Guide

Best Cybersecurity Newsletters in 2026: 10 Picks Compared

The best cybersecurity newsletters in 2026, compared by cadence, price and audience: Risky Bulletin, SANS NewsBites, tl;dr sec and 7 more, all free but one.

The best cybersecurity newsletters in 2026 are Risky Bulletin, SANS NewsBites, tl;dr sec, TLDR InfoSec, Krebs on Security, The Hacker News, CISA's own alerts, Unsupervised Learning, Last Week in AWS, and Cyberpresso. Nine of the ten cost nothing. Only Unsupervised Learning gates its deepest issues behind a paid tier, and it does not publish that price on its own site. tl;dr sec and TLDR InfoSec are the strongest all-around picks for a busy security team.

The best cybersecurity newsletters at a glance

Newsletter Publisher Cadence Price Best for
Risky Bulletin Risky Business Media 3x a week Free Fast, opinionated news roundups
SANS NewsBites SANS Institute Semiweekly Free Execs who want the week in five headlines
tl;dr sec Clint Gibler Weekly Free AppSec and cloud security practitioners
TLDR InfoSec TLDR Media Daily Free A five-minute daily habit
Krebs on Security Brian Krebs As published Free Deep, original breach investigations
The Hacker News The Hacker News As published + weekly digest Free Breaking vulnerability and exploit alerts
CISA alerts and advisories CISA Varies (KEV updates continuously) Free Authoritative, government-sourced advisories
Unsupervised Learning Daniel Miessler Weekly Free tier, paid tier Security, AI and culture in one read
Last Week in AWS Corey Quinn Weekly Free AWS teams tracking cloud security news
Cyberpresso Dupple Daily Free SOC and security leads, five minutes a day

Dupple data: our own daily list has grown to 27,000 subscribers with a 28% open rate, as of September 2026, per Dupple's Beehiiv audience figures. That is the vantage point we are ranking from, including our own newsletter, disclosed openly below.

1. Risky Bulletin, the fastest read on what just happened

Risky Bulletin is Risky Business Media's free news arm, written by Catalin Cimpanu, at the outlet Patrick Gray founded in 2007. It publishes three times a week with short, punchy write-ups on breaches, malware campaigns, and government cyber policy, without the padding most news sites add to stretch a story.

Its standout is speed paired with a recognizable editorial voice: Cimpanu covers more ground per issue than most competitors, and Gray's Risky Business podcast, on the same media network, gives the same stories a second, longer pass for readers who want depth. Watch out: it reads more like a wire feed than an analysis piece, so pair it with something that explains why a story matters, not just what happened.

2. SANS NewsBites, the executive-friendly digest

SANS NewsBites is the SANS Institute's semiweekly summary of the week's most important security stories, each one annotated by a named SANS instructor. It is free to join.

The annotations are the reason people keep it: instead of just a headline and a link, a working practitioner adds two or three sentences of context on why a given patch or breach matters and what to do about it. Watch out: twice a week means it lags same-day coverage. Treat it as a curated recap for people who cannot follow daily feeds, not a first-alert source. It pairs well with a deeper look at how AI is changing the SOC for teams weighing where to spend their reading time.

3. tl;dr sec, the pick for AppSec and cloud practitioners

tl;dr sec is Clint Gibler's weekly newsletter, built around a stated seven-minute read time and free to subscribe. It has passed 90,000 security professionals, by the vendor's own count, and focuses on tools, research, and talks rather than breaking news.

The standout is curation quality: Gibler reads deeply in application security, cloud security, and now AI-agent security, and links the talks and open-source tools actually worth your time instead of everything that shipped that week. Watch out: it assumes a practitioner audience. A newsletter it is not for beginners looking for explainers; start with our generative AI in cybersecurity piece first if the acronyms feel unfamiliar.

4. TLDR InfoSec, the daily five-minute habit

TLDR InfoSec is a free daily newsletter from the TLDR Media network, aimed squarely at SOC analysts and CISOs who want threats, vulnerabilities, and tools in a five-minute read. It has reached roughly 410,000 subscribers, the largest audience of any pick on this list.

The scale is the standout: a daily cadence with that many readers means stories get vetted fast, and the format never drifts from its five-minute promise. Watch out: breadth comes at the cost of depth. It is a headline scanner, not an investigative source, so treat it as your daily filter and go to Krebs on Security or Risky Bulletin when a story needs the full story.

5. Krebs on Security, for the story behind the breach

Krebs on Security is Brian Krebs's independent investigative site, free to follow by email, with an alert landing in your inbox each time he publishes rather than on a fixed schedule. He posts several times a month, not daily.

The standout is original reporting: Krebs breaks stories other outlets later cite, tracing breaches back to the criminal forums and infrastructure behind them instead of summarizing a press release. Watch out: the irregular cadence means it is not a news-of-the-day source. Use it for the handful of stories a year that deserve a deep dive, and a faster feed like TLDR InfoSec or The Hacker News for everything else.

6. The Hacker News, for the exploit that needs patching now

The Hacker News offers a free email signup that flags coverage as it publishes, plus a weekly "ThreatsDay Bulletin" that rounds up 20 or more smaller stories the daily coverage did not get its own headline for.

The standout is speed on active exploitation: it is one of the first outlets to flag a CVE moving from disclosed to exploited in the wild, which matters for patch prioritization. Watch out: without a fixed daily cadence, volume in your inbox varies with the news cycle. Pair it with our EDR and endpoint protection comparison once you know which systems are exposed.

7. CISA alerts and advisories, the official record

CISA, the U.S. Cybersecurity and Infrastructure Security Agency, publishes free advisories and the Known Exploited Vulnerabilities (KEV) catalog on a rolling basis, with no editorial spin and no vendor angle to weigh.

The standout is authority: when CISA adds a CVE to the KEV catalog, federal agencies face a binding patch deadline, so it is the most actionable single signal a defender can act on. Watch out, and this one is time-sensitive: CISA states on its own bulletins page that it will discontinue the weekly Vulnerability Bulletin at the end of fiscal year 2026, on September 28, 2026, in favor of the KEV catalog and individual advisories. If you rely on the old weekly digest, switch to the KEV feed before it goes dark.

8. Unsupervised Learning, for security plus the bigger picture

Unsupervised Learning is Daniel Miessler's weekly newsletter on cybersecurity, national security, AI, and where the three intersect. It runs a free tier and a paid member tier; the site does not publish a subscriber count or the member price, so treat both as check current pricing rather than fixed figures.

The standout is scope: Miessler connects a vulnerability disclosure to what it means for AI policy or national security in the same issue, a lens most security-only newsletters skip. Watch out: that breadth means less pure technical depth per issue than tl;dr sec, and the paid tier's contents and price are not visible until you sign up.

9. Last Week in AWS, for cloud teams specifically

Last Week in AWS is Corey Quinn's free weekly newsletter on Amazon Web Services news, written with sharp, opinionated commentary the site itself bills as "AWS News Sprinkled With a Side of Snark."

Its standout for security teams is coverage of AWS's IAM, networking, and service changes that quietly reshape your attack surface, explained in plain language instead of AWS's own documentation style. Watch out: it is an AWS newsletter that touches security, not a dedicated security newsletter. If AWS is not your primary cloud, or you want cloud security specifically rather than AWS news broadly, it is the wrong fit; our SIEM cost breakdown is more useful if your gap is detection tooling rather than cloud-provider news.

10. Cyberpresso, five minutes a day for SOC and security leads

Cyberpresso is Dupple's own daily cybersecurity newsletter, disclosed here and ranked on the same criteria as every competitor above. It sends free, five days a week, summarizing the day's most relevant breaches, CVEs, and vendor moves in a five-minute read, and as of September 2026 it reaches 27,000 subscribers with a 28% open rate.

The standout is focus for a working security team: stories are picked for operational relevance, not virality, and cross-referenced against our own top AI cybersecurity companies and AI for incident response coverage so a reader can go deeper the same day. Watch out: at 27,000 subscribers it is smaller than TLDR InfoSec or tl;dr sec, so it will not have the community and job-board network effects those larger lists have built up.

How to pick a cybersecurity newsletter for your team

Match the cadence to the job. A CISO who reads on Sunday night wants SANS NewsBites' twice-weekly digest or Unsupervised Learning's weekly analysis, not a daily flood. An analyst on rotation wants TLDR InfoSec or Cyberpresso for a same-day scan, and The Hacker News or CISA's KEV feed for anything that demands action today.

Do not subscribe to five newsletters that cover the same ground. Risky Bulletin, TLDR InfoSec, and The Hacker News overlap heavily on breaking news, so pick one for daily coverage and add a specialist like tl;dr sec for AppSec depth or Last Week in AWS if your stack is AWS-heavy. Krebs on Security earns its slot for the handful of investigations a year that no aggregator covers first.

Vendor announcements and pricing pages are useful, but a newsletter should also tell you when a headline product claim does not hold up; our CrowdStrike review is an example of the depth a good weekly digest should point you toward. Check what a newsletter assumes you already know. tl;dr sec and The Hacker News assume you can parse a CVE ID and a stack trace. SANS NewsBites and Cyberpresso are written to be readable by a manager who does not touch a terminal daily. If your team is deciding whether to bring AI tools like ChatGPT into security workflows at all, our ChatGPT for cybersecurity guide covers the data-handling rules first, before the newsletter question.

For coverage that goes beyond security into the wider AI and tech news your team also tracks, Dupple's best AI news sources roundup on our sister site is worth a look.

Methodology

We checked each newsletter's own site or Substack page in September 2026 for cadence, price, and subscriber count, and read a sample of recent issues rather than relying on marketing copy alone. Cyberpresso's own figures come from Dupple's live Beehiiv audience data, the same source behind our cybersecurity statistics page. We did not accept a third-party subscriber estimate for any pick; where a vendor does not publish a number, this page says so instead of guessing. No newsletter here paid for placement, and inclusion is by editorial judgment of fit for a security-team audience.

FAQ

What is the best cybersecurity newsletter overall in 2026?

There is no single best pick because the newsletters serve different jobs. For a daily five-minute scan, TLDR InfoSec (free, roughly 410,000 subscribers) or Cyberpresso (free, 27,000 subscribers) fit best. For practitioner depth, tl;dr sec is the strongest free weekly pick. For investigative reporting, Krebs on Security has no real substitute.

Are cybersecurity newsletters free?

Almost all of them, yes. Of the ten compared here, nine are entirely free: Risky Bulletin, SANS NewsBites, tl;dr sec, TLDR InfoSec, Krebs on Security, The Hacker News, CISA's alerts, Last Week in AWS, and Cyberpresso. Only Unsupervised Learning runs a paid member tier alongside its free tier, and it does not publish that price on its subscribe page.

What is the best free cybersecurity newsletter for beginners?

SANS NewsBites and Cyberpresso are written to be readable without deep technical background, since each item gets a plain-language explanation of why it matters. tl;dr sec and The Hacker News assume more existing knowledge, like reading a CVE ID or a stack trace, so save those for once the basics feel familiar.

How often should a security team read a cybersecurity newsletter?

Match cadence to the role. Analysts on rotation benefit from a daily scan (TLDR InfoSec, Cyberpresso, or The Hacker News), while a CISO or manager usually gets more value from a twice-weekly or weekly digest (SANS NewsBites, tl;dr sec, or Unsupervised Learning) that filters out the noise a daily feed cannot avoid.

Is CISA's newsletter reliable for patch prioritization?

Yes, and it is the most authoritative single source on this list, since CISA sets a binding patch deadline for federal agencies when a vulnerability enters its Known Exploited Vulnerabilities catalog. Note that CISA is discontinuing its weekly Vulnerability Bulletin at the end of fiscal year 2026, on September 28, 2026, so subscribe to the KEV catalog and advisory feeds directly rather than the older weekly digest.

Does Krebs on Security send a daily digest?

No. Brian Krebs publishes on no fixed schedule, several times a month rather than daily, and the free email option alerts you each time a new investigation goes up rather than bundling stories into a digest. Treat it as a source for depth on major stories, not a daily news habit.

Why is Cyberpresso on this list if you publish it?

Because a "best cybersecurity newsletters" page that leaves out a real, independently rankable option to avoid the appearance of bias would be less useful, not more honest. Cyberpresso is disclosed above as Dupple's own newsletter and judged on the same cadence, price, and audience criteria as every other entry, including a real weakness: its subscriber base is smaller than the largest picks here.

Cite this: Cyberpresso, "Best Cybersecurity Newsletters in 2026," Dupple, September 2026.

Cyberpresso sends the cybersecurity stories that actually matter for a security team, in five minutes, every weekday morning, free.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free