Which cybersecurity news sources are most reliable?
Primary sources are reliable by construction: CISA’s Known Exploited Vulnerabilities catalog, the National Vulnerability Database, vendor security advisories and national CERT bulletins. Among news outlets, judge reliability by four things: named bylines, links to primary documents, a visible corrections policy, and whether the outlet distinguishes what is confirmed from what an attacker merely claims.
The four-part test is portable and takes seconds. Is the story signed by a named person? Does it link to the advisory, filing or research it describes, rather than to another news article? Does the outlet publish corrections when it gets something wrong? And does it separate confirmed fact from claim — most importantly, does it report a ransomware gang’s victim listing as an allegation rather than as an established breach? An outlet failing the fourth test will be wrong in a specific, predictable way: too early and too certain.
Primary sources sit above all of this because they are the thing the news is about. CISA’s Known Exploited Vulnerabilities catalog records vulnerabilities with evidence of exploitation in the wild. The National Vulnerability Database enriches CVE records, but since 15 April 2026 it prioritises only CVEs in CISA KEV, in federal software, or designated critical under Executive Order 14028; everything else is marked lowest priority and not scheduled, so a bare NVD record means nobody has assessed it yet rather than that the flaw is minor. Vendor advisories are definitive about that vendor’s own products. National CERTs publish for their own constituencies. None of these is fast, and none tells you what it means for you — which is what news is for.
Reliability and speed pull in opposite directions. The first report of an incident is frequently the attacker’s own leak-site post, and the gap between that and confirmation by the named organisation is routinely weeks. An outlet that publishes in hour one and an outlet that publishes in week three are not competing on quality; they are answering different questions. Decide which you needed before judging either.
A caution about aggregation, including ours. As of September 2026 the sec-news.ai archive draws on 29 configured news sources; the six SANS items in it are SANS NewsBites, itself a curated summary of other outlets, not Internet Storm Center handler diaries. An aggregator inherits the reliability of what it aggregates and adds a second chance to introduce an error. Read the summary to decide whether to open the original, then judge the original by the four tests above.