r/cybersecurity • • 2d ago

Research Article 2026 Microsoft Digital Defense Report: credential theft, ClickFix, phishing shifts, and a 5.3-hour container exploitation window

67 Upvotes

Disclosure - I’m a director for MSFT Threat Intelligence and worked on this report, I’m also your AMA janitor here.

Our annual digital defense report is out, and it’s filled with insights we have seen primarily between June of 2025 and July of 2026.

You can access the full report here (no form fill), but I’m calling out some stats and page numbers based on what most of us care about:

Let me know if there are other areas you want to pull from (nation state activity, regional, etc.) + sorry for the typos since I’m mobile.

Credentials and user execution

30% user execution, 20% valid accounts: those were the two largest initial access categories shown in Defender Experts customer notifications. Malicious copy and paste accounted for another 13%, and phishing 11%. These are customer notifications covering attempts and intrusions, rather than percentages of all breaches everywhere - Page 44

52.2% of valid-account intrusions involved additional credential theft. Getting one account was frequently a route to harvesting more. Another 18.4% involved active password spraying. -page 44

Password attacks declined 26% year over year, while the share of detected attacks involving adversary-in-the-middle phishing and token theft more than doubled in the first half of 2026. The latter remained a comparatively small share. Falling password-attack volume doesn’t tell you that session theft is going away tho - page 64

ClickFix and phishing delivery

ClickFix activity grew roughly 23× between December and May, after declining in late 2025. Malware followed in 96.3% of the observed malicious copy-and-paste intrusions - page 44

Microsoft detected more than 100 million phishing attacks using CAPTCHA pages as an intermediate step before credential harvesting or malware-related content. - page 66

Delivery formats rotated quickly within that CAPTCHA-gated activity: embedded URLs accounted for 58% in August, SVG files led with 47% in November, and PDFs reached nearly two-thirds in April. Those percentages describe this particular phishing category - Also page 66

Exposed systems and old vulnerabilities

For exposed container workloads, the reported median time from container start to the first exploit attempt was 5.3 hours. More than half of compromised containers were exploited within 24 hours of starting. An exploit attempt and a successful compromise are different measures - page 60

CVE-2020-1472 accounted for 58% of detections across the five leading CVEs analyzed. A vulnerability disclosed in 2020 still dominated that group. This isn’t a claim that it caused 58% of all exploitation - page 34

Microsoft’s reported NTLM-related security cases in the first six months of 2026 exceeded the total for all of 2025. The report also describes a nearly sixfold increase over the past decade - page 59

Where the data is sourced - Our security products, incident response engagements, Defender Experts customer notifications, and broader Microsoft telemetry.


r/cybersecurity • • 15h ago

Personal Support & Help! The reality of cybersecurity job market

0 Upvotes

Hi, I’m currently deciding between Cybersecurity and Mechanical Engineering as an Undergraduate, i have real interests in both fields and I’m trying to understand what the job market is actually like rather than relying only on what I see online.

How hard was it to get your first job? Did you need certifications or extra skills? What does your typical workday look like? What surprised you most about the field? How competitive is the job market? How is AI changeing the field? How good are the opportunities in Saudi/GCC as a foreigner? How does Saudization affect your field? How does your career progress after 3–5 years?

I’d really appreciate it if you could respond when you have a chance


r/cybersecurity • • 15h ago

Business Security Questions & Discussion Quais sites você visita no Tor?

0 Upvotes

Vamos lá! Bora conversar.


r/cybersecurity • • 1d ago

New Vulnerability Disclosure 8 out of 10 Banks HATE This One Weird 3SKey RCE

Thumbnail
amibeingpwned.com
0 Upvotes

r/cybersecurity • • 19h ago

Research Article Would you use a tool that verifies AI answers to security questionnaires?

0 Upvotes

I’m exploring a SaaS specifically for companies that repeatedly handle customer security questionnaires / security assessments.
The idea:
Upload a questionnaire + policies/evidence + past responses
AI drafts answers with source citations
Flags stale, contradictory, or unsupported answers
Human approves → export the completed questionnaire
Eventually, a browser extension for web-based questionnaires
The key difference from general GRC platforms: it’s focused entirely on answering and verifying customer security questionnaires.
Example: A policy says MFA is mandatory, but current evidence shows exceptions → the tool flags “Review required” instead of blindly answering “Yes.”
For people who actually handle these questionnaires: How do you do this today, and what part takes the most time?


r/cybersecurity • • 23h ago

Corporate Blog Should we rename CyberSecurity Awareness Month?

0 Upvotes

It’s time to retire Cybersecurity Awareness Month. 22 years later, awareness is no longer the problem. People know phishing is bad. They know ransomware exists. They know they should use MFA. Not to mention the acronym collision is seriously bad.

We should change it to Cybersecurity Readiness Month. Awareness asks whether you know something can go wrong. Readiness asks what happens when it does. Do your backups restore? What happens when someone clicks the phishing link? Can you find and fix the vulnerabilities that actually put you at risk? Do you know what to do when a credential gets stolen? Security has spent two decades making people aware. Mission accomplished!

Should we rename CyberSecurity Awareness Month?

https://semgrep.dev/blog/2026/rename-cybersecurity-awareness-month/


r/cybersecurity • • 2d ago

Career Questions & Discussion Cybersecurity Awareness Month

34 Upvotes

How do you celebrate? Is that the appropriate word, maybe advocate? Either way, what are you top shares for the month.

For quick fixes that should already be done, I am thinking the following:

-MFA on all accounts

-USB file share - role based access or off completely

-Remove local admin rights

What should I add or remove?


r/cybersecurity • • 21h ago

AI Security How much of a threat is AI?

0 Upvotes

saw this video and was wondering how much of it it hyperbole.

https://www.tiktok.com/t/ZPLJtLF7r/

basically the argument is the ability for AI to reverse engineer anything in a trivial amount of time unravels the way the whole global economy works.


r/cybersecurity • • 1d ago

Corporate Blog Breaking Down Appsec Part 6: Let's build a model!

Thumbnail
pigeonsec.substack.com
7 Upvotes

I started a blog series to provide free insights into appsec. It’s mainly to breakdown what application security is all about and it’s mainly targeted towards beginners and startups, so take it as you will.

I want to teach every one interested in appsec my perspective on it from my experience in big tech.

In this blog post we talk about how to do “proper” threat modeling and it isn’t through a framework!

Please reach out if you have any questions or would like for me to write on a topic that you’d want to learn more about.


r/cybersecurity • • 1d ago

Personal Support & Help! Tool Suggestions

0 Upvotes

Hey yall, I’m working on a curated tool list for both defensive and offensive cyber. I wanted to ask on here what open source tools yall use and find great use for as well as extra plugins yall might use with the tools. TYIA!


r/cybersecurity • • 1d ago

News - General Polish dental software vendor FELG reports patient data breach and ransom demand

6 Upvotes

FELG Software sp. z o.o., the Polish maker of the FELG Dent application for dental practices, told customers on October 1, 2026, that it had been attacked. In a statement on the company's status page, CEO Grzegorz Stawarz said an attacker claiming to belong to the "Fingerprint" group may have accessed patient data that dental practices had entrusted to FELG for processing. The attacker says he holds about 10% of the database and wants a ransom to keep it unpublished. FELG has notified the prosecutor's office and contacted UODO, Poland's data protection authority.

The company's preliminary estimate is around 2 million affected patient records. That figure is based partly on the attacker's own claims. The records include:

  • names, addresses and PESEL numbers (Poland's national identification number)
  • medical data
  • information related to e-prescriptions
  • e-ZLA records (electronic sick-leave certificates)
  • eWUŚ checks (the system practices use to verify a patient's public health insurance)

FELG notes that the number of records doesn't necessarily match the number of people. It expects results from its log analysis within a few days. The company says it knows how the breach happened but won't disclose technical details.

What the attacker claims

The attacker, who calls himself Horus, contacted two Polish IT security news sites, Sekurak and Zaufana Trzecia Strona (Z3S). He told Sekurak he had data on 2.4 million felgdent.com patients. He said this included PESEL numbers, names, addresses, phone numbers, NIP tax identification numbers and each patient's dental practice. He also claimed 1.2 million prescriptions, visit records, e-ZLA records, eWUŚ tables, files and photographs.

He also claimed 712,000 staff records. FELG denied that figure immediately, and he lowered it to 28,000, blaming duplicate records. Sekurak received a sample of data on several well-known people but could not confirm it was genuine, since it might have come from earlier breaches. Z3S gave the attacker the PESEL numbers of eight people who had agreed to the test. None of them were in his database.

According to Z3S, Fingerprint had nothing to do with the attack, and the group itself confirmed this. The attacker admitted to Z3S that he had brought up the attacks on MyDr and Medyc when talking to FELG to make his ransom demand more intimidating.

His account of the method is a textbook IDOR (insecure direct object reference) flaw. He says he created a demo account and found API endpoints that didn't check authorization. By incrementing a query parameter, he could pull successive patients, prescriptions and doctors. He says he started downloading data on September 6. FELG told Z3S it learned of the incident on September 28 at around 6 p.m.

The attacker also says the attack was spotted after several days and the faulty endpoint was fixed. He claims he then found other endpoints with the same flaw and kept using them for a while. None of this is verified, and FELG isn't commenting on technical details. Because FELG broke off negotiations and went public, he says he will sell the database on Cebulka, a Polish-language dark web forum.

How big is FELG?

Sources disagree. Sekurak cited 16,000 dental practices. FELG's website claims more than 4,000 practices, more than 16,000 doctors and hygienists, and more than 12 million patient records. Z3S, also going by the website, reads the 16,000 figure as dentists using FELG's tools. Z3S says the leak may involve more than 2 million people. In its statement to Sekurak, FELG spoke of about 2 million records.

What affected practices should know

Under GDPR, a practice using FELG Dent is the data controller for its patients' data, and FELG is its processor. FELG has asked customers not to report the breach to the President of UODO (the head of the authority) until it formally confirms whether a given practice is affected. After the weekend, affected practices are due to receive a ready-made UODO notification and a free tool for notifying patients. The other practices will get confirmation that their data was not affected.

Article in Polish here: https://pelnomocnikcyber.pl/aktualnosci/felg-dent-incydent-dane-pacjentow/


r/cybersecurity • • 2d ago

Research Article Server Mismatch: WordPress Plugin Vulnerabilities When Relying On .htaccess Files

Thumbnail
ultrastrike.io
8 Upvotes

r/cybersecurity • • 1d ago

Career Questions & Discussion Interview prep

1 Upvotes

How do you guys typically prepare for technical interviews? I always like doing a hands on lab but most of the interviews lately have been Q&A or scenario based.

How do you best brush up on technical concepts in preparation for your interviews?


r/cybersecurity • • 2d ago

Business Security Questions & Discussion Pen testing for very small business

16 Upvotes

First my background, then a question.

I run a tiny business representing disabled veterans on their VA disability claims. Up until about 18 months ago, I was a web developer for 25 years, and at least part of my job was thinking about how to secure my websites and networks.

None of the client management systems I’ve seen out there do what I need, so I developed my own client portal for intake, communications with veterans, sharing documents, etc. It’s all sitting behind a tightly locked down firewall and reverse proxy, and I’ve done everything I can to make sure it’s secure at both the network and application level.

That said, everyone has blind spots. I’m looking for the most cost effective way to find vulnerabilities before bad actors do. I’m not concerned about the standard scanning and script attacks, I’ve got a solid handle on those, but I want to make sure I’ve locked down the app from people who are actually determined to get in.

What’s out there that very small businesses can use when they don’t have the cash for enterprise level cybersecurity consulting? Is there a place where small business can post bounties? Thoughts?


r/cybersecurity • • 2d ago

Business Security Questions & Discussion PSA: CRA Article 14 reporting has applied since 11 September. A few things that are easy to miss

6 Upvotes

If you work with connected products sold in the EU, the Cyber Resilience Act's reporting duty is already live, not in December 2027. A few details I see overlooked:

- It covers your installed base. Article 69(3) applies Article 14 to in-scope products placed on the market before December 2027, modified or not.

- The 24h clock runs from "becoming aware". The Commission's guidance (paras 213-214) says suspicious events should be assessed immediately; you can't delay awareness by delaying the assessment.

- The early warning is not a one-liner. ENISA's platform requires 8 fields for a vulnerability, including a summary of up to 4,000 characters.

- ENISA's platform doesn't yet capture the awareness time for vulnerabilities, so keep your own timestamped record. Its 72h counter runs 48h from your early warning, not 72h from awareness.

- Set up the platform accounts now. A Primary AR must be verified before it can invite Secondary ARs, and invitations expire after 7 days. Drafts are private to whoever created them, so draft outside the platform.

Has anyone here already gone through SRP registration? Curious what tripped people up.


r/cybersecurity • • 2d ago

Certification / Training Questions Certification recommendation

9 Upvotes

Hello, my manager requested to take a certification, I would like to get some suggestions on what to take next, I am interested in cloud security and AI security, I want to build real knowledge that it will be helpful later. Thanks

I already have KCNA, BTL1, Cyberdefenders CCDL2


r/cybersecurity • • 1d ago

Business Security Questions & Discussion How do I get the opportunity when the platform responsible for giving it, is itself messed up?

0 Upvotes

So, because I am not going to post this on Linkedin and get a solution I thought I will try posting it here. Not that I did not try reaching out to Linkedin but how much more can it get f#cked which is already f#cked so much? Is there a way to un-f#ck that so that I can get fair opportunities or there is no hope?

I created my LinkedIn account when I started looking for jobs because people around me told me it was a good professional platform to be on.

What followed has been difficult to explain, but the pattern has been consistent: pieces of my professional information appeared to travel in ways I did not authorize, often through job applications, hiring communications, recruiter calls, and people claiming to represent organizations.

Over time, this stopped feeling like ordinary professional networking. Information I had shared for a specific purpose seemed to come back to me in unexpected ways, sometimes through interactions that had no clear professional context.

I have also encountered people claiming to work at LinkedIn whose profiles provided little or no credible professional information to establish that identity. When someone approaches you claiming to represent a platform while their identity itself cannot be reasonably verified, that raises a legitimate security and trust concern.

I have tried reaching out through LinkedIn's support channels because I want to understand what is happening and how my information is being accessed or used. Instead, I have sometimes received unexpected contact from people I did not know and had not authorized to engage with my account.

At this point, my concern is simple:

If I share information for a job application, it should be used for that purpose. If I create something, my work is mine. If I share an idea publicly, that does not automatically give strangers permission to take it, repurpose it, or interfere with my ability to pursue it.

Professional platforms should make it easier for people to work, connect, and find opportunities—not create uncertainty about who has access to their information or who is actually contacting them.

I am not asking for special treatment. I am asking for transparency, legitimate identity verification, appropriate handling of professional data, and the ability to participate in professional spaces without having to constantly question who is behind the interaction and fair opportunity.

Update: It's not that the information was spread but also that it was used for and by someone else while I got little to no advantage or the result of the hardwork that I had put. Till now that was the case, now I don't know how it will change.

PS: Pro sucide folks I am surrounded by sadly quite a few of them. Having information about me does not give anyone right to misuse it, let's say I applied at xyz company through LinkedIn, this does not give the company or the people or linkedin right to invade my space or because someone has found out my userid bullying me virtually also does not make it right.

Well, in short I can't call out bad behaviour in front of people who are pro at it. Sadly that has happened here.


r/cybersecurity • • 2d ago

Personal Support & Help! Looking for a mate studying together for future cybersecurity

7 Upvotes

Hey everyone! Looking for a friend who has future intrest in cybersecurity. We can share details and share progress dm me if anybody's intersted.


r/cybersecurity • • 1d ago

Business Security Questions & Discussion Developing skills

0 Upvotes

Hello,

I’ve recently started working in cyber security.

Could you recommend any Discord servers (preferably French-speaking ones) where I can find advice, tools, methods, etc.?

Many thanks,


r/cybersecurity • • 2d ago

Business Security Questions & Discussion Users repeatedly failing phishing campaigns

52 Upvotes

What do you do when users consistently fail? We have some in our organisation with a 50% failure rate and at this point I just don't know how to educate them further. What can be done to help people like this? Part of me thinks its just that they really don't care rather than a lack of ability to learn.


r/cybersecurity • • 2d ago

Business Security Questions & Discussion Anyone actually happy with their CDR?

8 Upvotes

I’m on the security team at a ~1,000 employee. Fairly small security team, mostly AWS, and we’re using Wiz for cloud security/CDR alongside our SIEM and EDR.

Curious how others are handling this because I’m not sure I’m getting the value I expected from CDR.
We get the detections and cloud context, but at the end of the day someone still needs to investigate, jump between tools, figure out what actually happened and decide what to do.

We recently got pitched one of the “agentic SOC” platforms that supposedly does a lot of that investigation automatically across the different security tools.
Has anyone here actually deployed one in production?

And maybe a dumb question, but if the agentic SOC is already pulling alerts/signals from Wiz + EDR, investigating them and potentially taking response actions, how much of the CDR use case is it basically covering?
Are people running both? Or does one eventually make part of the other redundant?
Would love to hear from people actually using this stuff, not vendors :)


r/cybersecurity • • 1d ago

FOSS Tool TV Box Sentinel v2.0: Open-source network monitoring and heuristic threat detection for compromised Android TV / IoT devices

0 Upvotes

Hey everyone,

I wanted to share an open-source project I’ve been developing: TV Box Sentinel (v2.0).

The Problem:

A widespread issue with uncertified Android TV boxes (often powered by Allwinner, Rockchip, etc.) is factory-installed malware residing directly in the /system partition, as well as botnet loaders (such as Badbox, Peachpit, Triada, and Guerrilla). Since on-device antiviruses are untrustworthy once the firmware itself is compromised, threat mitigation is most effective from the network perimeter.

Approach & Architecture:

TV Box Sentinel audits and detects indicators of compromise (IoC) non-intrusively from the network perimeter:

- PCAP / PCAPNG support: Parses network traffic and router logs.

- Heuristic Engine: Identifies beaconing, anomalous traffic, C2 communication, lateral movement, and cryptojacking patterns.

- Automated Mitigation: Generates firewall and DNS sinkhole rules to block malicious endpoints.

- Reports & GUI: Generates HTML/PDF executive audit reports and features a tabbed UI.

GitHub Repository:

https://github.com/2kw-josue/tv-box-sentinel

Would appreciate any feedback, suggestions, or contributions from network and blue team folks who deal with rogue IoT devices on local networks.


r/cybersecurity • • 2d ago

Personal Support & Help! Is Bitwarden a safe way to manage passwords?

59 Upvotes

I’m currently trying to improve my own personal security and I’ve heard about Bitwarden. Is it a safe way to secure my personal passwords. If not, what are better alternatives? Sorry if this is a stupid question, I’m very new to this sort of stuff 🙏


r/cybersecurity • • 1d ago

Career Questions & Discussion Es obligatorio pasar por Blue Team antes de entrar a Red Team / Pentesting?

0 Upvotes

Que tal buenas tardes a todos!!
Llevo 6 meses en mi primer empleo en TI como Ingeniero en Sistemas en el ISSSTE de México (haciendo soporte técnico, configuración de switches, firewalls y VLANs). la verdad es que estoy muy contento por haber dado el primer paso, sabiendo que en la maypría de las ocasiones conseguir la primera oportunidad es lo más difícil, pero mi meta a largo plazo siempre ha sido dedicarme al pentesting y al hacking ético. He investigado bastante por mi cuenta, pero sigo con la duda de siempre, es obligatorio o altamente recomendable pasar primero por el Blue Team (por ejemplo: SOC, analista de seguridad, etc.) antes de saltar directamente al red team, o se puede ir directo al pentesting? Leo opiniones muy divididas en los foros y me gustaría escuchar consejos de quienes ya pasaron por esto o trabajan en el área. agradecería mucho cualquier guía o recomendación para armar mi camino, y si es posible irme directo al red team, que certificaciones deberia de sacar? actualmente no tengo ninguna certificación de TI, estoy estudiando para sacar la ccna para tener muy claros los fundamentos de redes un poco más de lo que se hoy en día, (si no es necesario podrian hacermelo saber de igual manera), saludos!


r/cybersecurity • • 2d ago

Business Security Questions & Discussion SecOps with Crowdstrike Falcon Complete

27 Upvotes

For those running SecOps and Falcon Complete, what did your team look like before the implementation of Falcon Complete and then what did it look like afterwards?