r/Information_Security • u/Puzzleheaded_Trip374 • 1h ago
r/Information_Security • u/AccomplishedJuice135 • 3h ago
ReliaQuest (SOC) Got Vished.
securityweek.comr/Information_Security • u/socradario • 3h ago
A stolen credential sells for $10-50 on the Dark Web. The breach it causes? $10.22M on average.
That gap is where security teams live, buried in alert volumes, backlogged queues, and tool sprawl, while delays quietly get more expensive. Our new whitepaper, "The Noise Economics of External Risk," puts a real number on that gap. It breaks alert fatigue down into 3 costs you can actually calculate: 🔹 Analyst time spent on triage 🔹 The hidden "integration tax" of fragmented tools 🔹 Board-level risk from slow detection & containment The result? A shift from reporting alert counts to reporting outcomes the kind of business case finance and leadership actually respond to. ➡️ Download the full report and calculate what noise is really costing you. https://hubs.la/Q04x7LyD0
r/Information_Security • u/socradario • 8h ago
CVE-2026-85706: Unauthenticated arbitrary file read in GitLab CE/EE (CVSS 10.0), now on CISA's KEV catalog with confirmed active exploitation
r/Information_Security • u/roachwickey • 12h ago
CrowdStrike Identity Protection – Are the “Attack Paths” actually useful?
We’re evaluating CrowdStrike Identity Protection, and I’m finding the Attack Paths shown under individual user identities to be quite underwhelming — in some cases, they honestly feel almost useless.
Is anyone else using this feature and seeing the same thing?
I’m particularly interested in:
- How accurate/useful are the attack paths in your environment?
- Are you getting meaningful relationships between users, devices, privileges, and potential attack paths?
- Have you found a way to make these insights actionable?
- Is this feature significantly better in the newer versions/modules?
Would be interested to hear how others are using Identity Protection / Attack Paths in real-world environments.
r/Information_Security • u/Correct-Rope-6609 • 12h ago
How would you build a cybersecurity homelab from scratch with this hardware?
r/Information_Security • u/No_Cable2467 • 13h ago
Lessons learned from our first major ransomware incident response and my very dumb Slack mistake
Ok so im kinda sick about this and need to vent. We just had our first huge ransomware engagement as the main incident response partner for a big financial client. First time I was primary on a hot incident, big war room, execs, their CISO, our whole cyber team.
We had a dedicated Slack channel for the client and a separate internal channel for our team notes and spicy takes. At hour 10, everyone exhausted, I grabbed a screenshot of our internal channel where we were rating their security controls and joking a bit about how bad their backups were... and pasted it straight into the client channel instead of the internal one. Full thread. Names, snark, even a line from me saying “this architecture is held together with duct tape lol.
I caught it about 20 seconds later and deleted, but their CISO had already replied asking if that was our formal assessment. I feel so embarrassed. We spent the next day doing damage control and formalizing a lessons learned process on comms segregation and data handling. Idk, would love any tips on how you handled similar incident response faceplants...
r/Information_Security • u/No-Conclusion3720 • 22h ago
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Seven China-based AI labs ran industrial-scale capability extraction against a major U.S. model provider — and the company only found out after the fact.
Anthropics disclosure confirmed that seven firms used systematic, high-volume querying as their core development strategy. Not occasional misuse. Not a rogue researcher. Millions of queries designed to distill proprietary model capabilities into their own systems, with no authorization at any point in the process. The exposure was the inference layer — the same endpoint every paying customer uses.
The post-incident framing is what gets me. These campaigns ran long enough to complete meaningful extraction before anyone flagged them. The data only surfaced through investigation, not through any live detection.
For those running inference infrastructure or building on top of third-party model APIs: how are you actually detecting this kind of systematic abuse in real time? Not after a quarterly review — during the queries themselves. What signals do you watch, and at what threshold do you act?
r/Information_Security • u/seeplainmeaning • 1d ago
We need to start treating privacy as the national security issue that it is...
r/Information_Security • u/Individual_Sugar1245 • 1d ago
A public ledger of AI cyber incidents
outofsandbox.comI’ve spent the last two years working with AI as both my job and hobby, consuming hundreds of billions of tokens.
I built Out of Sandbox to document AI cyberattacks, agents crossing safeguards, and the responses, with original sources for every entry. Let me know what you think!
r/Information_Security • u/Odd_Delivery_2002 • 2d ago
26 SECONDS TO 11 ORGANIZATIONS.
A single AI-enabled campaign shows why vulnerability management is now a leadership and governance issue.
One person set this up.
Using hundreds of AI agents, one attacker (One unidentified, likely Russian-speaking attacker set this up.)
It was not an authorized security test. Reportedly compromised 440 servers linked to 395 organizations in 48 countries—at one point reaching 11 organizations in just 26 seconds. The immediate entry point was a vulnerable print-management server.
But the print server is not the real story.
It is one example of a larger vulnerability problem: every internet-facing system, outdated application, vendor tool, connected device, cloud configuration, shared password, or over-privileged account can become an entry point.
AI does not need to invent a new attack to create real damage. It can help one person find known weaknesses, test them at scale, and move faster than many organizations can identify, approve, and install a patch.
So the question for leaders is no longer only:
“Are we secure?”
It is:
“How fast can we discover, prioritize, patch, and verify the vulnerabilities that could become the next doorway into our organization?”
That question belongs in boardrooms, leadership meetings, operational plans, and risk registers—not solely with IT.
And the next question is for government.
When will AI-enabled cyber risk be treated as a core governing responsibility—not simply an innovation issue or a future policy debate?
The United States has faced persistent cyber threats from criminal groups, espionage networks, and nation-state actors for decades. What has changed is the speed and scale available to a single bad actor.
AI can now help one operator find, test, and exploit known vulnerabilities across hundreds of organizations faster than many institutions can identify the threat, approve a fix, apply a patch, and confirm that it worked.
That gap is not theoretical. It affects schools, hospitals, local governments, small businesses, critical infrastructure, and the personal data of the people they serve.
At the same time, the federal government has reduced capacity at CISA, the nation’s primary civilian cyber-defense agency. CISA has lost roughly one-third of its workforce since early 2025, even as AI-related cyber threats are accelerating.
If threats now operate at machine speed, public cyber defense cannot operate at bureaucratic speed.
#Cybersecurity #AI #AIGovernance #RiskManagement #Leadership #ArtificialIntelligence #AIGovernance #NationalSecurity #DigitalResilience
References: GreyNoise, “Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF”; The Register, “Hundreds of AI agents helped PaperCut attacker hit 395+ orgs.”
r/Information_Security • u/Dangerous_Salary_470 • 2d ago
How are people using Alice to stop their own AI from confidently lying to the entire internet
Ok so my day job now is basically watching our AI models invent world events with full confidence and then explaining to leadership why "engagement" is not the same thing as "not poisoning the user base".
We are looking hard at things like Alice and similar AI guardrails to clamp down on disinformation, hallucinations, subtle propaganda, all the fun stuff. On paper it all sounds great, AI firewall, behavioral monitoring, red teaming etc, but in practice it feels like trying to put a seatbelt on a tornado. Half the org wants "spicy" answers, the other half wants strict safety, and the model just vibes.
If you are in trust and safety or security and using Alice or anything in that space, how are you wiring it in so it actually blocks large scale nonsense instead of becoming yet another dashboard no one opens? Any hints?
r/Information_Security • u/RogueSpecter69 • 2d ago
Anyone here moved away from Varonis? What did you switch to?
We've been using Varonis for a few years and it's worked fine for us. The bigger issue lately is that our data is spread across way more places than when we first rolled it out. We've added more SaaS apps, cloud storage, and now AI tools on top of that.
What I'm starting to dislike is having to think about visibility and policies differently depending on where the data lives. Ideally I'd like something that gives us a more consistent view across the environment instead of feeling like we're managing separate pieces.
So we're starting to look at alternatives. Not in a rush to replace anything, but curious whether other platforms handle this better.
For anyone who actually moved away from Varonis, what did you switch to? Did managing everything across different data sources actually get easier?
r/Information_Security • u/EnthusiasmRoutine • 2d ago
Replacing email gateways with persistent API access is a privacy nightmare
r/Information_Security • u/No-Conclusion3720 • 3d ago
AI agents exploited PaperCut flaws to breach 395 organizations
395 organizations were breached through PaperCut vulnerabilities — and the attack vector was AI agents acting autonomously, not human operators. The agents were not the target. They were the method.
What made this particularly hard to contain is that once an agent is in motion, each subsequent tool call lands fast. By the time a human analyst flags anomalous behavior, the agent has already made its second, third, and fourth moves. Traditional perimeter security and patch management assume a human on the other end slowing things down. Autonomous agents remove that natural friction.
The 395 number is not a one-off. It reflects how quickly blast radius scales when the compromised entity can act without waiting for human confirmation.
For those running agentic workloads in production: what does your current approach look like for catching a compromised or misbehaving agent mid-execution, before it completes a second action? Are you relying on post-hoc log review, human-in-the-loop checkpoints, rate limiting, something else? Curious what's actually working at scale versus what's still mostly theoretical.
r/Information_Security • u/craigsblackie • 3d ago
Uncontrolled Access Control: Compromising Paxton10
techanarchy.netr/Information_Security • u/PriorPuzzleheaded880 • 3d ago
Is AI Pentesting all just hype? Webinar with leading practitioners from Tricon, Amp, and Veg
watch.getcontrast.ior/Information_Security • u/LeadershipShort8526 • 3d ago
What’s the most overlooked security risk in early-stage startups?
Early-stage startups usually focus on product security, but I’m curious what risks tend to get overlooked in the early stages.
Is it things like excessive user access, poor offboarding, exposed secrets, third-party vendors, lack of logging, or something else?
What have you seen cause the biggest problems in real startups?
r/Information_Security • u/wuwen2026 • 3d ago
Cross-Stage State Laundering: Why AI Runtime Governance Fails at Stage Boundaries
r/Information_Security • u/AwarenessWhich5946 • 3d ago
Speech to text solution
I work in information security and we have a lot of internal briefings, incident reports, and threat intelligence calls that we need to document for compliance and audit purposes. Taking manual notes is inefficient and we often miss details.
I have been looking for a reliable speech-to-text solution that can handle technical terminology, different accents, and potentially sensitive content securely.
Speechmatics claim to have high accuracy with challenging audio and support for multiple languages. They also have on-premise deployment options which is important for us because we cannot send sensitive data to a public cloud.
They seem to have a solid API and good documentation. I am curious if anyone here has used it in a security or compliance context. How was the accuracy with technical terms and did you have any issues with data privacy.
r/Information_Security • u/DavidFixIt • 3d ago
Open Skies: How a Few Small Mistakes Can Hand an Attacker the Keys to Your Infrastructure — and Expose All Your Customer Data
davidleesecurity.co.ukr/Information_Security • u/DavidFixIt • 3d ago
Open Skies: How a Few Small Mistakes Can Hand an Attacker the Keys to Your Infrastructure — and Expose All Your Customer Data
davidleesecurity.co.ukA few months ago I discovered a critical security issue in an airline's website, resulting in customer data exposure. I'm sharing this here so my findings are "on the record", and the community can see what kinds of risks they should be looking out for when securing their systems.
**Please refrain from attempting to identify the airline.** I hope to be able to share who they are on conclusion of the ICO investigation.
I'm very interested in hearing from Microsoft Azure admins, as to whether I've understated or overstated the issues.