The Meta-Index
A curated directory of high-signal cybersecurity podcasts, YouTube channels, newsletters, blogs, and threat feeds — the sources practitioners actually read.
Podcasts
-
Michael Bazzell on practical OSINT tradecraft and personal privacy.
-
Practitioner-focused pentest stories and security tooling tips.
-
Unscripted conversation on application security and code review practice.
-
Interviews and discussion on security careers and practitioner topics.
Quiet · 426d since last post -
Investigative reporting on cyber conflict from Recorded Future News.
-
Weekly interviews on securing AWS, Azure, and GCP in practice.
-
Eight-minute weekday news summary, no interviews or filler.
-
Long-form narrative interviews with hackers, breach responders, and insiders.
Quiet · 15d since last post -
Weekly roundup of breach and incident response news from a defender's perspective.
Quiet · 32d since last post -
Interviews with detection and SecOps leaders on tooling and pipelines.
Quiet · 127d since last post -
Multi-show security news and interview network.
-
Weekly news roundup with practitioner commentary on what actually mattered.
-
Five-minute daily briefing on new threats and vulnerabilities.
-
Working cryptographers on real protocol and implementation flaws.
Quiet · 22d since last post -
Long-running weekly deep-dive on security news and cryptography.
-
Irreverent weekly take on breaches and scams; a good entry point.
-
Daniel Miessler's podcast on security, AI, and technology trends.
YouTube
-
Windows forensics and DFIR technique, tightly scoped and practical.
-
Conference archive; the year's significant offensive research.
-
Methodical Hack The Box walkthroughs; the standard OSCP prep channel.
-
Malware teardowns, CTF walkthroughs, and tooling for working analysts.
-
Approachable deep dives on malware internals and low-level systems.
Quiet · 44d since last post -
Bug bounty recon and live hunting sessions.
-
Live malware unpacking and reverse engineering sessions.
-
Bug bounty craft and hacker mindset, high production quality.
-
Practical pentest and OSINT courses aimed at people breaking in.
Quiet · 186d since last post -
Conference talks on cloud attack and defense, vendor-neutral.
Newsletters
-
Marco Lancini's weekly cloud security roundup.
-
Zack Allen's roundup of detection research, tooling, and writeups.
-
Daily curated summary of security news and policy developments.
-
Mike Privette on the business and funding side of security.
-
Written companion to the podcast; three editions a week.
-
Twice-weekly summary with commentary from SANS instructors.
-
Zack Whittaker's weekly digest with a strong privacy lean.
-
Daniel Miessler on security, tooling, and where the field is heading.
-
Ross Haleliuk on how the security industry actually works.
Quiet · 22d since last post -
Weekly digest of appsec talks, tools, and research. Dense and well-curated.
Blogs
-
The reference for open-source investigation methodology.
-
CrowdStrike's threat research and incident response blog.
-
Cybersecurity news and vendor-contributed articles.
-
Deep vulnerability research writeups; the reference standard for the genre.
-
Investigative cybercrime reporting, frequently ahead of mainstream coverage.
-
Updates on the MITRE ATT&CK adversary tactics and techniques framework.
Quiet · 141d since last post -
Mozilla's security engineering and Firefox security updates.
Quiet · 37d since last post -
Official OWASP project and community announcements.
Quiet · 72d since last post -
Patrick Wardle's macOS malware analysis and free defensive tooling.
Quiet · 25d since last post -
Thoughts from the field
-
Novel web attack classes, often defining the technique everyone later uses.
Quiet · 22d since last post -
Rapid7's vulnerability research and product security blog.
-
Bruce Schneier on cryptography, surveillance, and security policy.
-
Snyk's application security research and developer security content.
-
Active Directory attack paths and the detections that catch them.
-
Full intrusion walkthroughs with timelines and detection opportunities.
Quiet · 23d since last post -
Engineering-heavy posts on cryptography, fuzzing, and program analysis.
-
Breach analysis and web security from the person behind Have I Been Pwned.
-
Cloud vulnerability research and cross-tenant isolation findings.
-
Fast, blunt writeups on edge-device and enterprise software vulnerabilities.
Quiet · 33d since last post
Threat Feeds
-
Authoritative US advisories on exploited vulnerabilities and ICS issues.
-
The KEV catalog — what is actually being exploited, not just scored.
-
Archive of public exploits and vulnerable software, maintained by Offensive Security.
-
Daily handler diaries on live attack traffic and emerging activity.
-
MalwareBazaar, URLhaus, and ThreatFox — community malware and IOC feeds.
Quiet · 50d since last post -
Community-curated links to security research and writeups from across the web.