NTBugTraq (if you're interested in Windows NT/2000/XP) or the original BugTraq for Unix OSes.
Win2KSecAdvice...not as good, but can have some interesting discussions.
The vendor mailing list for any product you have (Microsoft Security Bulletins, NAI-Macafee product alerts, etc...
--Woodie