Signing you in...

Please wait while we verify your authentication

How-to guide

How to Get Daily Cybersecurity News in Your Inbox — Signal, Not Vendor Pitches

Published July 3, 2026

It's 11pm and you're scrolling Twitter when a researcher posts a CVE for the exact firewall you manage. Nobody paged you — you just got lucky.

The good news? You can replace that luck with a system in about two minutes — and the first edition is free.

In this guide, I'll show you how to get daily cybersecurity news in your inbox with MorningMail, a tool I built. Every morning, an AI agent searches the web fresh and writes you a short email: actively exploited CVEs, patches, breach disclosures, NIS2 — with the advisories linked.

Let's set it up.

Try it yourself — your first edition is free →

What you'll build

How to Get Daily Cybersecurity News in Your Inbox — Signal, Not Vendor Pitches — Cybersecurity · Industry brief

Security newsletters write for an imagined admin who runs every product at once. You don't. You run a specific estate — Windows servers, a Fortinet perimeter, Microsoft 365, one legacy Linux box nobody admits to owning — and 90 percent of any generic digest is about someone else's stack.

MorningMail starts from your instruction instead. You describe that estate once, and every morning an agent searches current sources and writes the report itself — severity, affected versions, advisory linked. It's not a link forwarder like Google Alerts: you get the conclusion, not a pile of matches to triage.

And your prompt keeps that context permanently, so the brief scales with the day. Quiet morning? A genuinely short email. A KEV addition that hits your stack? It leads — because you told the agent what "hits your stack" means.

See it live: today's edition

So here's a real example. This is today's edition of exactly this newsletter — written by the agent this morning, based on the example prompt from this guide. Not a mockup: I run it myself on MorningMail.

Edition from August 22, 2026

Cybersecurity · Industry brief
Saturday, August 22, 2026
Cybersecurity · Industry brief

Channel goes vertical, CTO launches AI fund, defense contractors balk

2 min read

ScanSource acquires MicroAge

Distributors are no longer arms-length middlemen.

ScanSource is paying $220.5 million in cash for MicroAge, a value-added reseller and managed service provider, pulling 2,400 customers and 200 employees into direct ownership [Quelle: Channel Dive]. CEO Mike Baur plans to rent MicroAge's engineering and Octum.ai consulting capacity back to ScanSource's channel partners, capturing hardware and services revenue that currently bypasses the distributor tier entirely. Converged Technology Professionals CEO Joe Rittenhouse calls this trend fundamental: customers now demand integration and post-deployment support, not vendor comparison.

Expect more tuck-ins as distributors compete upstream.

CrowdStrike CTO launches AI security fund

Agentic AI just got its own venture thesis.

CrowdStrike global CTO Elia Zaitsev is leaving to launch Cognition, a $170 million venture fund targeting startups building security for autonomous agents [Quelle: Konsulteer]. Cognition plans three to four concentrated bets annually at seed and Series A stages, focusing on detection of prompt injection, agent permission control, and AI identity management—new attack surfaces traditional SIEM platforms weren't built for. The thesis reflects what CrowdStrike itself is now engineering: security layers designed for systems that act autonomously rather than just log events.

Watch whether other vendor CTOs follow Zaitsev out the door.

CrowdStrike takes security to midmarket

Enterprise security is going retail through partners.

CrowdStrike is pushing Project QuiltWorks—its AI-driven vulnerability platform—down to small and midmarket businesses via Arrow Electronics, Pax8, TD Synnex, and managed service providers [Quelle: Channel Dive]. Each dollar of CrowdStrike sales generates over $7 in partner services across the customer lifecycle, making MSPs effective outsourced security arms rather than just fulfillment arms. The model wraps enterprise-grade detection around partner expertise, reaching SMBs that can't afford dedicated teams.

Channel conflicts—particularly with Zip Security—will test whether vendors and MSPs can coexist in the same pipeline.

Defense contractors lose faith in CMMC readiness

Pentagon compliance confidence is collapsing fast.

Only 65 percent of contractors submitting 2026 CMMC self-assessments reported high confidence in their accuracy, down from 89 percent in 2025, according to a CyberSheath report [Quelle: Cybersecurity Dive]. The median contractor believes it is only 70 percent ready for certification review, though adoption of core practices like multifactor authentication (63 percent) and vulnerability management (44 percent) has ticked up. The DOD suspended Phase II requirements in July citing excessive compliance costs, yet the Trump administration continues prosecuting defense firms under the False Claims Act for misrepresenting security posture.

Contractors are now calling for supply-chain vendors—MSPs and managed security providers—to face identical DFARS requirements.

Sources
ScanSource to buy MicroAge for $220.5M in another convergence ...
ScanSource to buy MicroAge for $220.5M in another convergence ...
22 hours ago ... Security · AI & Automation · Emerging Tech · Policy & Regulation · Money Matters ... Private equity, cybersecurity drive managed services industry consolidation.
channeldive.com
AI Summary

ScanSource is acquiring value-added reseller and managed service provider MicroAge for $220.5 million in an all-cash transaction, adding over 2,400 U.S. customers and 200 employees. The acquisition, announced in ScanSource's Q4 earnings report, represents a strategic shift in the enterprise cybersecurity and IT services distribution market—moving from arms-length distributor relationships toward direct ownership of service providers. CEO Mike Baur indicated the company plans to rent MicroAge's engineering and consulting resources (including its Octum.ai AI consulting business) to technology advisors in ScanSource's Intelisys channel, addressing service gaps and capturing hardware and professional services revenue that currently bypasses distributors. Industry observers, including Converged Technology Professionals CEO Joe Rittenhouse, characterize this consolidation trend as reflecting fundamental changes in partner value models, with customers increasingly demanding integration, implementation, and post-deployment support capabilities rather than vendor comparison services. The deal mirrors ScanSource's 2024 acquisition of technology advisor business Resourcive, signaling a broader consolidation pattern in the IT channel as distributors move upstream to interface directly with end customers.

Visit source
CrowdStrike CTO Leaves to Launch $170 Million AI Cybersecurity ...
CrowdStrike CTO Leaves to Launch $170 Million AI Cybersecurity ...
12 hours ago ... The move reflects a broader shift taking place across the cybersecurity industry. ... enterprise security market. Zaitsev's move is particularly notable ...
konsulteer.com
AI Summary

CrowdStrike's global CTO Elia Zaitsev is launching Cognition, a new $170 million venture fund focused on AI-enabled cybersecurity, alongside former CrowdStrike corporate development executives Gur Talpaz and Tayler Sipperly. The fund plans to make three to four concentrated investments annually at seed ($6 million average) and Series A ($15 million average) stages, targeting startups developing security solutions for agentic AI systems and enterprise AI adoption. Cognition's thesis centers on agentic AI creating new attack surfaces and security risks as organizations deploy autonomous agents with access to corporate systems, data and workflows, requiring new classes of security platforms distinct from traditional enterprise security products. The move reflects broader industry shifts as cybersecurity vendors develop tools for monitoring agent behavior, controlling permissions, detecting prompt injection attacks and managing AI identities across enterprise environments. (Source: Axios reporting cited in article)

Visit source
CrowdStrike mobilizes cybersecurity coalition to defend SMBs
CrowdStrike mobilizes cybersecurity coalition to defend SMBs
10 hours ago ... In early August, the company corralled Arrow Electronics, Pax8, TD Synnex and several other channel firms to mobilize the midmarket push. The move comes amid a ...
channeldive.com
AI Summary

CrowdStrike is expanding Project QuiltWorks, its cyberdefense alliance, from large enterprises to small and midsized businesses through channel partners including Arrow Electronics, Pax8, TD Synnex, and managed service providers. The initiative integrates CrowdStrike's AI-driven vulnerability discovery with partner expertise and services from OpenAI and Anthropic. The model allows MSPs to wrap enterprise-grade security capabilities around their own services for SMB customers lacking dedicated security teams, with Omdia research indicating each dollar of CrowdStrike sales generates over $7 in partner services opportunities across the customer lifecycle. Channel Dive reports this reflects broader vendor interest in SMB opportunities, with CrowdStrike positioning partners as outsourced security arms rather than fulfillment arms, though potential conflicts exist—such as with Zip Security, which already sells competing managed security platforms.

Visit source
Defense contractors still struggling with basic CMMC requirements
Defense contractors still struggling with basic CMMC requirements
11 hours ago ... Defense contractors are concerned about their compliance with cybersecurity requirements, a new report found. ... Filed Under: Strategy, Policy & Regulation ...
cybersecuritydive.com
AI Summary

Defense contractors are experiencing declining confidence in their cybersecurity readiness under the U.S. military's Cybersecurity Maturity Model Certification (CMMC) program, according to a CyberSheath report published Thursday. Only 65% of contractors that submitted 2026 self-assessment scores reported high confidence in their accuracy, down from 89% in 2025 and 94% in 2024, with the median contractor believing it is only 70% ready for certification review. The Department of Defense suspended CMMC's second phase in July citing excessive compliance costs, though first-phase requirements remain in effect. Contractors continue struggling with evolving requirements, evidence production, and compliance demonstration, though mean self-assessment scores have improved to +51 in 2026 and adoption of key security practices like multifactor authentication (63%), secure backups (48%), and vulnerability management (44%) has increased. The Trump administration continues prosecuting defense firms under the False Claims Act for misrepresenting cybersecurity compliance, reinforcing accountability despite delayed third-party certification requirements. Contractors surveyed also called for expanding DFARS cybersecurity requirements to managed security service providers, managed service providers, and other technology vendors to address supply-chain vulnerabilities (CyberSecurityDive, citing CyberSheath report).

Visit source
Compiled overnight by MorningMail.aiDelivered at 07:00
Take this newsletter into your library

One click creates your own editable copy — change the prompt, the delivery time, everything.

Browse all editions →

You could get this general version into your inbox right now — and then fine-tune it to your very specific needs. Here's how to do it:

Step by step: from zero to your first edition

The whole setup takes about two minutes. And every screenshot below comes straight from the real product — nothing is mocked up.

  1. Step 1 Open morningmail.ai

    No account yet, nothing to install — the landing page IS where you compose. A friendly press robot introduces itself above one big input, and beside it a sample morning shows you what the email looks like before you have typed a word.

    Open morningmail.ai
  2. Step 2 Type your topic: Cybersecurity

    Type Cybersecurity into that one input. There is nothing to pick and no form to fill — as you type, a draft section forms on the paper beside you, carrying your topic in a tinted badge and the quiet prompt "↵ Enter adds it", and the ↵ Enter key at the end of the input turns orange.

    Type your topic: Cybersecurity
  3. Step 3 Press Enter (or that orange key) — and read what the agent was told

    There's nothing to set up first — morningmail.ai opens on the composing surface itself: one input, a live paper beside it. Type Cybersecurity, press Enter, and the section arrives with a beat badge, a suggested headline and an Assignment already written — the actual prose telling the agent what to go looking for overnight. You read the agent's marching orders before any account exists.

    The highest-value edit here is scoping it to your estate. Click the Assignment and make it yours: "We run Windows Server, Fortinet firewalls and Microsoft 365 for 800 users in the EU. Lead with actively exploited CVEs and vendor advisories for that stack, then NIS2; skip vendor product announcements." The one-tap tweaks under the field help too — for security I'd keep "+ name sources" on, so every claim arrives with the advisory attached.

    Press Enter (or that orange key) — and read what the agent was told
    The exact prompt your section starts with
    Releases, benchmarks and the sharpest take on Cybersecurity from the past 24 hours — compressed to what a builder actually needs.
  4. Step 4 Send your free first email

    Happy with the paper? Hit “Send my free first email”. The sign-up appears right there — the paper never leaves the screen — and asks the only thing it still needs: where to send it. Email and password, or Google. No card, and the first email is free.

    Send your free first email
  5. Step 5 Watch it being written

    Now the desk goes to work in front of you: working out what to look for, searching the web, reading the best sources, writing your section, composing a subject line, handing it to the post. A minute or two later: "It's in your inbox."

    Watch it being written
  6. Step 6 Afterwards: the time, the days, the readers

    Everything else lives in the builder, once you have a paper to tune. Set the delivery time (07:00 by default) and which weekdays it runs, add readers — up to 100 — and add more topics the same way you added the first: by typing. Nothing here needs deciding on day one.

    Afterwards: the time, the days, the readers

Get more out of your brief

Put your asset list in the prompt
This is the single biggest quality lever. "Exploited vulnerabilities in Fortinet, Citrix, Exchange and VMware products first" turns a general news brief into something close to a personal advisory feed — written as prose you can forward.
Ask for exploitation status, not just severity
A CVSS 9.8 nobody exploits can wait for the maintenance window; a 7.2 with active exploitation cannot. Add "state whether each vulnerability is known to be exploited in the wild" and the brief starts triaging the way you do.
Reserve one slot for regulation
NIS2 obligations and incident-reporting deadlines move slowly, then suddenly. A line like "include one regulatory or compliance item when material" keeps you ahead of the audit without letting policy news crowd out patches.
Send it to the whole ops team
Templates support multiple recipients, so on-call and the sysadmin group read the same brief before the morning check-in. Everyone argues from the same three stories instead of three different Slack links 😊
Keep the tone dry and the sections short
Each section has its own length and tone settings. For security, terse wins: set the section to short, ask for bullets, and let the linked advisories carry the detail. Two minutes of reading — your time belongs to the follow-up.

Good sources to anchor your brief on

The agent searches the open web every morning and cites where it read things. These are the sources I'd point it at in your prompt:

  • CISA Known Exploited Vulnerabilities catalog — The de facto triage list: vulnerabilities confirmed exploited in the wild, with remediation deadlines the rest of the industry treats as a benchmark.
  • Microsoft Security Response Center (MSRC) — The primary source for Patch Tuesday and out-of-band fixes. If you run Windows anywhere, a brief that cites MSRC directly beats any second-hand patch roundup.
  • Krebs on Security — Independent investigative reporting on breaches, cybercrime and the ecosystem behind them — often ahead of official disclosures, always sourced.
  • The Hacker News — High-frequency coverage of vulnerabilities, campaigns and research. A useful breadth signal; your brief should chase its stories back to the underlying advisories.
  • BSI / CERT-Bund advisories — Germany's federal security office publishes advisories and situation reports that matter for any EU operation — and for NIS2, the national implementation is where obligations get concrete.
  • NVD (NIST) — The canonical CVE record: scores, affected configurations, references. The place your change ticket ultimately points to, whoever broke the story.

Frequently asked questions

How much does this cost after the free edition?
The first edition is free, no credit card. After that you pay per send in credits — a few per section, depending on the AI model tier it uses. Credits never expire, so a quiet month wastes nothing.
Isn't this what Google Alerts does?
Honestly — no. Alerts mail you every page that mentions your keyword, and for "cybersecurity" that's a firehose of vendor content you still have to read. Here the agent searches fresh each morning, filters against your prompt, and writes the report with the advisories linked.
Does it cover CVEs and Patch Tuesday?
Yes — if your prompt asks for them, and it should. Tell the agent to lead with actively exploited vulnerabilities and vendor advisories for your stack, and Patch Tuesday summaries arrive the morning after, MSRC and vendor pages linked.
Is this a replacement for a threat-intel platform?
No — it's a reading brief, not detection tooling. It won't watch your logs or your attack surface. What it replaces is the hour of morning triage across feeds, subreddits and newsletters — by writing the summary you'd have assembled by hand.
Can it track NIS2 and other regulatory changes?
Yes. Write it into the prompt — for example "include NIS2 implementation news and incident-reporting guidance for Germany when material." The agent re-reads its instructions every morning, so the regulatory thread stays warm without you chasing it.

Your inbox, your editor

Build your own AI-written brief in two minutes. The first edition is on me — no credit card required.

Build your brief — free

I am always happy to answer questions and I'm open to feedback. Feel free to reach out at any time: marius@morningmail.ai