The Meta-Index
A curated directory of high-signal cybersecurity podcasts, YouTube channels, newsletters, blogs, and threat feeds — the sources practitioners actually read.
Podcasts
-
Unscripted conversation on application security and code review practice.
-
Investigative reporting on cyber conflict from Recorded Future News.
-
Weekly interviews on securing AWS, Azure, and GCP in practice.
-
Eight-minute weekday news summary, no interviews or filler.
-
Long-form narrative interviews with hackers, breach responders, and insiders.
-
Interviews with detection and SecOps leaders on tooling and pipelines.
Quiet · 82d since last post -
Weekly news roundup with practitioner commentary on what actually mattered.
-
Five-minute daily briefing on new threats and vulnerabilities.
-
Working cryptographers on real protocol and implementation flaws.
-
Irreverent weekly take on breaches and scams; a good entry point.
-
Michael Bazzell on practical OSINT tradecraft and personal privacy.
YouTube
-
Windows forensics and DFIR technique, tightly scoped and practical.
-
Conference archive; the year's significant offensive research.
-
Methodical Hack The Box walkthroughs; the standard OSCP prep channel.
-
Malware teardowns, CTF walkthroughs, and tooling for working analysts.
-
Approachable deep dives on malware internals and low-level systems.
-
Bug bounty recon and live hunting sessions.
-
Live malware unpacking and reverse engineering sessions.
Quiet · 49d since last post -
Bug bounty craft and hacker mindset, high production quality.
-
Practical pentest and OSINT courses aimed at people breaking in.
Quiet · 141d since last post -
Conference talks on cloud attack and defense, vendor-neutral.
Newsletters
-
Marco Lancini's weekly cloud security roundup.
-
Zack Allen's roundup of detection research, tooling, and writeups.
-
Daily curated summary of security news and policy developments.
-
Mike Privette on the business and funding side of security.
-
Written companion to the podcast; three editions a week.
-
Twice-weekly summary with commentary from SANS instructors.
-
Zack Whittaker's weekly digest with a strong privacy lean.
-
Daniel Miessler on security, tooling, and where the field is heading.
-
Ross Haleliuk on how the security industry actually works.
-
Weekly digest of appsec talks, tools, and research. Dense and well-curated.
Blogs
-
The reference for open-source investigation methodology.
-
Deep vulnerability research writeups; the reference standard for the genre.
Quiet · 81d since last post -
Investigative cybercrime reporting, frequently ahead of mainstream coverage.
-
Patrick Wardle's macOS malware analysis and free defensive tooling.
Quiet · 123d since last post -
Novel web attack classes, often defining the technique everyone later uses.
Quiet · 178d since last post -
Bruce Schneier on cryptography, surveillance, and security policy.
-
Active Directory attack paths and the detections that catch them.
-
Full intrusion walkthroughs with timelines and detection opportunities.
Quiet · 34d since last post -
Engineering-heavy posts on cryptography, fuzzing, and program analysis.
-
Breach analysis and web security from the person behind Have I Been Pwned.
-
Cloud vulnerability research and cross-tenant isolation findings.
-
Fast, blunt writeups on edge-device and enterprise software vulnerabilities.
Quiet · 31d since last post
Threat Feeds
-
Authoritative US advisories on exploited vulnerabilities and ICS issues.
-
The KEV catalog — what is actually being exploited, not just scored.
-
Daily handler diaries on live attack traffic and emerging activity.
-
MalwareBazaar, URLhaus, and ThreatFox — community malware and IOC feeds.