Recomputed on every load

Who covers what in cyber security

By Nick Forshteyn · CISO AI
Figures as at 29 September 2026

We read and tag every cyber security story we can find. Across 1769 of them from 28 outlets, the interesting result is not what gets covered. It is how differently each subject is covered: across its 30 stories, remote code execution is 63.3% one outlet, while law enforcement, at 32 stories, is split across 10 outlets with none holding more than 18.8%.

How this is measured. Every story CISO AI holds, published between 23 May 2025 and 28 September 2026: 1769 in total from 28 outlets, counting the 53 publishers whose stories arrive through the financial wire as one. 4 outlets silent for more than a week and far longer than their usual gap are marked as last seen and cannot carry a headline claim. Each is summarised and tagged by topic when it arrives, and a story usually carries several tags, so topic shares sum past 100%. Counts are of stories, not words. These figures are computed when you load the page, so they move as the archive grows. The limitations are set out at the end, and they matter.

Some subjects have an owner. Others have nobody.

For each topic we count how many distinct outlets covered it and what share the leading outlet holds. Topics with fewer than 8 stories are excluded, because below that one extra story swings the percentage wildly. The two topics named above clear a higher bar again — 25 stories and 3 outlets — because a headline claim should not turn on a sample small enough for one outlet's back catalogue to move.

TopicStoriesOutletsLeading outletIts share
AI security 312 25 The Hacker News 21.5%
vulnerability 274 18 The Hacker News 34.3%
cryptocurrency 263 5 Financial press wire 94.3%
data breach 221 15 Financial press wire 46.6%
patch management 176 18 The Hacker News 36.4%
vulnerability management 144 18 The Hacker News 27.1%
malware 137 15 The Hacker News 51.8%
phishing 132 16 The Hacker News 31.8%
Stories per topic, for the 8 largest topics. A story usually carries several tags, so topics overlap and the counts deliberately do not sum to 1769.

remote code execution is mostly The Hacker News. Of its 30 stories, that one outlet wrote 19, and only 7 outlets covered the subject at all. Skip that publication and you miss 63.3% of it.

law enforcement is the opposite. At 32 stories it is spread across 10 outlets, with the largest, The Record, holding just 18.8%. No single publication is a reliable way to follow it.

Concentration is not the same as volume

The 7 largest outlets still publishing, The Hacker News, Financial press wire, Dark Reading, Infosecurity Magazine, CISA, The Register, The Record, produced 1277 of the 1769 stories, or 72.2% of everything. That sounds like a concentrated market, and by raw output it is. The topic table shows why that is misleading: the outlets that dominate the total are not the ones that own every subject.

The Hacker News: 420 stories (23.7%) Financial press wire: 409 stories (23.1%) Dark Reading: 175 stories (9.9%) Infosecurity Magazine: 86 stories (4.9%) CISA: 81 stories (4.6%) The Register: 54 stories (3.1%) The Record: 52 stories (2.9%) 21 other outlets: 492 stories (27.8%) 72.2% top 7 outlets
Share of all 1769 stories, by outlet. Outlets that have stopped publishing are counted under "other". Recomputed on every load, so the split moves as the archive grows.

The practical version: a reader following one masthead is not getting a smaller version of the whole picture. They are getting a picture with specific, predictable holes in it, and which holes depends entirely on which masthead.

What this means if you are trying to keep up

If you follow a single source, choose it for what you need to see rather than for general reputation. The Hacker News carries 21.5% of AI security; The Hacker News carries 34.3% of vulnerability; Financial press wire carries 94.3% of cryptocurrency.

If you would rather not maintain a reading list, that is what the weekly briefing is for: every one of these 1769 stories is summarised in plain language, and each topic above has its own page, including AI security, vulnerability, cryptocurrency, data breach.

Limitations, which are real

  • These are the outlets we ingest, not the whole press. Topic shares describe this corpus. A different feed list would produce different percentages.
  • Tagging is model-generated. Topics are assigned automatically when each story is summarised. It is consistent, which is what matters for comparing topics against each other, but it is not a human taxonomy and it will disagree with one at the margins.
  • Counts are of stories, not significance. A one-paragraph advisory and a three-thousand-word investigation count the same here.
  • Outlets join the corpus over time. A source we started reading recently carries only the stories published since it joined, so its share understates its actual output, and comparisons against long-standing sources favour the incumbents. Shares converge as the archive grows.
  • The window is still filling. Feeds deliver stories dated days earlier, so recent counts rise for a while after the fact. That is also why this page is computed rather than published: a figure written into a page was wrong within hours.
  • Outlets stop. A feed that goes dark keeps its stories in the archive. An outlet silent for more than 7 days and more than 3 times its own usual gap between stories is labelled with the date it was last seen wherever this page names it, and is not allowed to carry a headline claim, but its past stories still count in the totals.
  • The financial wire is one outlet here. It delivers each story under the original publisher's name; counting those as separate outlets inflated the outlet count and made cryptocurrency look more fragmented than the press actually is. Leak-site trackers are excluded altogether: a listing is not a story.
  • Cite it with the date you read it, shown above, since the numbers move as the archive grows.

Comments

No comments yet.

To comment, confirm your email once. We send a sign-in link; no password to remember.

Your name appears with your comment; your email never does. By continuing you accept our terms and privacy policy.