Attribution
Sources
Everything here is written by somebody else. This digest reads public feeds, decides which stories are worth a practitioner's attention, and links out; it does not host, mirror or reproduce anyone's articles. The headline, a one-line reason to read, and a short summary are all that appear, and every item links to the original.
The publications below are named because their work is public, widely known, and linked from every item that draws on it. They have not been asked, and naming them here implies no endorsement of this digest by them. It is not the complete list of what is read.
Listed publications
8-
AI security
- Embrace The Red (opens in a new tab) embracethered.com
- Simon Willison on prompt injection (opens in a new tab) simonwillison.net
-
Cross-cutting
- Hacker News (opens in a new tab) hn.algolia.com
-
DFIR
- Cellebrite (opens in a new tab) cellebrite.com
- Didier Stevens (opens in a new tab) blog.didierstevens.com
- Magnet Forensics (opens in a new tab) magnetforensics.com
- The DFIR Report (opens in a new tab) thedfirreport.com
-
Defense, cloud & appsec
- Cloudflare Blog (opens in a new tab) blog.cloudflare.com
- Datadog Security Labs (opens in a new tab) securitylabs.datadoghq.com
- Elastic Security Labs (opens in a new tab) elastic.co
- GitHub Security Blog (opens in a new tab) github.blog
- Google Security Blog (opens in a new tab) security.googleblog.com
- Red Canary (opens in a new tab) redcanary.com
-
Governance, risk & compliance
- CERT-EU Advisories (opens in a new tab) cert.europa.eu
- Cybersecurity Dive (opens in a new tab) cybersecuritydive.com
- Dark Reading (opens in a new tab) darkreading.com
- NCSC UK (opens in a new tab) ncsc.gov.uk
- NIST Cybersecurity Insights (opens in a new tab) nist.gov
- Schneier on Security (opens in a new tab) schneier.com
- Troy Hunt (opens in a new tab) feeds.feedburner.com
-
Offensive research
- Bishop Fox (opens in a new tab) bishopfox.com
- PortSwigger Research (opens in a new tab) portswigger.net
- Rapid7 (opens in a new tab) blog.rapid7.com
- Trail of Bits (opens in a new tab) blog.trailofbits.com
- watchTowr Labs (opens in a new tab) labs.watchtowr.com
-
Threat intelligence & incidents
- 404 Media (opens in a new tab) 404media.co
- Ars Technica Security (opens in a new tab) arstechnica.com
- BleepingComputer (opens in a new tab) bleepingcomputer.com
- Check Point Research (opens in a new tab) research.checkpoint.com
- Cisco Talos (opens in a new tab) blog.talosintelligence.com
- CrowdStrike (opens in a new tab) crowdstrike.com
- CyberScoop (opens in a new tab) cyberscoop.com
- ESET WeLiveSecurity (opens in a new tab) feeds.feedburner.com
- GreyNoise (opens in a new tab) greynoise.io
- Krebs on Security (opens in a new tab) krebsonsecurity.com
- Microsoft Security (opens in a new tab) microsoft.com
- Proofpoint (opens in a new tab) proofpoint.com
- Recorded Future (opens in a new tab) recordedfuture.com
- Securelist (opens in a new tab) securelist.com
- SentinelLabs (opens in a new tab) sentinelone.com
- Sophos Threat Research (opens in a new tab) news.sophos.com
- The Hacker News (opens in a new tab) feeds.feedburner.com
- The Record (opens in a new tab) therecord.media
- The Register Security (opens in a new tab) theregister.com
- Unit 42 (opens in a new tab) unit42.paloaltonetworks.com
- Volexity (opens in a new tab) volexity.com
- WIRED Security (opens in a new tab) wired.com
- Zscaler ThreatLabz (opens in a new tab) zscaler.com
-
Vulnerabilities & advisories
- CISA Advisories (opens in a new tab) cisa.gov
- CISA KEV (opens in a new tab) cisa.gov
- NVD (opens in a new tab) services.nvd.nist.gov
- Project Zero (opens in a new tab) googleprojectzero.blogspot.com
- SANS ISC Diary (opens in a new tab) isc.sans.edu
If you publish one of these
If you would rather not be read, would rather not be named on this page, or think something here misrepresents your work, say so and it will be acted on. No argument, no form to fill in. Write to cf@dsy.sh and it will be read by a person.
Removal is the default answer to a removal request. Nothing here is worth publishing over a publisher's objection.