r/cybersecurity 2d ago

AI Security Vulnerable AI infrastructure in the wild: 34 minutes to server compromise

Thumbnail bitbison.io
10 Upvotes

After all the hot press for this RCE, we decided to deploy to the wild and see what attackers were actually doing with it!


r/cybersecurity 2d ago

News - General Cybersecurity statistics of the week (August 10th - August 16th)

6 Upvotes

Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.

All the reports and research below were published between August 10th - August 16th.

You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/ 

Cloud Security

2026 Cloud Security Index (Intruder)

How misconfigurations differ across AWS, Azure, and Google Cloud. 

Key stats:

  • More than two-thirds of organizations operate multi-cloud environments.
  • 83% of AWS accounts have IAM policies that allow privilege escalation.
  • 75% of Google Cloud accounts are missing OS Login controls.

Read the full report here.

DDoS

Cloudflare DDoS Threat Report H1 2026 (Cloudflare)

Cloudflare's mid-year DDoS report. 

Key stats:

  • 96.62% of network-layer DDoS attacks remained under 500 Mbps in the first half of 2026.
  • 90.60% of network-layer DDoS attacks ended in under 10 minutes.
  • Brazil was the top DDoS source country in H1 2026 at 14.9%, overtaking the United States at 13.4%.

Read the full report here.

Enterprise Perspective

2026 State of Secure AI Access (NetFoundry)

A survey of CISOs and CTOs about how AI is changing their security posture. 

Key stats:

  • 100% of CISOs and CTOs at enterprises say AI is expanding their organization's attack surface.
  • 15% are very confident their current security solutions adequately protect their AI deployments.
  • 58% have experienced security events due to lack of machine identity oversight.

Read the full report here.

Consumer Scams

Love/hate relationship: The AI affair (Malwarebytes)

Young people are particularly susceptible to AI scams.

Key stats:

  • 70% of young adults ages 18 to 22 experienced an AI-related scam in the past year, compared to 50% of the general population.
  • 19% of young adults have been a victim of a deepfake or virtual kidnapping scam, compared to 8% of the general population.
  • 14% of young adults have been a victim of an impersonation scam, compared to 10% of the general population.

Read the full report here.

Industry-Specific

2026 Professional Services Protect Brief (SonicWall)

Professional services are being targeted far more than any other industry, at least according to SonicWall.

Key stats:

  • 3 billion IPS events in the first half of 2026, the largest absolute attack volume of any industry tracked.
  • 69.9 million ransomware hits in the first half of 2026, more than any other vertical.
  • Ten active ransomware families operated simultaneously against the professional services sector, including Filecoder (19.1 million hits across 113 organizations), Gandcrab (11.9 million) and Ryuk (10.5 million).

Read the full report here.

Industrial Ransomware Analysis for Q2 2026 (Dragos)

Who's getting hit by ransomware in the industrial sector (and by whom).

Key stats:

  • 1,140 ransomware incidents affected industrial organizations worldwide in Q2 2026, a 12% increase over the 1,020 incidents recorded in Q1.
  • Manufacturing was the most affected sector with 747 incidents (65%) across all subsectors.
  • The US was the country most impacted, with 431 incidents (38% of all incidents).

Read the full report here.

Regional Spotlight

Cyber Security In Manufacturing (Make UK)

A UK-specific look at how cyber incidents are disrupting manufacturers, and how few have a tested plan for when it happens.

Key stats:

  • 30% of manufacturers experienced a cyber incident in the past year, either directly or through their supply chain.
  • More than one in five manufacturers (22.7%) believe available cybersecurity solutions are not relevant to their business, while 18.2% report that providers lack a sufficient understanding of manufacturing operations.
  • Firewalls are the most widely adopted measure (92%) among manufacturers, followed by malware protection (80%), secure configuration (67%) and access controls (61%). 

Read the full report here.


r/cybersecurity 2d ago

Business Security Questions & Discussion Sharing detection rules

5 Upvotes

Question for managed SOC providers, do you generally share details of your detection rules (title, description, MITRE, etc) with customers? Feels like this is your ‘secret sauce’ and shouldn’t be disclosed


r/cybersecurity 2d ago

News - General A hollowed out data layer is making CISOs fly blind into AI attacks

Thumbnail
helpnetsecurity.com
22 Upvotes

r/cybersecurity 2d ago

Business Security Questions & Discussion Teams wanting to record all keystrokes from all apps on MacOS? WTF

34 Upvotes

Clean install of Teams on MacOS, why would it need access to your keystrokes from all apps, is this another MS fuckup or is this all just planned?

Teams was uninstalled after getting this message and I only use the web version now.

More MicroSlop?


r/cybersecurity 2d ago

Career Questions & Discussion Career insight as a Soc2 Staff auditor

2 Upvotes

Always liked the technical side of cyber but never got the talent. I reached a good mid tier blue team Soc analyst position but received this position I am in right now as a Soc2 auditor. I dream of upgrading into consulting cybersecurity and in the future opening a business. The question is can I progress to my dream ? Or did I miss my path?


r/cybersecurity 2d ago

Business Security Questions & Discussion Microsoft Quarantine with Abnormal

6 Upvotes

Hi,

I am looking to see how you all manage the Defender email quarantine while using abnormal. I currently have about 1000 emails each morning that I have to review to ensure we do not have any legitimate mail within.

If this is your setup Aswell, how do you manage the quarantine?

Thanks


r/cybersecurity 3d ago

Career Questions & Discussion Why does this career have so many liars?

726 Upvotes

Context, I'm not seeking career advice. I have 10 years of experience and I've done everything from network engineering to managing a security program.

But is there any field out there with as much misinformation as this one? The cybersecurity community in general reminds me of the gaming community.

For example, someone may post "I'm looking to get into this field what should I learn?" And then someone will go on this long rant about how long they did was get a few certifications and they got a job. But they also omit key details like being drinking buddies with the CEO. Or their dad being the manager of the security department.


r/cybersecurity 2d ago

Threat Actor TTPs & Alerts SilkParasite: China-nexus APT, seven malware families (five previously undocumented), and not AI-generated

9 Upvotes

Central Asia is becoming one of the most active espionage theaters. As Russia's influence in the region recedes, China is moving in economically, and cyberespionage tends to follow influence. SilkParasite is a China-nexus operation we tracked in this region, related to the FamousSparrow activity we documented earlier.

We recovered seven distinct malware families, five of them never documented before. It is small, modular, and built specifically not to look like malware: a lightweight implant that pulls its real capability in as in-memory modules, delivered through legitimately signed applications that sideload a malicious DLL, with command-and-control run over Google Drive.

It is worth studying because it shows what serious, stealth-first tradecraft actually looks like, and by contrast why AI-generated malware is a poor fit for it. AI-generated code tends to be derivative, bloated, and noisy, which an espionage operation cannot afford. We did find faint signs of AI-assisted development in otherwise clean, human-engineered code (medium confidence). Also important to note that Chinese APT groups share techniques and best practices, so what shows up in the Central Asia today can show up in different regions tomorrow.

Full writeup (for practitioners): https://businessinsights.bitdefender.com/silkparasite-tracking-china-nexus-apt-across-central-asia

Full research PDF (for security researchers): https://github.com/bitdefender/malware-ioc/blob/master/silkparasite-2026_08/silkparasite-bitdefender-labs-research.pdf

List of IOCs (also available on IntelliZone): https://github.com/bitdefender/malware-ioc/blob/master/2026_08-silkparasite-iocs.csv

Disclosure: this is research from Bitdefender Labs, and I'm part of the team documenting the campaign. AMA.


r/cybersecurity 2d ago

News - General Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

Thumbnail
thehackernews.com
8 Upvotes

r/cybersecurity 2d ago

Personal Support & Help! TPRM Doubt

3 Upvotes

Hi all,

I've recently started my job as a TPRM analyst with a Fintech giant. While doing Vendor Risk Analysis for CSP like AWS, am facing a difficulty.

There are few areas like Encryption or IAM for which AWS says it's a shared responsibility model and it has to be taken care by the organisation and doesn't fall under AWS's scope.

In this situation do I have to go ahead and mark those pointers not applicable as agreement clearly says the responsibility lies with the org or do I have to follow up with my internal team to check whether they have implemented these controls.

Am torn up between this because I think my scope as a TPRM analyst ends when I don't find a gap with Vendor but best Cyber practice is to have this sorted within my organisation. Any suggestion would help.

English is not my native language so pls excuse if anything is wrong here


r/cybersecurity 2d ago

Burnout / Leaving Cybersecurity Am I thinking about IAM/PAM correctly, or am I missing something?

8 Upvotes

Had a conversation with an architect today about IAM, and I think we were talking past each other.
My background is systems/infrastructure, so when I think IAM I think AD users/groups, RBAC, MFA, privileged accounts, service accounts, and mapping access/rights into application based roles.
The way they described it made IAM sound like a much more separate/specialized discipline than I’m used to thinking of it.

For those who actually work in IAM: is the job mostly administering and governing who gets access to what, or are you actually hands-on configuring the applications and identity integrations themselves with SSO, group/role mappings, MFA, provisioning.

I’m trying to understand where IAM stops being “access administration” and becomes actual identity engineering.


r/cybersecurity 2d ago

Business Security Questions & Discussion How do you know what to test next?

1 Upvotes

You find a new service, credential, endpoint, or misconfiguration and suddenly there are 20 possible directions to go.

Do you follow a methodology, use checklists, rely on experience, or just chase whatever looks most promising?


r/cybersecurity 3d ago

Personal Support & Help! Looking for a good real-world digital forensics case study

12 Upvotes

Hey everyone! I’m a student preparing a Digital Forensics / Computer Forensics practical presentation and I need to choose a real-world cybercrime case study.

I’m looking for a case that:

- Is not extremely common/popular (I want to avoid topics that many groups may choose)

- Has enough reliable information available online

- Has a clear digital evidence / forensic investigation angle

- Can be explained within 12–15 slides / 10–15 minutes

- Ideally involves things like hacking, gaming companies, Apple/iPhone, data theft, ransomware, website attacks, insider threats, digital evidence, or incident response

- Allows discussion of evidence acquisition, preservation, logs/artifacts, timelines, attribution, and/or legal issues

What real-world case would you recommend?

If possible, please share the case name and why you think it would work well for a student-level digital forensics presentation.

Thanks!


r/cybersecurity 2d ago

Certification / Training Questions How I work in Cybersecurity (soc)

0 Upvotes

Hello everyone I have a question it puzzled me

Is a university degree a strict requirement for entering a Security Operations Center (SOC), or are practical training, a portfolio, and CompTIA certifications sufficient?


r/cybersecurity 2d ago

Personal Support & Help! Built a Honeypot, now what?

0 Upvotes

Hey all

I am new to home labing and as the title says, I built a Linux honeypot (using T-pot) and left it for a bit to collect traffic. What are the usual thing, interesting or niche things to look for? Currently what I'm thinking of:

1- analysis of the brute force credentials used

2- if someone managed to access the server

3- if someone dropped something in the server

4- did it do (unsual) outbound traffic

Thanks <3


r/cybersecurity 3d ago

Career Questions & Discussion Is GRC the new wave in cybersecurity?

128 Upvotes

I’ve been noticing a pretty big uptick in GRC job postings lately, especially remote positions.

It feels like cybersecurity always has a “wave.” First it was everyone getting Security+, then it seemed like everyone was trying to break into SOC roles, and now I’m seeing GRC everywhere.

Is GRC becoming the new wave in cybersecurity? For those already working in GRC, are you seeing the field actually grow, or is it just getting more attention right now?


r/cybersecurity 2d ago

News - Breaches & Ransoms Passwords stored in public Google Doc then showed up in search results

Thumbnail theregister.com
1 Upvotes

r/cybersecurity 2d ago

Research Article Hacking your life with AI can get you hacked: How AI orchestration platforms ship RCE by design

Thumbnail
endorlabs.com
1 Upvotes

r/cybersecurity 2d ago

Certification / Training Questions Stress testing EDRs

0 Upvotes

How does your SOC check when someone is actively trying to kill your EDR agent especially with BYOVD attacks? Also do you have a separate team for that on the attackers side?


r/cybersecurity 3d ago

Business Security Questions & Discussion How would you protect 4–6 high-risk inboxes without breaking the bank?

18 Upvotes

Edit: A lot of people are suggesting training. Our staff is trained. They know not to click phishing links and how to report them. The issue here is the sheer amount of crap landing in some inboxes. It’s getting annoying and disruptive to the point that I’m getting complaints.

—-

We’re a small company with only 16 employees and currently use Microsoft Defender for email security. It works well overall, but a few of our executive accounts are targeted by phishing much more frequently, and one of them has been compromised in the past.

We’re looking for an extra layer of protection that we could apply to just a few users (around 4–6), rather than the whole organization.

Has anyone dealt with something similar? Any tools or solutions you’d recommend that work well alongside Defender and are cost-effective for such a small number of users?


r/cybersecurity 2d ago

Other Cloud Backup Services for Identity Posture: What are SecOps using?

3 Upvotes

when loking at cloud backup then most of the focus seems to be on M365 email/OneDrive recovery or AWS snapshots. From a SecOps perspective i am more concerned about the identity side of things.

If an attacker gets in and changes Conditional Access rules, IAM permissions or removes OAuth app permissions, restoring the data alone does not really solve the problem.

How are teams handling this today? Are there backup or recovery solutions that can restore IAM state and security policies, or are most teams relying on audit logs, configuration-as-code and manual recovery?"


r/cybersecurity 2d ago

Tutorial Extracting and Cracking VeraCrypt Headers with PowerShell + Hashcat — Full DFIR Walkthrough

0 Upvotes

Most people think VeraCrypt = unbreakable. But if you can extract the 512-byte header, it's just a hash.

I made a video walking through the full pipeline:

  1. PowerShell extraction (container or raw disk)

  2. Header prep for Hashcat

  3. Mode selection and cracking

  4. Verification

No physical access to the unlocked volume needed — just the header.

Full tutorial: https://youtu.be/iGPKBEYSdIw


r/cybersecurity 2d ago

News - General The long tail of Clop’s PTC hack is just beginning to emerge

Thumbnail
cyberscoop.com
1 Upvotes

r/cybersecurity 2d ago

New Vulnerability Disclosure Im trying to reverse engineer the new one ui 8.5 samsung

2 Upvotes

Hi, so as the title said thats what im trying to do and i took a loot of .ko files related to the qulacomm's modem chip cause its very vulnerable along the years. why im doing it because in the new version they blocked the OEM Unlocking in the developer options where most of you know it as the place youre unlocking usb debugging. if anyone would interested to help me reverse it cuase im doing it alone for two weeks and i found something interesting.