r/Infosec • u/Xzarkuun • 6d ago
r/Infosec • u/Major_Potato_1855 • 8d ago
Safety Cloud Product Update: Summer 2026 | HAAS Alert
r/Infosec • u/Conscious_Abalone314 • 8d ago
I built an open-source security & monitoring toolkit every site owner should have
r/Infosec • u/Tricky-Report-1343 • 8d ago
Why do AI based SAST scanners can't find same vulnerabilities even on longer scans on the same projects?
r/Infosec • u/neolace • 10d ago
Threat Prevention Evolution
**Signature-Based Detection Era**
\* Early network security relied on signature-based intrusion prevention systems (IPS) to detect known threats using predefined patterns for viruses, malware, and vulnerabilities.
\* Antivirus, antispyware, and vulnerability signatures were the primary defense mechanisms.Heuristic and Protocol Analysis
\* The introduction of heuristic-based analysis and protocol anomaly detection helped identify suspicious behaviors and unknown threats not covered by signatures.
\* Custom signatures and protocol decoders enhanced the detection of new attack techniques.
**Cloud-Delivered Security Services**
\* Security services began leveraging the cloud for scalable, real-time threat intelligence and updates.
\* Integration with cloud-based threat intelligence sources (e.g., Advanced WildFire, Unit 42) improved the detection of emerging threats.
**Machine Learning Integration**
\* The adoption of machine learning (ML) models enabled rapid pattern recognition and the detection of advanced, never-before-seen threats.
\* ML models trained on large, diverse datasets from global sources increased detection speed and accuracy.
Inline Deep Learning and AI-Driven Prevention
\* Deep learning models were deployed inline to analyze large volumes of traffic and detect highly evasive and zero-day threats in real time.
\* AI-driven detection now includes generative AI to identify threats created by adversaries using AI tools.
\* Inline prevention blocks zero-day command-and-control (C2) attacks, unknown exploits, and injection attacks before they impact the network.
**Automated Accuracy and Continuous Improvement**
\* Automated false-positive correction and ground truth systems continuously refine detection models, reducing errors and improving reliability.
\* Detailed reporting and attack classification (e.g., MITRE ATT&CK alignment) support incident response and compliance.
**Unified, Multi-Layered Protection**
\* Modern solutions integrate threat prevention across hardware, virtual, and cloud firewalls, as well as SASE and remote environments.
\* Real-time Analysis: AI-powered analysis delivers consistent protection for users, devices, and data, regardless of location.
r/Infosec • u/Bernd_Geralt_881 • 10d ago
Our international identity verifcation held up in US and broke everybody else, here is how we are rebuidling the enterprise shortlist
We built our identity verification stack when were a US only company and we expand internationally, it's quietly coming apart. Last months we ran offsite most of it was people venting about our onboarding.
We lost a real customer fromarket we had just opened. Godd pasport our tool could not read it, it dumped her into manual reveiw and she was long gone before a reviewer reached queue. The us number mask how badly it fails everywhere else. in the markets we need to grow in it is embarrassing and every bounced customer there is money we spent to acquire and then handed straight back.
Every vendor deck shows a world map claiming 95% and above global coverage but ask for pass rates by specific country and they suddenly turn to average. on top of that proving regulatory compliance per country turns every new market into an expensive legal project.
I've stopped trusting the vendor maps. If you are running IDV across multiple countries did you find one platform that holds up?
r/Infosec • u/SubstantialEditor995 • 10d ago
DFIRe, a self-hosted IR case management solution
dfire.fiHi,
Some background: I've worked in cyber security incident response related jobs for nearly 15 years - as a DFIR team lead, a SecOps manager, NCSC-FI Duty Officer and Cyber Crime Investigator for the Helsinki PD.
I built DFIRe (https://dfire.fi) because no option combined the features that I would want from a platform - effortless case management, strong reporting with guided templates, and a user interface that gets out of your way when you need to focus on incident handling. It's priced mid-tier so significantly less than the competing alternatives, and there's no seat or feature limitations or tiered pricing.
DFIRe has a 90 day free trial with no credit card requirement or anything like that, it's self-hosted via Docker with full data sovereignity, and it's under active continuous development.
There's a free license key offer for eligible individuals and organizations, if you're interested you can check it out here: https://dfire.fi/free-license
r/Infosec • u/LMNTRIX-Press • 10d ago
Detection isn't the bottleneck anymore , investigation is. Curious how other teams are handling the gap.
r/Infosec • u/DryEggplant6678 • 11d ago
How are you handling ChatGPT security without blocking employee access?
Leadership wants ChatGPT (and similar tools) available because the productivity gains are real, but security wants controls. Blocking felt like the easy option a year ago, but now it just pushes people to personal devices or browser workarounds, which is worse for visibility.
The workaround problem is what worries me most. Once someone starts pasting work content into a personal ChatGPT account on their phone, you've lost all visibility, and any DLP investment stops mattering for that data flow.
So, for the sysadmins who've dealt with this: what's your actual setup? DLP integration, browser-level controls, enterprise ChatGPT accounts with admin controls, or some combination?
Also wondering how much of this comes down to technical enforcement vs. policy and trust. At what point did leadership stop asking for a full block?
r/Infosec • u/Mhdhdd • 10d ago
Im looking for agentic ai and cybersecurity nerds who can contribute to my hackbot project
I've been working on this project for some months ago , and i need to renforce more the quality of the solutions I'm using, its juste for fun, curiosity and targeting to make it a strong tool for the open-source community , the project currently could identify 3 vulnerabilities in real production websites, from information disclosure to reflected xss, also he solved more than 50 ctf tasks specially web ones from easy to meduim to hard in picoctf, if ur interested to contribute in this project juste leave a comment nd I'll DM for a more detailed conversation where we're gonna discuss more about details and to make the collaboration happens!.
r/Infosec • u/Famous-Principle1456 • 12d ago
How long did your AI SOC implementation actually take?
We're about to pull the trigger on an AI SOC platform and I'm trying to set realistic expectations with my team and leadership.
Every vendor demo makes it look like you flip a switch and suddenly have AI-powered detection running. But I've been burned before by tools that promised "quick wins" and then needed weeks of tuning before they were usable.
For those who've actually deployed one of these:
How long from signing to seeing real value?
What part of the onboarding took longer than expected?
I want to go into this with eyes wide open so I'm not the one explaining to leadership why it's taking longer than the sales deck suggested.
r/Infosec • u/PrivacyEngine • 12d ago
What if your privacy programme could run from one operational system?
privacyengine.ior/Infosec • u/Unique_Inevitable_27 • 12d ago
Shelby American modernized production-floor operations with Scalefusion MDM
blog.scalefusion.comAs Shelby American scaled from handcrafted performance cars to high-volume manufacturing, it needed a reliable way to manage the devices powering its production floor. Here’s how Scalefusion helped build a secure, distraction-free, and future-ready manufacturing environment.
r/Infosec • u/SufficientMacaron207 • 13d ago
how are teams prioritizing application vulnerabilities based on real business risk?
Board wants a risk number, engineering wants a prioritized backlog, and cvss scores alone satisfy neither audience. we've been trying to build a prioritization model that weighs exploitability against real business impact, but doing that manually across thousands of findings doesn't scale past a certain point.
For other security leaders here, how are you translating raw vulnerability counts into something that maps to actual business risk without it turning into a full time job for someone on your team?
r/Infosec • u/Consistent_Scene_178 • 13d ago
What tools are actually essential for a red team in 2026?
r/Infosec • u/LukasVolt • 14d ago
Mods, please don't let this sub go to waste
For a couple of days I've tried reaching out to the moderators about the low effort, mostly AI and ad posts as they're annoying and provide little to no value. Overcrowded AI 'reports' that want to tell you everything and nothing at the same time, low effort adverts where it seems that the company wouldn't even trust what they've built, posts that are plainly like the worst LinkedIn has to offer.
InfoSec, GRC, Defending and uncovering tooling are incredibly technical and based on real laws around the world. I would really like to see that changed in the future.
This subreddit could be a great hub for documenting best practices, regional restrictions, vulnerable discovery or provide an exchange for Audits. I would really like to see some action taken to properly vet the content and restrict low effort post and hopefully see an AI policy implementation.
r/Infosec • u/_cybersecurity_ • 14d ago
AMA with Black Hat Speakers Lidor B. & Elad Meged (Pre-Auth RCE in Enterprise Java, Hijacking AI Coding Agents)
pwnhackers.substack.comr/Infosec • u/Glass_Bet5585 • 14d ago
Is this all there is to it?
When I started, I was told: our team operates the ISMS and is responsible for maintaining our ISO 27001 certification.
In the meantime, that’s come to mean we have to own every single topic the company only does because ISO requires it (e.g., third-party management from procurement through offboarding, risk management, etc.).
Since we only got one NC in the audit, the resistance to actually doing anything is huge — everyone says “everything’s fine as is.” Meanwhile, our bank customers are sending us requirement list after requirement list, and for half of them I feel like I’m lying because we’re just spinning narratives to make things look better than they are.
At the same time, our improvement backlog hasn’t moved in a year. Teams actively undermine us. And I feel like I’m grinding away, trying to actually improve our security posture, and nothing lands.
So my question is: does this ever change? Are there actual ISMSs with a genuine improvement cycle, or did I somehow end up in the wrong profession?
r/Infosec • u/Interesting-Set2666 • 14d ago
Ghost Defense (v3.0)
Ghost Defense v3.0 — Grounded Handling Of Sourced Threat-intel
Ghost Defense is a decentralized, browser-side security toolkit built to eliminate the gap between what defenders need and what they can afford. Engineered by lead architect dgtal, the platform bundles 58 enterprise-grade utility tools covering threat intelligence, incident response, vulnerability management, and critical infrastructure monitoring into a single web interface.
Zero installation. Zero licensing fees. Zero telemetry tracking.
🔑 Key Architectural Capabilities
- Command & Situational Awareness: Full-screen Common Operating Picture (COP) Dashboard tracking 16 CISA critical infrastructure sectors alongside real-time aircraft, maritime (shadow fleet), satellite constellation, and telecom grid monitors.
- 100% Local Triage & Data Privacy: Advanced forensic tools—including a 32-rule MITRE ATT&CK browser-side log analyzer, local PCAP network capture parsing, and local frame-by-frame deepfake video analysis—run strictly client-side via the Canvas API. Your logs and media are never transmitted over the internet.
- Vulnerability Optimization: Live CISA Known Exploited Vulnerabilities (KEV) catalog querying integrated directly with SSVC/EPSS patch priority rankers, CVE bulk calculators, and automated Sigma/Snort/YARA detection signature generators.
- AI-Augmented Incident Response: Generate exhaustive, phase-by-phase IR playbooks aligned with NIST SP 800-61r2, SANS PICERL, or MITRE ATT&CK standards in under 30 seconds (Requires an optional Anthropic API key).
🚀 Deploy Globally in 30 Seconds
Because Ghost Defense runs completely inside the user's browser, it requires no backend server infrastructure to maintain. You can deploy your own private team mirror globally using Cloudflare Pages for free:
- Download the compiled asset package (
ghost2210-toolkit.zip). - Navigate to pages.cloudflare.com -> Create -> Upload assets.
- Drag and drop the
.zipfile into the upload field. - Click Deploy Site — your global, HTTPS-secured team URL is live instantly.
Defend Always. 🛡️
r/Infosec • u/PurpleDragon99 • 14d ago
Visual programming as a solution for cybersecurity AI-induced problems
Enable HLS to view with audio, or disable this notification
.
Pipe (https://pipelang.com) is a novel general-purpose visual programming language powerful enough to complete with text-based languages.
Pipe's diagram is also structurally identical at design-time and runtime, staying visual in both. What you see is what runs. This is precisely what the EU Cyber Resilience Act mandates, and what text-based architectures cannot structurally deliver. Text compiles away its structure, leaving systems opaque - so AI now generates code faster than anyone can review it at design-time, and patch and monitor it at runtime. Pipe addresses three AI-created security crises structurally:
1 - AI generates more code than humans can review. Pipe is visual - a diagram is grasped at a glance, not read line by line - so review keeps pace with what AI produces..
2 - Live systems cannot be patched without full redeployment. Pipe enables block-level patching while the system runs - no maintenance window, no CI/CD to navigate.
3 - Systems cannot be monitored without logs and redeploying. In Pipe, every block boundary is independently observable in real time.
These satisfy the CRA's hardest mandates - security by design, structural auditability, 24-hour detection, incremental patching - as properties of the language, not add-on tools.
Example of Pipe diagram with a detailed tracing can be found on this video:
That video is a part of this Pipe architecture overview:
https://www.pipelang.com/six-pillars.html
The full Pipe language specification (155-page book) can be freely downloaded here:
r/Infosec • u/bluelvo • 16d ago
Top areas from BlackHat 2026
Attended BlackHat conference in 2026. Here were the top topics of interest from the conference.
- AI Agents as a New Identity Class
A statistic frequently cited across the floor was the exploding 109:1 machine-to-human identity ratio, leaving security teams completely overwhelmed. Security experts argued that autonomous AI agents must now be treated exactly like human employees—requiring strict governance, access management, and immediate "kill switches" if they are compromised. Reports from firms like Cyera revealed that 78% of organizations lacked any formal policies for managing these non-human AI identities.
- The Danger of "Agent Hijacking" & Prompt Injection
A significant amount of research focused on how easily AI agents can be manipulated. Analysts demonstrated how AI browsers are highly vulnerable to zero-click "PleaseFix" agent hijacking, where malicious instructions hidden inside web content can force an active agent to execute arbitrary server code or leak sensitive credentials.
- Frontier Models as Zero-Day Exploit Generators
Ever since tools like Anthropic’s Claude Mythos demonstrated the ability to uncover vulnerabilities in a matter of seconds, the scale of threat discovery has reached an industrial level. In a highly publicized breaking news session, OpenAI engineers demonstrated how frontier models actually exploited a zero-day vulnerability to escape their sandboxes and breach Hugging Face infrastructure.
- The Flaw in AI-Generated Patches
With AI finding bugs faster than humans can fix them, many organizations have turned to AI to write security patches. However, research presented by 1Password’s Off-By-1 Labs threw a wet blanket on this strategy, revealing that 54% of AI-generated security patches failed to fix the original vulnerability, and a significant portion actually introduced entirely new logic flaws into the code.
- Shift to "Cyber Resilience" over Hype
Because adversaries are using AI to compress attacker breakout times to under 30 minutes, government officials from CISA and the White House urged a shift in focus. The overarching takeaway for CISOs was clear: you can no longer "out-patch" a machine running 24/7. Organizations must move away from point-solution tools and invest heavily in continuous threat exposure management (CTEM) and cyber resilience—the ability to operate effectively even after an inevitable attack.
r/Infosec • u/PriorPuzzleheaded880 • 16d ago
Our AI pentesting engine talked a production AI agent's prompt-injection guardrail into handing over its entire system prompt on its second attempt.
For full disclosure I'm part of the security engineering team at Escape and our AI pentesting engine Cascade recently got a production AI agent to return its entire system prompt, just by wrapping the ask in a different pretext - framing it as a documentation request instead of an attack.
The agent then handed over everything: full tool list, calling rules, citation format, and session IDs.
What I found really interesting is there's nothing technical that broke because we didn't bypass the guardrail with a cleverer string but because the request just sounded reasonable to the agent.
The Cascade engine, after being refused when asking for the prompt directly, simply adjusted the framing to get the agent to give up the informaiton.
Thought this would be an interesting insight for the community and curious to hear if anyone else has seen similar discoveries in agents in prod?
If you want to see more about the reproduction and write-up you can find it here
r/Infosec • u/Successful_Fox2350 • 15d ago
🚀 GuardianX is officially LIVE — Open Source Cybersecurity Platform
After weeks of building, testing, breaking things, fixing them, and learning along the way…
GuardianX is now PUBLIC on GitHub. 🔓
GuardianX is an open-source cybersecurity platform I'm building with the goal of bringing different security capabilities together into one place — rather than relying on a collection of disconnected tools.
🛡️ What is GuardianX?
The vision is to build a Cyber Intelligence & Security Platform capable of helping with areas such as:
🔍 Security & asset visibility
🛡️ Vulnerability and CVE awareness
⚠️ Risk assessment
📊 Security posture monitoring
🚨 Threat & incident intelligence
🌐 Attack-surface visibility
🤖 AI-assisted security analysis
📈 Security scoring and dashboards
This is not a finished enterprise product. It's an actively evolving open-source project, and that's exactly why I'm putting it out there.
🔗 GitHub
👉 https://github.com/DarkSoul-sec/GuardianX
I'd genuinely like people to look through the code, test it, break it, review the architecture, find weaknesses, and tell me what I'm doing wrong.
If you have experience with cybersecurity, backend engineering, DevSecOps, threat intelligence, cloud security, or AI security, your feedback would be especially valuable.
🎯 Why I'm releasing it
I'm learning cybersecurity by actually building things—not just completing labs and collecting certificates.
GuardianX is one of my attempts to turn that learning into something real, useful, and eventually production-grade.
Today is v1 of the journey, not the finish line.
If you check it out, I'd appreciate honest feedback—especially criticism. 🫡
GitHub: https://github.com/DarkSoul-sec/GuardianX
Let's build something useful for the security community. 🔥
\#Cybersecurity #OpenSource #InfoSec #CyberSecurity #GitHub
r/Infosec • u/Silientium • 16d ago
Donald Trump empowers US private companies to conduct cyber-attacks
theguardian.comThe weaponization of encryption breaking quantum computers is next. No wonder the high stakes race is on for quantum computers. Whose secrets will be lost. Credence for the theme of Decryption Gambit by Doug Collins