What are the best cybersecurity news websites?
No single site is best; each is best for one job. BleepingComputer, The Hacker News and SecurityWeek carry the daily volume. Krebs on Security, The Record and 404 Media break original stories. CyberScoop covers United States policy. SANS Internet Storm Center serves practitioners. Much security news originates in vendor research blogs, which are the actual primary source.
The distinction worth making is between outlets that originate stories and outlets that carry them. Krebs on Security has published independent investigative work since 2009 and posts only a few times a month, usually things nobody else had. 404 Media, founded in 2023 and owned by its four journalists, does the same for hacking, surveillance and data brokers. The Record is the editorially independent newsroom owned by Recorded Future, and runs without a paywall. BleepingComputer, founded in 2004 by Lawrence Abrams as a computer help site, became one of the most reliable sources of ransomware detail and joined the No More Ransom project in 2018. CyberScoop is the one to read for United States federal policy, procurement and CISA.
Volume rankings measure something else entirely. As of September 2026, the sec-news.ai archive holds more than 600 articles gathered since April 2026 from 29 configured feeds, resolving to 21 publications — and thehackernews.com, securityweek.com, cybersecuritynews.com and bleepingcomputer.com supply about 80% of them, with Infosecurity Magazine, The Record, Dark Reading and News4Hackers forming the next tier and everything else in single figures. That is what reaches a digest after selection, not a measure of publishing rate, and it reflects which feeds we run. A large share of what appears in the high-volume outlets started life as a vendor report, a court filing or somebody else’s investigation.
That matters when you are deciding what to trust. An aggregator repeating a claim does not corroborate it; four sites carrying the same story usually means one source and three rewrites. Follow the links back. If a story cannot be traced to a vendor advisory, a regulator filing, a court document or named original reporting, treat it as unconfirmed however many places you have seen it.
For practitioners the useful additions are not news sites at all. The SANS Internet Storm Center publishes daily handler diaries and a short StormCast podcast built on sensor data rather than press releases. Vendor research blogs — Talos, Unit 42, Mandiant, Microsoft Threat Intelligence, Google Threat Intelligence — are where a large fraction of significant findings are actually published first, with the caveat that every one of them is also marketing for the vendor that wrote it.