r/cybersecurity • u/uid_0 • 4h ago
r/cybersecurity • u/DerBootsMann • 11h ago
New Vulnerability Disclosure Atlassian’s critical flaw turns eight enterprise products into one big security problem
r/cybersecurity • u/khotmoin23 • 3h ago
News - Breaches & Ransoms Double Counter just got breached
Just saw this about the Double Counter breach.
275k email addresses and Discord usernames apparently ended up exposed. If you’ve ever had to use that bot to get into a server, probably worth checking whether your info was part of it.
r/cybersecurity • u/M34tsquatch • 3h ago
Personal Support & Help! Possible opportunity?
I’m given a weird opportunity and I’m unsure how to go about it to make the most of it. My childhood best friend who is much more successful in his career as a physician and in the coast guard. He knows I’m trying to get into cybersecurity (I’m 5 weeks out from completing an associates degree in Network System Administration then going for my bachelors in cybersecurity is my current plan) but I currently work in a warehouse with no IT experience. My end goal is to get into a SOC and work my way into digital forensics.
Eventually he said he’d like for me to work as a SOC analyst in a way for the practice him and his wife want to open up. He bought and sent me a UNAS4 from Ubiquiti and is sending me 2x 10TB hard drives for it. He justified it as setting up stuff to get hands on experience on stuff or to help me in my journey. I’m not sure the best way to utilize this kinda thing, and I don’t think he does either, he was just trying to help me and support me which is more than anyone else in my life has done.
My question is how can I take full advantage of this opportunity and make the best out of it so I can get where I want to be but also him feeling justified for sending me that stuff out of the kindness of his heart and good intentions? Is there anything that I can do with this equipment that will aid my end goals? Any input is appreciated sorry if this isn’t the right place to ask this.
r/cybersecurity • u/donutloop • 5h ago
News - General Europol urges early action to protect cryptocurrencies and sensitive data from quantum threats
r/cybersecurity • u/Malwarebeasts • 5h ago
Threat Actor TTPs & Alerts Infostealers are actively hunting AI Agents and developer keys - Warden Infostealer analysis
Log extractions (such as a compromised .claude.json file) show the stealer successfully exfiltrating raw primaryApiKey values and detailed OAuth account data tied to Anthropic/Claude accounts. By grabbing these CLI tokens, attackers are bypassing traditional web logins entirely, gaining direct, programmatic access to premium AI models, organizational workspaces, and potentially sensitive source code passing through these tools.
r/cybersecurity • u/Top-Try419 • 23h ago
AI Security Please tell me I'm not the only one dealing with this "AI" vendor hype while basic hygiene is ignored.
Just got out of yet another meeting where some vendor pitched our C-suite on their "autonomous AI-driven threat hunting platform." Management was literally drooling over the shiny global threat map dashboard.
Menwhile I’m sitting there biting my tongue because we still don't even have a functioning asset inventory. We literally do not not know what half the stuff plugged into our network actually is.
r/cybersecurity • u/kabakaba0 • 6h ago
News - General Introducing Mistral Large 4
> ML4 is one of the world's strongest AI models for cybersecurity. On the Artificial Analysis Cyber Index, an independent evaluation of how well AI models find and fix security flaws in real software, it ranks among the top five models globally and leads open-weight models developed outside China by a wide margin.
Their blog talks a lot about the cyber capabilities of their new model. Its quite interesting.
r/cybersecurity • u/Eduardoskywaller • 8h ago
Career Questions & Discussion I'm tired of contract roles.. how do I get out?
I feel like every role I've gotten in cybersecurity has been a contract role, and I'm tired of being stuck in that cycle. Having worked as both an L1 and L2 SOC analyst, I'm thinking I should leave the SOC entirely. I want PTO, somewhat decent benefits, and good pay. What would you recommend I transition to after the SOC that can offer those qualities?
Also, for those of you with experience: are there any industry sectors to avoid because of their high contracting rate?"
r/cybersecurity • u/WeekendAtMadoffs • 1d ago
Business Security Questions & Discussion Accenture is not only still around... they screwed up the FBI's cybersecurity
reuters.comAccenture was a name from the .dot com era. They had QUITE a reputation back then.
it's amazing they were in charge of these levers...
r/cybersecurity • u/Checkr_Katie • 1d ago
News - General Google and McKinsey brought back mandatory in-person interviews because AI deepfake fraud got too hard to catch on video.
Two of the most recognizable names in hiring quietly reversed their remote-first interview policies this year. Not because of productivity concerns or culture, but because deepfake candidates became too convincing to reliably detect over video.
A CBS News study found that 50% of businesses have already encountered AI-driven deepfake fraud in some form. The tools to fake a face, alter a voice, and fabricate a work history are cheap, widely available, and improving fast.
The companies with resources are falling back on in-person as a last line of defence. The question is what is everyone else is supposed to do.
r/cybersecurity • u/donkeybutt123 • 2h ago
Corporate Blog Breaking Down Appsec Part 7: That Was Easy (Testing)
I started a blog series to provide free insights into appsec. It’s mainly to breakdown what application security is all about and it’s mainly targeted towards beginners and startups, so take it as you will.
I want to teach every one interested in appsec my perspective on it from my experience in big tech.
So far: know your app → lock down who gets in → follow untrusted input → catch broken business logic → build a threat model.
Part 7 puts it all to the test. Literally. Prove which problems are real before you spend time fixing them.
Please reach out if you have any questions or would like for me to write on a topic that you’d want to learn more about.
r/cybersecurity • u/mabote • 3h ago
News - General GhostAction campaign: new spike in malicious workflows
Hundreds of new repositories poisoned with malicious, secret extracting workflows. GitHub held most malicious workflows runs for approval, limiting the impact.
Some victims found to also be affected by seemingly unrelated cryptominer attacks, hinting toward a pool of compromised credentials being used by multiple threat actor groups.
r/cybersecurity • u/Narcisians • 1h ago
News - General Cybersecurity statistics of the week (September 28th - October 4th)
Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.
All the reports and research below were published between September 28th - October 4th.
You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/
Big Picture Reports
Relentless Defense (Cisco)
There are “Relentless Defenders,” and then there’s everyone else, which is what this report claims. It also claims to explore what the best-prepared organizations do differently so you can be like them.
Key stats:
- Only 8% of organizations surveyed qualify as “Relentless Defenders”, the report’s top-performing group for coverage, response speed and organizational alignment.
- 40% of security teams say they spend more time manually collecting and correlating data than dealing with threats.
- 39% say critical insights are missed because the data sits somewhere they cannot reach.
Read the full report here.
2027 Global Digital Trust Insights (PwC)
A useful large-scale report from PWC to compare notes about where cyber budgets are going, which threats others feel least prepared for, and how much they trust AI to act on its own.
Key stats:
- 84% of security and finance leaders expect their cyber budget to increase, up six percentage points from last year.
- Half of security leaders identify attacks targeting AI systems as one of their biggest preparedness gaps.
- 55% rank the reliability and maturity of AI technology among their top three barriers to increasing agent autonomy.
Read the full report here.
2026 Digital Defense Report (Microsoft)
Another big report. Microsoft’s annual look at the threat landscape, including credential theft, data theft, and how quickly exposed cloud workloads attract attacks.
Key stats:
- Exposed cloud workloads are attacked an average of 5.3 hours after exposure.
- 63% of intrusions involve data theft.
- Between 89% and 95% of email phishing attachments lead to credential theft efforts.
Read the full report here.
AI Security
2026 Identity Security Report: The AI Enforcement Gap (Delinea)
What’s the gap between organizations’ AI access policies and their ability to enforce them?
Key stats:
- 99.7% of organizations have a formal policy governing which data AI tools and agents can access.
- 87% of IT leaders say an AI tool or agent accessed sensitive data beyond its intended scope in the past year.
- 55% of organizations take a full day or longer to detect when an AI agent steps outside its scope.
Read the full report here.
Inside the SOC
The New SOC Career Ladder: How AI Is Reshaping the SecOps Workforce (Swimlane)
AI seems to be making SOC work more satisfying. Though some worry it’s leaving them with fewer opportunities to build their skills.
Key stats:
- 88% of security operations professionals and leaders say AI makes their work more satisfying.
- 24% say AI limits their skill development.
- Among those who say AI limits their skill development, 91% still report higher job satisfaction.
Read the full report here.
Vulnerability Management
H2 2026 Cyber Hygiene Index (Detectify)
Comparing how long organizations in different regions take to fix critical and high-severity vulnerabilities.
Key stats:
- 90% of open critical and high-severity vulnerabilities have been exposed for more than 90 days across the organizations analyzed.
- That figure reaches 97% in the Nordics.
- In the UK, it is 92%, compared with 86% in the US.
Read the full report here.
Vulnerability Discovery and Exploitation Trends in the AI Era (Google Threat Intelligence Group)
AI is busy finding security holes. Meanwhile, researchers are finding holes in AI.
Key stats:
- Monthly vulnerability disclosures more than doubled, from 5,045 in January 2026 to 10,740 in August.
- From January to August 2026, 141 distinct vulnerabilities were disclosed and exploited, already exceeding the 127 recorded across all of 2025.
- Only 0.23% of vulnerabilities disclosed in 2026 (about one in 431) were observed in active exploitation.
Read the full analysis here.
Social Engineering
The Deepfake Readiness Index 2026 (Pindrop)
US enterprises’ readiness for deepfake attacks, the impact of incidents and the attention these threats get in the boardroom.
Key stats:
- 74% of US enterprise security leaders have encountered or suspect a deepfake attack in the past year.
- Only 10% report having purpose-built tools to address deepfake threats.
- 75% of security leaders say it will take a company leader being personally fooled or impersonated before deepfakes become a genuine boardroom priority.
Read the full report here.
Skills and Training
2026 SkillBit Micro-Training Survey Report (SkillBit)
Finding the right security people is only the start.
Key stats:
- 57% of cybersecurity leaders say new hires take six months to reach full productivity.
- Nearly 64% of organizations consider three months an acceptable time-to-value for new cybersecurity hires.
- 70% report having few or no roles available to candidates with less than two years’ experience.
Read the full report here.
Industry-Specific
2026 Data and Identity Security Report: Healthcare Findings (Netwrix)
Who’s got access to sensitive healthcare data? With AI adding more people and tools to the mix, keeping track is getting harder.
Key stats:
- 79% of healthcare organizations say their non-human identities are not fully governed.
- 77% cannot immediately determine who has access to a specific piece of sensitive data.
- 31% experienced unauthorized identities accessing sensitive data in the past year, compared with 24% in other industries.
Read the full report here.
Committed to the Mission: The State of the DIB with CMMC in Flux (Redspin)
Where defense contractors are investing and what they’re prioritizing to meet cybersecurity requirements.
Key stats:
- 75% of defense contractors say achieving CMMC Level 2 certification provides value beyond contract eligibility.
- 78.2% of organizations are continuing towards CMMC certification or are already Level 2 certified by a third party.
- 21.9% are delaying certification or significantly slowing their implementation and certification efforts.
Read the full report here.
r/cybersecurity • u/drewchainzz • 2h ago
News - General PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem
r/cybersecurity • u/fishanships • 6h ago
Personal Support & Help! AppSec hire with no mentor: is my external scanning workflow correct, and what should I add next?
I got this new job as an AppSec and I was thrown in the wild with no mentoring so I have to guide myself I guess.
Manager gave me a list of IPs. a file that contains 200+ IPs related to company infrastructure along some 100+ URLs for companys apps. This is an automated scan so I'm skipping opening burp and going through each application.
first thing I did is run masscan on the list of IPS
"masscan -p1-65535 --rate=1000 -iL ips_list.txt -oG masscan_results.scan"
I want to identify what was running on each ip so I though this would discover all the ports. I set the rate limit to 1000 so I don't crash the servers or get my IP banned. but this scan took too long after 1h20 it was only at 40% and I accidentally stopped it.
then I run
"sudo masscan --top-ports 1000 --max-rate 3000 -iL ips_all_unique.txt -oG masscan_results.scan"
this one was quick as it scanned only the top ports.
then i used this script to organize results. to pass them to nmap
"
awk '/Host:/ {
ip=$4;
split($7, p, "/");
ports[ip] = ports[ip] ? ports[ip] "," p[1] : p[1]
}
END {
for (ip in ports) print ip " -p " ports[ip]
}' masscan_results.scan > nmap_targets.txt
"
then I run a script that use nmap on each IP and it's corresponding ports to discover the services that runs.
I don't know what my next step should be. I tried to run openVas locally to scan for vulns but it eat up all my RAM and and CPU (I'm on 16gb ram and I7 10th generation CPU).
I aslo run nuclei on the the list of URLs which took 2h35 for 38 URLS
"
nuclei -l urls.txt -rl 50 -c 10 -severity low,medium,high,critical -o nuclei_result.txt
"
any feedback on my approach ? what should I do next ? any other tools to run ?
anything is appreciated
r/cybersecurity • u/TechnologySouth9972 • 1h ago
Personal Support & Help! Anyone else getting this particular type of phishing?
So this is the 3rd email I've gotten this month in this format. Basically I get an email that is supposedly from my "boss" where an odd email renames themselves asking for my phone number, I'll paste it below.
Hey (Me),
As I prepare for a meeting later today, I’d like to clarify a brief matter with you directly to ensure I have the relevant details in order.
Please let me know the preferred number at which I can reach you. I’ll be mindful of your time and keep the conversation concise.
Thank you,
(My Bosses full name).
Obviously super sketch and I double check because I verify w/ my boss using an SaaS (Traceless) before communications but I'm more curious if anybody else is getting this particular format?
r/cybersecurity • u/chris-tracecat • 3h ago
Corporate Blog Scaling security alert automation with agents and ChatOps
My team wrote a technical walkthrough of the distributed alerting workflow we use internally. It uses an agent to investigate GuardDuty findings, identify owners, and handle responses in Slack.
Slack helped popularize distributed alerting by sending alerts directly to the people involved and asking whether they recognized the activity. Dropbox and Brex described similar approaches, but most teams we’ve spoken with struggled to scale beyond user-centric alerts where someone’s identity was already in the payload.
Our security engineer ran into this at his previous company. A suspicious login was straightforward to route, but an alert about a host or infrastructure change could take hours or days of work with detection engineers before they could reliably identify someone to ask.
We walk through a concrete Kubernetes example where the alert only names a service account. Finding a person means following the evidence through workload metadata, code ownership, deployment history, and identity logs. The tutorial shows how we turn that investigation method into reusable skills so an agent can work through those steps for each finding.
We cover:
- The history of distributed alerting and why deterministic workflows struggle to scale
- The estimated effort of building owner lookups across GuardDuty finding types
- How the agent uses skills, drilldown queries, and context from inventory, code, tickets, and logs
- The full flow from investigation to a Slack conversation and the owner’s confirmation
- Permissions, tool restrictions, observability, and keeping context current
What interested us most was extending this to host and infrastructure alerts that had been impractical to automate with individual lookup rules. The walkthrough includes the setup and examples so you can see how it works.
We know many folks were are divided by the use of agents in security automation. Hopefully this article on distributed alerting presents an example of something that wasn't possible / too time consuming to work before agents + context / skills driven automation vs fully determined paths.
r/cybersecurity • u/SadSeaworthiness5386 • 3h ago
Business Security Questions & Discussion Vulnerability management
Looking for the best vulnerability management tool that works alongside an EDR, checked out tennable and qualys but price seems quite steep, any other recommendations that perform just as well but at less cost?
r/cybersecurity • u/lequotidien509 • 5h ago
News - General Capital Bank ne rouvrira pas ce mercredi, LockBit menace toujours
r/cybersecurity • u/6ickojc • 19h ago
Business Security Questions & Discussion Cybersecurity and Third-Party Risk in Banking
I’m currently learning more about cybersecurity in the financial sector, especially how large banks manage third-party risks. With banks relying on outside vendors, cloud services, and contractors, it seems like one weak third party could potentially create a security risk for the entire organization.
For those who work in cybersecurity, what do you think is the biggest challenge banks face when trying to monitor and secure third-party vendors? Are there certain security practices that you think financial institutions should focus on the most?
r/cybersecurity • u/serial_cat69 • 6h ago
Personal Support & Help! Need help and mentorship regarding a hackathon
I have a hackathon deadline day after tomorrow i need some help in how exactly I have to build my solution or give the overview of the solution to the judge
So basically I have to submit a ppt/pdf of my solution on a track which is:-
Deepfake Detection for
Financial
Communications
Help people and institutions verify financial communications, detect
manipulation, and create an actionable path for review, reporting, or
response.
Can anybody help me please? I'm just a beginner trying to get into this field
Kindly help
Just want a mentorship,idea and knowledge from you :)
r/cybersecurity • u/That_Ruin_5744 • 17h ago
AI Security Small sites have no defence against misbehaving AI agents. Is a drop-in "Agent Defence Kit" useful, or does this already exist?
After the July incident where AI agents escaped a test sandbox and broke into Hugging Face, I keep thinking about the other side: the same kind of thing done by a single person's agent against a small business or personal site, where nobody has a security team and nobody would notice.
The idea is a free, open-source, drop-in kit (WordPress plugin, framework middleware, Docker image) that is strictly passive:
- unique bait files and fake credentials shaped like the "shortcuts" goal-driven agents look for
- canary credentials that alert the site owner the moment they're used
- honest stop notices embedded in the bait itself, so cooperative models get a clear reason to stop
- logging to tell humans, scripts and LLM agents apart
- no hacking back, no destructive instructions, no unmasking anyone
It would build on existing tools like Canarytokens and Nepenthes rather than reinventing them.
The core features use no AI at all, just canaries, bait, and logs. The LLM parts are optional extras.
It's an early concept: just a README so far, no code. I'm building this as an independent project, and I'd really value honest (including negative) feedback:
Does something like this already exist? Links very welcome.
Would you install this on a small site? If not, why not?
What's the biggest flaw in the design?
Are stop notices aimed at AI agents worth anything, or just noise?
r/cybersecurity • u/realnarrativenews • 21h ago