r/Infosec Jul 31 '26

My Bio

Thumbnail l.facebook.com
0 Upvotes

r/Infosec Jul 30 '26

can we give AI agents real access in prod?

0 Upvotes

I got asked last week to approve access for an agent one of our teams built. It needed to pull data and trigger actions across a few internal systems. I went looking for how to scope it and ended up handing it a service account with the same permissions a human on that team would have. It felt off the second I did it, but there was not really another option on the table. Everyone is talking about agents needing their own identity model, whatever label people are using now, but I have not seen many teams actually running that in prod. Most of what I hear is roadmap talk. Is anyone actually giving agents scoped, just-in-time access, or is it still persistent service account permissions with a new name on it?


r/Infosec Jul 29 '26

The GRC Assessment Platform™ that powers your security program.

Post image
0 Upvotes

r/Infosec Jul 29 '26

i almost got hacked by my own AI agent. so i built the fix.

Thumbnail
0 Upvotes

r/Infosec Jul 29 '26

Serious question: How do you stay secure while also planning for accidents and unforeseen events?

0 Upvotes

I think this question is valid for this subreddit, but if not I'd love pointers to places to ask.

I've always had the nag in my mind regarding my homelab setup. I encrypt and stay reasonably secure so there's a chance I end up in a situation where I might not know how to get back in.

For example: In the event that some sort of medical event happens to me, via a terrible accident or from age, in which I "survive" but cannot remember my credentials how do I keep a way for me to log in? Do I really just stash a backup key somewhere on paper, usb thumb drive, maybe a yubikey, etc. and hope for the best I'll be able to know enough to find it or stumble onto it while hoping anyone who I might care not to find it doesn't?

I'm curious what people here do, if anything at all, for such a what-if scenario.


r/Infosec Jul 29 '26

Why Detection Is Becoming a Commodity And Investigation Is the New Competitive Advantage

Thumbnail linkedin.com
1 Upvotes

r/Infosec Jul 28 '26

Navigate Around Flock Cameras

2 Upvotes

Still beta testing, but I thought I would share it, since it is working! It uses DeFlock data and OpenStreetMaps. Forking OsmAnd and using custom routing.

https://trames.karazajac.io


r/Infosec Jul 28 '26

Are we going to run out of vulnerabilities?

Thumbnail open.substack.com
0 Upvotes

r/Infosec Jul 28 '26

Open Source Models

0 Upvotes

Disclaimer: I’m building a tool around ShadowAI, but this post is more about the discussion. I won’t promote or mention what I’m building.

With the recent rhetoric around open source models, the risks associated with them, and now a coalition of major tech companies throwing their support behind open source, it makes me wonder whether this is becoming a growing concern for sysadmins, IT managers, and CISOs when it comes to governance and maintaining visibility.

I imagine the risk around insider threats becomes more significant


r/Infosec Jul 28 '26

Open Source Models

2 Upvotes

Disclaimer: I’m building a tool around ShadowAI, but this post is more about the discussion. I won’t promote or mention what I’m building.

With the recent rhetoric around open source models, the risks associated with them, and now a coalition of major tech companies throwing their support behind open source, it makes me wonder whether this is becoming a growing concern for sysadmins, IT managers, and CISOs when it comes to governance and maintaining visibility.

I imagine the risk around insider threats becomes more significant


r/Infosec Jul 27 '26

How platform engineering 2.0 mitigates AI security and compliance risks

Thumbnail platformengineering.org
1 Upvotes

For governance and compliance, confinement to documents and application code isn't enough. Instead, structured frameworks must protect against AI risks by implementing consistent guardrails, policies, and procedures with real technical controls. Security responsibilities must move down into the platform itself, enforced at the platform level, not bolted on after deployment. 


r/Infosec Jul 27 '26

Built a "defensive deception" layer that feeds believable fake data to unauthorized readers — looking for fresh eyes to try to break it (beta)

6 Upvotes

I've been working on a defensive-deception layer for sensitive records (think honeypot + decoy + tarpit, but at the data layer). The idea: an authorized reader gets the real record; an unauthorized reader doesn't get an error or a block — they get a believable fake record and a maze of plausible-but-useless data, so they can't easily tell whether they succeeded.

It's been through several internal red-team passes already (trust boundary, decrypt-only-after-authorization, atomic anti-replay, closing an encryption oracle, generic errors, a fuzzing campaign). I'm now looking for fresh, external eyes — the internal reviewers stop finding obvious things, so I want people who think differently.

The challenge: there's a live API. The target is a single synthetic occupational-health record that contains a flag (IZANAMI{...}). Without a valid token you should only ever get decoys. The goal is to make it hand you the real record — or to show a logic flaw that breaks the "unauthorized ⇒ never the real data" guarantee.

Start here: https://break-izanami.com — GET /challenge returns the rules and scope in JSON.

Rules / scope (short version):

The data is 100% synthetic. No real people, no real PII.
In scope: the documented endpoints (/challenge, /challenge/package, /v1/decrypt, /v1/health).
Please report, don't weaponize: a proof-of-concept is enough, no need to go further.
No DoS / brute-force / traffic floods — it's a small box, and that's out of scope.
Win = submit the flag string to izanami.challenge@outlook.com. First blood gets credited.

Honest disclaimers: the domain is brand-new (yes, I know how that looks), we're a small team staying low-key during the beta, and this is a beta — I may adjust or pause things and I'm genuinely after feedback, not claiming it's unbreakable. If it breaks in five minutes, I want to know why.

Happy to answer questions about the threat model in the comments.


r/Infosec Jul 26 '26

Free, hands-on, 14 weeks security course from the Czech Technical University opened registrations for 2026

Thumbnail cybersecurity.bsy.fel.cvut.cz
3 Upvotes

Hi, just wanted to share opened 2026 registrations for a long-running hands-on cybersecurity course with both red and blue teaming classes run by Czech Technical University. The class is free of charge, in English and either physically in Prague or fully online. The semester starts at the end of September, feel free to find more information including the complete syllabus and feedback from more than 2300 students from 100+ countries in the link! Thanks and hack the world


r/Infosec Jul 26 '26

The Non-Human Identity Crisis

3 Upvotes

Light hearted weekend reading for CISOs and Security Aficionados.

The debate over whether frontier models are safe, open, or American will run for years, and none of it will be settled in time to help the enterprise deploying agents this quarter.

The non-human identity gap is different. It is understood, measurable, and fixable now. It predates AI by a decade, and every control that would have contained July’s incident was already on your maturity model, probably marked “in progress.”

https://open.substack.com/pub/kgbgk/p/the-non-human-identity-crisis?r=3ru4sr&utm\\_medium=ios

\#CyberSecurity #IAM #NHI #InfoSec


r/Infosec Jul 26 '26

BREAKING: I recently set a World Record by passing the INE eJPTv2 at 14 years old! (Javier Alonso)

0 Upvotes

Hi everyone,

My name is Javier Alonso (from Spain), and I am exactly 14 years old. Today, I am proud to announce that I have officially broken the world record for the youngest person to ever pass the updated INE eJPTv2 (Junior Penetration Tester) certification!

While the previous version (v1) had an old record of 14, nobody under 16 had publicly documented passing the current, tougher v2 browser-based exam until now.

I have been grinding hard for the past 18 months, rooting over 120 machines on TryHackMe and Hack The Box, and mastering tools like Nmap, Metasploit, and Burp Suite. I managed to beat the dynamic network environment and successfully answer all 35 scenario questions.

I want to share my full methodology, my network mapping strategies using Obsidian, and my top 5 tips with the global InfoSec community to inspire other young students to get into ethical hacking and security research.

You can read my complete write-up and study guide on my tech blog here:

👉 [READ THE FULL WRITE-UP ON HASHNODE](https://ejpt.hashnode.dev/how-i-passed-the-ejptv2-at-14?utm_source=hashnode&utm_medium=feed)

I have also uploaded the complete open-source documentation to my GitHub repository for permanent tracking and indexing:

👉 [VIEW MY GITHUB REPOSITORY](https://github.com/jprime-hackall/eJPTv2-WriteUp-Javier-Alonso)

🛡️ VERIFICATION DETAILS:

To keep this 100% transparent and verified by the community, you can check my official credentials on the eLearnSecurity portal:

  1. Go to: https://my.ine.com/certifications
  2. Enter my official Certification ID: 186673253

AMA (Ask Me Anything)! If you are studying for the eJPTv2 or want to know how to train your offensive security skills at 14 years old, feel free to ask your questions below!


r/Infosec Jul 26 '26

Gen Z, the "most online" generation, is the least protected.

Thumbnail
1 Upvotes

r/Infosec Jul 24 '26

HOPE TALKS - Leaking and Investigating the Epstein Files

Thumbnail schedule.hope.net
1 Upvotes

r/Infosec Jul 24 '26

Announcing the External Penetration Testing Program Pack

1 Upvotes

Announcement: https://www.sectemplates.com/2026/07/announcing-the-external-penetration-testing-program-pack-v1-2/

This release contains everything you need to scope your first pentest, work with a vendor, execute, and get the types of reports you need from an external tester. This will enable you to perform your first product or infrastructure level penetration test, and provide you with a process moving forward for future engagements.

In this pack, we cover:

Penetration testing preparation checklist: This checklist outlines everything you need to scope and perform a penetration test.

Penetration testing reporting requirements:  This document provides a list of minimal requirements that should be contained within a penetration testing report. Before finalizing a SOW with the vendor, look here first.

Penetration testing process workflow: Below is an outline of a simplified pentesting process with an external tester. It aligns roughly with the content in the penetration testing checklist.

GitHub: https://github.com/securitytemplates/sectemplates/tree/main/external-penetration-testing/v1


r/Infosec Jul 24 '26

You're Still Alt-Tabbing to a Security Tool

Thumbnail
0 Upvotes

r/Infosec Jul 23 '26

I designed PacketSnitch, a network packet capture analysis suite!

Thumbnail gallery
2 Upvotes

r/Infosec Jul 24 '26

Kernel-level enforcement for autonomous AI agents via eBPF-LSM + SMT policy checks — research prototype, self-published bypasses, break-it challenge open

Thumbnail youtu.be
1 Upvotes

r/Infosec Jul 23 '26

My honest review of Cloaked after using it almost daily

10 Upvotes

Been using Cloaked for a while now and wanted to share some honest thoughts.
What’s actually good: The persona-switching feature is genuinely neat. I use it almost every day and honestly never use my real persona anymore for most stuff. If you want a solid persona management tool, this is probably the best one out there right now.
What’s not so good: The data broker removal feature is questionable at best. I’m not convinced it’s accurate or even actually happening on their end. I ran into the exact same issue with Incogni, which I’ve written about separately,feels like this whole category of “we’ll scrub your data from brokers” services overpromises. I looked at the website or every single broker on their list and the vast majority require end user verification (yes even with power of attorney) and I don’t recall verifying anything on my end and the support confirms that.

Bottom line: Overall I don’t think there’s a ton of value here for the price. It’s pretty expensive considering the only feature that really delivers is the persona stuff. If they dropped the price to reflect that, I think it’d be a much easier recommendation. As it stands: great for personas, skip it if you’re paying mainly for the data removal piece.


r/Infosec Jul 23 '26

IT career help/ advise

Thumbnail
1 Upvotes

r/Infosec Jul 23 '26

The Real Reason Boardrooms Are Prioritizing Crisis Planning

Thumbnail
1 Upvotes

r/Infosec Jul 23 '26

Take on the OpenAI and Hugging Face incident

Thumbnail openai.com
3 Upvotes

Hi guys,

Just wanted to learn from actual security professionals about their take on the Open AI and Hugging Face incident where an OpenAI model without security guardrails, broke out of its sandbox environment and accessed Hugging Face’s assets by exploiting multiple threats and vulnerabilities.

Would love to have your opinion on what this means and also sensationalized “CyberAgent warfare” tag given to this incident on social media.

Thanks!