- [web] [rss] Krebs on Security (Brian Krebs)
- [web] [rss] Graham Cluley
- [web] [rss] Hot for Security
- [web] [rss] lcamtuf (Michal Zalewski)
- [web] [rss] Troy Hunt
- [web] [rss] Full Disclosure (mostly vulnerability disclosures)
- [web] [rss] F-Secure Labs
- [web] [rss] SANS Internet Storm Center
- [web] [rss] SANS Curated News
- [web] [rss] SANS Industrial Control Systems Blog
- [web] [rss] SANS Digital Forensics and Incident Response Blog
- [web] [rss] Exploit DB
- [web] [rss] Microsoft Security Response Center
- [web] [rss] Dave Shackleford
- [web] [rss] Google Project Zero issue tracker
- [web] [rss] Google Project Zero blog
- [web] [rss] Google Online Security Blog
- [web] [rss] Carnal0wnage (Chris Gates)
- [web] [rss] OpenDNS Labs
- [web] [rss] Dark Reading
- [web] [rss] Help Net Security
- [web] [rss] Verizon Security Blog
- [web] [rss] Errata Rob (Robert Graham)
- [web] [rss] Wh1t3 Rabbit (Rafal Los)
- [web] [rss] Schneier on Security (Bruce Schneier)
- [web] [rss] Social-Engineer
- [web] [rss] Common Exploits (Daniel Compton)
- [web] [rss] McAfee Labs
- [web] [rss] CSO Online Dashboard / Security News
- [web] [rss] Uncommon Sense Security (Jack Daniel)
Podcasts
...and a few not necessarily security-related:
- SANS Internet Storm Center
- Chet Chat (Sophos Security)
- Southern Fried Security
- Brakeing Down Security
- Defensive Security
- Paul's Security Weekly
- Social-Engineer
- Down the Security Rabbithole (Wh1t3 Rabbit's DtSR)
...and a few not necessarily security-related:
- nixcraft (rss) - knowledge of all things *nix
- Command Line Kung Fu (rss) - just what it says, for Windows, *nix, and Powershell
- iptables tutorial - great primer on the *nix iptables firewall
Along with some useful finds:
- CapTipper: Malicious HTTP traffic explorer tool. Point it at a PCAP or live traffic and easily pull out hosts, conversations, downloaded files, etc.
- Bit.ly to track malware outbreaks: A short piece using bit.ly's click analysis to view geographic distribution and infection rates.
- Pemcrack: ErrataRob's tool to crack SSL PEM files that hold encrypted private keys (first authored to crack the Superfish cert)
- Recommended forensic reading: a list of books
- APTNotes: Github repository of whitepapers, docs and articles related to APT campaigns
- Telerik Fiddler: web debugging proxy
Please reply in the comments below if you have a favorite that I overlooked!