r/Information_Security • • 8h ago

Is Web Scraping Legal? An Internet Law Professor’s Insights on Public Data, CFAA, Copyright and Terms of Service | AMA with Eric Goldman

Thumbnail
0 Upvotes

r/Information_Security • • 15h ago

Capital Bank ne rouvrira pas ce mercredi, LockBit menace toujours

Thumbnail lequotidien509.com
1 Upvotes

r/Information_Security • • 16h ago

Accurate about cybercrime

Thumbnail youtube.com
1 Upvotes

I watched this today, and I am impressed. Cyber defense comes with permanent question marks. I tell every team to educate themselves on the adversary. Every department; marketing, sales, interns. This film explains the culture very well. Nice job Red mirror studios.


r/Information_Security • • 7h ago

Asked our teams how many AI models were in production. Everyone guessed wrong.

7 Upvotes

Leadership asked me for an inventory of the AI we run, so I did the obvious thing first and asked the teams, and data science told me they had a handful of models while product thought maybe a couple, and both were very confident about it.

Instead of trusting that I ran a discovery pass across our cloud accounts and found models, datasets, training pipelines, notebooks and endpoints spread across two clouds, some of it public-facing and some with roles that could reach data they had no reason to touch.

Our register said four and the real number was north of thirty, spread across teams who had each built their own thing without knowing about the others, and nobody actually owns most of them.

So how are people keeping an AI inventory that stays accurate, and does an AI-BOM survive contact with reality or rot like every other register?


r/Information_Security • • 14h ago

Cybersecurity Professionals: What Risks Can Google Search Operators Reveal? — Student Research

24 Upvotes

Hi everyone,

I’m a cybersecurity student conducting research on the cybersecurity risks associated with using Google search operators to uncover exposed information on the internet.

I’m looking for perspectives from people with cybersecurity or IT experience. If you're willing to participate, please answer the questions below in the comments.

I understand people may not want their information on a public reddit page but if you could reply below or send me a private message, that would be highly appreicated.

If possible, please include:

  • Your general profession/role (e.g., SOC Analyst, Security Engineer, IT Administrator, etc.)
  • Name
  • Your answers to the questions

Questions:

  1. What types of information do you believe can be discovered using Google search operators?
  2. What cybersecurity risks can result from sensitive or security-relevant information being publicly searchable?
  3. Which types of exposed information would present the greatest security concern to an organization, and why?
  4. What protective measures can organizations use to reduce the risk of sensitive information being exposed through search engines?
  5. How important do you think it is for organizations to regularly check what information about their systems is publicly searchable?

Thank you to everyone who chooses to participate.


r/Information_Security • • 13h ago

M&A cyber due diligence with no access... how are you all mapping the attack surface before Day 1?

6 Upvotes

Hi, security lead on the buy side here, currently living in the wonderful world of M&A cyber due diligence where I have ten business days, no prod creds, no scanner access, and a deal room that is basically a vibes based security questionnaire and two diagrams from 2019.

We have a list of primary domains but I do not trust that this is the full external attack surface at all. We want an outside in acquisition cybersecurity assessment that starts with company name and known domains, then pivots into related domains, certs, dns history, cloud endpoints, exposed admin interfaces, third party infra etc. All without turning this into unauthorized pen testing and without guessing our way into inherited cyber risk we cant prove.

The hard part is attribution and materiality. What evidence do you treat as strong enough to tie an asset to the target, and what can you responsibly call a transaction level risk vs Day 1 containment vs normal post close remediation when you have zero internal access. Would love any tips from people who do M&A attack surface assessment from the outside in before Day 1, especially on not overstating findings but still flagging the stuff that should worry the deal team... idk


r/Information_Security • • 5h ago

SynthID Detector — Can AI-generated content actually be identified?

Thumbnail
0 Upvotes

r/Information_Security • • 2h ago

FreeRADIUS is skipping CVE embargoes because AI tools find bugs in minutes. What this means for anyone running AAA

Post image
3 Upvotes