Case file
Twenty blogs and newsletters that earn a spot in the Sentinel's inbox
News sites cover the day; blogs and newsletters build the model. These twenty are the Sentinel’s editorial selection of the personal sites, research blogs, and digests that pass the only inbox test that matters: when the email arrives, does reading it change what the Sentinel does next? Official links; reviewed yearly per the disclosures policy.
The individual voices. Personal blogs with institutional influence.
- Schneier on Security — Bruce Schneier, blogging since 2003. The single longest-running high-signal commentary feed in the field; read it for the frame, not the headlines.
- KrebsOnSecurity — Brian Krebs’s investigative blog, still breaking cybercrime stories the wires follow days later.
- Troy Hunt — the Have I Been Pwned founder’s blog and weekly newsletter; authentication, breach analysis, and honest product post-mortems.
- Daniel Miessler — Unsupervised Learning — the weekly digest connecting security, AI, and the internet’s future; the newsletter side of the podcast pick.
- tl;dr sec — Clint Gibler’s research digest, weekly; the fastest way for a busy practitioner to know what the academic and lab world shipped.
- Graham Cluley’s blog — the veteran commentary side of Smashing Security; skeptic first, always quotable.
- Scott Helme’s blog — the headers, HSTS, and web-hardening diaries of the securityheaders.com founder; practical, testable, close to this site’s own case files.
The research blogs. Institutional, but written like practitioners.
- PortSwigger Research — James Kettle and colleagues publishing the request-smuggling-class breakthroughs as they happen.
- Google Cloud Security (Mandiant) — the Mandiant threat-research stream; incident-grade write-ups of intrusions most vendors only summarize.
- Microsoft Security Response Center blog — the primary source for Microsoft’s vulnerability handling; read before the third-party recaps.
- WeLiveSecurity — ESET’s research and commentary desk, consistently strong on APM-class reporting.
The specialists.
- The DFIR Report — real intrusion post-mortems with timelines, tooling, and command trails; the closest public thing to reading a case file end to end.
- Bellingcat — open-source intelligence investigations as journalism; the verification craft transfers directly to security work.
- ImperialViolet — Adam Langley on TLS, cryptography engineering, and why the “obvious” protocol idea is wrong.
- Latacora’s blog — home of “Cryptographic Right Answers”; the practical-crypto reference practitioners actually apply.
- Hacker Factor Blog — long-running forensics commentary and the annual “how to spot a fake” field notes.
- SANS Internet Storm Center Handler Diaries — the daily handler diaries behind Stormcast; instrument readings from the live internet.
The digests and feeds.
- SANS NewsBites — twice-weekly editorial digest; the oldest surviving executive summary done right.
- Help Net Security — the daily newsletter and news desk; disciplined, quiet, never fear-selling.
- CISA Alerts & Advisories — not a blog, the feed that outlives all blogs: every advisory the Sentinel’s case files cite as primary source.
How the Sentinel keeps this honest
Editorial selection dated 20 September 2026, re-verified annually. The unsubscribe test is the criterion: each of these has, on at least one occasion, changed how the Sentinel works. Publications that die — and several veteran outlets have — are retired from the list with dated notes, not left as dead links.
Sources & attributions
- Each entry links to its official site or newsletter home, as published by the author or organization.
- Curation criteria and update policy: Disclosures — editorial & sourcing policy.
- Companion pieces: Twenty sites in scope, Twenty podcasts on rotation.