Is it the vendors sites, like microsoft and redhat? A security site like securityfocus? A maillist like bugtraq

yes...

i never rely on any one site...i visit them all...(that are relevant...we don't run linux here) as well as all of the major AV software vendors...it's amazing how differently they all respond...

just book mark em and make it a rountine with your morning coffee...