How it works
A machine-written security & AI digest
kyber.today publishes a daily recap of the most important cybersecurity and AI news, with a focus on where the two intersect. Every issue is gathered, triaged, written, and tagged by an automated pipeline — no human edits it before it goes live. 47 issues published so far.
The pipeline
Each issue is the output of five stages. The per-issue funnel line (“61 of 68 sources → 399 gathered → 399 triaged → 38 clustered → 38 written”) is exactly this pipeline narrowing the day’s news down.
- Gather. Pulls every source in a config file — security & AI blogs, CVE/advisory feeds, national CERTs (Nordics/EU/Ukraine), Hacker News topic searches, and curated infosec/AI accounts on X. Everything is normalized, de-duplicated by URL, and filtered to a freshness window.
- Triage.
claude-haiku-4-5clusters the candidates across sources (the same story from several outlets becomes one cluster) and scores each on intrinsic importance and how well it matches the reader profile. - Rank. Clusters are ordered in code by importance + interest + cross-source corroboration, so a well-reported story and an on-profile niche one both surface.
- Write.
claude-opus-4-8drafts the recap from the top clusters, leading with the biggest stories and quoting community reaction (X replies / Hacker News comments) where it adds something. - Enrich & publish.
claude-haiku-4-5extracts a summary and normalized tags (topics, vendors, threat actors, CVEs, malware, models). The result is committed as a markdown file and this static site is rebuilt.
Is there human review?
No. The digest is written and tagged entirely by AI models and published automatically on a schedule — there is no editor in the loop. Treat it as a machine summary of public reporting, not as original or verified journalism. Every claim links to its primary source; when a story is thin or a listing is unconfirmed, the digest is meant to say so — but the models can still be wrong, miss context, or misattribute. Verify anything important against the linked source.
How stories are chosen
Selection is driven by three signals — intrinsic importance, match to a stated reader interest profile (offensive/defensive security, cloud & identity, AI/LLM security, threat intel, EU/Nordic regulation), and how many independent sources corroborate a story. Recently-covered stories are suppressed, and a genuine development of an earlier story is presented as a continuing thread that links back to previous coverage.
Corrections & contact
Because the pipeline is automated, the best correction is at the source: every item links out, so follow the link for the authoritative account. Sources and the reader profile are version-controlled and evolve over time.
Comments, suggestions, corrections, or a source worth adding? Email root@kyber.today — feedback on what to cover, what to cut, and what the pipeline got wrong is genuinely welcome.
Sources
Pulled every run: 27 feeds & advisories, 23 X accounts plus 2 topic searches, 8 Hacker News topics, and 8 Mastodon accounts. This list is generated from the live config.