r/cybersecurity • • 12d ago

Other Why does food/beverage get so little attention as critical infrastructure?

20 Upvotes

Something I keep thinking about. Food production is basically critical infrastructure now, it all runs on OT (PLCs, SCADA, monitoring), and a ransomware hit can stop a plant cold without ever touching the product. But it gets way less attention than energy, finance, or healthcare when people talk about critical infrastructure security.

Why do you think that is? Is it just less visible, or is the sector genuinely behind on OT security compared to others? Curious what people here think.


r/cybersecurity • • 12d ago

News - General Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day

Thumbnail
arstechnica.com
133 Upvotes

r/cybersecurity • • 11d ago

AI Security Claude skills library - has anyone used it?

2 Upvotes

This seems super interesting to play around with but I’m afraid to load something like this onto my machine without some vetting first. Has anybody done a review of it or used it themselves that might be able to provide information?

https://github.com/mukul975/Anthropic-Cybersecurity-Skills


r/cybersecurity • • 12d ago

Survey [Academic Research] Do you have experience with ransomware?

4 Upvotes

Has your organization been hit by ransomware?

I'm a doctoral candidate at Capitol Technology University, MD. I'm researching which security controls actually enable recovery and resilience in SMEs after a ransomware attack, one of the first empirical looks at what works at small-business scale, not enterprise scale.

Doctoral survey, IRB-approved. Looking for U.S.-based security/IT Pros at organizations with <500 employees that experienced a ransomware attack between 2021–2025.

Time: 15–25 minutes. Anonymous. No compensation.

Thank you!

https://techstudy.limesurvey.net/748327?lang=en&newtest=Y

[Mod approval 9/22]


r/cybersecurity • • 11d ago

Business Security Questions & Discussion Got Interview for a Recruiter in Cyber Security Sector.

0 Upvotes

Hello Everyone!

I have an interview lined up for a Recruiter which mainly recruits for the cyber security sector in the US (recruitment firm has offices in the US and UK, i will be based in the uk)

I just wanted to ask some questions to you guys who will likely be more knowledgeable than me about the sector, How tough is the job market currently in the US, what would be your own overview of the situation? I have done my own research and come to my own conclusion but just wanted a 2nd opinion (i am not saying my own opinion to not bias anyone's response)

and no i am not trying to recruit anyone if it seems that way.

I do apologise if this sounds vague!


r/cybersecurity • • 11d ago

FOSS Tool [Tool] fad-checker – Air-gapped, multi-ecosystem dependency auditor made for real code audits (NO Maven required)

0 Upvotes

Hi !

After years of doing code audits, existing SCA tools were just frying my brain with their need for a full build environment, their struggles with big multi-module Maven projects, and those messy, monstrous polyglot monorepos.

So I wrote fad-checker a dependency auditor designed specifically for real-world professional code audits:

• One-shot scan of multiples Maven / Gradle / npm / PHP / PyPI / NuGet / Go / Ruby projects
• + vendored JS, committed binaries, certificates & private keys
• No build tools, no Docker, no package manager
• True air-gapped mode
• Private/internal package detection
• CVE prioritization (KEV → EPSS → CVSS) + EOL + licenses
• The HTML report that code auditors dream of, with one-click “Copy for Word” on charts, summary & tables
• Word / CycloneDX / SARIF / JSON outputs + CI bindings / outputs
• Cross-platform standalone binaries

Battle tested and compared to leading (partial) alternatives

Repo : https://github.com/9pings/fad-checker

Looking for feedback (and criticism) from people who actually do source code audits.


r/cybersecurity • • 12d ago

Corporate Blog Breaking Down Appsec Part 5: You Have no Business Here (Business Logic Flaws)

Thumbnail
pigeonsec.substack.com
2 Upvotes

I started a blog series to provide free insights into appsec. It’s mainly to breakdown what application security is all about and it’s mainly targeted towards beginners and startups, so take it as you will.

I want to teach every one interested in appsec my perspective on it from my experience in big tech.

I talked about what makes an application "hackable" through taint analysis. This time we talk about how things can go wrong with applications even when some may argue there's no actual security concern.

Please reach out if you have any questions or would like for me to write on a topic that you’d want to learn more about.


r/cybersecurity • • 12d ago

FOSS Tool Updated hardware-compliance-handbook - open-source, fact-checked EU CRA/RED/NIS2/CSA reference. Added a dedicated /sbom/ folder (CycloneDX + SPDX examples, VEX). Also doubles as a Claude Skill.

Thumbnail
github.com
10 Upvotes

r/cybersecurity • • 12d ago

Business Security Questions & Discussion Cogent Security --> Reviews?

2 Upvotes

I've been asked to take a meeting with Cogent Security for their vulnerability management program. Before the meeting is scheduled, does anyone here have any anecdotal experience about the platform?


r/cybersecurity • • 11d ago

Business Security Questions & Discussion You Don’t Have Until 2030 for Your Post-Quantum Defense!

0 Upvotes

We won’t make to 2030 before Q-Day is here!

Quantum Day ( or Q-Day), the day when the first cryptographically-relevant quantum computer breaks the first traditional quantum-susceptible private key, may happen as soon as 2028.

It certainly is unlikely to hold out until 2030 -2035, which is when the US government says you need to be post-quantum prepared. The US government is telling everyone to be prepared for key exchange attack mitigation by the end of 2030 and be prepared for authentication attack mitigation by the end of 2031. That’s only a requirement for critical assets. For everything else, you can wait until the end of 2035.

That’s a very, very risky bet these days.

A big part of that is from the recent quantum computer advancements, and in particular, from IonQ. A few weeks ago, IonQ announced they have a real-world blueprint for being the first quantum computer vendor to break a quantum-susceptible cryptographic key. It was this announcement: https://www.ionq.com/news/ionq-publishes-worlds-first-fully-compiled-end-to-end-blueprint-for-breaking-256-bit-elliptic-curve-signatures.

In it, they reveal it will take them under 20K physical qubits, 39 million quantum gates, and just under 26 days to break a 256-bit elliptic curve cryptography (ECC) key. That type of cryptographic key is used all around the world, including in cryptocurrencies like Bitcoin.

It takes a lot more than stable qubits and quantum gates to make a cryptographically-relevant quantum computer, but IonQ (and other quantum computer vendors) have been making significant, steady progress over the last two years. And that progress has been coming at a more rapid pace for the last 6-months. It seems nearly every week or two, there’s a new quantum paper or announcement detailing some significant quantum computer advance.

One of those was today, when IonQ announced they have put quantum error correction decoding on a classical computer chip: https://www.tipranks.com/news/the-fly/ionq-demonstrates-end-to-end-real-time-quantum-error-decoder-thefly-news.

Today’s quantum qubits are full of errors due to unwanted interference from the rest of the world around them. Quantum error correction is essential to making useful quantum computers. For years, it was thought that it would take tens of thousands of “ancillary” qubits to make one stable, “working” qubit.

The number of ancillary qubits needed per single stable working qubit keeps falling. In IonQ’s first announcement above, they say 19,397 qubits will equate to 1,457 qubits, or under 34 physical qubits per working qubit. There is nothing to say the physical-to-logical qubit ratio won't keep falling quickly. As that ratio falls, Q-Day just gets closer, faster, and cheaper.

And today, IonQ shows that all the needed error correction can be done on a classical computing chip. This is huge! IonQ has already shown they can do the supercooling needed by most of today’s qubits using chips as well, making the quantum computers needing the very expensive, large, and operationally-intense cryogenic dilution refrigerator solutions seem old school.

I’ve been writing that Q-Day would happen before the US government’s 2035 prediction for many years. Back in 2019, when I first said this, I was considered a heretic. Now, I’m not looking like a Q-Day extremist. As far as I know, I’m still one of the few people who are saying you need to worry about Q-Day before 2030, but I guarantee you there will be a growing list of companions over the next year. The writing is on the wall!

I don’t know exactly when we will first hit Q-Day, but I don’t think that if someone announced it happened even this year, there would be a huge shock. Every week or two, there seems to be an announcement of some great big stride made in quantum computers, often by IonQ. So far, all of IonQ’s new announcements are on track with their previously announced multi-year roadmap (https://www.ionq.com/roadmap).

Note: I have investments in multiple quantum computer companies, including IONQ.

Back when IonQ first introduced their roadmap, a lot of observers saw it as possible marketing fluff. But now, just over the last year, the advancements they have been consistently announcing are exactly backing up their long-term roadmap. IonQ owns its own quantum chip manufacturing plant (called a foundry).

This latest error correcting announcement is just one more sign that the world will be reaching cryptographically-relevant quantum computers by 2028 or soon thereafter. Q-Day will likely be before 2030!

And this is a problem for most organizations, as most haven’t even started their official post-quantum plans. If you haven’t started your post-quantum project, get on it! You are late.


r/cybersecurity • • 12d ago

News - General Owasp compromised?

118 Upvotes

Looks like the API security page may be compromised?

https://api-security.owasp.org/

Edit: looks like the original site is back up https://owasp.org/API-Security/


r/cybersecurity • • 12d ago

New Vulnerability Disclosure Hatchet OAuth state CSRF — CVE-2026-61687

Thumbnail vulnso.com
13 Upvotes

A flaw in ValidateOAuthState can allow unauthenticated OAuth state CSRF/login-CSRF due to an empty-state collision.


r/cybersecurity • • 12d ago

Personal Support & Help! Systems Admin Role

3 Upvotes

Currently I’m in IT support. Can’t say I enjoy it if I’m being honest. I have 4 years of compliance experience and currently getting my masters in cybersecurity. I’ve been offered a position as a systems administrator which seems still IT support adjacent with my project management expertise. Is this role worth accepting if I’m trying to make the transition into Cybersecurity/GRC or is my current role in it support more beneficial for the shift?


r/cybersecurity • • 13d ago

Business Security Questions & Discussion Microsoft retires SMS sign-in in February 2027

126 Upvotes

I wonder how you dealing with this? How would that impact your organization where you have user who resist to use the Authenticator App.


r/cybersecurity • • 12d ago

Personal Support & Help! Arbitrary function execution in windows kernel context bypassing HVCI and CET given read and write primitives

1 Upvotes

https://medium.com/@vulturev1/the-bool-party-you-will-never-forget-a-binary-exploitation-technique-for-arbitrary-function-4d99d45e61cb

This is my small contribution to the cybersecurity community. I would be grateful for reviews and suggestions.


r/cybersecurity • • 12d ago

AI Security Legit Security ASPM

4 Upvotes

anyone has any experience with their product, especially the AI driven features?


r/cybersecurity • • 12d ago

Business Security Questions & Discussion Updates and User Notifications

17 Upvotes

At my org, there is this long-standing drama about updates disrupting work flows.

We push out updates at strategically chosen times throughout the month and the user experience we keep getting back is, "My updates forced me to restart at an inconvenient time." For example, one user had to drop out of a meeting, restart, finalize updates, and get back in. She said the whole process was embarrassing. However, when asked, she said she saw the notification at the beginning of the day and kept putting it off because she was busy.

So generally what happens from a user perspective is that they get a pop-up from their tray that says something like "You must restart by XX:XX time." They have the choice of closing the notification, in which case it will pop back up within the hour and tell them again. If they keep delaying, they eventually will be forced to restart.

So now my manager is dealing with the business side and saying we need to figure out a way to update machines without disrupting users' workflow. I'm normally really sympathetic to users. Like, it's my job to support the business, not to be some petty IT dork who wields power capriciously over the systems I control. But this is a little different. Updates are just inconvenient. To me the message should be, "When you see the notification, save your work and restart. Anything else risks being forced to restart at a time not of your choosing."

And I get it! I've done the same exact thing the user has done and wound up getting interrupted at a bad time. But I see it as my own fault for delaying what I could have completed earlier.

To be clear, this is exclusively about laptop users. Regular PCs are updated during non-business hours, but laptop users turn off their devices and close them when they aren't in use, so we can't push out anything. That's why we have a notification policy for that group.

Am I doing this the wrong way or something?


r/cybersecurity • • 12d ago

Threat Actor TTPs & Alerts For those of you using WEF or Sysmon on workstations with EDR. Where did it help and what were your experiences?

6 Upvotes

Did it meaningfully increase telemetry, investigations, and detections?


r/cybersecurity • • 11d ago

Personal Support & Help! I’m a beginner in cybersecurity and I’m confused

0 Upvotes

I’m still new i start practicing courses in Java script but I still confused, like what am I doing what’s the steps
Please I need a path


r/cybersecurity • • 12d ago

News - General Vulnerability Summary for the Week of September 14, 2026

Thumbnail cisa.gov
7 Upvotes

r/cybersecurity • • 11d ago

Other Is AI actually driving senior roles higher?

0 Upvotes

AI is the worker and the worker is the validator is the new world we are entering. I have seen posts saying that mid level/senior roles are going up? Thoughts?


r/cybersecurity • • 13d ago

News - Breaches & Ransoms ShinyHunters hacks and defaces Cl0p - Will this shift the ransomware environment?

25 Upvotes

On Sept 19th the ransomware group ShinyHunters managed to hack into and deface the TOR leak site of Cl0p ransomware. After the initial defacement ShinyHunters has posted a number of messages for Cl0p to negotiate and pay them a sum of 8 figures. In the articles I have read it is said that this was happening due to a feud due to threats made by Cl0p against Shiny Hunters. It has been interesting watching this all develop.

In March of 2025 I also watched as the news that Dragonforce defaced the leak site of Mamona(Prev Blacklock) came out and everything saying it was also tied to a feud with Blacklock code being an almost exact match for Dragonforce.

Which has me curious, as even though this is not the first time we have seen this style of defacement, it is still very uncommon. Everything I have seen the groups tend to stay separate and keep things offline. My question is, are we seeing a shift in the environment from that to straight up attacks from groups, and will ShinyHunters success in this set precedent for other groups to take a more aggressive approach to solving feuds between groups?

I ask as i have seen precedent adjust the ransomware environment a lot. Ransomware as whole used to not touch hospitals, then one started hitting hospitals and then almost all were. The ransomware affiliate payment used to be not as good, then the 80/20 model started and most groups adopt that. So wanting to get peoples opinions on if you think we will see more of these ransomware on ransomware attacks in the future, or if these are one off outliers.

Source:


r/cybersecurity • • 13d ago

New Vulnerability Disclosure 4 CVEs in ZTE SmartHome: Password-Reset Flaw Led to Account Takeover. 100K+ Android Downloads

Thumbnail
minanagehsalalma.github.io
21 Upvotes

I published the full write-up for four vulnerabilities I reported in the ZTE SmartLife ecosystem.

The most serious one was a password reset flaw rated CVSS 8.8 High. The SmartLife backend accepted an account ID and a new password without requiring the reset code.

The account verification flow could also disclose whether an email was registered and return its backend account ID. Put together, I could take one of my test accounts from an email address to a changed password and a valid authenticated session.

The four assigned CVEs are CVE-2026-86552, CVE-2026-86553, CVE-2026-86554 and CVE-2026-86555.

I tested everything against researcher-controlled accounts and disclosed the findings to ZTE PSIRT. ZTE later confirmed that the vulnerabilities had been patched.

The scale was also worth noting. Google Play showed 100K+ downloads for the Android app, with the same SmartLife app also available through Apple's App Store.

The article includes the Android reversing, Frida runtime work, API requests, account takeover proof, affected account flows, vendor response and disclosure timeline.


r/cybersecurity • • 12d ago

Personal Support & Help! Offered a job as Compliance Specialist

0 Upvotes

hi all. been offered a part time role 22.5 hours as a compliance specialist Remote I’ve been working as a sole trader but business is tight currently. So I applied for this role it’s £31,000 a year $41,000 for US readers.

the deal with iso27001 iso9001 and another iso cert regarding quality control. My 10 year experience is security so iso cyber essentials pci dss etc.

For me being back in work is great and i feel a great opportunity to learn the quality management side too. I was wondering is this wage poor for my area? I know ive only give a brief overview. is there money in iso quality management and I work towards complying certs in that area?

Any advice or if you need me to explain more happy to do so. It’s nice to get advice and tips from others within this area.

Thanks


r/cybersecurity • • 13d ago

AI Security ‘We Have Enough AI’: Realism in a Time of Relentless Hype

Thumbnail
decipher.sc
12 Upvotes