Staying updated on cybersecurity threats, trends, and tactics is tough when you’re busy keeping systems safe. I’ve rounded up the cybersecurity newsletters I trust most to help you scan headlines, dive into analysis, and stay ready for whatever hits your inbox next.
Best Cybersecurity Newsletters Shortlist
Here's a shortlist of the best cybersecurity newsletters I think are worth subscribing to:
- Krebs on Security - Best for in-depth investigative reporting
- The Hacker News - Best for breaking security updates
- SANS NewsBites - Best for annotated security news
- Crypto-Gram - Best for security and policy insights
- Dark Reading - Best for breach and threat reporting
- CyberWire Daily Briefing - Best for high-signal security news
- Risky Business - Best for global threat and policy analysis
- Unsupervised Learning - Best for security, AI, and tech commentary
- tl;dr sec - Best for AppSec, AI, and tooling insights
- Graham Cluley's Security (GCHQ) Newsletter - Best for opinionated infosec news
The 16 Best Cybersecurity Newsletters
Below are my summaries of the best cybersecurity newsletters that made it onto my shortlist, plus others worth mentioning. My reviews offer a look at each newsletter's audience, frequency, cost, and more.
1. Krebs on Security - Best for in-depth investigative reporting

- Audience: Cybersecurity professionals, IT leaders, and researchers
- Size: 62,000+ subscribers
- Frequency: 1-2 times per week
- Cost: Free
Krebs on Security is Brian Krebs's independent publication, launched in 2009 after his decade-long tenure at The Washington Post. It's built a reputation as one of the most trusted sources for investigative cybersecurity journalism, with a readership that spans security researchers, IT professionals, and CISOs.
Why subscribe? Brian consistently breaks stories before mainstream outlets—his reporting on major data breaches, cybercriminal operations, and fraud networks goes several layers deeper than typical security news coverage.
If you're someone who wants to understand not just what happened but how and why, this is the newsletter for that. It's especially valuable if you're tracking threat actors, supply chain risks, or the cybercrime business.
2. The Hacker News - Best for breaking security updates

- Audience: Security analysts, IT teams, and cybersecurity professionals
- Frequency: Daily
- Cost: Free
Founded in 2010 by Mohit Kumar, The Hacker News has grown into one of the most widely-read cybersecurity news outlets in the world. It covers everything from zero-day vulnerabilities and data breaches to malware campaigns and nation-state attacks, making it a go-to daily resource for security teams.
Why subscribe? What sets THN apart is the sheer speed and volume of coverage—you get breaking vulnerability disclosures and threat intelligence delivered to your inbox as stories unfold, not after the fact. The daily email keeps you up to date on active exploits, newly patched CVEs, and emerging attack campaigns without having to monitor multiple sources.
3. SANS NewsBites - Best for annotated security news

- Audience: CISOs, IT managers, and senior security professionals
- Frequency: Twice a week
- Cost: Free
SANS NewsBites is a twice-weekly newsletter from the SANS Institute that distills the most important cybersecurity stories of the week into annotated summaries written by SANS instructors and subject matter experts.
Why subscribe? What makes NewsBites different is the expert commentary layered onto each story—you're not just getting a link to a breach disclosure or CVE, you're getting context from practitioners who understand the implications. That editorial layer makes it genuinely useful for decision-making, whether you're briefing leadership or assessing whether a newly disclosed vulnerability affects your environment.
4. Crypto-Gram - Best for security and policy insights

- Audience: Security professionals, cryptographers, and policy makers
- Frequency: Monthly
- Cost: Free
Crypto-Gram is a free monthly newsletter by Bruce Schneier—cryptographer, security author, and one of the most respected voices in the field—that has been running since 1998. Each issue compiles his latest essays and commentary on security, cryptography, privacy, and policy.
Why subscribe? Unlike news-focused newsletters, Crypto-Gram is about perspective: Schneier weighs in on why things matter, what the security community is getting wrong, and how technology intersects with surveillance, policy, and society. If you want to think more critically about the field you work in—not just stay current on CVEs—this is worth your time.
5. Dark Reading - Best for breach and threat reporting

- Audience: Enterprise security teams, CISOs, and IT security professionals
- Frequency: Daily
- Cost: Free
Dark Reading is one of the most established cybersecurity news publications around, run by Informa TechTarget and written for enterprise security teams, CISOs, and security researchers.
Its newsletters pull from 14 topic areas—including application security, cloud security, threat intelligence, and ICS/OT—so you can stay current on the specific domains that matter to your role.
Why subscribe? What sets Dark Reading apart is its coverage paired with genuine depth: you're getting daily reporting on breaches, vulnerabilities, and emerging cybersecurity threats, written by editors who collaborate with researchers and industry analysts.
If you work across multiple security domains or need to brief stakeholders on what's happening in the threat landscape, this daily newsletter gives you a reliable, well-sourced starting point. You can also tailor what you receive by signing up for topic-specific newsletters rather than a single catch-all feed.
6. CyberWire Daily Briefing - Best for high-signal security news

- Audience: Cybersecurity professionals, analysts, and policy makers
- Frequency: Daily
- Cost: Free
The CyberWire Daily Briefing is a free weekday newsletter from N2K Networks that delivers a concise rundown of the day's cybersecurity news—covering threats, vulnerabilities, policy, and the security marketplace.
It's built for security professionals who need to stay informed without spending hours across multiple sources.
Why subscribe? What I find valuable here is the editorial discipline: every issue is tightly scoped to what actually matters that day, spanning technology, law, research, and industry trends in a format you can get through quickly. It covers the full range of security topics rather than specializing in one domain, which makes it a solid daily baseline whether you're in a SOC, a leadership role, or a policy-adjacent function.
7. Risky Business - Best for global threat and policy analysis

- Audience: Security and intelligence professionals, CISOs, and policy analysts
- Frequency: Four times a week
- Cost: Free
Risky Business is a cybersecurity media brand that's been running since 2007, publishing four newsletter editions per week across two titles: Risky Bulletin (news, three times a week) by Catalin Cimpanu, and Seriously Risky Business (policy and intelligence, weekly) by Tom Uren.
Why subscribe? What sets Risky Business apart is the depth of geopolitical and policy context it brings to security coverage—if you're tracking state-sponsored threat actors, Chinese or Russian APT activity, or how cyber policy is evolving globally, this is one of the few newsletters that treats those topics with real analytical weight.
Catalin Cimpanu's news editions are fast and technically grounded, while Tom Uren's weekly edition is the one I'd point to if you want considered analysis rather than just headlines.
8. Unsupervised Learning - Best for security, AI, and tech commentary

- Audience: Security practitioners and technologists tracking AI and tech trends
- Frequency: Weekly
- Cost: Free
Unsupervised Learning is Daniel Miessler's long-running weekly newsletter covering cybersecurity, AI, national security, and technology through a mix of curated news and original essays.
Miessler is a well-known security practitioner and creator of projects like SecLists and Fabric, and he brings that practitioner perspective into every issue.
Why subscribe? What makes this one different is the editorial lens: Miessler isn't just summarizing what happened, he's telling you what it means and where things are headed, especially at the intersection of AI and security.
If you want to think more clearly about how AI is reshaping the threat landscape—attack surfaces, LLM vulnerabilities, AI policy—this is one of the few newsletters that engages those questions seriously rather than superficially.
9. tl;dr sec - Best for AppSec, AI, and tooling insights

- Audience: Application security engineers and technical security practitioners
- Size: 90,000+ members
- Frequency: Weekly
- Cost: Free
tl;dr sec is Clint Gibler's weekly newsletter delivering the best security tools, conference talks, and research in about seven minutes.
Gibler recently joined OpenAI to lead cyber efforts, and that practitioner-to-researcher-to-operator trajectory shows in what he covers and how he covers it.
Why subscribe? The newsletter's strength is curation with judgment: Gibler doesn't just link to things, he contextualizes why they matter, which makes it genuinely useful for AppSec engineers and security researchers who want to stay current on tooling, LLM security, and offensive research without spending hours doing it themselves.
Recent issues lean heavily into AI security—prompt injection, AI agent attack surfaces, LLM vuln hunting—so if that's where your work is heading, you'll find this especially relevant. It’s one of the best weekly reads for practitioners who care about both the tools and the ideas driving the field forward.
10. Graham Cluley's Security (GCHQ) Newsletter - Best for opinionated infosec news

- Audience: Infosec professionals, IT admins, security-aware readers, journalists
- Size: 100,000+ members
- Frequency: 1-3 times per week
- Cost: Free
GCHQ is Graham Cluley's free weekly newsletter—a tongue-in-cheek nod to the UK intelligence agency—delivering cybersecurity news, commentary, and analysis straight from one of the industry's most recognized independent voices.
Cluley has been in the security space since the early 1990s, with stints at Sophos and McAfee before going independent.
Why subscribe? What sets this apart from aggregator-style newsletters is Cluley's willingness to share a real opinion—you're not just getting links, you're getting his take on why something matters. Coverage spans breaches, malware, scams, and privacy issues, with a tone that's accessible without being dumbed down.
If you also listen to the Smashing Security podcast (which he co-hosts), the newsletter is a natural complement that keeps you up to date between episodes.
11. Zero Day - Best for investigative cyber journalism

- Audience: Cybersecurity professionals, researchers, policymakers, journalists, and academics
- Frequency: Irregular
- Cost: Free, or from $10/month for premium content
Zero Day is Kim Zetter's independent publication covering investigative cybersecurity and national security journalism—launched in 2021 and now running on its own platform at zetter-zeroday.com. Zetter is a former WIRED staff writer and author of Countdown to Zero Day, the definitive account of the Stuxnet operation.
Why subscribe? This isn't a digest or a link roundup—each issue is a single, deeply reported original story on topics like nation-state hacking, zero-day markets, surveillance, and election security. Zetter regularly breaks exclusive stories you won't find elsewhere, drawing on her deep sourcing across government, intelligence, and the security research community.
If you work in security and want to understand the bigger geopolitical picture behind the threats you're defending against, this is one of the sharpest sources available.
12. SecurityWeek Daily Briefing - Best for threat updates for enterprise security teams

- Audience: Enterprise security teams, CISOs, SOC analysts, and security architects
- Frequency: Daily
- Cost: Free
The SecurityWeek Daily Briefing is a free email newsletter from SecurityWeek, one of the longest-running enterprise cybersecurity news outlets, founded in 2010.
It's written and edited by a team of experienced security journalists, including Ryan Naraine, Eduard Kovacs, and Ionut Arghire.
Why subscribe? Each issue covers the day's most relevant threats, vulnerabilities, breaches, and regulatory developments—with particular depth on ICS/OT security, cloud, and enterprise topics that general tech news tends to overlook. You'll also get access to expert columns and early awareness of SecurityWeek's industry events, which are worth knowing about if you're a CISO or senior practitioner.
It's a solid daily baseline if you want broad enterprise security coverage without having to monitor multiple news sources yourself.
13. Help Net Security - Best for a global cybersecurity news roundup

- Audience: Security professionals, managers, and CISOs at global organizations
- Frequency: Daily, weekly, twice a month, or monthly (based on reader preference)
- Cost: Free
Help Net Security is an independent cybersecurity publication founded in 1998, making it one of the oldest continuously running sources in the field, run by a dedicated editorial team led by Editor-in-Chief Zeljka Zorz.
It offers a suite of newsletters you can mix and match—daily, weekly, twice-monthly, and monthly—so you subscribe at whatever cadence fits your workflow.
Why subscribe? The content spans breaking news, technical deep dives, expert opinion, and management-level analysis, making it useful whether you're hands-on in a SOC or operating at the CISO level. I'd particularly highlight the (IN)SECURE Newsletter, which surfaces editor's choice picks twice a month and tends to go deeper than a straight news digest.
14. CISO Series Newsletter - Best for witty security leadership commentary

- Audience: CISOs, security leaders, and cybersecurity vendors
- Frequency: Bi-weekly
- Cost: Free
The CISO Series Newsletter is the email companion to the CISO Series media network, produced by veteran tech journalist David Spark alongside co-hosts Andy Ellis and Steve Zalewski.
It recaps weekly podcast episodes and live events across shows like Defense in Depth and Cyber Security Headlines, with a deliberately candid, humor-forward voice that sets it apart from straight news digests.
Why subscribe? What makes this newsletter genuinely different is its focus on the friction between security practitioners and vendors—it treats that relationship as a worthy topic in its own right, not just background noise. If you're a CISO or security leader who regularly deals with vendors, you'll find the perspective refreshingly honest.
I'd also recommend checking out the weekday Cyber Security Headlines companion newsletter if you want a quick daily news brief alongside the weekly format.
15. Return on Security - Best for cybersecurity business and market news

- Audience: Security leaders, CISOs, founders, and cybersecurity investors
- Frequency: Weekly
- Cost: Free
Return on Security is a weekly cybersecurity market briefing written entirely by Mike Privette, a former CISO who bills himself as "The Cybersecurity Economist." Every issue covers funding rounds, M&A activity, and market shifts—think business intelligence, not threat alerts.
Why subscribe? If you're a security leader who needs to understand where the industry is moving—which vendors are getting funded, which categories are consolidating, and what the broader market signals mean for your decisions—this is one of the few newsletters that treats those questions seriously.
Mike writes everything himself, so the analysis has a consistent, practitioner-informed point of view rather than a generic editorial voice. I'd particularly recommend the long-form deep dives alongside the weekly briefing; pieces like his annual state of the cybersecurity market go well beyond what a 5-minute brief can cover.
16. CloudSecList - Best for cloud security research and tool updates

- Audience: Cloud security engineers, managers, and technical leaders worldwide
- Size: 12,000+ members
- Frequency: Weekly
- Cost: Free
CloudSecList is a weekly cloud security newsletter curated personally by Marco Lancini since 2019, now with 300+ issues delivered to 12,000+ subscribers every Sunday. It covers cloud security research, tooling, and provider updates across AWS, Azure, GCP, and Kubernetes.
Why subscribe? Every link Marco includes is something he's personally read and vetted — there's no RSS aggregation or automated summarization, so you're getting a practitioner's judgment on what's actually worth your time. The coverage spans technical deep dives, new offensive/defensive tooling, and cloud provider security releases, which makes it useful whether you're hands-on in the cloud or leading a cloud security function.
What’s Next?
Boost your SaaS growth and leadership skills. Subscribe to our newsletter for the latest insights from CTOs and aspiring tech leaders. We'll help you scale smarter and lead stronger with guides, resources, and strategies from top experts!
