Coverage
Sources
Everything already tracked. Check this list before proposing a source — if it’s here, it’s covered.
10
tracked
7
feeds working
2
feeds broken
1
manual only
What the labels mean
- live
- Feed works. The bot checks it daily.
- quiet
- Feed works, but the source rarely publishes.
- broken
- Feed URL fails. The bot skips it until someone fixes the URL.
- no feed
- Worth reading, but has no RSS. Writeups are added by hand.
Research & labs
4James Kettle's team. Original research, consistently top tier.
URL corrected — the old blog.projectdiscovery.io feed redirects here.
Deep vulnerability research on enterprise software — the Craft CMS RCE, the PAN-OS auth bypass, the Next.js middleware bypass. Still publishing after the Searchlight Cyber acquisition, but the old RSS feed (blog.assetnote.io) returns 404 and no replacement feed exists. Worth reading anyway; writeups from here get added manually.
Feed is fine, but posts are infrequent.
Platforms
3URL corrected — blog.intigriti.com redirects here. Includes Bug Bytes.
Responde 200 pero devuelve HTML en vez de RSS, así que el parser saca cero entradas. Hace falta encontrar la URL real del feed.
Returns 404. Needs a replacement feed URL — good first contribution.
Researchers
2Ben Sadeghipour. Feed is valid; last post was February 2025.
Feed válido, pero el último post es de agosto de 2023.
Podcasts
1Justin Gardner (Rhynorater) and Joel Margolis (teknogeek). By hackers, for hackers. The feed's <link> field always points at the homepage instead of the episode, so the bot can't dedup reliably and skips this source entirely — add episodes manually with the real URL from criticalthinkingpodcast.io.
Missing something?
If you follow a bug bounty blog or podcast that isn’t listed, add it. The only requirement is that the author is part of the community or has demonstrable results. Fixing a broken feed URL counts too — it’s the fastest contribution to review.
How to contribute →