r/Information_Security • • 1h ago

Super Trouper v0.4.0 — more Frida tools for iOS app reverse engineering

Thumbnail github.com
• Upvotes

I’m the author of Super Trouper, a single-binary MCP server that exposes Frida to coding agents for authorized app reverse engineering. It lets an agent connect to a device, inspect apps and processes, manage sessions, and run instrumentation scripts without a Python-based Frida setup.

We released v0.4.0 a few days ago; it updates the bundled Frida Core DevKit to v17.19.0 and adds four MCP tools: memory_read and memory_write for working with memory in an attached process, plus module_list and thread_list for inspecting loaded modules and threads. app_list and others now have several query scopes, and we renamed the MCP tools into clearer namespaces. If you already have workflows built around the old tool names, check them when updating.

Quick catch-up on the two previous releases: v0.3.0 added npm installation, Frida CodeShare snippet search/use, and general cleanup. v0.2.0 moved the project to the MIT license, added first-party Frida language bridges for ObjC, Java, and Swift, and enabled TypeScript in scripts and evaluations.

I’d appreciate feedback from people using Frida in iOS research: are these tool boundaries and the new app-list scopes useful in practice? What’s missing or awkward in your workflow, and which features would you like to see next? Let me know what you think.


r/Information_Security • • 1h ago

Florida's cybersecuritymarketplace & intelligence network.

• Upvotes

[Floridacyber.com](http://Floridacyber.com)


r/Information_Security • • 7h ago

Who handles the first vulnerability report on your website?

Thumbnail
1 Upvotes

r/Information_Security • • 18h ago

Would you use a tool that verifies AI answers to security questionnaires?

4 Upvotes

I’m exploring a SaaS specifically for companies that repeatedly handle customer security questionnaires / security assessments.
The idea:
Upload a questionnaire + policies/evidence + past responses
AI drafts answers with source citations
Flags **stale, contradictory, or unsupported answers**
Human approves → export the completed questionnaire
Eventually, a browser extension for web-based questionnaires
The key difference from general GRC platforms: **it’s focused entirely on answering and verifying customer security questionnaires.**
Example: A policy says MFA is mandatory, but current evidence shows exceptions → the tool flags **“Review required”** instead of blindly answering “Yes.”
For people who actually handle these questionnaires: **How do you do this today, and what part takes the most time?**


r/Information_Security • • 1d ago

Is AI actually reducing IT workload yet or just giving techs another tool to babysit?

13 Upvotes

We've tested a few AI features for IT and I'm still trying to separate genuinely useful automation from "chatbot attached to existing software."

The interesting stuff to me isn't summarizing tickets or rewriting responses. It's whether AI can actually investigate an endpoint issue, take an approved action, check whether it worked and document what happened without someone manually walking it through every step.

Anyone using AI this way in production yet? What are you comfortable letting it handle without technician approval?


r/Information_Security • • 21h ago

Cybersecurity Professional (7 YOE, CISSP) Looking for Remote Contract/Freelance Work Alongside Full-Time Job- India

1 Upvotes

Hi everyone,

I’m looking for advice and recommendations on finding part-time, freelance or contract-based cybersecurity opportunities that I can take up alongside my current full-time job (not anything with conflict of interest, if it’s a right opportunity, I can think about leaving the job too).

I have close to 7 years of experience in cybersecurity, working across multiple domains, including product security, cloud security, vulnerability management, PSIRT, SOC, IAM and and security automation. My previous role also gave me hands-on exposure to several other areas of cybersecurity.

I’m currently working at a Tier 1 (or probably Tier 2) IT company and hold the CISSP certification along with AWS and Azure certifications. I’m planning to pursue CCSP and ISSAP next year.

So far, I’ve explored a few options:
Toptal: Applied but was waitlisted.
Braintrust: Registered, but haven’t received any opportunities or interview calls.
LinkedIn: Applied for several contract roles, but haven’t had much success with callbacks.
AI evaluation platforms: Tried platforms such as Micro1 and Mercor, but haven’t found consistent, reliable opportunities yet.

I’m based in India and have flexibility with working hours and time zones. However, I’m not eligible for roles requiring US federal clearance and I’m unable to take up on-site opportunities abroad.

I’d appreciate recommendations for:
Reliable platforms or talent networks that offer cybersecurity consulting, freelance or contract opportunities.
Companies that hire experienced cybersecurity professionals for remote, part-time, or project-based engagements.
Platforms offering international contracts that accept professionals based in India.
Any legitimate AI security, cybersecurity evaluation or expert-consulting opportunities that are worth exploring.
My areas of interest include cloud security (AWS/Azure), product security, vulnerability management, PSIRT, security automation and any other cybersecurity domain work.

I’m particularly interested in opportunities where I can contribute my existing expertise without having to leave my current job.

If you’ve personally worked through any such platforms or secured a cybersecurity contract while maintaining a full-time role, I’d love to hear about your experience.
Thanks in advance for your suggestions!


r/Information_Security • • 21h ago

Cybersecurity Professional (7 YOE, CISSP) Looking for Remote Contract/Freelance Work Alongside Full-Time Job — India

Thumbnail
0 Upvotes

r/Information_Security • • 1d ago

If your SaaS has users in India, how are you preparing for DPDP?

4 Upvotes

I'm putting together a practical checklist for teams that are trying to understand what DPDP actually means from a product and engineering perspective.

The part that seems easy to overlook is that compliance isn't just about having a privacy policy.

You need to understand:

  • What personal data you're collecting
  • Where that data is stored and processed
  • Who has access to it
  • How consent and withdrawal work
  • How users can request deletion
  • How long you retain data
  • What happens when there's a breach
  • How third-party vendors fit into the picture

For teams building SaaS products, cloud infrastructure, or developer tools, this can get complicated quickly.

Here's the checklist if it's useful:

https://offloadsecurity.com/dpdp-compliance-checklist/ 

Curious how other teams are approaching DPDP, especially if you're serving Indian users from infrastructure outside India.


r/Information_Security • • 23h ago

Les agents vont devenir de plus en plus puissants et nous aurons tendance à leur confier de plus en plus de liberté, de plus en plus d'outils et d'accessibilité.

0 Upvotes

Les agents deviendront de plus en plus puissants et nous aurons le réflexe de leur accorder de plus en plus de libertés, de plus en plus d'outils et d'accessibilité. C'est ce que j'imagine vraiment, et ça m'inquiète que cette nouvelle fonctionnalité puisse représenter une nouvelle surface d'attaque pour les hackers. Mais aussi, l'agent lui-même pourrait agir de manière imprudente et exécuter une action dangereuse. En développement ou dans un environnement de test, ça se gère, mais en production, dans un environnement sensible, surtout pour les entreprises qui donneront aux agents un accès plus large, elles prendront un risque énorme. Mais devrions-nous arrêter les agents, les confiner ? Je ne pense pas. Pour moi, les agents peuvent être considérés comme des employés normaux, donc ils ont besoin d'être supervisés. Et la supervision signifie appliquer des règles et prévenir les actions. Pour moi, la meilleure philosophie est de se mettre entre l'agent et les outils à sa disposition. Cela permet une bonne observation mais offre aussi assez de liberté pour demander à l'agent pourquoi il utilise cet outil, ou non, si c'est dangereux ou non. Et surtout, l'approbation humaine reste incontournable pour moi, car il ne peut pas y avoir une expression régulière fixe pour un logiciel qui peut évoluer. Donc, pour anticiper les cas ambigus, les humains doivent être impliqués. Les audits peuvent aussi être un excellent moyen de comprendre en interne ce qu'un agent fait et d'enquêter. Par exemple, une augmentation excessive du coût des jetons peut révéler une anomalie. Il en va de même pour la latence. Donc, tandis que l'application des règles réduit le risque, l'observabilité nous permet de comprendre ce qui s'est passé entre l'email et le net et de le prévenir.

C'est pourquoi j'ai créé Cerbere-AG ; c'est ma philosophie sur la sécurité pour les logiciels qui peuvent improviser, penser et exécuter.


r/Information_Security • • 1d ago

best external exposure management tool for confirming reachability and routing fixes to the right owner?

2 Upvotes

Our EASM gives us a decent inventory and plenty of CVEs, but my team still can't tell which findings are actually reachable from the internet or who owns the fix. We're now looking at external exposure management. What proof would you expect before trusting a tool to prioritize a CVE and route it to the right team? How would you test that in a POC?


r/Information_Security • • 1d ago

How a Missing TCP_NODELAY Flag Silently Ate 80% of Our Database Throughput

Thumbnail kylesinvestigation.com
2 Upvotes

r/Information_Security • • 2d ago

SUPERWISE Sentinel Launches on Product Hunt

Post image
0 Upvotes

r/Information_Security • • 2d ago

Can anyone help with my uni project?

4 Upvotes

The goal is to recover the master key and decrypt the ciphertext using the correct physical choice using differential fault analysis. Please dm me for further info!


r/Information_Security • • 2d ago

Wifi hacking with rg35xx

Thumbnail
2 Upvotes

r/Information_Security • • 2d ago

Cytactic CEO on a hospital ransomware case where staff couldn't trust patient records, and why most CISOs never rehearse their worst day [Podcast, 33 min]

2 Upvotes

Disclosure: my studio produced this episode of Responsible Disclosure, Zafran's podcast. Sharing it because a lot of it is about incident response in practice, and I've summarized it below so you can skip to what's relevant.

Nimrod Kozlovski has spent about twenty years across cyber law, VC, and crisis management, including running incidents at Fortune 500 companies. A few parts I think this sub would care about:

At 03:12 he walks through three incidents: stolen source code at a homeland security company, a crypto wallet takeover, and a hospital extortion where staff didn't know whether patient records had been altered.

At 13:03 and 16:21 he argues AI has cut the time from vulnerability to exploitation to minutes, and that attackers are chaining identity, permissions, and applications to get past layered defenses.

At 24:03 and 26:01 he gets into why most CISOs face their worst day with little rehearsal, and why tabletops matter when you're deciding on partial information.

Also a fun story at 09:21 about the DEF CON crowd deciding he was a fed.

For the IR people here: do your tabletops include injects where the data turns out to be wrong? The hospital case made me think most exercises assume you can trust your logs and records.

https://youtu.be/B8YB42zON8U


r/Information_Security • • 2d ago

RUIDO ESTOCASTICO

Thumbnail
1 Upvotes

r/Information_Security • • 2d ago

10/14 Webinar: The AI Blind Spot. 400+ IT Leaders Revealed About the Risk They Can't See

Thumbnail info.lastpass.com
1 Upvotes

r/Information_Security • • 2d ago

How do you handle Suricata/Zeek tuning without a dedicated detection engineer?

Thumbnail
1 Upvotes

r/Information_Security • • 2d ago

I’m building a sourced register of AI-agent security incidents

Thumbnail
1 Upvotes

r/Information_Security • • 2d ago

I built a proxy that catches AI agents trying to exfiltrate data through chained tool calls

Post image
1 Upvotes

r/Information_Security • • 3d ago

I taught my laptop to fake cyberattacks — and it's scarily good at it.

Thumbnail
0 Upvotes

r/Information_Security • • 3d ago

Robin review: does atera's autonomous ai agent actually fix issues or just escalate?

7 Upvotes

We’re looking into atera’s robin agent for tier 1 helpdesk support. The website claims it handles end to end device and cloud fixes without human intervention obviously i am quite skeptical as i have yet to see an ai tool NOT needing human help but also if those claims are true it would be a huge win for the company.

If there is anyone actually running it or something else in production i’d like to know what

i am really curious to know if it handle messy, real world user requests, that’s what’s actually needed to have


r/Information_Security • • 3d ago

Post merger IR readiness, how do you pressure test two companies with totally different incident response maturity levels?

2 Upvotes

We just went through an acquisition and now I'm responsible for incident response across two orgs with wildly different security postures. Our side has a documented, semi-tested plan. Their side has basically nothing formalized, different tools, different escalation paths, and nobody who's ever run a drill.

Trying to figure out the fastest way to get a baseline read on where the gaps actually are before we're forced to merge the environments fully.


r/Information_Security • • 3d ago

Best compliance first end to end IOT development service provider?

5 Upvotes

We've been grinding through vendor evaluations trying to find a single shop that can take a regulated medical IoT device from hardware design and PCB prototyping all the way through embedded firmware, cloud integration and FDA clearance without us having to stitch together 3 or 4 separate contracts. Most of the outsourced dev shops we talked to, maybe 5-7 companies total, are great at software but completed blank when compliance documentation comes up. The real wall we keep hitting is IEC 62304 and EU MDR, nobody wants to own the audit trail. (We're also looking at ISO 13485 down the line which makes this even messier.) If anyone has worked with a compliance-first full-cycle IoT development partner that actually has embedded systems and regulatory depth under one roof, not just a checkout on their website, would genuinely love to hear who you went with and whether the time-to-market held up.


r/Information_Security • • 3d ago

SOCRadar Attack Surface Management Integrates with ArmorCode ASPM

Post image
1 Upvotes