daily cyber × ai intelligence

index

How it works

A machine-written security & AI digest

kyber.today publishes a daily recap of the most important cybersecurity and AI news, with a focus on where the two intersect. Every issue is gathered, triaged, written, and tagged by an automated pipeline — no human edits it before it goes live. 47 issues published so far.

The pipeline

Each issue is the output of five stages. The per-issue funnel line (“61 of 68 sources → 399 gathered → 399 triaged → 38 clustered → 38 written”) is exactly this pipeline narrowing the day’s news down.

  1. Gather. Pulls every source in a config file — security & AI blogs, CVE/advisory feeds, national CERTs (Nordics/EU/Ukraine), Hacker News topic searches, and curated infosec/AI accounts on X. Everything is normalized, de-duplicated by URL, and filtered to a freshness window.
  2. Triage. claude-haiku-4-5 clusters the candidates across sources (the same story from several outlets becomes one cluster) and scores each on intrinsic importance and how well it matches the reader profile.
  3. Rank. Clusters are ordered in code by importance + interest + cross-source corroboration, so a well-reported story and an on-profile niche one both surface.
  4. Write. claude-opus-4-8 drafts the recap from the top clusters, leading with the biggest stories and quoting community reaction (X replies / Hacker News comments) where it adds something.
  5. Enrich & publish. claude-haiku-4-5 extracts a summary and normalized tags (topics, vendors, threat actors, CVEs, malware, models). The result is committed as a markdown file and this static site is rebuilt.

Is there human review?

No. The digest is written and tagged entirely by AI models and published automatically on a schedule — there is no editor in the loop. Treat it as a machine summary of public reporting, not as original or verified journalism. Every claim links to its primary source; when a story is thin or a listing is unconfirmed, the digest is meant to say so — but the models can still be wrong, miss context, or misattribute. Verify anything important against the linked source.

How stories are chosen

Selection is driven by three signals — intrinsic importance, match to a stated reader interest profile (offensive/defensive security, cloud & identity, AI/LLM security, threat intel, EU/Nordic regulation), and how many independent sources corroborate a story. Recently-covered stories are suppressed, and a genuine development of an earlier story is presented as a continuing thread that links back to previous coverage.

Corrections & contact

Because the pipeline is automated, the best correction is at the source: every item links out, so follow the link for the authoritative account. Sources and the reader profile are version-controlled and evolve over time.

Comments, suggestions, corrections, or a source worth adding? Email root@kyber.today — feedback on what to cover, what to cut, and what the pipeline got wrong is genuinely welcome.

Sources

Pulled every run: 27 feeds & advisories, 23 X accounts plus 2 topic searches, 8 Hacker News topics, and 8 Mastodon accounts. This list is generated from the live config.

Feeds & advisories
BleepingComputerCERT-EUCERT-SE (Sweden)CERT-UA (Ukraine)CERT.dk (Denmark)CISA AdvisoriesDark ReadingEmbrace The RedGoogle Project ZeroGoogle Research BlogHorizon3 Attack TeamKrebs on SecurityLobsters (security)Microsoft Threat IntelligenceMIT Technology Review (AI)NCSC-FI (Finland)NCSC-NL (Netherlands)NCSC-UKSANS Internet Storm CenterSchneier on SecuritySecurityWeekTalkbackThe DecoderThe DFIR ReportThe Hacker NewsThe RecordwatchTowr Labs
X / Twitter
@vxunderground@cyb3rops@malwrhunterteam@taviso@simonw@goodside@DailyDarkWeb@ido_cohen2@FalconFeedsio@DarkWebInformer@blackorbird@nextronresearch@ESETresearch@watchtowrcyber@HuntressLabs@Unit42_Intel@Mandiant@ipurple@thegrugq@dinosn@_r_netsec@TheZvi@emollick
Hacker News topics
AI securityprompt injectionLLMAIvulnerabilityransomwarezero-daydata breach
Mastodon
@malwaretech@infosec.exchange@hacks4pancakes@infosec.exchange@mttaggart@infosec.exchange@dangoodin@infosec.exchange@troyhunt@infosec.exchange@netbiosx@infosec.exchange@GossiTheDog@cyberplace.social@campuscodi@mastodon.social