Case file

Twenty security sites the Sentinel keeps in scope

A practitioner’s bookmark bar is a radar display. These twenty sites are the Sentinel’s editorial selection of the ones worth keeping in scope daily or weekly — news desks for what broke, research labs for what it means, and databases for checking any of it. Links go to official homes; reviewed yearly per the disclosures policy.

News desks.

  1. The Hacker News — the industry’s highest-volume independent desk; best read as the “what happened” layer before the research blogs supply the “what it means”.
  2. BleepingComputer — incident reporting with real technical detail, plus the forums where victims and responders actually trade notes.
  3. The Register — Security — irreverent, fast, and reliably skeptical of vendor press releases; the antidote to cheerleading.
  4. Ars Technica — Security — Dan Goodwin-class deep reporting on intrusions and the exploitable details of the modern stack.
  5. WIRED — Security — the long-form end: state-sponsored operations and the journalists (Andy Greenberg) who break them open.
  6. Recorded Future News — The Record’s newsroom model, still the best attempt at intelligence-grade daily reporting.
  7. CyberScoop — policy, Congress, and the agencies — the government-side beat.
  8. SecurityWeek — solid enterprise-vulnerability and event coverage.
  9. Dark Reading — the practitioner-oriented aggregation layer for enterprise defense news.
  10. Infosecurity Magazine — European-focused industry coverage and conference-season signal.

Research labs. Where the primary sources live.

  1. Google Project Zero — the bug-class essays and in-the-wild exploit-chain analyses that reset the industry’s baseline every few years.
  2. Cisco Talos Intelligence — threat intelligence at carrier scale, with the snort rules to act on it.
  3. Unit 42 — Palo Alto’s research arm; strong malware-family and threat-actor tracking.
  4. Securelist — Kaspersky’s research vault, home of the APT post-mortems that named the industry’s most famous operations.

Databases and free instruments.

  1. MITRE ATT&CK — the shared vocabulary of adversary behavior. If two teams can’t communicate, it’s because they haven’t read this.
  2. National Vulnerability Database — the CVE dataset’s canonical mirror; noisy, essential, and always worth querying before trusting a headline.
  3. Exploit-DB — OffSec’s public archive of proof-of-concept code and Google-dork catalog; a lab resource, not a vending machine.
  4. Shodan — the search engine for internet-exposed devices; the fastest way to understand why “temporarily public” becomes “permanently public”.
  5. VirusTotal — the first stop for any suspicious file, URL, or hash; the de-facto shared memory of the malware world.
  6. Have I Been Pwned — Troy Hunt’s breach-search utility and API; the single most useful public service this industry has built.

How the Sentinel keeps this honest

Editorial selection dated 20 September 2026, re-verified annually, no paid placements. Sites that fold (as several veteran outlets have in recent years) come off the list with a dated note rather than a dead link. Where personal blogs and newsletters rather than sites belong, see Twenty blogs and newsletters.

Sources & attributions

  1. Each site links to its official home; sections described are as the publishers present them.
  2. Curation criteria and update policy: Disclosures — editorial & sourcing policy.
  3. Cross-references: Twenty YouTube channels, Twenty podcasts on rotation.