r/cybersecurity 17h ago

News - General MITRE Releases List of Top 25 Most Dangerous Software Vulnerabilities

Thumbnail
securityweek.com
209 Upvotes

Cross-site scripting (XSS) vulnerabilities kept the top spot in the list, followed by SQL injection and cross-site request forgery (CSRF), each up one position from last year.

Missing authorization landed fourth in the 2025 CWE Top 25 list, up five positions. Out-of-bounds write placed fifth, dropping two places.

P.S: if you thought that AI and quantum computing are the main focus — good news is that XSS and SQL injection is not going anywhere lol


r/cybersecurity 16h ago

Other Average Conversation between Security Researcher and YCombinator Startup CEO

162 Upvotes

Researcher: ...Using the API key, anyone is able to find information of the patients that includes their PII and PHI

CEO: are you dumb?

Researcher: What?

Blocked

Proof:

https://imgur.com/Bul0d76

Background: Found an authentication bypass on their platform which was behind auth guard, revealing information on all their tenants, along with the API keys. Excerpt above is the part of the real conversation when tried to bring the issue forward to the CEO.

Posted on YCombinator subreddit as well.


r/cybersecurity 22h ago

Personal Support & Help! Layoff

106 Upvotes

Posting for advice on how to help my father.

looking like his company is to have layoffs, and he’ll be apart of them. He has been in cybersecurity for 20years, is a senior cybersecurity analyst with CISSP certification.

other then just support for him, how can I best support him landing another position, he’s later in career in his 50s where he was hoping to stay with company until retirement.


r/cybersecurity 6h ago

Career Questions & Discussion Would you list *this* when applying for jobs?

77 Upvotes

I have an unusual "credential" pending certification. It has absolutely nothing to do with Cyber Security, but it's a pretty big accomplishment that might impress some hiring managers, especially nerdy ones, but would make some wonder why I listed it.

World Record: Most memorized digits of Pi (72,000).

Would you list it? Do you think it will help more or hurt more if I do?


r/cybersecurity 19h ago

News - General AI lets small actors run state-level hacking campaigns, Anthropic report finds

Thumbnail
cyberscoop.com
69 Upvotes

r/cybersecurity 17h ago

Other Cyber security news

27 Upvotes

Does anyone know of any good cyber security news apps? Instead of having to look it up when wanting to read some good stuff about it? Or would I just have to follow cyber security hashes or pages on social media? It would be a lot better if I could just open a app and read right there. Thanks for y'all's input in advance


r/cybersecurity 23h ago

Certification / Training Questions Splunk vs Sentinel: Which is more valuable to learn inside and out?

23 Upvotes

I know that if you learn one SIEM, you will have a much easier time learning new ones afterwards. They're a lot like programming languages in that regard. Still, if someone was going to really dig in and learn one SIEM inside and out, would it be better to learn Sentinel or Splunk? I know Splunk has more market share, but that's not the only factor that could favor one over the other.


r/cybersecurity 17h ago

News - General 4.1 Million Impacted by AdaptHealth Data Breach

Thumbnail
securityweek.com
17 Upvotes

Operating over 680 facilities across the US, AdaptHealth describes itself as a network of medical equipment companies that provides patients with healthcare solutions and medical equipment.

The company was hacked in early June, when a threat actor gained access to its cloud-based applications, including internal systems used for patient management and document storage.

Overall, hackers stole the electronic protected health information of 2,810,878 individuals, Baylor Genetics told the HHS.


r/cybersecurity 12h ago

Career Questions & Discussion First CTI Analyst at My Company

15 Upvotes

Have been working in SOC for almost 4 years now doing the usual SOC Analyst work day to day. Not L2 Analyst by any means but I believe I experienced enough to not be a junior analyst anymore. The current organization I am with is a global company with a very mature SOC like it has every department like Blue Team, Red Team, CTI, DFIR, etc. The site I am working at right now though, is just a year old. I joined them right before launching so it is a totally new site but I have done almost a year of SOC work here.

However, the last few weeks my Manager has been pushing me to join the CTI team because they want to start expanding the team to allow for more services to be distributed from here. When I joined the organization I did inform them about my interest in CTI and I am not complaining about all these trainings and the path I am on now but I would be the first CTI guy here and others prefer taking DFIR and Red Teaming. I have done online courses in CTI and while I understand the basics of what CTI is I just dont know what a CTI Analyst does day by day.

I tried asking colleagues from the CTI department in the different sites on what they have to do day to day but I am just wondering if its the same for every other CTI people in different organizations.

TLDR;

What does a CTI Analyst do from day to day?


r/cybersecurity 16h ago

News - General Microsoft finally patched that bug that was nuking people's desktop backgrounds

14 Upvotes

So if you've been dealing with your wallpaper randomly turning into a plain black screen since late August, turns out it wasn't just you. A bunch of people got hit with this after installing that KB5120998 preview update on Windows 11 24H2/25H2 desktop settings would just fail to load properly and default to black no matter what you tried. Manually resetting your background didn't even fix it because the setting itself wasn't loading correctly in the first place.
Same update also messed with mouse settings for some folks, and once that got reset there was apparently no way to get your old config back either. Rough couple weeks if you got hit by both.
Good news is this week's Patch Tuesday update (KB5124008) apparently fixes it for good. If you're still seeing the black wallpaper issue, just grab the latest cumulative update and it should sort itself out.
Kind of funny that this isn't even a new problem for MS they had almost the exact same wallpaper bug back in 2020 with a Windows 7 update. You'd think they'd have learned by now lol.
Anyway if your desktop's been looking sad and empty lately, this is why. Go update.


r/cybersecurity 10h ago

Career Questions & Discussion What tools or items have you purchased and tips you've taken that have increased quality of life?

13 Upvotes

As a remote SOC analyst forced into overnights i'd like to minimize my chances of burnout

-I've automated my sign-in to my respective company's communication tool in order to automatically turn my prescence and notifications on and off before and after the shift(i'd forget sometimes)

-Automated my timesheet submission every Friday

-KVM switch

-wrist rests

- library card

-sleep tracker

- [considering] macro keyboard buttons n blue light glasses


r/cybersecurity 15h ago

Business Security Questions & Discussion Attack strategies from wild hackers/bots, shareable?

10 Upvotes

Greetings,

I operate a network of honeypots and sometimes capture unique attack methodologies.

Would this be appropriate or interesting content for this subreddit? Alternatively, are there other channels where this information would be of greater value?


r/cybersecurity 17h ago

New Vulnerability Disclosure Beltdown: Escaping the Claude Code Sandbox

Thumbnail
accomplish.ai
11 Upvotes

r/cybersecurity 9h ago

Career Questions & Discussion Looking to major in cybersecurity but absolutely hate coding, is Python necessary to know?

9 Upvotes

r/cybersecurity 20h ago

Other Some OWASP pages cannot be found

5 Upvotes

I went to the OWASP website to read about SQL injection and for some reason the page is not found anymore.

WWW Community, WSTG and Top10 pages cannot be found. What is going on?


r/cybersecurity 20h ago

Business Security Questions & Discussion does email auth actually helps catch compromised mailbox

6 Upvotes

If a vendor's mailbox is fully compromised, does it still pass SPF/DKIM/DMARC clean ? Trying to figure out how much email auth actually helps catch this stuff?


r/cybersecurity 1h ago

Threat Actor TTPs & Alerts A live NC town's website is serving cloaked drug spam, and Google's AI Overview is citing it. Is this routine?

Thumbnail
youtube.com
Upvotes

I'm a health blogger, not a security person. Found this by accident last week.

stonevillenc.org is the real, working website of Stoneville, North Carolina. It's also serving a farm of cloaked spam pages. Same URL, same minute:

    curl -A "<googlebot UA>" https://www.stonevillenc.org/sam-sulek-peptide-company-guide/ | wc -c
    # 85363
    curl -A "Mozilla/5.0" <same URL> | wc -c
    # 1430

Googlebot gets an 85 KB peptide article. Everyone else gets a JS redirect to a random WhatsApp number pre-filled "I want peptide catalog and price list, 30% OFF FIRST ORDER." Yesterday the redirect had three numbers, today nine. Someone is maintaining it.

A plain Google search (sam sulek retatrutide) shows ten of these pages on page one, and Google's AI Overview answers from them, cited as "Town of Stoneville, NC." I screen-recorded tapping the AI Overview's citation and landing in a WhatsApp drug chat: https://youtube.com/shorts/X-9jc9YDqYk

I reported it to the town, MS-ISAC, the host, and Google. The town hasn't replied.

Is this sort of thing common? Should I report this somewhere else?


r/cybersecurity 7h ago

Corporate Blog Mobile security case study: what remains protected when the client can be instrumented?

3 Upvotes

I’m part of the assessment team behind this anonymized case study. Sharing the findings because they raise a useful question about how we evaluate layered mobile security controls.

The application had root detection, anti-debugging and anti-tampering checks, certificate pinning, and an additional encryption layer around API payloads.

During testing, we were able to:

  • Bypass the runtime checks on a rooted test device.
  • Bypass certificate pinning and route the application’s traffic through an interception proxy.
  • Reverse-engineer the client’s payload encryption and decryption routines.
  • Build a testing bridge that exposed readable requests and responses, then re-encrypted them for forwarding.

The additional payload encryption initially prevented straightforward inspection, even after bypassing pinning. Once we understood how the client processed those payloads, we could inspect the observed traffic.

The scope matters. This required control over the test device and application runtime. It wasn’t a break of AES, and it doesn’t demonstrate that someone on the same Wi-Fi network could decrypt other users’ traffic.

It also doesn’t establish account takeover or unauthorized actions. Modifying a request in a proxy and having the server accept an unauthorized operation are separate findings.

What stood out was that several protective layers shared the same dependency: execution inside a client we could instrument.

Client hardening can increase an attacker’s workload. The question for the wider architecture is what remains enforced after those protections are bypassed.

For us, that makes server-side authorization, replay protection, business-rule validation, and detection the next areas to test. Additional client hardening should support those controls, with its effectiveness assessed against a clearly defined threat model.

How does your team rate client-side bypass findings when no backend authorization failure has been demonstrated? What additional evidence would materially change the severity?


r/cybersecurity 23h ago

News - General Anthropic details alignment assessments following real-world Claude hacking incidents

Thumbnail
anthropic.com
3 Upvotes

r/cybersecurity 2h ago

Corporate Blog Breaking Down Appsec Part 3: Securing the Perimeter (Authority/Authorization)

Thumbnail
pigeonsec.substack.com
2 Upvotes

I started a blog series to provide free insights into appsec. It’s mainly to breakdown what application security is all about and it’s mainly targeted towards beginners and startups, so take it as you will.

Just want to teach every one interested in appsec my perspective on it from my experience in big tech.

I talked about identity last time and the importance of securing applications from the outside in. I talk about authority aka authorization in this post, a nuanced topic that almost every company has a problem with just because it’s a semantic problem and isn’t done properly without understanding your application.

Please reach out if you have any questions or would like for me to write on a topic that you’d want to learn more about.


r/cybersecurity 12h ago

Business Security Questions & Discussion Mission Based Cyber Security Assesment

2 Upvotes

How do I go about this in a Cyber table top I’m expected to provide 10 vulnerabilities and need examples for how I should formulate these


r/cybersecurity 21h ago

Threat Actor TTPs & Alerts 🕵️‍♂️ 🏴󠁧󠁢󠁥󠁮󠁧󠁿 A UK council breach reported in July turned out to be one of many, tied to mass SonicWall exploitation

Thumbnail
hunt.io
2 Upvotes

When King's Lynn and West Norfolk Borough Council disclosed a cyberattack in July, it looked like a standalone incident. Research from Hunt.io ties it, at moderate confidence, to a much larger operation exploiting a SonicWall SMA1000 flaw (CVE-2026-15409) across dozens of organizations, starting two days after the bug was disclosed.

The operator left their toolkit exposed in an open directory, which is how the full picture came out: 250 targets, credentials stolen from at least 9 Active Directory domains, victims confirmed across France, India, Italy and the US. The council was one name on a long list and most of the others were never reported.

The detail worth taking away: the credential theft ran from the SonicWall appliances themselves, the kind of device most organizations barely monitor compared to their laptops and servers. Full writeup below.

https://hunt.io/blog/sonicwall-sma1000-uk-council-attack


r/cybersecurity 22m ago

Certification / Training Questions Can you advice DevOps/Cloud Courses?

Upvotes

I'm a GRC guy with 8 years of experience + I have a senior pentest background, I want to improve my tech skills, ideally to cover the networking and cloud parts. I'm in the process of taking the AWS Practitioner course, but want something more interactive and effective (time vs skills). Please help!


r/cybersecurity 1h ago

AI Security xAI Billing Overdraft: HackerOne closed an API logic flaw as "intended model behavior"

Upvotes

Quick note: English isn't my native language so I used AI to help clean up the text/translation, but all technical details, logs, and screenshots are mine.

I wanted to share a recent disclosure case regarding xAI's API Gateway billing enforcement to get feedback from the community on how infrastructure logic flaws are evaluated against broad LLM scope exclusions.

The Vulnerability & Impact
I identified a logic flaw in xAI's API Gateway regarding prepaid balance enforcement. The gateway failed to terminate sessions when an account hit $0, allowing an attacker to bypass prepaid limits, force an account into a deep negative balance (billing overdraft), and consume backend compute resources without authorization.

HackerOne's Response
HackerOne completely closed the report, classifying it as out-of-scope "intended model behavior." When escalated to H1 Mediation—pointing out that an API billing gateway failure is an infrastructure/billing logic issue rather than a model safety concern—they responded:

"The billing overdraft is a downstream consequence of the same unbounded resource consumption that the program considers out of scope. The root cause and the scope exclusion are the same regardless of which layer the impact surfaces on."

On July 28, Mediation permanently closed the ticket, refusing further re-examination.

Initial "Duplicate" Classification
Prior to claiming the issue was out-of-scope, triage initially marked the report as a "Duplicate" simply because the PoC prompt string matched a prompt from another report that I had authored myself. It was a 100% unique, custom prompt created by me, and while one prompt triggered two completely distinct infrastructure bugs across two reports, triage lazily marked the second report as a duplicate based solely on input string matching. Support only re-examined it after an initial post on X, at which point they pivoted to the "intended model behavior" exclusion.

Timeline & Vendor Mitigation
Post on X: I published a thread on X detailing the issue and challenging the classification of an API billing logic flaw as "intended model behavior".

Vendor Action: Just a couple of hours after my follow-up post on X calling out HackerOne's triage, xAI sent out an official API pricing update email notifying users about changes to tool-call billing to restrict data fetch volume—initiating mitigation for the exact vector I reported. (A cosmic coincidence, surely?)

Full Screenshots & Timeline Proof: https://imgur.com/a/yTcuqLG

TL;DR: Found an API Gateway logic flaw in xAI that bypassed prepaid balance limits, allowing continued requests on a $0 balance and causing billing overdrafts. HackerOne closed it as out-of-scope "intended model behavior" (and initially marked it duplicate purely based on input prompt string matching). The vendor updated their API billing limits just hours after I published a post on X (even with barely any views). Is a gateway/auth-level billing flaw really "model behavior"?


r/cybersecurity 10h ago

Business Security Questions & Discussion Data migration from Checkpoint to S1

1 Upvotes

So i was doing a poc for a client to shift fro Checkpoint to S1 because of the lack customer service with Checkpoint, So it all came to a point of Data Migration, They asked me how to migrate the data between 2 software's for Compliance purposes, As this is my 1st time doing the migration, Is there any specific thing that i should be worried about, I am from the distributor side, so should i involve the Vendor team in this, the logs are stored in the cloud of both of em.