http://www.sqlsecurity.com
has a page dedicated strictly to patches and service packs.
Also, MS has a mailing list still I do believe but I forget where to find it and Shavlik (http://www.shavlik.com/) sends emails about MS patching.
Lastly, Windows Update now handles SQL Server so periodically checking by going to the site can be of help. Although I personally would not do the install from the client there, I would download it for install manually.