Unclassified // Open source

Writers and must reads

Follow these people to keep your own collection current, and read the standing columns rather than waiting for incident coverage. Everything below is open source: newsletters, blogs, social accounts, government advisories and published articles.

Jack Stone / Cyberscoop desk

Policy & strategy
CyberScoop

CyberScoop is the fastest reliable read on United States federal cyber policy, budgets and agency leadership changes. Use it to track who holds authority before you assess what an agency can actually do.

Jason Healey

Policy & strategy
Columbia SIPA / Lawfare

Healey is the clearest writer on cyber conflict history and whether defense is actually gaining advantage. Read him before you write any strategic judgment about escalation or deterrence.

Thomas Rid

Espionage & statecraft
Johns Hopkins SAIS

Rid supplies the historical baseline for influence operations and active measures, which keeps current disinformation claims proportionate. Read him whenever a campaign is described as unprecedented.

Patrick Gray

Threat intelligence
Risky Business

Gray interrogates vendor and government claims harder than most reporters, which is useful for confidence calibration. Listen for the pushback, not the headline.

Kevin Beaumont

Vulnerability & operations
DoublePulsar

Beaumont is usually first with practical exposure counts and exploitation reality during a mass vulnerability event. Use his numbers for tactical triage, and confirm against Known Exploited Vulnerabilities before you escalate.

Bruce Schneier

Policy & strategy
Schneier on Security

Schneier connects technical failure to incentives, regulation and public policy better than almost anyone writing. Read him for the structural argument, not for incident detail.

Lawfare cyber contributors

Policy & strategy
Lawfare

Lawfare is the standing reference for legal authorities behind United States cyber operations, including Title 10 and Title 50 questions. Check it before asserting what a command is permitted to do.

The Record newsroom

Threat intelligence
The Record (Recorded Future News)

The Record covers ransomware victim disclosure, government advisories and international enforcement with consistent primary sourcing. Use it to build the timeline for any long-running actor campaign.

Matt Burgess

Investigative reporting
WIRED

Burgess covers leak archives, extortion crews and platform security with steady access to primary documents. Read him when a dataset appears and its provenance matters.

Must-read articles and standing series

Read these in full before writing judgments on the topics they cover. Each entry links to the original open source publication.

  • Andy Greenberg · WIRED · 2017

    This is the clearest public account of purpose-built grid attack tooling. Read it before assessing any claim about critical infrastructure pre-positioning.

  • Andy Greenberg · WIRED · 2018

    The definitive case study on collateral damage from a state operation. Use it to argue why containment assumptions fail in wormable attacks.

  • Stalking the Wily HackerIntrusion analysis
    Cliff Stoll · Communications of the ACM · 1988

    The original long-form intrusion investigation, and still the best teaching text on patient tracking. Read it to see analytic discipline without modern tooling.

  • Joint advisory · Cybersecurity and Infrastructure Security Agency · 2024

    The primary government document behind most Volt Typhoon reporting. Read the advisory itself rather than secondhand summaries.

  • Kim Zetter · WIRED · 2023

    The most complete reconstruction of the SolarWinds intrusion and detection failure. Use it to frame supply chain risk beyond software bills of materials.

  • Citizen Lab researchers · The Citizen Lab · 2021

    The standing technical record on mercenary spyware targeting. Cite Citizen Lab directly when discussing commercial intrusion vendors.

  • Atlantic Council staff · Atlantic Council · 2025

    A continuing source of structured policy analysis on cyber norms, market incentives and defense posture. Pull from it when you need a strategic frame rather than an incident.

  • MITRE ATT&CK EvaluationsAdversary behavior
    MITRE Engenuity · MITRE · 2025

    The authoritative mapping between real actor tradecraft and detection coverage. Use it to translate any actor report into technique-level defensive gaps.

  • Cybersecurity and Infrastructure Security Agency · CISA · 2026

    The single best open prioritization list for exploitation actually observed in the wild. Check it before treating any vulnerability report as urgent.

  • The Record newsroom · The Record · 2026

    Continuous reporting on extortion crews, victim disclosure and law enforcement disruption. Use it to keep actor status current between vendor reports.