Skip to content

Curated list of threat intelligence newsletters, mailing lists, cyber daily briefs, and weekly reports for analysts, incident responders, and CTI teams.

Notifications You must be signed in to change notification settings

BrewedIntel/threat-intel-mailing-lists

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 

Repository files navigation

Threat Intelligence Mailing Lists & Cyber Newsletters

A curated list of mailing lists, newsletters, daily briefs, and weekly reports that provide high-quality threat intelligence. Ideal for CTI analysts, SOC teams, DFIR practitioners, and security researchers who want consistent, structured updates on global threats.


Table of Contents


Threat Intel Newsletters

High-signal mailing lists focused on threat activity, IOCs, infrastructure trends, and actor reporting.

Team Cymru – Dragon News Bytes (DNB)

https://www.team-cymru.com/dnb
Global threat activity digest with trends, botnet analysis, infrastructure changes, and high-value intelligence from Team Cymru's research team.

Recorded Future – Cyber Daily

https://www.recordedfuture.com/cyber-daily
Daily summary of vulnerabilities, threat actor activity, and key cyber events.

Unit42 (Palo Alto Networks) – Threat Intelligence Report

https://unit42.paloaltonetworks.com
Campaign reporting, malware analysis, and APT tracking.

AlienVault – OTX Pulse Newsletter

https://otx.alienvault.com
Community-driven threat indicators and trending threat summaries.

SANS Internet Storm Center – ISC Diary

https://isc.sans.edu
Daily write-ups on malware, exploits, and internet-wide anomalies.

Google TAG – Threat Analysis Group Reports

https://blog.google/threat-analysis-group
Research on nation-state campaigns and exploitation trends.

Cisco Talos Intelligence Updates

https://talosintelligence.com
Threat roundups, malware deep dives, and security advisories.


Industry Vendor Reports

Usually weekly or monthly, focused on actor tracking, malware families, and infrastructure trends.

CrowdStrike – Global Threat Intel Updates

https://www.crowdstrike.com/blog/category/threat-intel
Actor profiles, campaign breakdowns, and malware reporting.

Mandiant – Threat Intelligence Reports

https://www.mandiant.com/resources
APT reporting, IR case insights, exploitation trends.

Proofpoint – Threat Insights

https://www.proofpoint.com/us/blog/threat-insight
Email-based threat landscape and actor tracking.

SentinelOne – Labs Research

https://www.sentinelone.com/labs
Technical analysis, malware reverse engineering, and exploit research.

Check Point Research

https://research.checkpoint.com
Threat actor activity and technical reporting.

Kaspersky SecureList

https://securelist.com
Long-form malware research and campaign analysis.


Open-Source Intel Digests

Community-led, free resources summarizing broad cyber activity.

The DFIR Report

https://thedfirreport.com
Real-world intrusions analyzed from initial access to impact.

Risky Business – Newsletters & Show Notes

https://risky.biz
Weekly security news and threat summaries.

BleepingComputer Security Newsletters

https://www.bleepingcomputer.com
Timely reporting on ransomware and vulnerabilities.

Cyber Security News – The Hacker News

https://thehackernews.com
Industry news with a focus on exploitation and active threats.

CyberWire Daily Briefing

https://www.thecyberwire.com
Concise daily cyber news and threat insights.


Government & CERT Bulletins

Public advisories and alerts with high-value operational intelligence.

CISA – Cybersecurity Advisories & Alerts

https://www.cisa.gov/news-events/cybersecurity-advisories
Timely vulnerability and threat actor reporting.

US-CERT National Cyber Awareness

https://www.cisa.gov/uscert/ncas
Technical alerts and mitigation guidance.

NCSC (UK) Weekly Threat Report

https://www.ncsc.gov.uk
Threat landscape updates, advisories, and mitigation guidance.

ENISA Threat Landscape Reports

https://www.enisa.europa.eu
EU-focused threat data and annual intelligence.

CERT-EU Weekly Bulletins

https://cert.europa.eu
Threat intelligence and vulnerability summaries relevant to EU institutions.

Australian Cyber Security Centre (ACSC) Alerts

https://www.cyber.gov.au
Advisories for government and enterprise defenders.


Vulnerability & Advisory Feeds

Vuln-focused mailing lists and security advisories relevant for threat intelligence.

Full Disclosure Mailing List

https://seclists.org/fulldisclosure
Public disclosure of new vulnerabilities.

Bugtraq (historical archive)

https://seclists.org/bugtraq
Still useful for legacy reference.

CERT Coordination Center (CERT/CC)

https://www.kb.cert.org/vuls
Vulnerability notes and coordination summaries.

Exploit-DB RSS / mailing feed

https://www.exploit-db.com
Daily exploit and PoC updates.


Contributing

Have a mailing list, briefing, or threat intel newsletter to add?
Pull requests and contributions are welcome.

About

Curated list of threat intelligence newsletters, mailing lists, cyber daily briefs, and weekly reports for analysts, incident responders, and CTI teams.

Topics

Resources

Stars

Watchers

Forks

Packages

No packages published