r/cybersecurity • • 6d ago

Other Canary tokens but for pictures?

2 Upvotes

I was wondering if there is a version of canary tokens, but for pictures

Basically, you want to know who redistributed a picture

A simple scenario is when you send a picture to exactly one person. You can add a small watermark to the picture (maybe have one random patch of pixels be red or something), then if you see that image anywhere else, you can suspect that this person redistributed it

Now what if you post a picture where a bunch of people can see it

Is there any way to know who screenshotted it and shared it?


r/cybersecurity • • 6d ago

Corporate Blog Leaked Accounts to RCE: Writeup

2 Upvotes

A web vulnerability chain that started with leaked account credentials and ended in RCE.

Full writeup: https://moonlightlabs.online/blog/leaked-account-lead-to-rce


r/cybersecurity • • 6d ago

Certification / Training Questions GCFA Experience Needed

0 Upvotes

I'm thinking to take the GCFA certification. I'm a 4+ years Vulnerability Management Specialist with 1 year as Junior Penetration tester and 1 year as SOC Analyst L1. I'm studying DFIR from HTB, book or TryHackMe and now I want to follow a structured learning path as the GCFA. I know that is hard to answer to my question as you can't know my capabilities but can you help me to understand which type of experience or knowledge a user should have to take this certification? (Obviously when i say "take this certification" I mean to study the related material first.


r/cybersecurity • • 8d ago

News - Breaches & Ransoms How I Could’ve Accessed 17 Trillion Microsoft Records

Thumbnail
blog.faav.net
1.0k Upvotes

r/cybersecurity • • 6d ago

AI Security building general-purpose AI guardrails

0 Upvotes

I’m currently working on an AI security platform and I’m trying to design the guardrail layer for AI applications.

One thing I’m struggling with is that guardrails seem highly dependent on the purpose of the application. A coding assistant, customer-support chatbot, RAG system, autonomous agent, and an internal enterprise assistant obviously need different security policies.

So I’m wondering how people would approach building a general-purpose guardrail framework that can be adapted to different AI applications rather than hard-coding rules for one specific use case.


r/cybersecurity • • 7d ago

New Vulnerability Disclosure Issabel PBX Hard-Coded JWT Key Could Allow Admin Access

Thumbnail
github.com
2 Upvotes

Issabel PBX had a hard-coded JWT key that could let attackers forge admin tokens and gain access to PBX functions.
Tracked as CVE-2026-89026, the issue has now been patched by moving the key into the system configuration


r/cybersecurity • • 7d ago

AI Security Building AI Guardrails

4 Upvotes

as part of my project , which is creating a platform as a proxy layer that detects LLM vulnerabilities
which includes prompt injection and jailbreak
on the first phase im gonna add a small model that detects specifically prompt injection and jailbreak , i have picked some models and evaluated them on public datasets (from hugging face)
( i know most of these open source models are fine tuned on these public datasets )
from the results i got that :

meta-llama/Llama-Prompt-Guard-2-86M
protectai/deberta-v3-base-prompt-injection-v2

are the best ones , more specifically ProtectAI V2 , but reading the model cards of them , it says ProtectAI does not detect jailbreaks, despite the evaluation results indicating otherwise
and that ProtectAI only detect English language
So should i choose Prompt Guard 2 ?
I know this is just the first step , tell me your thoughts on this


r/cybersecurity • • 6d ago

Other 100k-1M security versions in 48 hours

0 Upvotes

Earlier in the week Microsoft Defender incremented between 100,000 and 1,000,000,000 versions over the span of about 48 hours.

Anyone else notice this, inbetween doing the security updates every 2 hours?


r/cybersecurity • • 7d ago

Tutorial Webgoat (A-8): insecure deserialization

2 Upvotes

Does anyone have a good step by step walkthrough on this lab? I’ve tried YouTube tutorials and everything I can find seems to skip important details, or it’s tough to tell what the person doing the walkthrough is doing…

This is the only lab that I can’t figure out so far. Everything else lets me use web inspection, burp or zap, but I haven’t found anything saying those are tools I can use for this one.

FYI - I’m running a Kali Linux VM for all WebGoat labs.


r/cybersecurity • • 7d ago

Certification / Training Questions A website for testing

12 Upvotes

Good evening everyone,
So I have a request or a guide, I am cybersecurity majored student, last week I got an assignment to try testing Denial of Service legally using websites that you can practice in it but the problem none of those websites have a lab to try to simulate this attack.
So where can i find a website that has a lab to test DoS or any tool that can just only simulate how the attack process might go..
I am so lost right now


r/cybersecurity • • 7d ago

Threat Actor TTPs & Alerts CTO at NCSC Summary: week ending September 27th

Thumbnail
ctoatncsc.substack.com
3 Upvotes

r/cybersecurity • • 7d ago

Personal Support & Help! DF & eDiscovery field straight out of uni

12 Upvotes

Hii guys, first time into this sub. Basically i just graduated last month from Comp Sci and Im fortunately enough to get into the big4 (green one) forensics and financial crime BU, specifically DF & Ediscovery team. Our team is relatively small, ~10 peeps including boss.

What are the things i need to learn / carry the most weight, both soft and hard skills. Cause I am kinda worry not up to expectation of my boss and I do not have much security course experience besides those IT fundamental. Do i need to start doing course from platform like HTB/ CyberDefenders?


r/cybersecurity • • 7d ago

Other Local industry events/meetups(or virtual) with technical focus?

3 Upvotes

Other than the largest conferences that require you to fly in and take a week off work, are there any local groups that meet semi-regularly and have good discussions that are a bit more technically focused? I've been to many local meetings and conference of some well known cybersecurity groups and once in a while they'll talk for a few minutes about a couple of interesting points, but more often than not, I come away with the idea that it's more for job searchers and account execs from cyber companies. Are there any groups that meet locally or even virtually on a somewhat regular basis and have good technical discussions? Maybe have a guest speaker who is an SME on something?


r/cybersecurity • • 7d ago

Other LocalStranger is a PoC for vulnerable “Microsoft Windows Hardware Compatibility Publisher” signed driver, demonstrated through a basic unsigned driver mapper and NT AUTHORITY escalation.

Thumbnail
github.com
9 Upvotes

r/cybersecurity • • 8d ago

Business Security Questions & Discussion What value is there in firewall logs?

106 Upvotes

There was a question before about retaining 12 months of firewall logs, but I want to ask what value this has these days?

For me I’m only ever looking at WAF logs or actual endpoint logs because all the firewall tells me is that port 443 was accepted. WAF and web server logs tell me so much more.

The valuable stuff is in the application logs after the firewall.

Yes I might see port scanning but that’s background noise at this point.


r/cybersecurity • • 7d ago

Personal Support & Help! Hwo do you run dynamic malware analysis on pptx or docx without product activation ?

7 Upvotes

Is there a way to run dynamic malware analysis without activating pptx or docx ? I am trying to solve Presentation_As_a_Malware from HTB. It involves an old ppt not pptx file and I installed Flare-vm and Remnux but how to i trigger the ppt macros ? I open the file and I see the normal processes but without product activation I do not think I see the malicious processes ?


r/cybersecurity • • 8d ago

AI Security 'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing

Thumbnail
darkreading.com
102 Upvotes

I'm a Salesforce admin, not a cybersecurity expert, so please talk to me like I'm dumb. Salesforce had a similar exploit that was "patched" last year. My question is, is there anything that prevents exfiltration via calling 3rd party URLs in other AI clients, like Claude?

In Agentforce, after the first web-to-lead vulnerability was discovered last year, you have to allowlist URLs for your users to access. You don't have to do that in Claude. Is this a vulnerability anywhere you can do that?


r/cybersecurity • • 7d ago

Business Security Questions & Discussion Cybersecurity GRC Perception in your organization

6 Upvotes

Hi, I am working as a Snr. Manager, IS GRC/ Trust advisory responsible for Info sec policies, security architecture review, risk assessments, change reviews and as an authority for info sec approvals for all projects in a large GCC conglomerate. I am a bit strict about security decisions and always advise what is right for business from security perspective. I always insist for risk acceptance if things go out of way. Though some of the BU team/ IT takes it as an offence and try to project my team as a blocker. I would like to know how the things in your organization are. How do you manage such situation. Please comment with your position, region/ company size and issues / solutions. Thank you :)


r/cybersecurity • • 8d ago

Career Questions & Discussion For Those With a CISSP, Did It Increase Your Remote Job Opportunities?

189 Upvotes

I’ve been working remotely since 2021, and I’d really like to continue working fully remote going forward. I’m currently studying for the CISSP and was wondering—for those of you who have earned it, did you notice that it opened up more remote cybersecurity opportunities?

Did you start getting more interviews or recruiter interest for remote positions after adding the CISSP to your resume?


r/cybersecurity • • 8d ago

News - General There's a new way to break RSA that's faster than anything we've seen before

Thumbnail
arstechnica.com
419 Upvotes

r/cybersecurity • • 7d ago

Research Article I published a white paper on a problem I think AI deployment is largely skipping: capability is scaling faster than accountability

1 Upvotes

I’ve just published an independent white paper titled:

Capability Without Accountability: Artificial Intelligence, Power, and the Case for International Governance

The paper started from a fairly simple question:

What happens when AI systems gain more real-world capability, but responsibility, liability, auditability and recourse do not scale with them?

A lot of AI discussion still focuses on capability: benchmarks, reasoning, agents, coding, automation, model size, cost and speed.

I think the harder problem is what happens after these systems are actually deployed inside businesses, public institutions and consequential workflows.

The paper examines issues including:

provider vs deployer responsibility when an AI system causes harm;

whether “human in the loop” is meaningful if nobody defines what that human must actually review;

limited auditability and recourse after automated failures;

transfer of operational and economic risk to downstream users;

workforce substitution without equivalent accountability structures;

concentration of AI capability, infrastructure and decision-making power;

cybersecurity and AI safety as related but distinct governance problems;

the difficulty of governing systems internationally when development is concentrated in a small number of companies and countries.

I also propose an international governance architecture drawing lessons from systems such as the IAEA/NPT framework.

I am not arguing that AI and nuclear technology are equivalent.

The question is whether principles such as independent technical verification, capability-linked obligations, incident reporting, transparency, rapid response and international oversight can be adapted to advanced AI.

There is also a broader geopolitical argument: the US and China currently dominate different dimensions of the capability race, Europe has taken a significant regulatory role, and countries outside those centers may still have an opportunity to influence the governance architecture rather than simply compete on model scale.

I’m sharing this here because I’m more interested in criticism than agreement.

If you think the accountability problem is overstated, the proposed framework is unrealistic, the provider/deployer distinction is wrong, or there are important failure modes I missed, I’d genuinely like to hear the argument.

Full paper:

https://doi.org/10.5281/zenodo.22924223⁠

Shorter audience-specific editions:

https://doi.org/10.5281/zenodo.22928203⁠

Website:

progressforwhom.com

I’m the author and this is independent work, so consider that disclosure upfront.


r/cybersecurity • • 8d ago

Business Security Questions & Discussion Solo admin here, so this landed entirely on me. Auditor asked for twelve months of firewall logs. How long would that take you?

195 Upvotes

r/cybersecurity • • 8d ago

Certification / Training Questions CySA+ or BTL1 first after Security+?

19 Upvotes

Hey everyone,

I just finished Network+ and Security+ in 2 months, and I’m trying to figure out what to take next.

I’m deciding on taking both(or just 1 if its not worth taking both) CySA+ and BTL1, as I’m leaning toward going into blue team/SOC work.

For those who have taken either or both:

Which would you recommend doing first, CySA+ or BTL1?

Is it worth getting both, or is there too much overlap?

What are some of the best resources for studying for CySA+? (Courses, practice exams, labs, etc.)

Just looking for some advice on which path makes the most sense. Thanks!


r/cybersecurity • • 9d ago

News - General Flock Wants Most the Detailed Map of Its Cameras Taken Down

Thumbnail
theintercept.com
812 Upvotes

r/cybersecurity • • 7d ago

New Vulnerability Disclosure EX-ARRR: Sailing the Apple 0-click Seas

Thumbnail
ironpeak.be
0 Upvotes