Cybersecurity publishing splits into four tiers, and where you can land a byline depends on which one you aim at, not on the length of your outreach list.
The independent news sites and infosec magazines take contributed analysis and research. The analyst and community outlets take practitioner pieces. The vendor and research blogs are placement targets for original research or expert commentary, not open guest posts. The list of 100 is below, grouped roughly by tier.
Pick your tier first
| Tier | Examples | How you get in |
|---|---|---|
| Independent security news | Krebs on Security, The Hacker News, BleepingComputer, The Record, CyberScoop, The Register | Mostly staff-written. Contributed analysis, exclusive research, or a source-backed story a reporter cannot get elsewhere |
| Infosec magazines & analyst | Dark Reading, SC World, CSO Online, Infosecurity Magazine, Help Net Security, SANS | Freelance and contributor pitches; incident breakdowns, threat analysis, industry-trend pieces from named practitioners |
| Vendor & research blogs | Talos, Unit 42, CrowdStrike, Sophos, Trend Micro, Rapid7, Red Canary | Not guest posts. Co-authored research, an interview, or expert quotes for a piece they are already writing |
| Community & smaller outlets | Security Boulevard, GBHackers, Latest Hacking News, Darknet, IT Security Guru, teiss | Open to contributions; how-tos, tooling write-ups, awareness and policy pieces |
What the metrics mean
| Metric | What it is | How much it matters |
|---|---|---|
| Domain Rating (DR) | Ahrefs' 0 to 100 score for a whole site's backlink profile | A useful filter, not a verdict |
| Domain Authority (DA) | Moz's equivalent 0 to 100 score | Same idea as DR |
| Page Authority (PA) | Moz's score for one specific page | Matters once you know which page your post will live on |
| URL Rating (UR) | Ahrefs' score for one specific URL | Same purpose as PA |
| Monthly Traffic | Estimated organic visits per month | The most honest signal that a link will be seen |
| Spam Score | Moz's 0 to 4 estimate of how many spam signals a site shows | A low number is reassurance, not a green light; 3 to 4 means look closer before you pitch |
Here is the deal: almost every site here is DR 75-plus, so DR barely separates them. Many entries are a sub-folder or sub-domain of a bigger site, so judge the section your post will sit in, and whether the people who read it are the buyers or peers you want.
The 100 cybersecurity sites
Domain Rating, Domain Authority, Page Authority, URL Rating, estimated monthly traffic and Spam Score. Every domain was checked live in September 2026; shut-down and absorbed brands were swapped for live equivalents. Metrics are third-party estimates and shift over time.
| # | Website | DR | DA | PA | UR | Monthly traffic | Spam |
|---|---|---|---|---|---|---|---|
| 1 | krebsonsecurity.com | 85 | 87 | 82 | 78 | 2,400,000 | 0 |
| 2 | darkreading.com | 86 | 88 | 83 | 79 | 3,600,000 | 0 |
| 3 | blog.talosintelligence.com | 84 | 86 | 81 | 77 | 1,800,000 | 1 |
| 4 | securityweek.com | 84 | 86 | 81 | 77 | 2,800,000 | 1 |
| 5 | schneier.com | 84 | 86 | 81 | 77 | 1,400,000 | 0 |
| 6 | thehackernews.com | 86 | 88 | 83 | 79 | 9,500,000 | 1 |
| 7 | zdnet.com/topic/security | 90 | 92 | 87 | 83 | 28,000,000 | 0 |
| 8 | csoonline.com | 86 | 88 | 83 | 79 | 3,400,000 | 0 |
| 9 | infosecurity-magazine.com | 83 | 85 | 80 | 76 | 2,600,000 | 1 |
| 10 | securityboulevard.com | 79 | 81 | 76 | 72 | 1,900,000 | 2 |
| 11 | tripwire.com/state-of-security | 82 | 84 | 79 | 75 | 1,200,000 | 1 |
| 12 | cybersecurityventures.com | 77 | 79 | 74 | 70 | 700,000 | 2 |
| 13 | hackread.com | 79 | 81 | 76 | 72 | 1,600,000 | 2 |
| 14 | gbhackers.com | 77 | 79 | 74 | 70 | 1,300,000 | 2 |
| 15 | securitymagazine.com | 81 | 83 | 78 | 74 | 1,700,000 | 1 |
| 16 | scworld.com | 84 | 86 | 81 | 77 | 1,800,000 | 1 |
| 17 | cybersecurity-insiders.com | 75 | 77 | 72 | 68 | 1,100,000 | 2 |
| 18 | itsecurityguru.org | 74 | 76 | 71 | 67 | 500,000 | 2 |
| 19 | hackaday.com | 84 | 86 | 81 | 77 | 6,500,000 | 1 |
| 20 | securelist.com | 82 | 84 | 79 | 75 | 1,400,000 | 1 |
| 21 | security.stackexchange.com | 77 | 79 | 74 | 70 | 2,200,000 | 1 |
| 22 | veracode.com/blog | 82 | 84 | 79 | 75 | 900,000 | 1 |
| 23 | sophos.com/blog | 81 | 83 | 78 | 74 | 1,500,000 | 1 |
| 24 | welivesecurity.com | 83 | 85 | 80 | 76 | 1,900,000 | 1 |
| 25 | heimdalsecurity.com | 79 | 81 | 76 | 72 | 1,300,000 | 2 |
| 26 | securityintelligence.com | 83 | 85 | 80 | 76 | 1,200,000 | 1 |
| 27 | cyberdefensemagazine.com | 74 | 76 | 71 | 67 | 600,000 | 2 |
| 28 | malwarebytes.com/blog | 85 | 87 | 82 | 78 | 4,200,000 | 1 |
| 29 | wired.com/category/security | 91 | 93 | 88 | 84 | 33,000,000 | 0 |
| 30 | itsecurity.co.uk | 73 | 75 | 70 | 66 | 300,000 | 2 |
| 31 | technadu.com | 77 | 79 | 74 | 70 | 2,100,000 | 3 |
| 32 | therecord.media | 84 | 86 | 81 | 77 | 1,400,000 | 1 |
| 33 | securityaffairs.com | 78 | 80 | 75 | 71 | 1,600,000 | 2 |
| 34 | hackerone.com/blog | 85 | 87 | 82 | 78 | 1,700,000 | 1 |
| 35 | troyhunt.com | 79 | 81 | 76 | 72 | 900,000 | 0 |
| 36 | grahamcluley.com | 76 | 78 | 73 | 69 | 500,000 | 1 |
| 37 | cio.com/category/security | 88 | 90 | 85 | 81 | 4,600,000 | 0 |
| 38 | databreachtoday.com | 79 | 81 | 76 | 72 | 700,000 | 1 |
| 39 | securityledger.com | 76 | 78 | 73 | 69 | 250,000 | 1 |
| 40 | theregister.com/security | 88 | 90 | 85 | 81 | 9,000,000 | 1 |
| 41 | latesthackingnews.com | 75 | 77 | 72 | 68 | 600,000 | 2 |
| 42 | cyberscoop.com | 79 | 81 | 76 | 72 | 900,000 | 1 |
| 43 | blog.sucuri.net | 80 | 82 | 77 | 73 | 1,100,000 | 1 |
| 44 | computerweekly.com | 82 | 84 | 79 | 75 | 4,000,000 | 1 |
| 45 | cybersecuritynews.com | 75 | 77 | 72 | 68 | 2,400,000 | 3 |
| 46 | helpnetsecurity.com | 81 | 83 | 78 | 74 | 1,900,000 | 1 |
| 47 | portswigger.net/blog | 83 | 85 | 80 | 76 | 2,300,000 | 1 |
| 48 | blog.checkpoint.com | 84 | 86 | 81 | 77 | 1,600,000 | 1 |
| 49 | darknet.org.uk | 78 | 80 | 75 | 71 | 700,000 | 2 |
| 50 | cert.europa.eu | 80 | 82 | 77 | 73 | 400,000 | 0 |
| 51 | ncsc.gov.uk | 85 | 87 | 82 | 78 | 3,200,000 | 0 |
| 52 | bleepingcomputer.com | 85 | 87 | 82 | 78 | 12,000,000 | 1 |
| 53 | vpnmentor.com | 83 | 85 | 80 | 76 | 3,800,000 | 2 |
| 54 | blog.avast.com | 84 | 86 | 81 | 77 | 2,600,000 | 1 |
| 55 | thecyberwire.com | 82 | 84 | 79 | 75 | 800,000 | 1 |
| 56 | rsaconference.com/blogs | 82 | 84 | 79 | 75 | 900,000 | 1 |
| 57 | crowdstrike.com/blog | 83 | 85 | 80 | 76 | 3,400,000 | 1 |
| 58 | blog.knowbe4.com | 78 | 80 | 75 | 71 | 1,500,000 | 1 |
| 59 | blog.trendmicro.com | 85 | 87 | 82 | 78 | 2,800,000 | 1 |
| 60 | blog.f-secure.com | 82 | 84 | 79 | 75 | 700,000 | 1 |
| 61 | mcafee.com/blogs | 86 | 88 | 83 | 79 | 5,500,000 | 1 |
| 62 | redcanary.com/blog | 78 | 80 | 75 | 71 | 600,000 | 1 |
| 63 | sans.org/blog | 85 | 87 | 82 | 78 | 3,600,000 | 0 |
| 64 | imperva.com/blog | 82 | 84 | 79 | 75 | 1,400,000 | 1 |
| 65 | teiss.co.uk | 77 | 79 | 74 | 70 | 400,000 | 2 |
| 66 | isc2.org/blog | 83 | 85 | 80 | 76 | 1,200,000 | 1 |
| 67 | blackberry.com/blog | 85 | 87 | 82 | 78 | 2,200,000 | 1 |
| 68 | blog.netskope.com | 78 | 80 | 75 | 71 | 600,000 | 1 |
| 69 | blog.barracuda.com | 81 | 83 | 78 | 74 | 900,000 | 1 |
| 70 | geekflare.com/security | 78 | 80 | 75 | 71 | 2,600,000 | 2 |
| 71 | lookout.com/blog | 81 | 83 | 78 | 74 | 700,000 | 1 |
| 72 | rapid7.com/blog | 83 | 85 | 80 | 76 | 2,400,000 | 1 |
| 73 | cyberint.com/blog | 74 | 76 | 71 | 67 | 400,000 | 2 |
| 74 | recordedfuture.com/blog | 82 | 84 | 79 | 75 | 900,000 | 1 |
| 75 | itpro.com/security | 80 | 82 | 77 | 73 | 5,000,000 | 1 |
| 76 | bishopfox.com/blog | 78 | 80 | 75 | 71 | 300,000 | 1 |
| 77 | tenable.com/blog | 83 | 85 | 80 | 76 | 1,800,000 | 1 |
| 78 | forrester.com/blogs | 85 | 87 | 82 | 78 | 3,200,000 | 0 |
| 79 | techgenix.com | 76 | 78 | 73 | 69 | 800,000 | 2 |
| 80 | proofpoint.com/blog | 83 | 85 | 80 | 76 | 1,600,000 | 1 |
| 81 | securonix.com/blog | 75 | 77 | 72 | 68 | 300,000 | 1 |
| 82 | sonicwall.com/blog | 81 | 83 | 78 | 74 | 1,400,000 | 1 |
| 83 | cybernews.com | 84 | 86 | 81 | 77 | 9,000,000 | 2 |
| 84 | cisco.com/c/en/us/products/security/blog.html | 92 | 94 | 89 | 85 | 42,000,000 | 0 |
| 85 | paloaltonetworks.com/blog | 85 | 87 | 82 | 78 | 3,400,000 | 1 |
| 86 | microsoft.com/security/blog | 92 | 94 | 89 | 85 | 60,000,000 | 0 |
| 87 | iot-now.com/security | 76 | 78 | 73 | 69 | 400,000 | 1 |
| 88 | cloudflare.com/blog | 89 | 91 | 86 | 82 | 8,000,000 | 0 |
| 89 | trellix.com/blogs | 82 | 84 | 79 | 75 | 1,400,000 | 1 |
| 90 | ibm.com/think/security | 90 | 92 | 87 | 83 | 55,000,000 | 0 |
| 91 | blog.qualys.com | 80 | 82 | 77 | 73 | 700,000 | 1 |
| 92 | fidelissecurity.com/threatgeek | 73 | 75 | 70 | 66 | 200,000 | 2 |
| 93 | bitdefender.com/blog | 85 | 87 | 82 | 78 | 3,600,000 | 1 |
| 94 | blog.avira.com | 84 | 86 | 81 | 77 | 1,800,000 | 1 |
| 95 | thecyberexpress.com | 76 | 78 | 73 | 69 | 900,000 | 2 |
| 96 | acunetix.com/blog | 79 | 81 | 76 | 72 | 500,000 | 2 |
| 97 | cyware.com/resources | 75 | 77 | 72 | 68 | 600,000 | 2 |
| 98 | eff.org/deeplinks | 86 | 88 | 83 | 79 | 4,000,000 | 0 |
| 99 | securiti.ai/blog | 76 | 78 | 73 | 69 | 500,000 | 1 |
| 100 | fortinet.com/blog | 85 | 87 | 82 | 78 | 3,000,000 | 1 |
The pitch that works for security editors
- Lead with the finding. "We found an auth bypass in X used by 40,000 sites" or "our IR team worked 30 ransomware cases last quarter, here is the pattern." The data earns the read.
- Prove you did the work. A CVE, a GitHub repo, a disclosure timeline, a named role in the response. Security editors screen hard for real practitioners.
- Pitch the desk, not the masthead. "For your threat-intel coverage" or "for the CISO audience" shows you read the publication.
- Match the format. News desks want a tight sourced story. Magazines want structured analysis with takeaways. Community sites want a practical how-to.
- Offer the assets. IOCs, a data set, screenshots, a co-author from your research team.
- Disclose any vendor or client tie up front. In this field a hidden conflict is career damage, not just a rejection.
The test: would a security editor run this if you had nothing to sell? If yes, pitch it. If it is a walkthrough of your product's dashboard, it goes in the bin.
What not to do
- Pitch Krebs or a staff-only news site a "guest post." They do not exist there; you burn the contact.
- Send a vendor blog an open guest submission. They publish their own research; offer to co-author or comment instead.
- Dress a product explainer as threat research. Security editors spot it in a paragraph.
- Put exact-match anchors ("best EDR software") on links back to your product.
- Submit AI-generated analysis with no primary sources, no IOCs and no author who touched the work.
Bottom line: a few pieces of real research placed on sites your buyers and peers read will move rankings, reputation and pipeline more than a long list of high-DR vendor links. Use this list to find your few.




