OSINT newsletter
Krebs on Security
Brian Krebs · Regular
Independent cybercrime, breach, and fraud reporting. Not a pure OSINT methods letter — essential source material investigators quote constantly.
Who it’s for
- Fraud and cybercrime investigators
- Defenders tracking criminal infrastructure and breach ecosystems
What you get
- Deep investigative articles
- RSS feed for a reader of your choice
How to use it
- 01
Use as source, not syllabus
Mine stories for infrastructure, aliases, and patterns — then verify on your own desk.
Strengths
- High-quality original reporting
- Long archive of fraud/breach context
Watch out for
- Not an OSINT techniques curriculum
Related in the directory
- NewsletterRead
SANS Internet Storm Center
Handler diaries and Stormcast at the edge of malware, internet observation, and threat awareness — OSINT-adjacent situational awareness for CTI-minded readers, not a people-search letter.
- GuideRead
OSINT for cybersecurity teams
From alert enrichment to infrastructure exposure — using open and commercial sources without pretending they replace a SIEM, EDR, or TIP.
- BookRead
Intelligence-Driven Incident Response
An O’Reilly text on how CTI and IR teams use intelligence — including open sources — to prioritise detection and response. It is not a people-search OSINT manual; it is the framing that keeps enrichment from becoming hobby collecting.
FAQ
Questions, answered
What is Krebs on Security?
Independent cybercrime, breach, and fraud reporting. Not a pure OSINT methods letter — essential source material investigators quote constantly.
Who is this newsletter for?
Fraud and cybercrime investigators; Defenders tracking criminal infrastructure and breach ecosystems. You’ll get: Deep investigative articles; RSS feed for a reader of your choice.