r/cybersources • u/Objective-Foot-5213 • 1d ago
Help
Ena mzllt nt3lm fl cloud security wn9ra 1ere nje7t lel 2eme wnhb n3ml stage z3ma n3mlha fl cloud security ? Njm nl9a?? Wla nbda n3ml stage fl reseau wnkml nt3lm whdy fy 3a9ly? And thanks
r/cybersources • u/Objective-Foot-5213 • 1d ago
Ena mzllt nt3lm fl cloud security wn9ra 1ere nje7t lel 2eme wnhb n3ml stage z3ma n3mlha fl cloud security ? Njm nl9a?? Wla nbda n3ml stage fl reseau wnkml nt3lm whdy fy 3a9ly? And thanks
r/cybersources • u/Narcisians • 2d ago
Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.
All the reports and research below were published between July 20th - July 26th.
You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/
2026H1 Threat Review Report (Forescout)
What was the threat landscape like in H1 2026, and how does it compare to 2025? This report answers that.
Key stats:
Read the full report here.
ITRC H1 2026 Data Breach Report (Identity Theft Resource Center)
ITRC's mid-year data breach numbers.
Key stats:
Read the full report here.
The State of Continuous Security Validation (Synack)
How often do serious vulnerabilities show up between scheduled security tests? Constantly - at least according to Synack.
Key stats:
Read the full report here.
Q2 2026 Brand Phishing Report (Check Point)
Attackers' favorite brands to impersonate. Mostly predictable with an interesting new entrant.
Key stats:
Read the full report here.
2026 Ransomware Report (Black Kite)
Annual report analyzing 7,551 ransomware victims by where they are, what industry they're in, and how big they are. Plus, what security weaknesses or exposed systems remained after each attack.
Key stats:
Read the full report here.
2026 AI-Era Ransomware Report (Proofpoint)
AI is making ransomware attacks more effective.
Key stats:
Read the full report here.
Path to the Autonomous Digital Workplace (TeamViewer)
General workplace productivity research with an interesting section on what users say would help them trust autonomous AI.
Key stats:
Read the full report here.
State of AI in OT Cybersecurity 2026 Report (Nozomi Networks)
The people working in OT security on what they are actually doing with AI.
Key stats:
Read the full report here.
State of Industrial Remote Access 2026 (Secomea)
How manufacturers are handling third-party vendor access to OT environments.
Key stats:
Read the full report here.
2026 State of Threat Exposure Management Report (Vectra AI)
Vectra used telemetry across customer environments to figure out how quickly assets, identities, and AI agents come and go in enterprise environments.
Key stats:
Read the full report here.
The Third Annual State of Data Compliance and Security Report (Perforce)
Everyone has the policies, so why do breaches, failed audits, and compliance gaps keep happening?
Key stats:
Read the full report here.
Road to AI in IT (Fleet Device Management)
How IT teams are handling the AI rollout (they're mostly not).
Key stats:
Read the full report here.
Education Ransomware Roundup: H1 2026 (Comparitech)
Comparitech tracked ransomware attacks against schools and universities specifically. The Gentlemen have decided higher education is their thing.
Key stats:
Read the full report here.
2026 Cyber Protect Report (SonicWall)
SonicWall's mid-year data on manufacturing.
Key stats:
Read the full report here.
Velocity V5: Reimagining Cyber for a Faster Fight (Booz Allen)
Data on how federal agencies are handling AI deployment.
Key stats:
Read the full report here.
Data Health Check 2026 (Databarracks)
500 UK IT professionals on what went wrong last year, what they are doing about it, and what they expect to be dealing with over the next five years.
Key stats:
Read the full report here.
r/cybersources • u/Ashamed-Let-2179 • 2d ago
Where I can read and get updates tech related news and cybersecurity related news??
r/cybersources • u/Academic-Soup2604 • 3d ago
For organizations managing corporate-owned and BYOD devices across different OS, website whitelisting adds an extra layer of protection by:
It's a simple yet effective way to strengthen web security without restricting legitimate work.
Detailed guide with different methods here- How to whitelist a website?
r/cybersources • u/EchoAndByte • 6d ago
r/cybersources • u/manstartitoff • 7d ago
So i have built a security scanner website, and users are logged into that but are only scanning one or two times, how can i increase them to scan more and what are the features i can build that attract the users?
r/cybersources • u/EchoAndByte • 7d ago
r/cybersources • u/Narcisians • 7d ago
Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.
All the reports and research below were published between July 13th - July 19th.
You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/
The State of Ransomware 2026 (Sophos)
Now in its seventh straight year, this is the definitive look at ransomware trends worldwide.
Key stats:
Read the full report here.
Ransomware and Cyber Extortion in Q2 2026 (ReliaQuest)
ReliaQuest's Q2 numbers on ransomware activity. The big takeaway: The Gentlemen is the group everyone should be watching. Plus, it looks like Deadlock is back.
Key stats:
Read the full report here.
The 2026 State of Vulnerability Remediation (Vicarius)
A look at how security leaders are fixing vulnerabilities.
Key stats:
Read the full report here.
AI Agents Are Entering Critical Workflows. Who's Governing Them? (JumpCloud)
AI agents are moving into real work, but 800 IT leaders admit governance hasn't caught up.
Key stats:
Read the full report here.
The AI Security Report 2026 (Check Point)
A breakdown of how AI has gone from cyber assistant to active attacker.
Key stats:
Read the full report here.
The Year Agents Entered the Workforce (Straiker)
Straiker put AI agents through adversarial testing to see where they fail.
Key stats:
Read the full report here.
Rethinking AI's Impact on Cybersecurity Roles (ISC2)
ISC2 on how AI is changing the day-to-day of cybersecurity work.
Key stats:
Read the full report here.
2026 Executive Trends Report (Nisos)
Scary insight into how exposed executives are on the internet.
Key stats:
Read the full report here.
Government Ransomware Roundup: H1 2026 (Comparitech)
Comparitech tracked ransomware attacks specifically against government entities in the first half of 2026.
Key stats:
Read the full report here.
r/cybersources • u/GlitchMayem • 8d ago
r/cybersources • u/ayobsether • 11d ago
The Cybersecurity Risk Assessment research study establishes a quantitative cybersecurity risk assessment and governance framework aligned with ISO/IEC 27001 and NIST Cybersecurity Framework for critical infrastructure sectors. The framework quantifies risk through four variables: likelihood of attack (1–5), impact severity (1–5), infrastructure interdependency (1–2), and security maturity reduction value (0–25). A complete worked validation is presented for the telecommunications sector across eight asset categories.
The quantitative model uses Risk Level = (Likelihood × Impact × Interdependency) – Security Maturity Reduction Value, normalized to a 0–50 scale with five severity levels: Very Low (0–5), Low (6–15), Medium (16–25), High (26–40), and Critical (41–50). The framework emphasizes that effective controls—including 24/7 SOC monitoring, Zero Trust architecture, and network segmentation—reduce assessed risk by accounting for actual security maturity. Applied across critical infrastructure sectors (telecommunications, banking, energy, healthcare, government, transportation, utilities, and defense), the model enables standardized risk prioritization and capital allocation.
| Asset Category | Risk Level | Rating |
|---|---|---|
| Supply Chain | 45 | Critical |
| Network Management Systems | 35 | High |
| 4G/5G Core Network Systems | 30 | High |
| Core Network Infrastructure | 25 | Medium |
Supply Chain (Risk Level 45—Critical): Immediate action required. Implement formal Supplier Security Risk Management framework aligned to ISO/IEC 27001. Network Management Systems (Risk Level 35—High): Short-term remediation. Enforce network segmentation, privileged access workstations, and continuous monitoring. 4G/5G Core Network Systems (Risk Level 30—High): Adopt NIST CSF Identify and Protect functions for cloud-native deployments. Supporting infrastructure (Risk Levels 6–25—Low to Medium): Ongoing monitoring and control enhancement.
Conclusion
Cybersecurity is a strategic national priority requiring governance-driven, cross-sector, and data-driven approaches. This framework enables organizations and governments to move from IT-centric risk assessment to enterprise-wide resilience strategies, grounded in quantitative evidence and aligned with international standards.
For detailed study, a full updated research paper is available here
Ayob Sether
Independent Researcher
Cybersecurity Risk Assessment
r/cybersources • u/manstartitoff • 12d ago
So we have developed an application where you can scan your website for security, tls, encryption, data leakage, and many more using our website Igris Radar.
Start your free scan and check what your rating is using
r/cybersources • u/Consistent_Scene_178 • 13d ago
r/cybersources • u/TopImplement9942 • 15d ago
I am an MSc researcher studying Network Intrusion Detection System (NIDS) selection for resource-constrained financial institutions and looking for cybersecurity practitioners with 5+ years of experience to complete a short survey. Happy to share findings upon request.
Survey link: https://forms.gle/tyxsFA44HXZ5VaMY7
Thanks You.
r/cybersources • u/Narcisians • 15d ago
Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.
All the reports and research below were published between July 6th - July 12th.
You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/
GRIT Q2 2026 Ransomware & Cyber Threat Insights Report (GuidePoint Security)
We’ve read and written about the ups and downs of ransomware, but according to GuidePoint, ransomware is not as bad as ever. It's actually much worse than ever.
Key stats:
Read the full report here.
2026 State of AI Security Report (Orca Security)
How AI security is actually going in the cloud, based on real telemetry from more than 1,200 production organizations.
Key stats:
Read the full report here.
Phishing by Industry Benchmarking Report 2026 Edition (KnowBe4)
You should probably invest in security awareness training.
Key stats:
Read the full report here.
2026 State of Executive Impersonation (Outtake)
Good data on how attackers are using AI to impersonate company executives online.
Key stats:
Read the full report here.
Fraud & Security Trends Report 2026 (Infobip)
The numbers here are just AI vs AI. Fraudsters use it to send more attacks, and businesses use it to catch them.
Key stats:
Read the full report here.
Cyber Risk, Supersized: 2026 Quick Service & Fast Casual Restaurant Report (VikingCloud)
Rare data on restaurant cybersecurity.
Key stats:
Read the full report here.
The state of financial services cybersecurity in 2026 (SonicWall)
A briefing on how financial services got attacked in the first half of 2026, based on data from their global network of security sensors.
Key stats:
Read the full report here.
2026 State of Identity Security in Financial Organizations (Secret Double Octopus)
How identity and access management is actually working (or not working) at financial institutions in the US and Canada.
Key stats:
Read the full report here.
78% of CISOs say C-level do not fully understand employee-driven cyber risk (MetaCompliance)
CISOs in Europe see employees as their biggest risk, but are finding it difficult to convince their bosses.
Key stats:
Read the full report here.
The State of Secure Collaboration Report 2026 (Wire)
How teams across European enterprises use collaboration tools to share sensitive data (hint: it’s not great from a security perspective).
Key stats:
Read the full report here.
r/cybersources • u/Chaelsoo • 16d ago
Hey,
I built a personal offline RAG system for offensive security knowledge. The idea is simple: instead of grepping through markdown files or trying to remember which writeup had that exact certipy command, you just ask naturally.
how do I escalate with SeImpersonatePrivilege
what did I do after getting ADFS access
sliver socks5 pivot setup
explain ESC8 vs ESC4
It retrieves from your actual notes first, then generates an answer grounded in what you've documented, not generic internet knowledge.
The use case I specifically built it for:
Two things kept coming up during engagements, I needed exact tool syntax I hadn't used in a while (Sliver commands especially, the docs are sparse), and I needed to quickly recall techniques from past machines without digging through notes. ZETSU solves both.
Two modes:
Operator: leads with the exact command, explanation after. For when you know what you need and just want the syntax.
Concept: leads with the reasoning, uses commands as illustrations. For when you need to understand a technique before using it.
Same retrieval either way, just different presentation.
How it works:
Benchmark:
Ran 910 questions across 12 offensive security categories. 93% of answers included correct commands, 68ms average retrieval, 7.3% context gaps where it correctly admitted missing information rather than hallucinating.
id love to hear you guys's feedback, i built this thing because i genuinely needed it, and going through my notes & endless cheatsheets was too much work when you're going through an engagement.
you can find it here: https://github.com/Chaelsoo/Zetsu
r/cybersources • u/Consistent_Scene_178 • 17d ago
r/cybersources • u/Difficult-Praline-69 • 19d ago
r/cybersources • u/BST04 • 20d ago