Reading List & People to Follow

The books, newsletters, blogs, podcasts, and practitioners CSOH members keep coming back to. Vendor-neutral, opinionated, and aging fast - please send PRs to add what's missing or correct what's stale.

A close-up of a stack of open books with pages fanned out, capturing a study atmosphere
Photo by Pixabay on Pexels

· · Vendor-neutral · View source on GitHub

The honest version: Lists like this are obsolete the moment they're published. Books get superseded, people change jobs and platforms, newsletters go quiet, podcasts wrap up. We're keeping this short on purpose - only what we'd actually re-recommend right now. If a name's missing or stale, open a PR or issue and we'll update it.

On social handles: we list which platform each person is most active on but skip exact handles unless they're stable and well-known. Search the name on the platform - well-known practitioners surface in the first result. This page ages slower that way.

On this page

  1. Books
  2. Newsletters
  3. Blogs (vendor research & individual)
  4. Podcasts
  5. YouTube & conference video
  6. People to follow on X / Bluesky / LinkedIn
  7. Communities worth joining
  8. Papers, frameworks & canonical reads
  9. Contribute or correct

The 6 ways CSOH members consume cloud security content

Each medium covers a different gap in your learning. Click a tile to jump to its picks.

Recommended reading-time split Suggested allocation of weekly cloud security reading across the six media types. Recommended weekly reading-time split (~3 hrs/week) ~3 hrs per week Newsletters · 15% (skim Mon AM) Blogs · 25% (deep dives, when relevant) Podcasts · 20% (commute / chores) Books · 15% (one chapter at a time) People (X/LI) · 15% (signal, not noise) Papers · 10% (one a month is plenty) "3 hours" sounds small but it's the average our members report sustaining without burning out.
Aim for breadth over volume. Three hours intentionally split across formats beats ten hours of doom-scrolling X.
A well-stocked bookshelf filled with various books in a library setting
Photo by cottonbro studio on Pexels

Books

Grouped by topic. None of these are required reading; pick the one that maps to whatever you're working on this quarter.

Each book title links to its Open Library entry - pick up the cover, ISBN, and your preferred bookseller from there.

Cloud security foundations

Identity & IAM

Containers & Kubernetes

AppSec & DevSecOps

Detection & incident response

AI / LLM security

Risk, leadership, and the meta-game

Newsletters

All free, all email. The six below earn their inbox slot by curating rather than aggregating - mostly weekly, with one daily for news junkies. If your inbox is already full, start with tl;dr sec and Cloud Security Newsletter; together they cover ~80% of what the community talks about each week.

tl;dr sec

Clint Gibler. The single most-cited security newsletter in our community. AppSec-leaning but cloud-heavy. Weekly.

NewsletterAppSecWeekly

Cloud Security Newsletter

Marco Lancini. The cloud-specific weekly. Curated, technical, no fluff.

NewsletterCloudWeekly

Last Week in AWS

Corey Quinn. Not security-only, but if you work in AWS at all this catches you up faster than the AWS What's New feed.

NewsletterAWSWeekly

Detection Engineering Weekly

Zack Allen. If detection is your day job.

NewsletterDetectionWeekly

Risky Business News

Catalin Cimpanu. Short, daily, broad security headlines with sharp commentary.

NewsletterNewsDaily

Resilient Cyber

Chris Hughes. Strategy, leadership, supply-chain angle.

NewsletterStrategySupply Chain

Blogs

Vendor research blogs (the good ones)

Not all vendor blogs are created equal. These earn their place because they publish original research, not product marketing.

Wiz Research

Cloud-native vulnerability research; the team behind several of the bigger cloud-CVE disclosures of the last few years.

BlogCloudResearch

Orca Security Research

Counterpart to Wiz - original cloud research with well-written write-ups.

BlogCloudResearch

Datadog Security Labs

Stratus Red Team comes from this team; consistently good detection content.

BlogDetectionResearch

AWS Security Blog

The first-party reference. Subscribe.

BlogAWSFirst-Party

Microsoft Security Blog

Defender / Sentinel / Entra updates plus MSTIC threat intelligence.

BlogAzureFirst-Party

Google Cloud Threat Intelligence

Mandiant + GCP. Probably the strongest threat-intel blog in cloud right now.

BlogGCPThreat Intel

Palo Alto Unit 42

Threat research with strong cloud and container coverage.

BlogThreat IntelContainers

SentinelLabs

Adjacent but high-quality, especially on offensive tooling.

BlogThreat IntelOffense

Individual blogs worth a feed slot

awsteele.com

Aidan Steele. Surprising and frequently eyebrow-raising AWS findings.

BlogAWSDeep-dive

Phil Venables

Google CISO. CISO-altitude essays; especially good on board-level security communication.

BlogStrategyCISO

Securosis

Rich Mogull and team. Cloud security commentary from someone who's been at it longer than most of the field.

BlogCloudLong-form
Cozy workspace setup with a laptop, book, and coffee cup on a wooden desk
Photo by Kaboompics on Pexels
A woman wearing headphones engaged in podcasting indoors by a window
Photo by Kaboompics on Pexels

Podcasts

Cloud Security Podcast

Ashish Rajan. The big one for our space. Practitioner interviews, vendor-fair, weekly.

PodcastCloudWeekly

Risky Business

Patrick Gray. Long-running, broader security but the news roundups are unmatched.

PodcastNewsWeekly

Darknet Diaries

Jack Rhysider. Narrative storytelling. The episodes on cloud breaches (Capital One, Code Spaces) are required listening.

PodcastStorytellingBreaches

Defense in Depth / CISO Series

David Spark. Cross-cutting security topics with senior practitioners.

PodcastCISOStrategy

SANS Internet Storm Center StormCast

Five-minute daily threat brief. Lowest possible activation energy.

PodcastThreat IntelDaily

Click Here

Recorded Future News. Polished journalism, weekly.

PodcastJournalismWeekly

YouTube & conference video

A few channels worth a subscription if you learn better by watching. Conference talks especially - many of the best cloud-security ideas show up on a fwd:cloudsec or KubeCon stage a year before they hit a book.

fwd:cloudsec

The cloud-security-only conference. Talks land on YouTube within weeks - the closest thing to a yearly state-of-the-field roundup.

YouTubeCloudConference

Black Hat

Annual talks on offensive research and novel attack classes. Filter for cloud / container / IAM tracks.

YouTubeOffenseConference

AWS Events

re:Inforce and re:Invent security tracks. First-party but the deep-dive sessions (400-level) earn their watch time.

YouTubeAWSConference

CNCF (KubeCon)

KubeCon and CloudNativeSecurityCon. Best single source for Kubernetes and supply-chain security talks.

YouTubeKubernetesConference

SANS Cloud Security

Free webcasts and conference recordings. Lecture-style, training-flavored.

YouTubeTrainingCloud

DEF CON (Cloud Village)

The Cloud Village track has matured into a genuinely strong cloud-attack research venue.

YouTubeOffenseConference

People to follow on X / Bluesky / LinkedIn

A short, opinionated list of practitioners who consistently publish things worth reading. Many of these folks post the same content on multiple platforms; the badges below each entry are name-searches on each platform - no stored handles, so the page ages slower. PRs welcome to add or update.

Cloud security depth

Detection, IR & offense

AppSec & DevSecOps

Strategy, leadership, broader security

Cloud journalism worth following

Three hours intentionally split across formats beats ten hours of doom-scrolling X. - the recommended weekly split, above

Communities worth joining

Where practitioners actually answer each other's questions. Beyond our own Friday Zoom and Signal chat:

Papers, frameworks & canonical reads

The handful of documents you'll keep returning to. All free.

Contribute or correct

This list is intentionally short and intentionally opinionated. It will go stale unless the community keeps it honest:

Where next