Case file

Twenty blogs and newsletters that earn a spot in the Sentinel's inbox

News sites cover the day; blogs and newsletters build the model. These twenty are the Sentinel’s editorial selection of the personal sites, research blogs, and digests that pass the only inbox test that matters: when the email arrives, does reading it change what the Sentinel does next? Official links; reviewed yearly per the disclosures policy.

The individual voices. Personal blogs with institutional influence.

  1. Schneier on Security — Bruce Schneier, blogging since 2003. The single longest-running high-signal commentary feed in the field; read it for the frame, not the headlines.
  2. KrebsOnSecurity — Brian Krebs’s investigative blog, still breaking cybercrime stories the wires follow days later.
  3. Troy Hunt — the Have I Been Pwned founder’s blog and weekly newsletter; authentication, breach analysis, and honest product post-mortems.
  4. Daniel Miessler — Unsupervised Learning — the weekly digest connecting security, AI, and the internet’s future; the newsletter side of the podcast pick.
  5. tl;dr sec — Clint Gibler’s research digest, weekly; the fastest way for a busy practitioner to know what the academic and lab world shipped.
  6. Graham Cluley’s blog — the veteran commentary side of Smashing Security; skeptic first, always quotable.
  7. Scott Helme’s blog — the headers, HSTS, and web-hardening diaries of the securityheaders.com founder; practical, testable, close to this site’s own case files.

The research blogs. Institutional, but written like practitioners.

  1. PortSwigger Research — James Kettle and colleagues publishing the request-smuggling-class breakthroughs as they happen.
  2. Google Cloud Security (Mandiant) — the Mandiant threat-research stream; incident-grade write-ups of intrusions most vendors only summarize.
  3. Microsoft Security Response Center blog — the primary source for Microsoft’s vulnerability handling; read before the third-party recaps.
  4. WeLiveSecurity — ESET’s research and commentary desk, consistently strong on APM-class reporting.

The specialists.

  1. The DFIR Report — real intrusion post-mortems with timelines, tooling, and command trails; the closest public thing to reading a case file end to end.
  2. Bellingcat — open-source intelligence investigations as journalism; the verification craft transfers directly to security work.
  3. ImperialViolet — Adam Langley on TLS, cryptography engineering, and why the “obvious” protocol idea is wrong.
  4. Latacora’s blog — home of “Cryptographic Right Answers”; the practical-crypto reference practitioners actually apply.
  5. Hacker Factor Blog — long-running forensics commentary and the annual “how to spot a fake” field notes.
  6. SANS Internet Storm Center Handler Diaries — the daily handler diaries behind Stormcast; instrument readings from the live internet.

The digests and feeds.

  1. SANS NewsBites — twice-weekly editorial digest; the oldest surviving executive summary done right.
  2. Help Net Security — the daily newsletter and news desk; disciplined, quiet, never fear-selling.
  3. CISA Alerts & Advisories — not a blog, the feed that outlives all blogs: every advisory the Sentinel’s case files cite as primary source.

How the Sentinel keeps this honest

Editorial selection dated 20 September 2026, re-verified annually. The unsubscribe test is the criterion: each of these has, on at least one occasion, changed how the Sentinel works. Publications that die — and several veteran outlets have — are retired from the list with dated notes, not left as dead links.

Sources & attributions

  1. Each entry links to its official site or newsletter home, as published by the author or organization.
  2. Curation criteria and update policy: Disclosures — editorial & sourcing policy.
  3. Companion pieces: Twenty sites in scope, Twenty podcasts on rotation.