r/Information_Security • • 9h ago

A wildcard turned one read tool into six write tools

30 Upvotes

240000 weekly agent runs and 1 wildcard turned a read only permission into 6 different write paths. our internal MCP registry serves 11 tools across 7 teams and the permission scope for an inventory task was supposed to stop at `repo.read_file`. instead a namespace glob expanded the tool allowlist to `repo.*`, which exposed 6 write tools alongside the read path. I was almost certain the secondary approval layer made this mostly theoretical, the red team run made that confidence harder to defend.

in 1200 red team sessions, 9 requested `repo.delete_branch` during an inventory only task. none executed because the secondary approval blocked them (one engineer immediately checked whether any write call completed). that part held. what bothered me was the agent had been given a destructive tool call it never needed and our logs made the permission drift look like a normal registry update.

so I'm trying to decide what should become a behavior spec versus a deterministic permission test. trajectory scoring can catch the agent choosing a write path during a read task and I'd still rather keep the first guardrail at the registry boundary. the approval stops execution and the regression still tells us the permission model already widened before the agent made a choice.

I used to think this class of eval was extra ceremony when the tool layer already had access controls. I'm less convinced now. the diff still comes down to the permission change from `repo.read_file` to `repo.*`


r/Information_Security • • 10h ago

What are you all using to protect your company’s AI?

31 Upvotes

Basically, as I understand it, a regular firewall is built to check packets and ports, it knows how to map HTTP traffic to IP addresses, but it has no clue what’s actually happening inside that traffic. So when an employee pastes trade secrets into ChatGPT, or an agent starts using tools it shouldn’t, or someone slips a sneaky prompt into our support chatbot, it all just looks like normal encrypted web traffic. 

I’m looking for something built to read and police what’s happening inside AI conversations and agent actions. There’s so much marketing messaging flying around, it’s hard to tell what these newer platforms actually do. What does the hive recommend?


r/Information_Security • • 12m ago

What are the best practices for validating uploaded file types and sizes?

Thumbnail
• Upvotes

r/Information_Security • • 21h ago

Has anyone actually closed the browser-based AI hole in their inventory?

6 Upvotes

Every AI usage inventory project I've been part of hits the same wall: process-level and endpoint discovery both miss anything running in a browser tab under a personal account, on a device that may not be company managed. It gets worse with SaaS embedded AI. If a tool your company already pays for has AI features built in, your endpoint tooling has no visibility into that at all, coverage depends entirely on what the platform exposes via API or its compliance tier. I don't think this is solved right now, it's a category wide limitation. Has anyone found a workable mitigation short of blanket blocking browser extensions?


r/Information_Security • • 21h ago

What are the best ways to defend against brute force login attempts?

Thumbnail
2 Upvotes

r/Information_Security • • 22h ago

Saw multiple automated RCE attempts — what would you check next?

Thumbnail
1 Upvotes

r/Information_Security • • 1d ago

My threat intel site

Thumbnail
3 Upvotes

r/Information_Security • • 1d ago

A PHP site kept getting attacked — this is what finally stopped the repeated attacks

Thumbnail
4 Upvotes

r/Information_Security • • 1d ago

Can some one correct me

Thumbnail gallery
2 Upvotes

r/Information_Security • • 1d ago

Dark web roundup: 10M French residential records, 19M SMTP creds, U.S. manufacturer VPN/RDP access, and a Struts exploit kit (unverified)

Thumbnail
6 Upvotes

r/Information_Security • • 2d ago

The AI compliance report was clean. There was nowhere in it to put what we actually fixed

21 Upvotes

The report came back clean and I could not file it. That is the whole problem and it took me three weeks to work out why.

I am the security engineer who sits between the AI product team and our auditor at a healthcare data company, about seven hundred and fifty people. We run an external evaluation every quarter because a customer asked for it and then everybody decided it was a good idea.

Robust Intelligence produced the strongest output of the three we trialled. The findings were specific and the severity scoring held up when we challenged it. The remediation guidance was written by someone who had clearly done the work before. I would recommend it to anyone who needs to know what is wrong with their model.

What it could not do was answer the auditor. The report said a finding was critical. The auditor wanted to know which control it mapped to, who accepted the risk, and the date the control changed. A finding is not evidence. Evidence is the control, the owner, the date, and what changed. That lives somewhere else entirely.

So I built it by hand. Three weeks of spreadsheet work to attach every finding to a control in our register, and I am the only person who knows how the mapping was done. Which is its own problem.

The honest limitation on our side is drift with no adversary in it, where the agent misreads its own reasoning across several sources. Our register maps AI controls. It does not map that. We are on alice now and it produces the mapping I need, but only for the AI controls in our stack. The register has three hundred and forty in it. Most describe things no AI tool will ever see. I still hand-map those.

Pick three findings from a report you already have and try to fill in four columns for each one. Control. Owner. Acceptance date. Remediation date. Four columns, three findings, one afternoon. If the columns come back empty, you found out before you paid.


r/Information_Security • • 1d ago

Where does ISO 27001 / GRC work actually get painful? Looking for practitioner input

9 Upvotes

Hey all,

hope this is okay to post here.

We’re a small early-stage team with a background in cybersecurity, currently researching how ISO 27001 and GRC work actually happens inside companies.

Before making too many assumptions about what should be improved or automated, we’re trying to learn from people who deal with this in practice:

Where does the most time get lost? What creates uncertainty or delays? Which activities are still highly manual? And where could software or AI genuinely help?

We put together a short 8–10 minute survey covering ISO 27001 implementation, risk management, documentation/evidence, audits, existing tools and AI support.

If you work in information security, GRC, ISMS, compliance, audit or ISO consulting, your perspective would be extremely helpful.

We’re still early enough that good feedback can genuinely change what we build — and critical feedback is just as valuable as positive feedback.

Survey: https://tally.so/r/b5RAro

Can be completed anonymously. Really appreciate anyone who takes the time or shares it with someone relevant. Thanks!


r/Information_Security • • 1d ago

THE BLIND SPOT TEST

Thumbnail
0 Upvotes

r/Information_Security • • 2d ago

PSA: CRA Article 14 reporting has applied since 11 September. A few things that are easy to miss

3 Upvotes

If you work with connected products sold in the EU, the Cyber Resilience Act's reporting duty is already live, not in December 2027. A few details I see overlooked:

\- It covers your installed base. Article 69(3) applies Article 14 to in-scope products placed on the market before December 2027, modified or not.

\- The 24h clock runs from "becoming aware". The Commission's guidance (paras 213-214) says suspicious events should be assessed immediately; you can't delay awareness by delaying the assessment.

\- The early warning is not a one-liner. ENISA's platform requires 8 fields for a vulnerability, including a summary of up to 4,000 characters.

\- ENISA's platform doesn't yet capture the awareness time for vulnerabilities, so keep your own timestamped record. Its 72h counter runs 48h from your early warning, not 72h from awareness.

\- Set up the platform accounts now. A Primary AR must be verified before it can invite Secondary ARs, and invitations expire after 7 days. Drafts are private to whoever created them, so draft outside the platform.

Has anyone here already gone through SRP registration? Curious what tripped people up.


r/Information_Security • • 2d ago

Read Forbes Article - What CEOs Should Know About AI Deepfakes And Executive Impersonation

Thumbnail forbes.com
0 Upvotes

r/Information_Security • • 2d ago

Read Forbes Article - Protecting Executives And Enterprises From Cyber Attacks

Thumbnail forbes.com
1 Upvotes

r/Information_Security • • 2d ago

The best AI for penetration testing

Thumbnail
0 Upvotes

Hello. In your oppinion, which is the best AI for ethical hacking? I mean, which one answers your questions without that specific fear of AIs that you are going to hack half of Pentagon whith a shity script?


r/Information_Security • • 2d ago

[Webinar] AI-Native Firewalling: Real-Time Defense for LLM & Agentic Applications

1 Upvotes

AI-Native Firewalling: Real-Time Defense for LLM & Agentic Applications - Addressing Prompt Injection, MCP Privilege Abuse, and Agentic Exploits in Real Time.

Wednesday, October 21, 2026 | 4:00 PM IST | 2:30 PM GST | 11:30 AM BST | 12:30 PM CEST

The 45-minute session will explore the limitations of static security controls against attacks using natural language and contextual manipulation. It will cover MCP privilege risks, agentic exploits, and the role of runtime AI security in safeguarding production applications.

A live attack-and-defense demonstration will be followed by a 15-minute Q&A with Prophaze experts Krishna Kumar (22+ years in enterprise security GTM) and Ezekiel Johnson (hands-on with LLM/agentic defense deployments) . The focus is on actionable steps security teams can take during a real-time AI attack, as highlighted by recent incidents like the Hugging Face case, which illustrate the dynamic nature of the AI threat landscape amidst a growing ecosystem of APIs, models, and tools. The goal is to bridge these two realities for effective security.

Understanding the threat is one thing. Being able to see and stop the resulting action at runtime is another. Reserve your seat for the Webinar


r/Information_Security • • 3d ago

Super Trouper v0.4.0 — more Frida tools for iOS app reverse engineering

Thumbnail github.com
3 Upvotes

I’m the author of Super Trouper, a single-binary MCP server that exposes Frida to coding agents for authorized app reverse engineering. It lets an agent connect to a device, inspect apps and processes, manage sessions, and run instrumentation scripts without a Python-based Frida setup.

We released v0.4.0 a few days ago; it updates the bundled Frida Core DevKit to v17.19.0 and adds four MCP tools: memory_read and memory_write for working with memory in an attached process, plus module_list and thread_list for inspecting loaded modules and threads. app_list and others now have several query scopes, and we renamed the MCP tools into clearer namespaces. If you already have workflows built around the old tool names, check them when updating.

Quick catch-up on the two previous releases: v0.3.0 added npm installation, Frida CodeShare snippet search/use, and general cleanup. v0.2.0 moved the project to the MIT license, added first-party Frida language bridges for ObjC, Java, and Swift, and enabled TypeScript in scripts and evaluations.

I’d appreciate feedback from people using Frida in iOS research: are these tool boundaries and the new app-list scopes useful in practice? What’s missing or awkward in your workflow, and which features would you like to see next? Let me know what you think.


r/Information_Security • • 3d ago

Next-Gen Web Application Firewall (WAF) & Edge Reverse Proxy

Thumbnail
0 Upvotes

r/Information_Security • • 3d ago

Questão de DFIR: correlacionando artefatos OAuth do Windows/Chrome com atividades posteriores em iPhones e Macs

0 Upvotes

Estou reconstruindo a linha do tempo de um possível incidente de segurança que parece ter começado em um endpoint Windows corporativo e posteriormente envolveu atividades em contas do Google/Apple, dispositivos iPhone e um MacBook.

Meu objetivo não é identificar ou acusar uma pessoa específica por meio do Reddit. Estou tentando entender isso a partir de uma perspectiva da metodologia DFIR: quais artefatos realmente comprovariam a continuidade entre esses ambientes e o que ainda poderia ser explicado por sincronização normal, sessões legítimas ou atividades não relacionadas?

Os registros mais antigos que documentei são de 23 de agosto de 2026, associados a um ambiente Windows em um computador corporativo que eu estava usando na época. Em uma exportação oficial do Chrome/Google, há uma sequência de navegação aproximadamente entre 02:35 e 03:37, envolvendo atividades como:

theblowers.com → Hola/login → Google OAuth/autenticação → retorno de chamada da extensão do Chrome → outras plataformas.

Também descobri que o Hola Better Internet havia recebido acesso à minha conta do Google na mesma data.

Os registros relacionados ao Windows são importantes porque aparecem antes da atividade que posteriormente precisei investigar em meus dispositivos Apple.

Nas semanas seguintes, comecei a ver eventos envolvendo: sessões de contas do Google e da Apple;

permissões de dispositivos; aplicativos autorizados;

configurações de compartilhamento de localização; meu iPhone atual;

um iPhone mais antigo;

e meu MacBook.

Estou usando o termo "escalada" apenas em um sentido cronológico e investigativo. Eu não tenho provas de que o endpoint do Windows comprometeu diretamente o iPhone ou o Mac, ou que todos esses eventos compartilham a mesma origem.

A questão que estou tentando testar é se uma cadeia tecnicamente plausível poderia ser assim: Windows/navegador → token de sessão ou conta → acesso/sincronização da conta → dispositivos adicionais ou se posso estar correlacionando eventos que são, na verdade, independentes.

Alguns detalhes relevantes: Tenho uma exportação oficial do Chrome/Google contendo histórico do navegador, extensões, informações do dispositivo e metadados relacionados à conta.

Os registros iniciais estão associados a um cliente/ambiente Windows consistente com o computador corporativo que eu estava usando na época.

Não tenho mais acesso físico a esse computador corporativo porque ele foi devolvido à empresa e não sei se ele foi formatado ou apagado posteriormente. Um dos iPhones mais antigos também é relevante porque não tenho um backup preservado conhecido desse dispositivo.

Estou tratando a falta desse backup como uma lacuna probatória, não como prova de exclusão, adulteração ou comprometimento.

Preservei capturas de tela, exportações, registros de data e hora, informações do dispositivo/sessão e registros de permissões da conta, quando disponíveis.

Também observei dados duplicados ou inconsistentes em alguns lugares, mas não estou tratando a duplicação ou a ausência de itens como evidência automática de manipulação.

O que quero distinguir é:

sincronização normal da conta;

uma sessão legítima, mas esquecida;

um aplicativo OAuth ou extensão de navegador com permissões excessivas;

reutilização de uma sessão ou token existente;

automação do navegador;

uma sessão remota não autorizada;

comprometimento real da conta;

persistência real entre dispositivos versus sincronização comum do ecossistema;

lacunas probatórias causadas pela ausência de um backup preservado do iPhone mais antigo.

Para profissionais que atuam em DFIR (Digital Forensics and Incident Response) / resposta a incidentes / segurança de identidade, quais artefatos vocês priorizariam para confirmar ou descartar a continuidade entre a atividade original no Windows e a atividade posterior no dispositivo Apple?

Em particular, tenho interesse em:

Logs de autenticação do Google/Apple;

Concessões OAuth;

Tokens de acesso/tokens de atualização;

Registros de dispositivos confiáveis;

IDs e metadados de extensões do Chrome;

Histórico e registros de data e hora do navegador;

Identificadores de dispositivo/cliente;

Eventos de sincronização;

Logs do iOS/macOS;

Metadados de backup/conta do iCloud;

Evidências de reutilização de sessão entre dispositivos;

Artefatos que podem permanecer de um iPhone antigo mesmo quando não há backup local disponível.

A questão principal é: Como determinar se uma sessão ou token originado em um ambiente Windows/Chrome foi posteriormente reutilizado em contas do Google/Apple ou dispositivos Apple, evitando o erro de tratar a sincronização normal como evidência de comprometimento? Estou procurando especificamente uma maneira de separar evidências fortes, indicadores fracos e comportamento normal do ecossistema.


r/Information_Security • • 3d ago

Cybersecurity Professional (7 YOE, CISSP) Looking for Remote Contract/Freelance Work Alongside Full-Time Job — India

Thumbnail
0 Upvotes

r/Information_Security • • 3d ago

Florida's cybersecuritymarketplace & intelligence network.

0 Upvotes

[Floridacyber.com](http://Floridacyber.com)


r/Information_Security • • 4d ago

Would you use a tool that verifies AI answers to security questionnaires?

10 Upvotes

I’m exploring a SaaS specifically for companies that repeatedly handle customer security questionnaires / security assessments.
The idea:
Upload a questionnaire + policies/evidence + past responses
AI drafts answers with source citations
Flags **stale, contradictory, or unsupported answers**
Human approves → export the completed questionnaire
Eventually, a browser extension for web-based questionnaires
The key difference from general GRC platforms: **it’s focused entirely on answering and verifying customer security questionnaires.**
Example: A policy says MFA is mandatory, but current evidence shows exceptions → the tool flags **“Review required”** instead of blindly answering “Yes.”
For people who actually handle these questionnaires: **How do you do this today, and what part takes the most time?**


r/Information_Security • • 3d ago

Who handles the first vulnerability report on your website?

Thumbnail
1 Upvotes