A Field Guide to Cybersecurity News Sources
8 min read · Updated Sep 22, 2026
Not all security sources do the same job. A breaking-news outlet, a government advisory, and a vendor research blog each have a different purpose, a different bias, and a different speed. Knowing which is which is half the skill of following the field. Here is how we think about the main categories — the same mix that feeds AttackFeed.
Security news publishers
These are the trade-press outlets: The Hacker News, BleepingComputer, The Register's security desk, CyberScoop, SecurityWeek, Infosecurity Magazine, and independent journalists like Krebs on Security. They're your fastest path to “what happened.”
- Best for: breadth and speed — breaches, arrests, policy, and the human story behind incidents.
- Watch for:headline pressure. The best (Krebs, BleepingComputer's technical write-ups) do original reporting; others repackage advisories with a spicier title. Always click through to the primary source for specifics.
Government agencies and national CERTs
CISA (US), the UK's NCSC, the FBI's IC3, and standards bodies like NIST publish advisories, alerts, and guidance. This is officialdom: slower, drier, and far more authoritative.
- Best for:ground truth. When CISA adds something to its Known Exploited Vulnerabilities catalog, that's a confirmed, act-now signal — not speculation. Government guidance is also the closest thing to a neutral reference.
- Watch for: latency and scope. Advisories are careful, which means they often trail the news by a day or two, and they focus on their own constituency (federal agencies, critical infrastructure).
ISACs and coordination centers
ISACs (Information Sharing and Analysis Centers) and coordination centers like Carnegie Mellon's CERT/CC and the SANS Internet Storm Center sit between government and industry. The SANS ISC's daily “diaries” in particular are a practitioner favorite — short, technical field notes from real analysts.
- Best for:practitioner-grade analysis and early warning of trends (spikes in scanning, new attack patterns) that haven't hit the mainstream yet.
- Watch for: access limits. Many sector ISACs (financial, health, energy) share their best material only with members, so the public feed is a fraction of what exists. REN-ISAC, for example, publishes no public feed at all.
Vendor and independent research
Security companies run some of the best research teams in the world — Palo Alto's Unit 42, Check Point Research, SentinelOne's Labs, Microsoft's threat intelligence, Google Project Zero, and boutique outfits like watchTowr. When a new campaign or zero-day is dissected, it's usually one of these teams doing it.
- Best for:depth — malware teardowns, threat-actor profiles, and original vulnerability discovery you won't get anywhere else.
- Watch for:the commercial angle. A vendor's research naturally highlights threats its products address. The technical findings are typically solid; just read the “what you should do” section knowing who wrote it.
Full-disclosure and mailing lists
The old-school channels — the Full Disclosure mailing list, exploit databases — are raw and unfiltered. This is often where a vulnerability or exploit surfaces first.
- Best for: being early, and for the unvarnished technical detail.
- Watch for: zero editorial layer. Accuracy and severity vary wildly; treat these as leads to verify, not conclusions.
How to combine them
A healthy security diet uses all five. Publishers and aggregators tell you something happened; government feeds tell you it's confirmed and serious; ISACs and vendor research tell you how it works; and mailing lists tell you it exists at all, sometimes before anyone else. AttackFeed pulls across all of these categories and tags each item so you can weight them yourself — see the About page for the full methodology, or jump into the live feed.