuidePoint Security | guidepointsecurity.com | 2 | GRIT ransomware and cyber-threat reports: group activity, sector and country breakdowns (vendor). |
| Halcyon | halcyon.ai | 6 | Ransomware group profiles and attack round-ups (vendor). |
| Have I Been Pwned | haveibeenpwned.com | 1 | Troy Hunt: verified breach datasets with record counts and data classes. Data licensed CC BY 4.0; attribution required. |
| Help Net Security | helpnetsecurity.com | 10 | Information security news and report round-ups. |
| HIPAA Journal | hipaajournal.com | 10 | US healthcare breaches built from HHS OCR filings. |
| Horizon3.ai | horizon3.ai | 0 | Exploit analysis of high-profile CVEs. |
| Hornetsecurity | hornetsecurity.com | 1 | Ransomware attack surveys and monthly threat reports (vendor). |
| Hudson Rock | infostealers.com | 3 | Infostealer-log driven compromises (vendor; verify claims). |
| Huntress | huntress.com | 3 | SMB-focused tradecraft and active exploitation reports. |
| Identity Theft Resource Center | idtheftcenter.org | 0 | Non-profit breach statistics and reports. |
| Infosecurity Magazine | infosecurity-magazine.com | 25 | UK/European cybersecurity news, regulation and breaches. |
| Intel 471 | intel471.com | 0 | Underground and cybercrime intelligence. |
| JFrog Security Research | research.jfrog.com | 1 | Open-source and supply-chain vulnerability research. |
| JPCERT/CC | jpcert.or.jp | 0 | Japan Computer Emergency Response Team (English feed). |
| Kaspersky Securelist | securelist.com | 2 | Kaspersky GReAT research (Russian-headquartered vendor; use for technical facts). |
| Krebs on Security | krebsonsecurity.com | 1 | Investigative cybercrime journalism by Brian Krebs. |
| Malwarebytes Labs | malwarebytes.com | 16 | Consumer-facing threat news: scams, malvertising, mobile. |
| MDSec | mdsec.co.uk | 0 | Red-team tradecraft research. |
| Microsoft Security | microsoft.com | 2 | Microsoft Security Blog incl. Microsoft Threat Intelligence and AI security research. |
| Microsoft Security Response Center | msrc.microsoft.com | 23 | Every Microsoft CVE as it is published (Security Update Guide). |
| NCSC UK | ncsc.gov.uk | 2 | UK National Cyber Security Centre. |
| NCSC-NL | advisories.ncsc.nl | 18 | Dutch National Cyber Security Centre advisories. |
| oss-security | openwall.com | 9 | Open-source security coordination list. |
| Outflank | outflank.nl | 0 | Red-team tradecraft research. |
| OWASP GenAI Security Project | genai.owasp.org | 0 | OWASP Top 10 for LLM applications and agentic security guidance. |
| Palo Alto Networks PSIRT | security.paloaltonetworks.com | 0 | Official Palo Alto Networks advisories. |
| Palo Alto Networks Unit 42 | unit42.paloaltonetworks.com | 4 | Threat actor profiles, malware analysis and incident-response trends. |
| PortSwigger Research | portswigger.net | 0 | Web security research. |
| Praetorian | praetorian.com | 1 | Offensive security research. |
| Proofpoint | proofpoint.com | 0 | E-mail threat landscape, initial-access brokers, TA-numbered actors. |
| Qualys | threatprotect.qualys.com | 3 | Qualys Threat Research Unit vulnerability analysis. |
| RansomLook | ransomlook.io | 11 | Independent leak-site tracker; cross-check for ransomware.live. Entries are claims, not confirmed incidents. |
| ransomware.live | ransomware.live | 16 | Independent leak-site tracker by Julien Mousqueton. Entries are claims made by criminal groups, not confirmed incidents; attribution to ransomware.live expected. |
| Rapid7 | rapid7.com | 3 | Vulnerability analysis and Metasploit research. |
| Recorded Future | recordedfuture.com | 4 | Insikt Group research. |
| SANS Internet Storm Center | isc.sans.edu | 10 | Daily handler diaries on observed attacks and honeypot data. |
| Schneier on Security | schneier.com | 9 | Bruce Schneier: security and policy analysis. |
| Security Affairs | securityaffairs.com | 10 | Very high-volume security news blog by Pierluigi Paganini. |
| SecurityWeek | securityweek.com | 10 | Professional cybersecurity news desk. |
| SentinelLABS | sentinelone.com | 2 | SentinelOne research on APT and cybercrime activity. |
| Simon Willison | simonwillison.net | 21 | Coined "prompt injection"; tracks LLM security incidents and papers (filter for security). |
| SOCRadar | socradar.io | 10 | Dark-web and ransomware group reports. |
| Sonar | sonarsource.com | 7 | Code-level vulnerability research in popular open-source applications. |
| SpecterOps | specterops.io | 2 | Identity and Active Directory attack-path research. |
| Splunk | advisory.splunk.com | 0 | Official Splunk security advisories. |
| Straiker | straiker.ai | 2 | AI agent attack research (STAR Labs). |
| Synacktiv | synacktiv.com | 25 | French offensive security research. |
| TechCrunch | techcrunch.com | 8 | Technology press; breaks and confirms large data breaches. |
| Tenable | tenable.com | 2 | Patch Tuesday breakdowns and CVE FAQs. |
| The DFIR Report | thedfirreport.com | 0 | Independent, detailed real-intrusion case studies with TTPs. |
| The Hacker News | thehackernews.com | 25 | High-volume daily cybersecurity news. |
| The Record | therecord.media | 5 | Independent newsroom funded by Recorded Future; cybercrime, government and policy. |
| The Register | theregister.com | 24 | UK technology press with a strong security desk. |
| ThreatDown | threatdown.com | 0 | Malwarebytes business unit: monthly ransomware reviews and group analyses. |
| Trail of Bits | blog.trailofbits.com | 2 | Applied research: cryptography, compilers, AI/ML security. |
| Trend Micro Research | trendmicro.com | 0 | Trend Micro threat research. |
| Ubuntu Security | ubuntu.com | 10 | Ubuntu Security Notices. |
| UpGuard | upguard.com | 0 | Vendor research on exposed data and misconfigured storage. |
| Volexity | volexity.com | 0 | Zero-day exploitation and APT disclosures; low volume, high impact. |
| watchTowr Labs | labs.watchtowr.com | 0 | Vulnerability research on edge devices with strong write-ups. |
| Wired | wired.com | 9 | Long-form security features. |
| Wiz | wiz.io | 3 | Cloud and AI-infrastructure vulnerability research (filter research from product news). |
| Wordfence | wordfence.com | 7 | WordPress ecosystem vulnerabilities. |
| Zero Day Initiative | zerodayinitiative.com | 26 | Trend Micro ZDI coordinated disclosures. |
| Zscaler ThreatLabz | zscaler.com | 1 | Zscaler threat research. |
Publishers who would like their content removed or attributed differently can use the takedown process.
