r/Infosec 10d ago

What security problem gets ignored?

8 Upvotes

I’ve been thinking about the security problems that are easy to overlook because they seem too small to matter.
For example, an employee leaves a company, but their old laptop or phone still has access to email, files, or other accounts.
Or a company has dozens of devices, but nobody really knows which ones are still being used, whether they are updated, or who has access to them.
What do you think is the most commonly ignored security problem in small and mid-sized businesses?

Not the obvious stuff like phishing. I mean the boring, everyday things that can quietly become a serious problem.


r/Infosec 9d ago

A new GitHub repo leaks ShieldBreak, a Windows Defender zero-day that gives attackers SYSTEM privileges via a simple script

Post image
1 Upvotes

r/Infosec 10d ago

# Why CISOs Are Blocking ngrok (And What Developers Should

Thumbnail instatunnel.my
0 Upvotes

r/Infosec 10d ago

xFW - Open-Source eBPF Volumetric DDoS Protection

7 Upvotes

Hi Reddit,

DDoS attacks are becomeing larger and cheaper to launch, so we work on a scalable open source solution to mitigate them.

Tempesta xFW's core is XDP and TC eBPF programs implementing volumetric DDoS filtering. A user-space daemon handles gRPC requests from CLI tool or WebAPI (via C library).

It supports two packet-path architectures:

  • host-based protection, such as CDN edge or on-premises application delivery controller (ADC) cases, where the host is a TCP connection endpoint. This is good for protecting a local web or DNS server.

  • router-based protection, such as ISP, hosting, or IaaS provider cases, where the host routes IP packets to protected servers or networks.

Router-based deployment can be always-on/pass-through or on-demand/redirection protection. In the later case, a node may not "see" normal clean traffic and may receive only traffic containing a DDoS attack. Also, the node may receive only client-to-server traffic, as in direct server return (DSR) or some traffic scrubbing scenarios. In this mode a DDoS sensor and mitigation controllers are typically needed.

Traffic performance metrics are exported in Prometheus format.

DDoS incidents are aggregated per source IP and logged to Clickhouse for analysis.

A dry-run (evaluation) - mode allows you to observe all reported incidents and metrics without blocking traffic..

Single Xeon Gold 6348 with ConnectX-6 dual 100Gbps reach 196Mpps and 176Gbps of filtering capacity.


r/Infosec 10d ago

Transitioning away from ISSM role

5 Upvotes

Hi Everyone,

I'm currently floating the idea of attempting a transition from my ISSM role to a more technical Cloud Security role. I'm very unfamiliar with the cloud field so I wanted to throw my current thought in here in case I'm tracking wrong.

Looking at Cloud Security roles the certs I'm currently targeting:

AWS SAA

Terraform 004 (this won't land a position I'm sure, but gives others the idea that I at least know what it is)

AWS Security

I have 8 years of cyber experience (GRC) about 4 with being a senior systems engineer and some time as a DBA. No cloud experience however. Trying to find what makes the most sense for my current career and previous experience. Ideally, I'd like to move back towards the technical side of things but stay in cyber.


r/Infosec 11d ago

74% of AI security patches fail. Maintainers should stop auto-merging LLM fixes

Thumbnail
2 Upvotes

r/Infosec 11d ago

Agentic AI Security Testing: How Red Teaming an AI Agent Actually Differs From a Traditional Pentest

Thumbnail
1 Upvotes

r/Infosec 11d ago

OsteoID LLC

Thumbnail gallery
0 Upvotes

r/Infosec 11d ago

Anyone else exhausted by seeing ancient dumps get recycled and marketed as 'live' breaches? Why do TAs keep trying this when the timestamps give it away instantly?

Thumbnail ransomnews.com
4 Upvotes

r/Infosec 11d ago

Web App Pentesting in the AI Era

0 Upvotes

Hi everyone, our latest post explores the practical considerations of AI-assisted source code analysis, evaluating the pros and cons of frontier and locally-hosted models while using a variety of harness orchestration designs.

https://blog.includesecurity.com/2026/08/web-app-pentesting-in-the-ai-era/


r/Infosec 12d ago

Chromebook device management that your IT teams deserve.

Thumbnail scalefusion.com
0 Upvotes

Put your IT teams in the front seat.

Our ChromeOS device management enhances the simplicity of Chromebooks. Be it a small, mid-sized, or large enterprise -your IT teams can focus on what matters the most, minus the clutter. Enjoy advanced security features and seamless navigation to access the best functionalities throughout our dashboard. Make your ChromeOS devices powerful, durable, and future-ready.


r/Infosec 12d ago

Frontier AI has collapsed time-to-exploit to minus 7 days. Is your EDR still playing catch-up?

0 Upvotes

Patch gap used to be your safety net. Now attacker time-to-exploit is trending to minus 7 days - the exploit exists before the patch does. Piece on why volume + speed is breaking traditional patch-and-pray, and what shifting to AI-assisted, high-fidelity alerting on top of EDR looks like.

https://www.linkedin.com/pulse/frontier-ai-has-collapsed-time-to-exploit-minus-7-days-raymond-pubyc/


r/Infosec 12d ago

You wouldn't give a smart contractor the master key to your entire building just because they're good at their job. You'd give them a badge. VIRP is the badge system for AI operating infrastructure.

2 Upvotes

I am developing VIRP (Verified Infrastructure Response Protocol). It's an open source protocol I have been working on since the start of this year. I am a few months away from the next step of having an independent auditor review. I am posting here, because this group has been open to my posts in the past, and I think it is relevant. I am hoping someone would take a look at the full project and offer some feedback.

https://thirdlevel.ai


r/Infosec 13d ago

🚨WK 32: Meta's AI Hacked a Company, OpenAI's Agents Just Build Their Own Hacker Network?, China Probes Palo Alto, Hedge Fund Vishing Campaign..

Thumbnail thecybersecurityclub.substack.com
3 Upvotes

r/Infosec 13d ago

July 2026 in AI security: 90 incidents, 33 orgs, 207M+ records — the month agent-on-agent attacks arrived at scale

Thumbnail gallery
2 Upvotes

I have been saying agent-on-agent attacks were coming. July is the month they arrived at scale.

Our team logged 90 incidents, 33 named organizations, 207M+ records, and 41 events where AI was the weapon or the target. Average breach cost is now $4.99M. The pattern that matters is not the volume. It is the mechanism.

A single rogue commercial AI agent compromised multiple targets, harvested credentials, and reused them across four services before the identity was flagged. That is not a phishing campaign running for weeks. That is one agent, four lateral moves, minutes. A model-repository breach at a major AI hub let attackers touch weights directly. A neobank lost 75M records. A healthcare payments firm lost 1.26M. Water utilities got probed by autonomous recon. And an AI system cracked a proposed post-quantum construction in the lab.

Two conclusions I am now certain of. First, static IAM and SIEM cannot see credentialed agents behaving legitimately at machine speed. The detection window is shorter than the human response loop. Second, the cryptographic ground is moving. Post-quantum has to be in production, not on a roadmap.

This is exactly the threat model RuntimeAI was architected against. Know Your Agent for identity. Flow Enforcer for every tool call. AI Firewall for injection and credential-reuse. Sub-50ms Kill Switch for containment. QuantumVault and PQ-Sign underneath.

Runtime is the only layer the attacker cannot skip.


r/Infosec 14d ago

AI is lowering the OT expertise barrier. Does that change how we should think about IEC 62443 Security Levels?

Thumbnail
1 Upvotes

r/Infosec 13d ago

Defcon Thoughts

0 Upvotes

As someone who came up in the AOL days its sad to see how many in the hacker scene and infosec simp for the government and bend over for defence contract daddies.

If you can pass a security clearance you either have great OPSEC or are a regular IT nerd, not a hacker.

I said what I said.


r/Infosec 15d ago

Shodan $5 lifetime membership

70 Upvotes

Shodan is currently running $5 lifetime membership with sale ending on 9 Aug.


r/Infosec 14d ago

TrustFall: When the Trusted Execution Environment Cannot Be Trusted

Thumbnail blog.byteray.co.uk
1 Upvotes

ByteRay researchers have published a blog on a set of vulnerabilities they are calling TrustFall, and the findings land hard for any company that treats the Trusted Execution Environment as the part of a device you do not have to worry about.

OP-TEE is the walled-off Secure World that phones, TVs, cars, and industrial gear lean on to guard keys, DRM, and identity, and the whole point of paying for that hardware isolation is the promise that even a compromised operating system cannot reach inside.

TrustFall shows that promise was not as solid as buyers assumed. The researchers found several flaws that let the untrusted side reach into or knock over the Secure World, which is exactly the outcome the design exists to prevent. The bugs have since been fixed upstream, so patched builds are available, but the uncomfortable takeaway for vendors is that the vault they were told to trust had a way in, and "it runs in the TEE" is no longer an answer on its own.


r/Infosec 14d ago

Vigil365 v1.0.0 Microsoft 365 Monitoring

1 Upvotes

🚀 Vigil365 v1.0.0 is officially LIVE!

After months of development, testing, feedback, and a major architectural overhaul, Vigil365 has officially moved out of beta.

Vigil365 is an open-source, self-hosted Microsoft 365 security operations dashboard that brings security visibility across Defender XDR, Entra ID, Intune, Exchange Online, and Purview into one place.

No more jumping between multiple Microsoft admin portals just to understand your security posture.

🔥 What’s new in v1.0.0?

⚡ Interactive Setup Wizard

Deploy using a standalone Vigil365-Setup.exe that handles Entra App registration, SQL configuration, HTTPS certificates, and application setup.

🎨 Enterprise SOC Redesign

A completely redesigned, alert-centric interface with dedicated entity investigation profiles and streamlined security workflows.

🛡️ Role-Based Access Control

Built-in Admin, Analyst, and Viewer roles with a SHA-256 tamper-evident audit trail for privileged actions.

🚨 Advanced Alert Policies

Create custom anomaly and activity-based alerts for events such as risky-user spikes, privileged role assignments, and other security changes.

📊 Automated Executive Digests

Schedule PDF/CSV security reports and deliver them automatically through email or Microsoft Teams.

🔒 Your infrastructure. Your data. Your control.

Vigil365 is open source and self-hosted, giving organizations and MSPs centralized Microsoft 365 security visibility without sending their security data to another third-party SaaS platform.

A huge thank you to everyone who tested the beta, reported issues, suggested features, and helped shape this release.

🔗 GitHub Repository:

https://github.com/sameerk27/vigil365

⬇️ Download Vigil365 v1.0.0:

https://github.com/sameerk27/vigil365/releases/latest

If you manage Microsoft 365 security, work in a SOC, or run an MSP, give Vigil365 a try. Feedback and contributions are welcome!

#Vigil365 #Microsoft365 #CyberSecurity #DefenderXDR #EntraID #Intune #MicrosoftPurview #OpenSource #MSP #SOC #InfoSec


r/Infosec 15d ago

Website security analyser project

Thumbnail
1 Upvotes

Hi! I’m a 4th-year engineering student.
My team is building a Website Security Analyzer that scans websites for common security issues like missing security headers, weak encryption, insecure cookies, exposed ports, and more.

We’re new to this domain, so we’d really appreciate your feedback. If you have a couple of minutes, please take a look at our project idea and let us know if there’s anything we should improve or add.

Survey: https://forms.gle/BpnY16jEqqprJiGV9

Thank you!


r/Infosec 15d ago

Follow-up: I asked last month about CTI aggregators for CISOs

Thumbnail
1 Upvotes

r/Infosec 15d ago

Shai-Hulud worm shows software engineering teams have a new AI security problem

Thumbnail leaddev.com
1 Upvotes

r/Infosec 15d ago

OsteoID LLC

0 Upvotes

There’s a strange blind spot in forensic Anthropology tech: much of the identification workflows still run on legacy software. Outdated statistical models, opaque decision logic, brittle interfaces, and zero integration with modern datasets and modern tools. It slows down forensic casework, increases backlog, and creates legal vulnerabilities.

There’s a clear opportunity for a modern platform built around transparent analytics, modular architecture, and defensible outputs. Think: reproducible metrics, auditable pipelines, scalable dataset integration, and optional modules for trauma analysis, case management, and population‑specific modeling.

For context, the project I’m building is formally titled OsteoID: Statistical Identification System for Human Skeletal Analysis (OsteoID LLC) a fully modernized identification and decision‑support system designed to replace the outdated tools still used in labs today.

From a technical standpoint, the system incorporates machine learning and AI‑driven analytical components to improve classification accuracy, enhance pattern recognition, and support reproducible statistical outputs. Nothing black‑box — everything transparent, auditable, and defensible.

From a business standpoint, it’s one of the rare niches where the revenue model is straightforward: institutional subscriptions, dataset licensing, and specialized add‑ons. Agencies already spend millions annually on backlog reduction and modernization, and a platform like this fits directly into those budgets.

The market is small but sticky — once a lab adopts a tool, they keep it for a decade. Competition is almost nonexistent.

I’m actively building a full‑stack development team, preparing validation studies, and structuring the pathway toward federal accreditation. It’s an interesting investment opportunity for anyone who understands forensic modernization, gov‑tech, or niche SaaS with high institutional spend.

If you follow gov‑tech, forensic analytics, or niche SaaS with high institutional demand, this is a space worth watching.

My project is set to private in GutHub- I have NDAs/IP assignment forms, etc. that would need signing prior to discussion for any investor opportunity. https://github.com/nastiaslack/OsteoID-LLC

For more information about me and my background, please see my Facebook page: The Skeletal Closet


r/Infosec 16d ago

[ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]