Get on some infosec mailing lists —
advisory bulletins, etc.
Advisories
CERT advisories:
http://www.cert.org —
Very high level, and they don't (usually)
appear until a fix is known.
CERT advisories are nice reminders,
but they should not be the way you
first hear about a problem!
You might find the C4I mailing list of interest,
if you don't mind esoteric discussions of
satellite link hardware and endless
self-promotion by certain self-proclaimed
"infowar experts".
Send a message (with no subject!) to
C4I-PRO-REQUEST@stl.nps.navy.mil
with a single line message along the lines of: subscribe C4I-PRO mylogin@mycompany.com