Skip to main content

Staying ahead of threats and industry shifts means keeping your inbox stocked with the right IT security newsletters. I’ve pulled together trusted newsletters that help you cut through noise and stay sharp, whether you’re troubleshooting, planning upgrades, or keeping leadership informed.

Best IT Security Newsletters Shortlist

Here's a shortlist of the best IT security newsletters I think are worth subscribing to:

  1. Krebs on Security - Best for cybercrime investigations
  2. The Hacker News - Best for timely vulnerability alerts
  3. Dark Reading - Best for enterprise security news and analysis
  4. SANS NewsBites - Best for expert-annotated cybersecurity headlines
  5. Crypto-Gram - Best for security leadership and policy analysis
  6. CyberWire Daily Briefing - Best for cybersecurity intelligence
  7. Risky Business - Best for independent news and policy analysis
  8. tl;dr sec - Best for technical roundups across AppSec, cloud, and AI
  9. SecurityWeek Daily Briefing - Best for enterprise security updates
  10. Infosecurity Magazine - Best for global threats and CISO insights

The 17 Best IT Security Newsletters

Below are my summaries of the best IT security newsletters that made it onto my shortlist, plus others worth mentioning. My reviews offer a look at each newsletter's audience, frequency, cost, and more.

1. Krebs on Security - Best for cybercrime investigations

Screenshot of sample Krebs on Security newsletter
KrebsOnSecurity uncovers cybercrime, security breaches, and the people behind major digital threats.
  • Audience: IT security professionals and cybersecurity researchers
  • Frequency: Multiple times per week
  • Cost: Free

Krebs on Security is Brian Krebs's independent investigative publication, covering cybercrime, data breaches, and threat actor activity with a depth you rarely find elsewhere. 

It's been a go-to resource for security professionals since 2009, when Krebs left The Washington Post to report on computer security full-time.

Why subscribe? If you want long-form reporting that actually follows the money—tracing ransomware gangs, fraud networks, and breach timelines back to their source—this is the one to bookmark. Brian Krebs has a reputation for breaking major stories before mainstream outlets pick them up, meaning you often get early, accurate intelligence on threats that could affect your environment.

2. The Hacker News - Best for timely vulnerability alerts

The Hacker News webpage
The Hacker News keeps security professionals updated on cyberattacks, vulnerabilities, and threat intelligence.
  • Audience: Cybersecurity professionals, IT administrators, and researchers
  • Frequency: Daily
  • Cost: Free

Hacker News was founded in 2010 by Mohit Kumar and has grown into one of the most widely read cybersecurity news outlets. It's built for IT and security professionals who need to stay current on vulnerabilities, breaches, and active threat campaigns.

Why subscribe? Where The Hacker News earns its place in your inbox is speed—CVE disclosures, active exploit alerts, and patch advisories land quickly, so you're not catching up days later. The daily format gives you a consistent pulse on what's happening across the threat landscape without having to hunt through multiple sources.

Get regular tech leadership wisdom for delivering better software and systems.

Name*
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form

3. Dark Reading - Best for enterprise security news and analysis

The sign up page for the Dark Reading newsletter
Dark Reading combines cybersecurity news with expert analysis and defensive best practices.
  • Audience: Enterprise security professionals, CISOs, and IT risk managers
  • Frequency: Daily
  • Cost: Free

Dark Reading has been covering enterprise cybersecurity for over 20 years and is operated by Informa TechTarget. It's aimed squarely at security leaders and practitioners working in complex enterprise environments.

Why subscribe? Dark Reading goes deeper than headlines—you'll find analysis across application security, cloud risk, ICS/OT, IAM, and more, so it's useful whether you're a CISO thinking about risk posture or an analyst tracking specific threat domains. The CISO Corner content is worth calling out if you're in a leadership role, as it focuses on strategic security decisions rather than just technical advisories. 

4. SANS NewsBites - Best for expert-annotated cybersecurity headlines

Sample of the SANS Newsbites newsletter in desktop version
SANS NewsBites curates the week’s important security stories with actionable expert insights.
  • Audience: Security executives and senior cybersecurity professionals
  • Frequency: Twice a week
  • Cost: Free

SANS NewsBites is a twice-weekly cybersecurity digest published by the SANS Institute, now in its 28th volume. Each issue curates the week's most significant security news and pairs it with expert commentary from practitioners within the SANS community.

Why subscribe? What sets NewsBites apart is that annotation layer—you're not just getting links; you're getting context from people who understand the operational implications of what they're covering, from Patch Tuesday breakdowns to critical infrastructure alerts.

It's especially useful if you're a senior practitioner or security leader who needs to stay informed but wants expert framing, not just raw headlines. 

5. Crypto-Gram - Best for security leadership and policy analysis

The Crypto-Gram newsletter landing page
Crypto-Gram delivers Bruce Schneier’s monthly insights on cybersecurity, privacy, and public policy.
  • Audience: Security pros, technologists, and policy experts worldwide
  • Frequency: Monthly
  • Cost: Free

Crypto-Gram is a monthly newsletter by Bruce Schneier—one of the most influential voices in cybersecurity—that has been running since 1998. It compiles his blog posts from the previous month into a single digest covering cryptography, privacy, AI security, surveillance, and the policy decisions shaping all of it.

Why subscribe? What Schneier brings that most security newsletters don't is a genuine policy and societal lens—he's a Harvard Kennedy School lecturer and EFF board member, so his commentary connects technical developments to their real-world implications in ways that go beyond patch notes and threat advisories. 

It's a particularly good fit if you're a senior practitioner or security leader who wants to think more deeply about where the field is heading, not just what's happening right now.

6. CyberWire Daily Briefing - Best for cybersecurity intelligence

The sign up page with newsletter archive of the CyberWire Daily Briefing
CyberWire Daily Briefing covers daily cyber threats, research, policy, and market developments.
  • Audience: Cybersecurity practitioners and decision-makers in all industries
  • Frequency: Every weekday
  • Cost: Free

The CyberWire Daily Briefing is a free weekday newsletter from N2K Networks that delivers a concise situational awareness digest covering threats, vulnerabilities, policy, and marketplace news. It's built for cybersecurity professionals who need to stay current without spending hours tracking multiple sources.

Why subscribe? The Daily Briefing covers a wide range—from active ransomware campaigns and supply chain attacks to CISA advisories and regulatory developments—so you're getting a broad view of the landscape in one place each morning. It's particularly useful if your role requires you to stay informed across domains, whether that's threat intelligence, compliance, or security leadership.

7. Risky Business - Best for independent news and policy analysis

The sign up page for the Risky Business newsletter
Risky Business breaks down important cybersecurity news and emerging security issues.
  • Audience: Security professionals, policymakers, and industry researchers worldwide
  • Frequency: Four times a week
  • Cost: Free

Risky Business is an independent cybersecurity media brand founded by Patrick Gray in 2007, publishing two free newsletters written by Catalin Cimpanu and Tom Uren. Between them, you get four editions a week covering everything from active threat intelligence to the policy and geopolitical forces shaping the security industry.

Why subscribe? What sets Risky Business apart is the caliber of its writers—Cimpanu is one of the most prolific security journalists working today, and Uren spent 15 years at the Australian Signals Directorate before turning to analysis. 

The Risky Bulletin covers operational news such as breaches, APTs, and law enforcement actions, while Seriously Risky Business takes a broader lens on government policy and intelligence.

8. tl;dr sec - Best for technical roundups across AppSec, cloud, and AI

The sample newsletter of the tl;dr sec
tl;dr sec curates actionable security research, tools, and industry developments.
  • Audience: Application and cloud security professionals and engineers
  • Size: 90,000+ members
  • Frequency: Weekly
  • Cost: Free

tl;dr sec is a free weekly newsletter written by Clint Gibler, a well-respected AppSec researcher who most recently led cyber efforts at OpenAI. Each issue distills the best tools, conference talks, research papers, and writeups across application security, cloud security, AI/ML security, and red teaming into a single digestible read.

Why subscribe? What I find valuable here is Gibler's curation judgment—he's a practitioner, so the resources he highlights are the ones engineers and security researchers actually use, not just trending headlines. Each issue tends to cover a focused set of topics in depth, so you come away with leads on real tools and techniques rather than just summaries. 

9. SecurityWeek Daily Briefing - Best for enterprise security updates

The sign up page for the SecurityWeek Daily Briefing newsletter
SecurityWeek Daily Briefing tracks emerging threats, security trends, and technology developments.
  • Audience: Enterprise CISOs, analysts, incident responders, and security leaders
  • Frequency: Daily
  • Cost: Free

The SecurityWeek Daily Briefing is a free daily newsletter from SecurityWeek, an enterprise cybersecurity publication that's been running since 2010. It's edited by Mike Lennon and features contributions from recognized names like Ryan Naraine and Kevin Townsend, covering everything from threat intelligence and malware to CISO strategy and ICS/OT security.

Why subscribe? If you're in a leadership or senior analyst role, this is a solid daily briefing that covers the full spectrum of enterprise security—incident response, risk management, cloud, endpoint protection, and network security—without narrowing to a single domain. The editorial perspective skews toward decision-makers, so the coverage tends to connect technical developments to business and strategic implications.

10. Infosecurity Magazine - Best for global threats and CISO insights

Screenshot of Infosecurity Magazine's webpage
Infosecurity Magazine explores emerging threats, security technologies, and industry trends.
  • Audience: Global information security professionals and CISO-level decision makers
  • Frequency: Weekly
  • Cost: Free

Infosecurity Magazine is a weekly newsletter from Reed Exhibitions (part of RELX Group), the same organization behind the Infosecurity Europe conference, making it one of the more institutionally grounded publications in the space.

It covers the full breadth of information security—from ransomware and threat intelligence to regulatory developments and cloud security—with a notably strong EMEA perspective alongside global coverage.

Why subscribe? What sets this one apart is the connection to the broader Infosecurity ecosystem, which means the newsletter often surfaces event-driven insights, expert commentary, and research that ties directly into what's being discussed at the industry level. Coverage skews toward senior practitioners and leaders, so the framing tends to connect technical developments to policy, compliance, and organizational risk.

11. CyberScoop - Best for federal cybersecurity news

The CyberScoop webpage screenshot
CyberScoop covers major cyberattacks, vulnerabilities, government policy, and emerging threats.
  • Audience: Federal cybersecurity leaders and enterprise IT security executives
  • Frequency: Daily
  • Cost: Free

CyberScoop is a daily cybersecurity newsletter run by Scoop News Group, a D.C.-based media company that also operates FedScoop and DefenseScoop. It covers threat intelligence, breaches, and industry developments with a distinctly strong lens on federal government cybersecurity policy and public sector initiatives.

Why subscribe? If your work touches federal IT security, government compliance, or public sector infrastructure, CyberScoop is one of the few newsletters that covers that intersection with real depth and consistency. You'll get daily coverage that connects enterprise security developments to what's happening at the policy and regulatory level in Washington—context that's hard to find elsewhere. 

12. Unsupervised Learning - Best for AI and security trend analysis

The sign up page of the Unsupervised Learning newsletter
Unsupervised Learning connects cybersecurity, AI, technology, and culture with thoughtful analysis.
  • Audience: CISOs, security professionals, hackers, and technologists
  • Size: 110,000+ members
  • Frequency: Weekly
  • Cost: Free

Unsupervised Learning is a weekly newsletter and podcast run by Daniel Miessler, a veteran security practitioner and creator of well-known open-source projects like SecLists and the Fabric AI framework. It covers the intersection of cybersecurity, AI, national security, and technology through curated summaries and original essays.

Why subscribe? What makes this one distinct is Daniel's analytical framing—rather than just reporting what happened, he contextualizes trends and connects security developments to broader shifts in AI and technology. Each issue reflects 5–20 hours of research and reading, so you're getting a distilled, opinionated take rather than a straight news digest. 

13. CISO Series - Best for security leadership and vendor insights

The sign up page for the CISO Series newsletter
CISO Series offers practical cybersecurity insights from CISOs and industry professionals.
  • Audience: CISOs, security leaders, and cybersecurity vendors
  • Frequency: Bi-weeekly
  • Cost: Free

CISO Series is a cybersecurity media network founded by David Spark, built around the relationship between security practitioners and the vendors who serve them. 

It publishes a weekly newsletter alongside daily news digests and live shows, all with a deliberately conversational and often humorous tone.

Why subscribe? Most security newsletters cover threats and tools—CISO Series covers the business and human dynamics of security leadership, including vendor relationships, buying decisions, and the conversations happening in CISO communities. The bi-weekly newsletter recaps the best discussions, podcast highlights, and community debates from the week, so you get a pulse on what security leaders are actually thinking and talking about.

14. Return on Security - Best for cybersecurity business and funding news

The sign up page with featured posts of the Return on Security newsletter
Return on Security breaks down the cybersecurity market for founders, investors, and security leaders.
  • Audience: Security leaders, CISOs, founders, and cybersecurity investors
  • Frequency: Weekly
  • Cost: Free

Return on Security is a weekly cybersecurity market briefing run by Mike Privette, a former CISO who now covers the industry as a self-described "Cybersecurity Economist." It's built for security leaders, founders, and investors who want to understand the business forces shaping the industry, not just the threat landscape.

Why subscribe? The flagship series, "Security, Funded," tracks funding rounds, M&A activity, and market category shifts every week—the kind of context that helps you understand where the industry is heading and why vendors are making the moves they are. If you're a security leader evaluating vendors, a founder building in the space, or just someone who wants to think about cybersecurity as an industry rather than a discipline.

15. Security Boulevard - Best for news from top security creators

Screenshot of the Security Boulevard webpage
Security Boulevard provides practical cybersecurity news and insights for security professionals.
  • Audience: IT security practitioners, CISOs, and DevSecOps engineers
  • Frequency: Daily
  • Cost: Free

Security Boulevard is a cybersecurity news and community platform launched in 2017 by Techstrong Group, home to the Security Creators Network—a collective of 400+ security bloggers and practitioners contributing original content. It's built for security professionals who want broad daily coverage across threats, cloud security, DevSecOps, application security, and CISO-level strategy.

Why subscribe? What sets Security Boulevard apart is the sheer range of perspectives it aggregates—you're not getting one editorial voice, but dozens of active practitioners and experts writing about what they're actually working through. The daily newsletter pulls from that pool alongside original reporting from staff writers like Michael Vizard, so you get both community-driven insight and professional journalism in one place.

16. GovInfoSecurity - Best for compliance-focused security news

The webpage of the GovInfoSecurity
GovInfoSecurity keeps security professionals current on cyber policy, threats, AI, and government security.
  • Audience: Government security leaders and compliance-focused IT professionals
  • Frequency: Daily
  • Cost: Free

GovInfoSecurity is a daily information security publication run by ISMG, focused specifically on the intersection of government, compliance, and cybersecurity. It covers risk management, regulatory updates, fraud, and data security with a public-sector lens.

Why subscribe? If your work touches government systems, compliance mandates, or regulated environments, GovInfoSecurity gives you coverage that general security newsletters skip—think policy changes, agency-level breach reporting, and compliance framework updates. You also get access to webcasts, whitepapers, and thought-leader interviews that go deeper than a typical news digest. 

17. This Week in 4n6 - Best for digital forensics and incident response news

Sample screenshot of the This Week in 4N6 newsletter
This Week in 4n6 keeps DFIR professionals current on forensic research, incident response, and industry tools.
  • Audience: Digital forensics and incident response professionals
  • Frequency: Weekly
  • Cost: Free

This Week in 4n6 is a free weekly digest run by Phill Moore—a Principal Security Researcher at Microsoft and SANS instructor—that has been tracking the DFIR community since 2016. Each edition collates blog posts, tool releases, podcasts, conference talks, and journal articles from across the digital forensics and incident response space.

Why subscribe? If you work in DFIR, threat hunting, or malware analysis, this is one of the most thorough community aggregators available—it saves you from tracking dozens of individual blogs and feeds yourself. You'll get links to new tool releases, practitioner write-ups, and research papers all in one place each week.

What’s Next?

Boost your SaaS growth and leadership skills. Subscribe to our newsletter for the latest insights from CTOs and aspiring tech leaders. We'll help you scale smarter and lead stronger with guides, resources, and strategies from top experts!

Katie Sanders

As a data-driven content strategist, editor, writer, and community steward, Katie helps technical leaders win at work. Her 15 years of experience in the tech space makes her well-rounded to provide technical audiences with first-hand operating wisdom so senior tech leaders can get clarity.



Tech leaders want to learn from peers who’ve been there. Katie surfaces hard-won lessons that help CTOs scale systems, teams, and strategy in the face of disruption.



Interested in being reviewed? Find out more here.