These posts by the Drupal security team are also sent to the security announcements e-mail list.
Drupal 8.2.7, a maintenance release which contains fixes for security vulnerabilities, is now available for download.
In addition to the news page and sub-tabs, all security announcements are posted to an email list. To subscribe to email: log in, go to your user profile page and subscribe to the security newsletter on the Edit » My newsletters tab.
You can also get rss feeds for core, contrib, or public service announcements or follow @drupalsecurity on Twitter.
In order to report a security issue, or to learn more about the security team, please see the Security team handbook page.
If you are a Drupal developer, please read the handbook section on Writing secure code.
There are many useful books about Drupal. Here are two that discuss security:
Tweets by @drupalsecurity
Drupal is a registered trademark of Dries Buytaert.