Brian Krebs
Investigative reportingKrebsOnSecurity
Read Krebs first when a breach, ransomware crew or fraud network surfaces, because he names the operators behind it before vendors do. Use his posts as leads for attribution work, not as final attribution.
Andy Greenberg
Espionage & statecraftWIRED
Greenberg is the reference narrative reporter on state cyber operations, especially Russian military intelligence activity against critical infrastructure. Read him to understand operational intent, then map the behavior to MITRE ATT&CK yourself.
Jack Stone / Cyberscoop desk
Policy & strategyCyberScoop
CyberScoop is the fastest reliable read on United States federal cyber policy, budgets and agency leadership changes. Use it to track who holds authority before you assess what an agency can actually do.
Jason Healey
Policy & strategyColumbia SIPA / Lawfare
Healey is the clearest writer on cyber conflict history and whether defense is actually gaining advantage. Read him before you write any strategic judgment about escalation or deterrence.
Thomas Rid
Espionage & statecraftJohns Hopkins SAIS
Rid supplies the historical baseline for influence operations and active measures, which keeps current disinformation claims proportionate. Read him whenever a campaign is described as unprecedented.
Ryan Gallagher
Investigative reportingBloomberg
Gallagher documents surveillance tooling and government contracting that rarely appears in vendor reporting. Use his work to understand collection capability, not just intrusion activity.
Catalin Cimpanu
Threat intelligenceRisky Business News
Cimpanu's newsletter is the highest signal daily roundup of intrusions, malware and takedowns anywhere in open source. Skim it every morning and pull the primary links out for your own collection.
Patrick Gray
Threat intelligenceRisky Business
Gray interrogates vendor and government claims harder than most reporters, which is useful for confidence calibration. Listen for the pushback, not the headline.
Kevin Beaumont
Vulnerability & operationsDoublePulsar
Beaumont is usually first with practical exposure counts and exploitation reality during a mass vulnerability event. Use his numbers for tactical triage, and confirm against Known Exploited Vulnerabilities before you escalate.
Zack Whittaker
Investigative reportingTechCrunch / this week in security
Whittaker's newsletter tracks data exposure, spyware and breach notification failures with unusual follow-through. Read it weekly to catch incidents that never reach the wires.
Bruce Schneier
Policy & strategySchneier on Security
Schneier connects technical failure to incentives, regulation and public policy better than almost anyone writing. Read him for the structural argument, not for incident detail.
Lawfare cyber contributors
Policy & strategyLawfare
Lawfare is the standing reference for legal authorities behind United States cyber operations, including Title 10 and Title 50 questions. Check it before asserting what a command is permitted to do.
The Record newsroom
Threat intelligenceThe Record (Recorded Future News)
The Record covers ransomware victim disclosure, government advisories and international enforcement with consistent primary sourcing. Use it to build the timeline for any long-running actor campaign.
Matt Burgess
Investigative reportingWIRED
Burgess covers leak archives, extortion crews and platform security with steady access to primary documents. Read him when a dataset appears and its provenance matters.