Skip to content

Search ThreatNotes

About

Security writing that respects your time.

ThreatNotes exists to turn security news into something you can act on — written by hand, with no sponsors and no filler.

Our mission

To make defensive security knowledge legible — so that understanding an attack does not depend on having the right job title, the right budget, or the right employer.

Security information is abundant and almost none of it is usable. Vendor blogs sell, advisories assume you already know, and the news cycle moves on before anyone explains why a thing worked. Meanwhile the people who most need the explanation — a solo admin, a first-year analyst, a developer who just inherited the on-call phone — are the least likely to get it.

ThreatNotes is the attempt to close that gap in public: take the week's real events, work out what actually happened underneath the headline, and write it down plainly enough that someone can use it the same day.

Our objectives

  1. Close the gap between news and action

    Most security coverage stops at what happened. Every piece here carries through to what a defender should actually do differently, at a level of detail you can hand to your team.

  2. Explain the mechanism, not just the label

    A CVE number is not an explanation. The goal is that a reader finishes a post able to describe how the attack works to somebody else — and to recognise the next variant of it.

  3. Make practice available to everyone

    Hands-on security training is usually expensive or gated behind an employer. The courses here are free to read, require no account, and assume you are starting from curiosity rather than a budget.

  4. Stay worth the subscription

    One email a week, every week, that a busy practitioner would still open on a bad day. If an issue would not clear that bar, it is better to ship it short than to pad it.

What we publish

  • Posts

    Long-form write-ups that take one incident or technique apart: how it actually worked, what it looked like in the logs, and what to change on Monday.

  • Courses

    Short lessons that end with you having done the thing rather than read about it. Each course builds one practical skill from start to finish.

  • Weekly News

    A hand-curated roundup every Tuesday. We link to the original reporting and add one line on why it changes what a defender should do.

How we work

Six commitments. If the site ever breaks one of these, it has stopped being worth reading.

No sponsored content, ever
Nothing appears here because someone paid for it. If a tool is named, it is because it did the job. There are no affiliate links and no vendor-written posts.
A person read it
Every roundup item and every write-up is read, understood, and summarised by a human. No aggregator dumps, no auto-generated filler passed off as analysis.
Credit goes to the source
When researchers or journalists break a story, we link to them and say so. Rewriting someone else’s work to capture the traffic is not reporting.
Proportionate, not breathless
Severity gets described accurately even when that makes a story less exciting. Fear is an easy way to grow an audience and a fast way to make one useless.
Mistakes get corrected in public
When something here is wrong, the page is updated, the change is dated, and the correction is visible. Quiet edits are how trust gets spent.
Your inbox is not the product
Signup is double opt-in, unsubscribe is one click, and the list is never sold, rented, or shared. One email a week is the whole deal.

Who it's for

Analysts and engineers who have to explain an incident to someone else by the end of the day. Developers who own security they were never trained for. People studying their way in, who need the mechanism rather than the acronym. And anyone tired of reading four hundred words to learn that a patch exists.

There is no assumed seniority. Posts say what a term means the first time they use it, and the courses start from zero on purpose.

Get in touch

Corrections are the most valuable mail we get — if something here is wrong, say so and it gets fixed and dated. Story tips, course requests, and disagreements are all welcome at hello@threatnotes.org.

One email a week. That's the whole deal.

New write-ups, course drops, and the Tuesday roundup. Double opt-in, one-click unsubscribe, never shared.

See what you’d get