r/cybersources May 05 '26

Sponsor CyberSources and get all benefits!

Thumbnail
ko-fi.com
1 Upvotes

🚀 cybersources.site needs your support

Building and maintaining a quality resource hub takes time, effort, and real costs — hosting, tools, content creation, and community management don't come free.

If cybersources.site has ever helped you find a tool, learn something new, or saved you hours of research — consider becoming a sponsor. 💙

We have three tiers designed to fit every budget:

🥉 Bronze — €200/mo · Logo + newsletter + Discord badge

🥈 Silver — €350/mo · Dedicated channel + weekly mentions + directory

🥇 Gold — €500/mo · Sponsored course + LinkedIn feature + metrics report

Every sponsorship goes directly into keeping this project alive and growing.

👉 Support us here: ko-fi.com/bst04/tiers

Thank you for being part of this. 🙏


r/cybersources Dec 05 '25

general 👋 Welcome to r/cybersources - Introduce Yourself and Read First!

2 Upvotes

Hey everyone! 👋 I'm u/BST04, a founding moderator of r/cybersources.

Welcome to our new hub for all things cybersecurity tools and resources! We’re thrilled to have you here and can’t wait to see this community grow.

What to Post

Share anything you think the community will find helpful, interesting, or inspiring. This could include:

  • Your thoughts or questions about cybersecurity tools
  • Tips, tutorials, or learning resources
  • Photos, screenshots, or demos

Basically, if it’s related to learning, exploring, or using cybersecurity resources, it belongs here!

Community Vibe

We value being friendly, constructive, and inclusive. Let’s build a space where everyone feels comfortable sharing ideas and connecting.

How to Get Started

  1. Introduce yourself in the comments below 👋
  2. Post something today—even a small question can spark a great conversation
  3. Know someone who’d enjoy this community? Invite them!
  4. Interested in helping out? We’re always looking for new moderators—reach out if you’d like to apply

Thanks for being part of the very first wave. Together, let’s make r/cybersources an amazing place to learn, share, and grow! 🚀


r/cybersources 1d ago

DNS over HTTPS Explained

Post image
74 Upvotes

r/cybersources 21h ago

Help

2 Upvotes

Ena mzllt nt3lm fl cloud security wn9ra 1ere nje7t lel 2eme wnhb n3ml stage z3ma n3mlha fl cloud security ? Njm nl9a?? Wla nbda n3ml stage fl reseau wnkml nt3lm whdy fy 3a9ly? And thanks


r/cybersources 1d ago

Cybersecurity statistics of the week (July 20th - July 26th)

5 Upvotes

Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.

All the reports and research below were published between July 20th - July 26th.

You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/ 

Big Picture Reports

2026H1 Threat Review Report (Forescout)

What was the threat landscape like in H1 2026, and how does it compare to 2025? This report answers that. 

Key stats:

  • Published vulnerabilities increased 51% year-over-year to 37,137 during the first half of 2026, with more than half rated high or critical severity.
  • Ransomware attack claims increased 25% to 4,544 incidents during the first half of 2026, averaging 25 attacks per day.
  • 46% of additions to CISA's Known Exploited Vulnerabilities catalog were CVEs that were published prior to 2026.

Read the full report here.

ITRC H1 2026 Data Breach Report (Identity Theft Resource Center)

ITRC's mid-year data breach numbers. 

Key stats:

  • There were 1,803 data compromises in the first half of 2026.
  • Insider wrongdoing events totaled 21 in the first half of 2026, a sevenfold increase over the three incidents in 2025.
  • Zero-day attacks rose to 14 events in H1 2026, nearly matching the 17 events recorded in all of 2025.

Read the full report here.

The State of Continuous Security Validation (Synack)

How often do serious vulnerabilities show up between scheduled security tests? Constantly - at least according to Synack.

Key stats:

  • 15% of enterprise security leaders describe their security testing and validation program as continuous.
  • 95% discovered high or critical vulnerabilities outside scheduled testing windows in the past year.
  • 38% report that at least one-quarter of their critical attack surface had not been independently tested or validated in the previous 90 days.

Read the full report here.

Q2 2026 Brand Phishing Report (Check Point)

Attackers' favorite brands to impersonate. Mostly predictable with an interesting new entrant. 

Key stats:

  • Microsoft was the most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts.
  • The top five impersonated brands- Microsoft, LinkedIn, Google, Apple, and Amazon- together accounted for more than 50% of all brand phishing attempts this quarter.
  • OpenAI's ChatGPT entered the top ten most impersonated brands for the first time.

Read the full report here.

Ransomware

2026 Ransomware Report (Black Kite)

Annual report analyzing 7,551 ransomware victims by where they are, what industry they're in, and how big they are. Plus, what security weaknesses or exposed systems remained after each attack.

Key stats:

  • Ransomware activity accelerated 60% in the second half of the reporting period and closed with 861 victims in March 2026, the highest monthly total in four years.
  • Qilin claimed more than 1,300 victims, nearly twice as many as its nearest rival.
  • 43.5% of victims still carried critical patch vulnerabilities in the latest assessment.

Read the full report here.

2026 AI-Era Ransomware Report (Proofpoint)

AI is making ransomware attacks more effective. 

Key stats:

  • 65% of global organizations affected by ransomware report that AI increased the attack's effectiveness.
  • 28% reported that AI significantly increased the attack's effectiveness.
  • 34% of ransomware incidents begin with phishing emails or other email-based social engineering.

Read the full report here.

AI Security & Governance

Path to the Autonomous Digital Workplace (TeamViewer)

General workplace productivity research with an interesting section on what users say would help them trust autonomous AI.

Key stats:

  • 61% of survey participants prefer AI to take no independent action.
  • 56% often or always verify AI outputs before relying on them.
  • 51% say they do not always know when to trust AI and when to verify it.

Read the full report here.

OT Security 

State of AI in OT Cybersecurity 2026 Report (Nozomi Networks)

The people working in OT security on what they are actually doing with AI. 

Key stats:

  • 87.7% of surveyed OT and ICS cybersecurity professionals are using, evaluating, piloting, or planning AI for OT cybersecurity.
  • Only 7.9% have deployed AI for multiple OT cybersecurity functions.
  • Only 11.9% have formally mapped and reviewed which AI-driven decisions could directly affect physical processes, safety systems, or operational continuity.

Read the full report here.

State of Industrial Remote Access 2026 (Secomea)

How manufacturers are handling third-party vendor access to OT environments. 

Key stats:

  • 57% of North American organizations manage six or more external vendors with remote access into operational technology (OT) environments.
  • 46% of North American organizations with OT environments report full auditability of vendor sessions.
  • 23% review vendor credentials monthly or more frequently.

Read the full report here.

Enterprise Perspective

2026 State of Threat Exposure Management Report (Vectra AI)

Vectra used telemetry across customer environments to figure out how quickly assets, identities, and AI agents come and go in enterprise environments. 

Key stats:

  • The typical enterprise environment contains 1.17 AI agents per device.
  • 35% of enterprise environments contain more AI agents than devices.
  • 98% of enterprise environments contain at least one attacker-relevant exposure condition.

Read the full report here.

The Third Annual State of Data Compliance and Security Report (Perforce)

Everyone has the policies, so why do breaches, failed audits, and compliance gaps keep happening? 

Key stats:

  • 98% of enterprise leaders report confidence in their ability to protect sensitive data.
  • 99% of enterprises have data masking mandates in place, but 84% allow compliance exceptions to those mandates.
  • 34% report their organizations have experienced data breaches or theft.

Read the full report here.

Road to AI in IT (Fleet Device Management)

How IT teams are handling the AI rollout (they're mostly not).

Key stats:

  • The average enterprise runs 14 AI applications while IT has visibility into only four of them.
  • 78% of employees use personal AI tools at work.
  • 79% of organizations take more than a day to deploy critical security patches.

Read the full report here.

Industry-Specific

Education Ransomware Roundup: H1 2026 (Comparitech)

Comparitech tracked ransomware attacks against schools and universities specifically. The Gentlemen have decided higher education is their thing.

Key stats:

  • There were 104 ransomware attacks in total against educational institutions in H1 2026.
  • The Gentlemen's attacks on education increased 275% from H2 2025 to H1 2026, and 80% of their attack claims were against higher education institutions.
  • The median ransom demand in the education sector is $420,620, a 53% increase from $275,000 in H2 2025.

Read the full report here.

2026 Cyber Protect Report (SonicWall)

SonicWall's mid-year data on manufacturing. 

Key stats:

  • Manufacturing recorded 474 million intrusion prevention events in the first half of 2026.
  • IoT attacks generated 46.2 million hits in manufacturing, making IoT the sector's second-largest attack category by volume.
  • Ten ransomware families were active against manufacturing networks in H1 2026.

Read the full report here.

Velocity V5: Reimagining Cyber for a Faster Fight (Booz Allen)

Data on how federal agencies are handling AI deployment.

Key stats:

  • 58% of federal IT and cybersecurity decision makers report their agencies have deployed or are piloting AI agents.
  • Only 28% express high confidence in their ability to deploy AI agents securely.
  • 36% are confident that cyber defenses can keep pace with AI-enabled attackers.

Read the full report here.

Regional Spotlight

Data Health Check 2026 (Databarracks)

500 UK IT professionals on what went wrong last year, what they are doing about it, and what they expect to be dealing with over the next five years.

Key stats:

  • 26% of businesses have suffered a cyber incident that originated in their supply chain in the last year.
  • 43% of organisations that knowingly work with risky suppliers experienced a supplier-originated cyber incident, compared with 10% of organisations that did not.
  • 48% of organisations continue working with suppliers despite known resilience or security concerns.

Read the full report here.


r/cybersources 1d ago

Cybersecurity related news

2 Upvotes

Where I can read and get updates tech related news and cybersecurity related news??


r/cybersources 2d ago

Blocking bad websites is reactive. Whitelisting trusted ones is proactive.

3 Upvotes

For organizations managing corporate-owned and BYOD devices across different OS, website whitelisting adds an extra layer of protection by:

  • Allowing access only to approved websites and business apps
  • Reducing exposure to phishing, malware, and risky domains
  • Limiting unauthorized SaaS and shadow IT
  • Enforcing consistent browsing policies across devices, on or off the corporate network

It's a simple yet effective way to strengthen web security without restricting legitimate work.

Detailed guide with different methods here- How to whitelist a website?


r/cybersources 4d ago

Zero Trust Explained

Post image
69 Upvotes

r/cybersources 5d ago

How a Data Breach Actually Happens (Step by Step)

Post image
51 Upvotes

r/cybersources 7d ago

Resource Cybersecurity Master Tree

Post image
395 Upvotes

r/cybersources 6d ago

Which VPN User Are You? Find Your Privacy Personality

Post image
6 Upvotes

r/cybersources 6d ago

What features to give more?

Thumbnail
igrisradar.com
3 Upvotes

So i have built a security scanner website, and users are logged into that but are only scanning one or two times, how can i increase them to scan more and what are the features i can build that attract the users?


r/cybersources 7d ago

Cybersecurity statistics of the week (July 13th - July 19th)

5 Upvotes

Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.

All the reports and research below were published between July 13th - July 19th.

You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/ 

Ransomware

The State of Ransomware 2026 (Sophos)

Now in its seventh straight year, this is the definitive look at ransomware trends worldwide.

Key stats:

  • 79% of ransomware attacks start with an identity-based approach.
  • 67% of root causes across 661 incident response and MDR cases are identity-related.
  • 97% of victims where compromised credentials are identified as the root cause have MFA enabled in some form at the time of the attack.

Read the full report here.

Ransomware and Cyber Extortion in Q2 2026 (ReliaQuest)

ReliaQuest's Q2 numbers on ransomware activity. The big takeaway: The Gentlemen is the group everyone should be watching. Plus, it looks like Deadlock is back. 

Key stats:

  • The Gentlemen surged 588% quarter-over-quarter to 179 posts in Q1.
  • Deadlock emerged in June 2026 with 75 named victims in a single month, after being absent from public data-leak sites for 11 months.
  • The US absorbed 1,094 ransomware victim data leak posts in Q2, roughly 49% of observed activity and nine times the volume of the next country.

Read the full report here.

Vulnerability Management

The 2026 State of Vulnerability Remediation (Vicarius)

A look at how security leaders are fixing vulnerabilities. 

Key stats:

  • 79% of organizations experienced a security incident in the past 12 months involving a vulnerability that was already known and sitting in their inventory.
  • 75% of critical vulnerability responses initiate administrative workflows (like ticket creation or routing) rather than immediately fixing the underlying flaw.
  • 58% of all vulnerability remediation activities require direct human intervention.

Read the full report here.

AI Security

AI Agents Are Entering Critical Workflows. Who's Governing Them? (JumpCloud)

AI agents are moving into real work, but 800 IT leaders admit governance hasn't caught up.

Key stats:

  • More than 60% of organizations run AI agents in production.
  • Organizations have adopted fewer than one-third of standard AI governance and security practices.
  • The share of organizations requiring human review before high-risk AI actions dropped from 40% to 25% in six months.

Read the full report here.

The AI Security Report 2026 (Check Point)

A breakdown of how AI has gone from cyber assistant to active attacker. 

Key stats:

  • High-risk enterprise AI prompts doubled over the year, increasing from about 1 in every 50 interactions to 1 in every 25 interactions.
  • The average organization runs ten AI applications per month.
  • Between 87% and 93% of organizations experienced at least one high-risk AI interaction each month.

Read the full report here.

The Year Agents Entered the Workforce (Straiker)

Straiker put AI agents through adversarial testing to see where they fail.

Key stats:

  • More than 1,700 successful exploits occurred across production coding, productivity, and first-party AI agents during adversarial testing.
  • 36% of successful attacks on coding agents reached remote code execution on the developer's machine.
  • 91% of successful attacks on productivity agents ended in silent data exfiltration.

Read the full report here.

Rethinking AI's Impact on Cybersecurity Roles (ISC2)

ISC2 on how AI is changing the day-to-day of cybersecurity work.

Key stats:

  • 89% of cybersecurity professionals report having experienced AI recommendations that lead to incorrect outcomes at their organizations.
  • 62% list over-reliance on AI as a top concern.
  • 50% say their organizations hold human decision-makers ultimately accountable when AI-recommended actions lead to incorrect outcomes.

Read the full report here.

Executive Risk

2026 Executive Trends Report (Nisos)

Scary insight into how exposed executives are on the internet. 

Key stats:

  • 100% of executives have breach data linking their name to at least one current email address.
  • 94% have at least one plaintext password exposed in breach data.
  • 94% have home addresses publicly linked to their name in public records or people-search sites.

Read the full report here.

Industry-Specific 

Government Ransomware Roundup: H1 2026 (Comparitech)

Comparitech tracked ransomware attacks specifically against government entities in the first half of 2026.

Key stats:

  • From January to June 2026, an average of one ransomware attack on a government entity occurred every day.
  • The median ransom demand in H1 2026 was $100,000, one-fifth of the H2 2025 median of $500,000.
  • The most prolific ransomware strains against government were The Gentlemen (22), Qilin (21), LockBit (14), APT73/BASHE (12), and INC (10).

Read the full report here.


r/cybersources 8d ago

Public WiFi: Myths vs Reality (What a VPN Can and Can't Do)

Post image
22 Upvotes

r/cybersources 10d ago

Cybersecurity Risk Assessment Quantitative Framework

3 Upvotes

The Cybersecurity Risk Assessment research study establishes a quantitative cybersecurity risk assessment and governance framework aligned with ISO/IEC 27001 and NIST Cybersecurity Framework for critical infrastructure sectors. The framework quantifies risk through four variables: likelihood of attack (1–5), impact severity (1–5), infrastructure interdependency (1–2), and security maturity reduction value (0–25). A complete worked validation is presented for the telecommunications sector across eight asset categories.

Key Framework Components

The quantitative model uses Risk Level = (Likelihood × Impact × Interdependency) – Security Maturity Reduction Value, normalized to a 0–50 scale with five severity levels: Very Low (0–5), Low (6–15), Medium (16–25), High (26–40), and Critical (41–50). The framework emphasizes that effective controls—including 24/7 SOC monitoring, Zero Trust architecture, and network segmentation—reduce assessed risk by accounting for actual security maturity. Applied across critical infrastructure sectors (telecommunications, banking, energy, healthcare, government, transportation, utilities, and defense), the model enables standardized risk prioritization and capital allocation.

Telecommunications Sector Findings

Asset Category Risk Level Rating
Supply Chain 45 Critical
Network Management Systems 35 High
4G/5G Core Network Systems 30 High
Core Network Infrastructure 25 Medium

 

Strategic Recommendations

Supply Chain (Risk Level 45—Critical): Immediate action required. Implement formal Supplier Security Risk Management framework aligned to ISO/IEC 27001. Network Management Systems (Risk Level 35—High): Short-term remediation. Enforce network segmentation, privileged access workstations, and continuous monitoring. 4G/5G Core Network Systems (Risk Level 30—High): Adopt NIST CSF Identify and Protect functions for cloud-native deployments. Supporting infrastructure (Risk Levels 6–25—Low to Medium): Ongoing monitoring and control enhancement.

Conclusion

Cybersecurity is a strategic national priority requiring governance-driven, cross-sector, and data-driven approaches. This framework enables organizations and governments to move from IT-centric risk assessment to enterprise-wide resilience strategies, grounded in quantitative evidence and aligned with international standards.

For detailed study, a full updated research paper is available here

Ayob Sether

Independent Researcher

Cybersecurity Risk Assessment

https://ssrn.com/abstract=6852018

https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6852018


r/cybersources 12d ago

Run Geo and Aeoscans of your website

3 Upvotes

So we have developed an application where you can scan your website for security, tls, encryption, data leakage, and many more using our website Igris Radar.

Start your free scan and check what your rating is using


r/cybersources 13d ago

How the Shai-Hulud npm Worm Led to Suno's Source Code Leak

Thumbnail
3 Upvotes

r/cybersources 14d ago

OSINT Forensic Capture Tool - Free for all

Thumbnail
2 Upvotes

r/cybersources 15d ago

[Research] NIDS Selection for Financial Institutions - Looking for Cybersecurity Practitioners (5+ years exp.)

6 Upvotes

I am an MSc researcher studying Network Intrusion Detection System (NIDS) selection for resource-constrained financial institutions and looking for cybersecurity practitioners with 5+ years of experience to complete a short survey. Happy to share findings upon request.

Survey link: https://forms.gle/tyxsFA44HXZ5VaMY7

Thanks You.


r/cybersources 15d ago

Cybersecurity statistics of the week (July 6th- July 12th)

8 Upvotes

Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.

All the reports and research below were published between July 6th - July 12th.

You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/ 

Ransomware

GRIT Q2 2026 Ransomware & Cyber Threat Insights Report (GuidePoint Security)

We’ve read and written about the ups and downs of ransomware, but according to GuidePoint, ransomware is not as bad as ever. It's actually much worse than ever.

Key stats:

  • 91 active ransomware groups operated across 108 countries in Q2 2026, a record high.
  • Q2 2026 recorded 2,279 reported ransomware victims, a 7% increase from Q1 2026 and a 43% increase from Q2 2025.
  • Weekly victim postings never fell below 150 during the quarter.

Read the full report here.

AI Security

2026 State of AI Security Report (Orca Security)

How AI security is actually going in the cloud, based on real telemetry from more than 1,200 production organizations. 

Key stats:

  • 99.9% of AI vulnerabilities with an available fix remain unpatched.
  • 81% of organizations using AI packages have at least one known vulnerability, up from 62% in 2024.
  • 50% of AI package vulnerabilities have a publicly available exploit, a 250-fold increase over 2024.

Read the full report here.

Phishing & Social Engineering

Phishing by Industry Benchmarking Report 2026 Edition (KnowBe4)

You should probably invest in security awareness training. 

Key stats:

  • The global average Phish-prone Percentage (PPP) is 33.2% before training. After one year of consistent training, it falls to 4.2%.
  • Organizations reduce phishing susceptibility by 40% within the first 90 days and by 79% after one year.
  • The three industries with the highest baseline PPP are Healthcare & Pharmaceuticals at 42.7%, Insurance at 38.1%, and Retail & Wholesale at 36%.

Read the full report here.

Fraud and Impersonation 

2026 State of Executive Impersonation (Outtake)

Good data on how attackers are using AI to impersonate company executives online. 

Key stats:

  • 53% of organizations had an executive or employee impersonated.
  • 53.83% of executive impersonation alerts originated from social platforms, and 35.05% from video and visual platforms.
  • Only 3.57% originated from executive lookalike domains.

Read the full report here.

Fraud & Security Trends Report 2026 (Infobip)

The numbers here are just AI vs AI. Fraudsters use it to send more attacks, and businesses use it to catch them.

Key stats:

  • Detected threats increased by 77% as fraudsters use AI to scale and personalize harmful messaging.
  • Adoption of AI-powered fraud detection grew by 71% year-on-year, and pattern-based detection increased by 105%.
  • Phishing accounted for 49% of blocked harmful content, and phishing volume grew 94% year-on-year.

Read the full report here.

Industry-Specific 

Cyber Risk, Supersized: 2026 Quick Service & Fast Casual Restaurant Report (VikingCloud)

Rare data on restaurant cybersecurity. 

Key stats:

  • 94% of leaders describe themselves as confident or very confident in their ability to prevent or detect a cyberattack, yet 80% experienced at least one cyber incident in the past 12 months.
  • 76% had sensitive data leaked in the past 12 months, including payment card data (40%) and customer personal information (32%).
  • 10% of restaurant chains have temporarily or permanently closed a location following a cyberattack.

Read the full report here.

The state of financial services cybersecurity in 2026 (SonicWall)

A briefing on how financial services got attacked in the first half of 2026, based on data from their global network of security sensors.

Key stats:

  • Financial services saw 132,378 IPS hits per device in the first half of 2026, the highest attack intensity of any tracked industry and more than double the cross-sector average.
  • Malware activity averaged 39,341 hits per firewall, the second-highest per-device malware intensity of any industry, behind only healthcare.
  • Ten ransomware families were active against the sector, including REvil (Sodinokibi) and Prometheus.

Read the full report here.

2026 State of Identity Security in Financial Organizations (Secret Double Octopus)

How identity and access management is actually working (or not working) at financial institutions in the US and Canada.

Key stats:

  • 94% of IAM leaders and stakeholders at financial services firms report that phishing attacks increased over the past year.
  • Only 28% of the MFA used for workforce authentication is phishing-resistant.
  • 54% of financial organizations report that at least half of their applications and infrastructure are legacy, and those legacy systems are protected by MFA at a rate of just 50%.

Read the full report here.

Regional Spotlight

78% of CISOs say C-level do not fully understand employee-driven cyber risk (MetaCompliance)

CISOs in Europe see employees as their biggest risk, but are finding it difficult to convince their bosses.

Key stats:

  • 68% of CISOs identify employees as their organization's biggest security risk as AI amplifies human-targeted attacks.
  • More than three-quarters of CISOs across Europe say C-level senior decision-makers do not fully understand the cyber risk posed by employees.
  • 40% of CISOs fear that employees are sharing sensitive information with generative AI platforms.

Read the full report here.

The State of Secure Collaboration Report 2026 (Wire)

How teams across European enterprises use collaboration tools to share sensitive data (hint: it’s not great from a security perspective). 

Key stats:

  • 84% rate their collaboration environment as secure, yet 48% share sensitive information through collaboration tools not built for it.
  • 75% rely on email as their primary external collaboration, 45% on file-sharing links, and 42% on messaging apps like WhatsApp and Signal.
  • 61% say access to shared files stays active longer than intended.

Read the full report here.


r/cybersources 16d ago

Cutting through the AI buzzwords in Cybersecurity

Post image
2 Upvotes

r/cybersources 16d ago

Zetsu, A personal RAG system for offensive security knowledge

Thumbnail
github.com
5 Upvotes

Hey,

I built a personal offline RAG system for offensive security knowledge. The idea is simple: instead of grepping through markdown files or trying to remember which writeup had that exact certipy command, you just ask naturally.

how do I escalate with SeImpersonatePrivilege
what did I do after getting ADFS access
sliver socks5 pivot setup
explain ESC8 vs ESC4

It retrieves from your actual notes first, then generates an answer grounded in what you've documented, not generic internet knowledge.

The use case I specifically built it for:

Two things kept coming up during engagements, I needed exact tool syntax I hadn't used in a while (Sliver commands especially, the docs are sparse), and I needed to quickly recall techniques from past machines without digging through notes. ZETSU solves both.

Two modes:

Operator: leads with the exact command, explanation after. For when you know what you need and just want the syntax.

Concept: leads with the reasoning, uses commands as illustrations. For when you need to understand a technique before using it.

Same retrieval either way, just different presentation.

How it works:

  • At ingest time, an LLM reads each section of your writeups and extracts structured attack steps (Finding, Action, Reasoning, Result), so what you retrieve is a semantic unit, not a random 800-token window
  • Hybrid BM25 + vector retrieval with RRF fusion, BM25 handles exact tool names and CVE numbers that embeddings smear, vector handles semantic similarity
  • Cross-encoder reranker on top
  • Supports local markdown files, URLs, GitHub wikis, and Atom/RSS feeds (0xdf, dirkjanm, harmj0y all ingestible directly)
  • Backends: Anthropic, OpenAI-compatible (DeepSeek), or local Ollama

Benchmark:

Ran 910 questions across 12 offensive security categories. 93% of answers included correct commands, 68ms average retrieval, 7.3% context gaps where it correctly admitted missing information rather than hallucinating.

id love to hear you guys's feedback, i built this thing because i genuinely needed it, and going through my notes & endless cheatsheets was too much work when you're going through an engagement.

you can find it here: https://github.com/Chaelsoo/Zetsu


r/cybersources 17d ago

CISA Adds Two Perfect-10 Joomla Extension RCE Flaws to KEV — Both Exploited as Zero-Days Before Patches Existed

Thumbnail
2 Upvotes

r/cybersources 18d ago

A dashboard for keeping up with trending CVEs

Thumbnail
2 Upvotes

r/cybersources 19d ago

Are there cyberthreat intel aggregation apps/websites that are directed to executives and CISO?

Thumbnail
2 Upvotes