http://securityfocus.com/archive/1 - Bugtraq, all kinds of stuff gets posted here, this is a great site to monitor if you have an interest in information security. Be careful though, I have seen code posted that was not what it was advertised as. Also check out vuln-dev and focus-virus for malicious code samples.
Found this on BT yesterday, this involves the GDI/jpeg issue that is currently circulating, we'll probably be seeing a mass mailer virus involving this exploit any day now:
http://www.easynews.com/virus.html
Then there's always the ubiquitous IRC, be careful there too
