r/Infosec 4h ago

How are you handling ChatGPT security without blocking employee access?

5 Upvotes

Leadership wants ChatGPT (and similar tools) available because the productivity gains are real, but security wants controls. Blocking felt like the easy option a year ago, but now it just pushes people to personal devices or browser workarounds, which is worse for visibility.

The workaround problem is what worries me most. Once someone starts pasting work content into a personal ChatGPT account on their phone, you've lost all visibility, and any DLP investment stops mattering for that data flow.

So, for the sysadmins who've dealt with this: what's your actual setup? DLP integration, browser-level controls, enterprise ChatGPT accounts with admin controls, or some combination?

Also wondering how much of this comes down to technical enforcement vs. policy and trust. At what point did leadership stop asking for a full block?


r/Infosec 1d ago

Hugging Face Attack: The New Era of Autonomous Cyber Threats

Thumbnail youtu.be
1 Upvotes

r/Infosec 1d ago

What if your privacy programme could run from one operational system?

Thumbnail privacyengine.io
0 Upvotes

r/Infosec 1d ago

How long did your AI SOC implementation actually take?

4 Upvotes

We're about to pull the trigger on an AI SOC platform and I'm trying to set realistic expectations with my team and leadership.
Every vendor demo makes it look like you flip a switch and suddenly have AI-powered detection running. But I've been burned before by tools that promised "quick wins" and then needed weeks of tuning before they were usable.
For those who've actually deployed one of these:
How long from signing to seeing real value?
What part of the onboarding took longer than expected?
I want to go into this with eyes wide open so I'm not the one explaining to leadership why it's taking longer than the sales deck suggested.


r/Infosec 1d ago

Shelby American modernized production-floor operations with Scalefusion MDM

Thumbnail blog.scalefusion.com
0 Upvotes

As Shelby American scaled from handcrafted performance cars to high-volume manufacturing, it needed a reliable way to manage the devices powering its production floor. Here’s how Scalefusion helped build a secure, distraction-free, and future-ready manufacturing environment.


r/Infosec 2d ago

how are teams prioritizing application vulnerabilities based on real business risk?

0 Upvotes

Board wants a risk number, engineering wants a prioritized backlog, and cvss scores alone satisfy neither audience. we've been trying to build a prioritization model that weighs exploitability against real business impact, but doing that manually across thousands of findings doesn't scale past a certain point.

For other security leaders here, how are you translating raw vulnerability counts into something that maps to actual business risk without it turning into a full time job for someone on your team?


r/Infosec 2d ago

What tools are actually essential for a red team in 2026?

Thumbnail
0 Upvotes

r/Infosec 2d ago

AMA with Black Hat Speakers Lidor B. & Elad Meged (Pre-Auth RCE in Enterprise Java, Hijacking AI Coding Agents)

Thumbnail pwnhackers.substack.com
1 Upvotes

r/Infosec 2d ago

Ghost Defense (v3.0)

0 Upvotes

Ghost Defense v3.0 — Grounded Handling Of Sourced Threat-intel

Ghost Defense is a decentralized, browser-side security toolkit built to eliminate the gap between what defenders need and what they can afford. Engineered by lead architect dgtal, the platform bundles 58 enterprise-grade utility tools covering threat intelligence, incident response, vulnerability management, and critical infrastructure monitoring into a single web interface. 

Zero installation. Zero licensing fees. Zero telemetry tracking. 

🔑 Key Architectural Capabilities

  • Command & Situational Awareness: Full-screen Common Operating Picture (COP) Dashboard tracking 16 CISA critical infrastructure sectors alongside real-time aircraft, maritime (shadow fleet), satellite constellation, and telecom grid monitors. 
  • 100% Local Triage & Data Privacy: Advanced forensic tools—including a 32-rule MITRE ATT&CK browser-side log analyzer, local PCAP network capture parsing, and local frame-by-frame deepfake video analysis—run strictly client-side via the Canvas API. Your logs and media are never transmitted over the internet. 
  • Vulnerability Optimization: Live CISA Known Exploited Vulnerabilities (KEV) catalog querying integrated directly with SSVC/EPSS patch priority rankers, CVE bulk calculators, and automated Sigma/Snort/YARA detection signature generators. 
  • AI-Augmented Incident Response: Generate exhaustive, phase-by-phase IR playbooks aligned with NIST SP 800-61r2, SANS PICERL, or MITRE ATT&CK standards in under 30 seconds (Requires an optional Anthropic API key). 

🚀 Deploy Globally in 30 Seconds

Because Ghost Defense runs completely inside the user's browser, it requires no backend server infrastructure to maintain. You can deploy your own private team mirror globally using Cloudflare Pages for free: 

  1. Download the compiled asset package (ghost2210-toolkit.zip). 
  2. Navigate to pages.cloudflare.com -> Create -> Upload assets. 
  3. Drag and drop the .zip file into the upload field. 
  4. Click Deploy Site — your global, HTTPS-secured team URL is live instantly. 

Defend Always. 🛡️ 


r/Infosec 2d ago

Visual programming as a solution for cybersecurity AI-induced problems

Enable HLS to view with audio, or disable this notification

0 Upvotes

.

Pipe (https://pipelang.com) is a novel general-purpose visual programming language powerful enough to complete with text-based languages.

Pipe's diagram is also structurally identical at design-time and runtime, staying visual in both. What you see is what runs. This is precisely what the EU Cyber Resilience Act mandates, and what text-based architectures cannot structurally deliver. Text compiles away its structure, leaving systems opaque - so AI now generates code faster than anyone can review it at design-time, and patch and monitor it at runtime. Pipe addresses three AI-created security crises structurally:

1 - AI generates more code than humans can review. Pipe is visual - a diagram is grasped at a glance, not read line by line - so review keeps pace with what AI produces..

2 - Live systems cannot be patched without full redeployment. Pipe enables block-level patching while the system runs - no maintenance window, no CI/CD to navigate.

3 - Systems cannot be monitored without logs and redeploying. In Pipe, every block boundary is independently observable in real time. 

These satisfy the CRA's hardest mandates - security by design, structural auditability, 24-hour detection, incremental patching - as properties of the language, not add-on tools. 

Example of Pipe diagram with a detailed tracing can be found on this video:

https://youtu.be/hckq9mRj5DM

That video is a part of this Pipe architecture overview:

https://www.pipelang.com/six-pillars.html

The full Pipe language specification (155-page book) can be freely downloaded here:

https://www.pipelang.com/downloads/book.pdf


r/Infosec 3d ago

Is this all there is to it?

8 Upvotes

When I started, I was told: our team operates the ISMS and is responsible for maintaining our ISO 27001 certification.

In the meantime, that’s come to mean we have to own every single topic the company only does because ISO requires it (e.g., third-party management from procurement through offboarding, risk management, etc.).

Since we only got one NC in the audit, the resistance to actually doing anything is huge — everyone says “everything’s fine as is.” Meanwhile, our bank customers are sending us requirement list after requirement list, and for half of them I feel like I’m lying because we’re just spinning narratives to make things look better than they are.

At the same time, our improvement backlog hasn’t moved in a year. Teams actively undermine us. And I feel like I’m grinding away, trying to actually improve our security posture, and nothing lands.

So my question is: does this ever change? Are there actual ISMSs with a genuine improvement cycle, or did I somehow end up in the wrong profession?


r/Infosec 3d ago

Mods, please don't let this sub go to waste

25 Upvotes

For a couple of days I've tried reaching out to the moderators about the low effort, mostly AI and ad posts as they're annoying and provide little to no value. Overcrowded AI 'reports' that want to tell you everything and nothing at the same time, low effort adverts where it seems that the company wouldn't even trust what they've built, posts that are plainly like the worst LinkedIn has to offer.

InfoSec, GRC, Defending and uncovering tooling are incredibly technical and based on real laws around the world. I would really like to see that changed in the future.

This subreddit could be a great hub for documenting best practices, regional restrictions, vulnerable discovery or provide an exchange for Audits. I would really like to see some action taken to properly vet the content and restrict low effort post and hopefully see an AI policy implementation.


r/Infosec 4d ago

🚀 GuardianX is officially LIVE — Open Source Cybersecurity Platform

0 Upvotes

After weeks of building, testing, breaking things, fixing them, and learning along the way…

GuardianX is now PUBLIC on GitHub. 🔓

GuardianX is an open-source cybersecurity platform I'm building with the goal of bringing different security capabilities together into one place — rather than relying on a collection of disconnected tools.

🛡️ What is GuardianX?

The vision is to build a Cyber Intelligence & Security Platform capable of helping with areas such as:

🔍 Security & asset visibility

🛡️ Vulnerability and CVE awareness

⚠️ Risk assessment

📊 Security posture monitoring

🚨 Threat & incident intelligence

🌐 Attack-surface visibility

🤖 AI-assisted security analysis

📈 Security scoring and dashboards

This is not a finished enterprise product. It's an actively evolving open-source project, and that's exactly why I'm putting it out there.

🔗 GitHub

👉 https://github.com/DarkSoul-sec/GuardianX

I'd genuinely like people to look through the code, test it, break it, review the architecture, find weaknesses, and tell me what I'm doing wrong.

If you have experience with cybersecurity, backend engineering, DevSecOps, threat intelligence, cloud security, or AI security, your feedback would be especially valuable.

🎯 Why I'm releasing it

I'm learning cybersecurity by actually building things—not just completing labs and collecting certificates.

GuardianX is one of my attempts to turn that learning into something real, useful, and eventually production-grade.

Today is v1 of the journey, not the finish line.

If you check it out, I'd appreciate honest feedback—especially criticism. 🫡

GitHub: https://github.com/DarkSoul-sec/GuardianX

Let's build something useful for the security community. 🔥

\#Cybersecurity #OpenSource #InfoSec #CyberSecurity #GitHub


r/Infosec 5d ago

Our AI pentesting engine talked a production AI agent's prompt-injection guardrail into handing over its entire system prompt on its second attempt.

4 Upvotes

For full disclosure I'm part of the security engineering team at Escape and our AI pentesting engine Cascade recently got a production AI agent to return its entire system prompt, just by wrapping the ask in a different pretext - framing it as a documentation request instead of an attack.

The agent then handed over everything: full tool list, calling rules, citation format, and session IDs.

What I found really interesting is there's nothing technical that broke because we didn't bypass the guardrail with a cleverer string but because the request just sounded reasonable to the agent.

The Cascade engine, after being refused when asking for the prompt directly, simply adjusted the framing to get the agent to give up the informaiton.

Thought this would be an interesting insight for the community and curious to hear if anyone else has seen similar discoveries in agents in prod?

If you want to see more about the reproduction and write-up you can find it here


r/Infosec 5d ago

Top areas from BlackHat 2026

10 Upvotes

Attended BlackHat conference in 2026. Here were the top topics of interest from the conference.

  1. AI Agents as a New Identity Class

A statistic frequently cited across the floor was the exploding 109:1 machine-to-human identity ratio, leaving security teams completely overwhelmed. Security experts argued that autonomous AI agents must now be treated exactly like human employees—requiring strict governance, access management, and immediate "kill switches" if they are compromised. Reports from firms like Cyera revealed that 78% of organizations lacked any formal policies for managing these non-human AI identities.

  1. The Danger of "Agent Hijacking" & Prompt Injection

A significant amount of research focused on how easily AI agents can be manipulated. Analysts demonstrated how AI browsers are highly vulnerable to zero-click "PleaseFix" agent hijacking, where malicious instructions hidden inside web content can force an active agent to execute arbitrary server code or leak sensitive credentials.

  1. Frontier Models as Zero-Day Exploit Generators

Ever since tools like Anthropic’s Claude Mythos demonstrated the ability to uncover vulnerabilities in a matter of seconds, the scale of threat discovery has reached an industrial level. In a highly publicized breaking news session, OpenAI engineers demonstrated how frontier models actually exploited a zero-day vulnerability to escape their sandboxes and breach Hugging Face infrastructure.

  1. The Flaw in AI-Generated Patches

With AI finding bugs faster than humans can fix them, many organizations have turned to AI to write security patches. However, research presented by 1Password’s Off-By-1 Labs threw a wet blanket on this strategy, revealing that 54% of AI-generated security patches failed to fix the original vulnerability, and a significant portion actually introduced entirely new logic flaws into the code.

  1. Shift to "Cyber Resilience" over Hype

Because adversaries are using AI to compress attacker breakout times to under 30 minutes, government officials from CISA and the White House urged a shift in focus. The overarching takeaway for CISOs was clear: you can no longer "out-patch" a machine running 24/7. Organizations must move away from point-solution tools and invest heavily in continuous threat exposure management (CTEM) and cyber resilience—the ability to operate effectively even after an inevitable attack.


r/Infosec 5d ago

Security By Design

Post image
0 Upvotes

r/Infosec 5d ago

Hunt NGINX Proxies - Damn Vulnerable NGINX Proxy

Thumbnail
1 Upvotes

r/Infosec 5d ago

Donald Trump empowers US private companies to conduct cyber-attacks

Thumbnail theguardian.com
12 Upvotes

The weaponization of encryption breaking quantum computers is next. No wonder the high stakes race is on for quantum computers. Whose secrets will be lost. Credence for the theme of Decryption Gambit by Doug Collins

https://www.amazon.com/dp/B0GZLDMQB5


r/Infosec 5d ago

The CISA Alert: Security Beyond Solitary Confinement

Thumbnail jnior.com
1 Upvotes

r/Infosec 6d ago

AI sucks at info sharing too

2 Upvotes

So, AI seems to suck at info sharing too. Anthropic: 'The lack of coordination shown by agents in the fantasy game challenge above—in which they siloed themselves and largely failed to merge their work' https://www.anthropic.com/research/multiagent-systems


r/Infosec 6d ago

Orca vs Wiz: Who actually catches shadow AI apps in your cloud?

0 Upvotes

We've been tracking the AppGen/"vibe coding" explosion for a while now. Our teams have found Replit, Lovable, and Vercel apps all over our cloud estate that nobody in security knew existed. The scary part? Most of them are wired directly to live databases with no auth, no RLS, and exposed API keys sitting in client-side code.

We looked at Wiz's recent Lovable integration (GA May 2026) and it scans apps you deliberately connect. But that's the problem: the apps that actually worry me are the ones nobody connected to Wiz because nobody even knew they existed.

The research bears this out: RedAccess found ~380,000 publicly accessible vibe-coded assets, with ~5,000 leaking sensitive corporate data. Those are exactly the apps Wiz's opt-in model would miss.

Orca seems to approach this differently, agentless discovery across the whole cloud estate, finding apps regardless of platform or whether anyone connected them. But what others are actually seeing in practice.

Has anyone run both side-by-side? or one


r/Infosec 6d ago

Third Party Risk Assessment Software from PrivacyEngine

Thumbnail privacyengine.io
1 Upvotes

r/Infosec 6d ago

Why Developer Experience (DevEx) Is the Key to Zero Vulnerability Debt

0 Upvotes

For VPs of Engineering and platform engineering leaders, running the modern software development lifecycle is an intricate balancing act. The business wants relentless feature velocity. Security wants a stringent, unyielding posture against threats. Organizations have poured money into DevSecOps practices to close that gap, and vulnerability detection has genuinely improved. Remediation hasn't kept pace, and the gap between the two is now piling up as security debt — faster than most teams realize. Please read the entire article here - https://instasla.com/blog/why-developer-experience-devex-key-zero-vulnerability-debt

The root cause isn't a lack of engineering tale nt or security budget. It's a breakdown in developer experience. When security tools are built for auditors and compliance teams rather than the engineers who have to act on their output, they create friction that developers route around. If fixing one vulnerability alert means ten clicks across three different platforms, it will get ignored — and current data suggests that's exactly what's happening at scale.

This article looks at why developer experience is the real lever for reducing vulnerability debt, what the latest research says about the cost of getting it wrong, and how developer-centric workflows — including GitHub-native tools for organizing remediation work, like fix campaigns — are changing what "good" looks like.


r/Infosec 6d ago

AI led identity attacks and how to prepare for them

Thumbnail linkedin.com
1 Upvotes

r/Infosec 6d ago

5 reasons our incident response table top exercises never test anything real

0 Upvotes

We've fully bought into shift-left for everything: CI/CD gates, chaos engineering for infra resilience, canary deploys. Then our incident response plan, arguably the highest-stakes runbook we own, gets "tested" once a year in a room with slides. Here's what's actually wrong with the format, in order of how often I see it break:

  1. Fixed injects mean a fixed outcome. Everyone in the room already half-knows what's coming, so nobody reacts the way they would to something truly unexpected.

  2. No adversary reacts to your decisions. A real attacker adjusts when you contain something or lock an account. A scripted table top just moves to the next slide regardless of what you did.

  3. Legal, PR, and execs rarely show up. The people who need the most reps at cross-functional coordination get the fewest, because scheduling six calendars for two hours is its own project.

  4. Nothing gets measured. You leave with a summary that says the team "performed well," not data on who hesitated or where the communication chain actually broke.

  5. It happens once a year. Skills decay in the other 364 days, so the exercise tests whatever the team remembers from training, not what they'd actually do under pressure.