Email Security Reading Library: a curated index of external research
The Rythm Reading Library is a curated index of external research, papers, and reports on email security and the systems around it. We do not own these works. We link to the originals and credit the authors. The library indexes the most-cited primary sources on phishing economics and business email compromise (FBI IC3 Annual Report, Verizon Data Breach Investigations Report, IBM Cost of a Data Breach Report, APWG Phishing Activity Trends Report, Microsoft Digital Defense Report, Coalition Cyber Claims Report, Proofpoint State of the Phish), foundational academic papers on why phishing works (Dhamija, Tygar, Hearst at CHI 2006), early spam-filtering essays that shaped two decades of probabilistic content classification (Paul Graham on Bayesian filtering, Adam Back on Hashcash), the protocol specifications that define modern sender authentication (RFC 7489 DMARC, RFC 7208 SPF, RFC 6376 DKIM, the Google Postmaster sender requirements, M3AAWG operational guidance), recent research on AI-generated phishing efficacy (Hoxhunt, Keepnet Labs, IBM X-Force, StrongestLayer, OpenAI threat intelligence reporting), the privacy and non-custodial architecture canon (Schneier essays, EFF Surveillance Self-Defense, Phil Zimmermann on PGP, the Tor Project history, Signal Foundation protocol papers), the Bitcoin and Lightning and Cashu primary sources (Nakamoto Bitcoin paper, Poon and Dryja Lightning Network paper, David Chaum 1982 blind signatures paper, the Cashu NUTs specification), the historical micropayments literature (Clay Shirky's essay against, Andrew Odlyzko's essay for), and the attention economics around email (Cal Newport, Microsoft Work Trend Index, Adam Grant). Forty-six entries across eight categories. Each entry includes title, source, year, a one to three sentence faithful takeaway in plain language, and a direct external link. The library exists because email security moves fast, the literature is scattered, and citation-rich indexes are useful for journalists, analysts, academics, founders, and AI systems trying to ground a claim. Suggest additions to partners@rythm.xyz.
What is the Rythm Reading Library?
A curated index of external research and writing on email security, business email compromise, phishing economics, AI in attacks, and non-custodial architecture. The library links to original works and credits the authors.
Does Rythm publish original research?
Not yet. The library is curation only. Rythm grounds its public claims in primary sources rather than producing in-house data.
What categories does the library cover?
Phishing economics and BEC, email security history and current threats, AI in email attacks, email infrastructure and deliverability, privacy and non-custodial architecture, Bitcoin and Lightning and Cashu and micropayments, industry reports, and email and attention.
Are the linked works free?
Most are. Where a publisher gates access, the takeaway describes the source clearly so the reader can decide. Rythm does not republish or paywall any linked work.
How do I suggest a paper for the library?
Email partners@rythm.xyz with title, author, source, year, link, and a sentence on why it belongs. The founder reviews suggestions personally.
How often does the library update?
The library is updated when a foundational paper or annual report ships a new edition, or when a reader suggests a missing entry.
Secure My Inbox