Top Security Newsletters
Curated and original email newsletters covering threat intelligence, detection engineering, cloud and application security, GRC, and the business of cybersecurity. Each entry is a recurring, reputable newsletter with a consistent publishing cadence.
16 curated entries · Last updated
Deepak Gupta Newsletter
San Francisco, USA
The Deepak Gupta newsletter publishes at guptadeepak.com on cybersecurity, identity and access management, LLM and AI security, and B2B SaaS growth, written for security and marketing practitioners scaling companies.
Unsupervised Learning
San Francisco, USA
Unsupervised Learning is Daniel Miessler's widely read newsletter and podcast curating the most important stories at the intersection of cybersecurity, AI, national security, technology, and society.
Venture in Security
Calgary, Canada
Venture in Security is one of the most widely read Substacks on the business of cybersecurity, covering go-to-market, product, investing, and how the security industry actually works.
Return on Security
Online
Return on Security is a weekly newsletter by Mike Privette covering cybersecurity and privacy funding, M&A, and the economics of the security market.
Detection Engineering Weekly
Online
Detection Engineering Weekly curates the most relevant research, tooling, and techniques for detection engineering, threat detection, and blue-team practitioners.
CloudSecList
London, UK
CloudSecList (The Cloud Security Reading List) is a weekly newsletter by Marco Lancini curating the best cloud-native security news, research, and tooling.
TLDR Information Security
San Francisco, USA
TLDR Information Security is a daily newsletter delivering the most important cybersecurity news, research, and tools in a quick, scannable format to a large practitioner audience.
This Week in Security
New York, USA
This Week in Security (~this week in security~) is a long-running weekly newsletter by journalist Zack Whittaker summarizing the most important cybersecurity stories with a reporter's perspective.
Vulnerable U
Austin, USA
Vulnerable U is a weekly newsletter by Matt Johansen blending cybersecurity news and analysis with a focus on the human side of security and personal resilience.
API Security Newsletter
Online
The API Security Newsletter (apisecurity.io) curates the latest API security breaches, vulnerabilities, standards, and best practices for developers and security teams.
BlockThreat: Blockchain Threat Intelligence
Online
BlockThreat (Blockchain Threat Intelligence) is a newsletter by Peter Kacherginsky covering cryptocurrency and Web3 security incidents, exploits, vulnerabilities, and defensive research.
SANS NewsBites
Rockville, USA
SANS NewsBites is a semiweekly newsletter from the SANS Institute summarizing the most important cybersecurity news, with expert commentary from SANS instructors and fellows.
GRC Engineer
Online
GRC Engineer is a newsletter by Ayoub Fandi focused on modern, engineering-driven approaches to security governance, risk, and compliance.
Infostealers by Hudson Rock
Tel Aviv, Israel
Infostealers by Hudson Rock publishes news, research, and reporting on infostealer malware and the credential-theft economy that fuels many modern breaches.
Hive Five by securibee
Online
Hive Five by securibee (Pusha B) is a weekly newsletter delivering a curated set of the most useful infosec news, web application security, and bug bounty resources.
This Week in 4n6
Online
This Week in 4n6 is a weekly roundup by Phill Moore covering the latest in digital forensics and incident response (DFIR): research, tools, and blog posts from across the community.
FAQs
Frequently Asked Questions
What are the best cybersecurity newsletters to subscribe to?
It depends on your focus. For curated industry news, tl;dr sec, TLDR Information Security, and Unsupervised Learning are widely read. For detection engineering, Detection Engineering Weekly. For the business of security, Venture in Security and Return on Security.
How do you choose which newsletters to list?
We list newsletters with a consistent publishing cadence, a clear editorial point of view, and a real practitioner or operator audience, spanning threat intel, cloud and app security, GRC, DFIR, and security go-to-market.