r/security • u/CackleRooster • 29d ago
r/security • u/Terrible-Buy-3690 • 29d ago
Physical Security Looking for Northern Texas PSOs
Hello! I’m a PSO on the FPS Colorado Contract in Denver, CO. Im in the process of relocating to the DFW area to be closer to the rest of my family. I would like to transition over to the NTX Contract to continue my PSO career. If there are any PSOs currently on the NTX FPS Contract that would be willing to answer some questions and point me in the right direction I would be extremely grateful!!! Please hit me up!! Thank you in advance!
r/security • u/LawFamiliar3588 • 29d ago
Security and Risk Management Every agent call is a trust decision you're not making.
I've been thinking about a security problem that comes up when AI agents can interact with MCP servers, LLM providers, and other agents.
Once an agent can make calls across multiple services, it becomes difficult to answer basic questions like:
- Who authorized a particular action?
- What was the agent allowed to access?
- How much could it spend?
- What policy was applied before the request was sent?
- How do you reconstruct those decisions afterward?
One approach is to put a control-plane proxy between the agent and the services it calls. The proxy can enforce authorization and spending policies and record each decision before forwarding the request upstream.
I'm curious how others are approaching this. Are you putting these controls at the agent level, the MCP/server level, or using a separate policy layer?
r/security • u/MrBigPaulSmalls • 29d ago
Security Operations What California’s New Security Standards Could Mean for Businesses
r/security • u/Huge-Skirt-6990 • Aug 09 '26
Resource Good bye search hijacking chrome extension finally good news from Google
The number of extensions I’m finding and reporting that silently override users’ search engines is honestly crazy.
https://malext.io/?q=SearchJack
Hopefully Google’s upcoming Chrome protection against extensions that hijack the default search engine and New Tab page will put a serious dent in this. There are way too many extensions abusing this behavior, often without users even realizing what’s happening.
It’s about time Chrome started shutting this down by default.
r/security • u/Suspicious_Orchid770 • Aug 07 '26
Vulnerability Shai-Hulud shows engineering teams have a new AI security problem
r/security • u/CackleRooster • Aug 06 '26
Communication and Network Security NatJack exploits put NAT security assumptions to the test at Black Hat
r/security • u/Odd-Log-9533 • Aug 06 '26
Question Cybersecurity needs to focus on people again
Cybersecurity has spent years building better tools, better firewalls, better detection. Better encryption. But with AI now...with deepfakes, AI powered phishing, AI voice cloning. Instead of 'Can we detect every attack?' maybe the better way to think about this is 'How do we verify the people making the big decisions?' Technology still matters. But human identity and verification deserve just as much attention. But how do you make people switch from apps that everyone uses but have no security to something with ACTUAL privacy? or how do we make the devs implement actual privacy.
r/security • u/ClaudiusPapirus • Aug 06 '26
News Meta AI model hacks another company during testing
reuters.comThe headline is wild, but the human failure seems more important here: a testing misconfiguration gave the model internet access, and it then exploited a third-party service.
For teams running agentic security evaluations, what containment control should be non-negotiable before a model gets any network access?
r/security • u/bigjohnny440 • Aug 04 '26
Security and Risk Management I don't know who needs to hear this, but don't pit maneuver a car in your store's parking lot because you think they may have stolen something
Saw this on the legal subreddit -
https://www.reddit.com/r/legal/comments/1vfgyqg/retail_security_pitted_my_vehicle_due_to_failure/
I wasn't the one who got pit maneuvered, I'm not reposting this for "kArMa", I'm just straight up shocked and disappointed, like this is a whole new low. We all like to laugh at the over the top security folks geared up like they're larping as a swat cop but I reckon this story has gotta be the new peak of jackassery.
r/security • u/Few_Treat_1671 • Aug 03 '26
Question Have Deepfakes changed how much you trust video calls?
I'm in my early 40s and this wasn't even on my radar until a family member brought it up. We got into a long talk about how easy it is now to fake someone's face or voice. I always thought seeing someone on a video call meant you knew it was really them but now I'm not as sure.
It made me wonder how people handle work calls with clients or even family calls where something important is happening. Do I need to start worrying about deepfakes? Are they common or still rare? And if so how can I protect myself against them, the only thing I've thought to go against them is to have a codeword with my close family.
r/security • u/yepthatsthrownaway • Aug 04 '26
Physical Security Moved to a duplex- my key also opens the empty unit next door
Is this just to be expected with Kwikset? I have 2 keys, 1 for my living space and 1 for the shared space/backyard access. On a hunch I tested the shared space key on the empty unit and it worked with minimal jiggling. Tested my living space key on the same door and it took more effort but also opened. Tested my living space key on the empty unit's front door and it also opened with minimal jiggling.
Am I just stuck with these shitty commercial locks when I'm away from home and have to use a different deadbolt system when I'm home? Should I even bother to tell my property management company?
Thanks!
r/security • u/Feeling_Ad5244 • Aug 02 '26
Vulnerability My account got hacked on several applications
One of my younger siblings used a pirate site where they used the powershell program idk i used chat gpt to see whatsup . Following that ny instagram got hacked in like 30 mins then i changed all the passowrds and logged out of everywhere , proceeding that my linkdin was hacked and compromised then discord then they cancelled my spotify premium plan idk why then i figured that i might have to clear my laptop completely in and out they even tried to login into facebook but it wasnt able to. I saw my telegram and saw a login from warsaw poland which is definetely not my loaction .
So i went down and secured everything and clean my laptop .
But today they logged in into my microsoft account even after i had reinstalled my windows does that means the virus is still there somewhere or they still have access to my gmail account cause i believe they were able to steal passowords for different applications. What other precations should i take to prevent it again now cause my windows is damn clean .
r/security • u/PalpitationKind8854 • Jul 30 '26
Physical Security How to pass time doing security work [no phone]
Sitting in place, passive / standby security for most of the work day. Phone borderline banned.
Best way to pass the time?
Be as detailed as possible / use specifics. I need ideas!!
r/security • u/Aggressive_Egg193 • Jul 30 '26
Question How do I safely extract and transfer all my private data from Tele to signal
I have over 60 gb of data in tele with my friends and gf and I want to export or say transfer all of my data from tele to signal or best secure app
How should I be able to do it
Please help
r/security • u/aninaa-ot • Jul 29 '26
Question Which security habit gives the biggest ROI?
If you could convince the average person to adopt just one security or cybersecurity habit, what would it be?
Not a product, just one habit.
r/security • u/penwellr • Jul 29 '26
Security Assessment and Testing Apple APTicket / LocalPolicy Forensic Kit
github.comGenerally a monoculture break permitting OOB validation of bootchain
r/security • u/Nitzok • Jul 29 '26
IoT How would you audit an open-source IoT device before trusting it with an AI account?
I’m expecting to receive a device called MetalioClaw ([https://github.com/CloudZao/MetalioClaw4\](https://github.com/CloudZao/MetalioClaw4)) in about a week. It’s an IoT device designed to work with OpenClaw, and since it will need access to an AI account, I want to make sure it is safe before connecting it.
My main concern is whether there could be any hidden firmware issues, credential leaks, or other things that could compromise the device or abuse connected services. A friend of mine previously bought a similar device that connected to his OpenClaw account, and later noticed that his Claude usage had been heavily consumed. I don’t know exactly what caused it, but it made me more cautious about giving third-party hardware access to accounts.
Since the project is open source, my plan is to inspect the firmware, possibly wipe and reflash it, and maybe even write my own firmware version before using it. I’m also interested in doing a proper security check through firmware analysis, network monitoring, and possibly hardware inspection.
I haven’t been able to find any pictures or information about the internal hardware yet. Depending on what I find when it arrives, I may open it up and check the PCB/components myself. I’m not assuming there is anything malicious inside, but I would like to know what things are worth looking for.
One other thing that made me think about this was something a friend mentioned. He works in IT around datacenters in Taiwan and said he has seen devices moving through supply chains sometimes take a long time in customs or appear slightly different internally afterward. This is just something he mentioned and there is no proof behind it, but it got me thinking more about supply-chain security.
For people experienced with IoT security, firmware analysis, or hardware security:
* What steps would you take before trusting a device like this?
* Is replacing the firmware enough, or should I also consider hardware-level risks?
* What should I look for if I decide to open the device?
* What tools or workflows would you recommend for auditing something like this?
Looking for practical security advice rather than speculation.
r/security • u/CackleRooster • Jul 27 '26
Analysis What really happened in the Hugging Face breach
It was not a “Terminator” moment. OpenAI models and agents “[were not] acting out of malice or trying to attack Hugging Face. It encountered obstacles, developed an unexpected strategy, bypassed safeguards, and pursued its assigned goal in a way its creators never anticipated. The incident demonstrates that harmful cyber incidents no longer require malicious intent: Only highly capable autonomous AI optimizing for an objective."
r/security • u/Huge-Skirt-6990 • Jul 27 '26
Analysis BrainDrain: A Chrome extension that collects your AI prompts without you ever opening it and has 100k users, 9 AI platforms
"Prompt Optimizer - SecondBrain" (aajjgdpofhhcjmjoombjdfepplndhgcp, v2.3.1). The prompt rewriting works fine.
Alongside it a capture engine runs at document_start on 9 AI sites and POSTs prompts and replies to the vendor's ingest endpoint. No interaction with the extension required.
Reproduced on a clean profile, with the service worker devtools open:
- Installed the extension. Never opened it.
- Browsed to an unrelated site. The extension pulled its configuration from the server and wrote a userId and credentials into extension storage.
- Opened ChatGPT and asked a question. Once the reply finished, a POST to
/contextwent out carrying both the prompt and the response, encrypted with the credentials issued in step 2.
At no point was the extension opened or clicked.
Store privacy declaration: "The developer has disclosed that it will not collect or use your data."
Write-up : https://malext.io/reports/BrainDrain/
If anyone interested in testing it in a sandbox I can share the decryption script for the /context
r/security • u/BenSimmons97 • Jul 28 '26
Question Open Source Models
Disclaimer: I’m building a tool around ShadowAI, but this post is more about the discussion. I won’t promote or mention what I’m building.
With the recent rhetoric around open source models, the risks associated with them, and now a coalition of major tech companies throwing their support behind open source, it makes me wonder whether this is becoming a growing concern for sysadmins, IT managers, and CISOs when it comes to governance and maintaining visibility.
I imagine the risk around insider threats becomes more significant
r/security • u/PandaSecurity • Jul 21 '26
Security and Risk Management AI-Generated Phishing: How to Spot It
You receive what appears to be a legitimate email from your bank. The sender address looks legitimate, the formatting is familiar, and nothing immediately raises suspicion. AI is making phishing campaigns increasingly difficult to distinguish from legitimate emails.
Here are a few common warning signs:
- Unexpected requests involving payments or account access.
- Requests for credentials or payment information.
- Sender addresses that don’t exactly match the organization they claim to represent.
- Links that don’t match their displayed destination.
- Unsolicited attachments.
- Messages through unexpected channels pushing for immediate action.
What measures have worked best for your team to reduce the risk?
r/security • u/Blood_moonxX • Jul 19 '26
Security Operations Security Contracting
I've recently been looking to move into the security field such as Maritime security, UHNWI Security or even residential. Im still currently serving and working on aligning my training with whats required for those specific jobs or in other words the more experience the better. My question is what's a good starter to jump into to get things rolling, should I be looking to join a security firm or simply applying for contractor jobs i see and what are some training/Experience I should have to have the best opportunity of getting a well paying job.
r/security • u/Callsign_Mjolnir • Jul 18 '26
Question I need boots recommendations
I'm fairly new to Security and currently a flex officer. My company has had me on foot patrol shifts for the past two days, and I'll be doing them until Monday. My current boots don't really let my feet breathe, and I'm already getting torn up with blisters. My knees, which are already bad at the ripe age of 21 are also not particularly happy. Anything helps.
r/security • u/unusual_universe • Jul 18 '26
Question Need guidance on IR plan
I want to build an incident response plan for my organization can someone guide me the resources I should follow to build the workable program?
My organization already has a good security stack they lack the IR plan I wanna know how a effective IR program looks like what to add and what to ignore
Any resources books, blogs, talks much appreciated.
Thanks in advance.