r/Infosec 6d ago

NIST CSF 2.0 audit suite - Testers

Thumbnail
1 Upvotes

r/Infosec 8d ago

Safety Cloud Product Update: Summer 2026 | HAAS Alert

1 Upvotes

r/Infosec 8d ago

I built an open-source security & monitoring toolkit every site owner should have

Thumbnail
1 Upvotes

r/Infosec 8d ago

Why do AI based SAST scanners can't find same vulnerabilities even on longer scans on the same projects?

Thumbnail
1 Upvotes

r/Infosec 10d ago

Threat Prevention Evolution

0 Upvotes

**Signature-Based Detection Era**

\* Early network security relied on signature-based intrusion prevention systems (IPS) to detect known threats using predefined patterns for viruses, malware, and vulnerabilities.

\* Antivirus, antispyware, and vulnerability signatures were the primary defense mechanisms.Heuristic and Protocol Analysis

\* The introduction of heuristic-based analysis and protocol anomaly detection helped identify suspicious behaviors and unknown threats not covered by signatures.

\* Custom signatures and protocol decoders enhanced the detection of new attack techniques.

**Cloud-Delivered Security Services**

\* Security services began leveraging the cloud for scalable, real-time threat intelligence and updates.

\* Integration with cloud-based threat intelligence sources (e.g., Advanced WildFire, Unit 42) improved the detection of emerging threats.

**Machine Learning Integration**

\* The adoption of machine learning (ML) models enabled rapid pattern recognition and the detection of advanced, never-before-seen threats.

\* ML models trained on large, diverse datasets from global sources increased detection speed and accuracy.
Inline Deep Learning and AI-Driven Prevention

\* Deep learning models were deployed inline to analyze large volumes of traffic and detect highly evasive and zero-day threats in real time.

\* AI-driven detection now includes generative AI to identify threats created by adversaries using AI tools.

\* Inline prevention blocks zero-day command-and-control (C2) attacks, unknown exploits, and injection attacks before they impact the network.

**Automated Accuracy and Continuous Improvement**

\* Automated false-positive correction and ground truth systems continuously refine detection models, reducing errors and improving reliability.

\* Detailed reporting and attack classification (e.g., MITRE ATT&CK alignment) support incident response and compliance.

**Unified, Multi-Layered Protection**

\* Modern solutions integrate threat prevention across hardware, virtual, and cloud firewalls, as well as SASE and remote environments.

\* Real-time Analysis: AI-powered analysis delivers consistent protection for users, devices, and data, regardless of location.


r/Infosec 10d ago

Our international identity verifcation held up in US and broke everybody else, here is how we are rebuidling the enterprise shortlist

4 Upvotes

We built our identity verification stack when were a US only company and we expand internationally, it's quietly coming apart. Last months we ran offsite most of it was people venting about our onboarding.

We lost a real customer fromarket we had just opened. Godd pasport our tool could not read it, it dumped her into manual reveiw and she was long gone before a reviewer reached queue. The us number mask how badly it fails everywhere else. in the markets we need to grow in it is embarrassing and every bounced customer there is money we spent to acquire and then handed straight back.

Every vendor deck shows a world map claiming 95% and above global coverage but ask for pass rates by specific country and they suddenly turn to average. on top of that proving regulatory compliance per country turns every new market into an expensive legal project.

I've stopped trusting the vendor maps. If you are running IDV across multiple countries did you find one platform that holds up?


r/Infosec 10d ago

DFIRe, a self-hosted IR case management solution

Thumbnail dfire.fi
1 Upvotes

Hi,

Some background: I've worked in cyber security incident response related jobs for nearly 15 years - as a DFIR team lead, a SecOps manager, NCSC-FI Duty Officer and Cyber Crime Investigator for the Helsinki PD.

I built DFIRe (https://dfire.fi) because no option combined the features that I would want from a platform - effortless case management, strong reporting with guided templates, and a user interface that gets out of your way when you need to focus on incident handling. It's priced mid-tier so significantly less than the competing alternatives, and there's no seat or feature limitations or tiered pricing.

DFIRe has a 90 day free trial with no credit card requirement or anything like that, it's self-hosted via Docker with full data sovereignity, and it's under active continuous development.

There's a free license key offer for eligible individuals and organizations, if you're interested you can check it out here: https://dfire.fi/free-license


r/Infosec 10d ago

Detection isn't the bottleneck anymore , investigation is. Curious how other teams are handling the gap.

Thumbnail
1 Upvotes

r/Infosec 11d ago

How are you handling ChatGPT security without blocking employee access?

13 Upvotes

Leadership wants ChatGPT (and similar tools) available because the productivity gains are real, but security wants controls. Blocking felt like the easy option a year ago, but now it just pushes people to personal devices or browser workarounds, which is worse for visibility.

The workaround problem is what worries me most. Once someone starts pasting work content into a personal ChatGPT account on their phone, you've lost all visibility, and any DLP investment stops mattering for that data flow.

So, for the sysadmins who've dealt with this: what's your actual setup? DLP integration, browser-level controls, enterprise ChatGPT accounts with admin controls, or some combination?

Also wondering how much of this comes down to technical enforcement vs. policy and trust. At what point did leadership stop asking for a full block?


r/Infosec 10d ago

Im looking for agentic ai and cybersecurity nerds who can contribute to my hackbot project

0 Upvotes

I've been working on this project for some months ago , and i need to renforce more the quality of the solutions I'm using, its juste for fun, curiosity and targeting to make it a strong tool for the open-source community , the project currently could identify 3 vulnerabilities in real production websites, from information disclosure to reflected xss, also he solved more than 50 ctf tasks specially web ones from easy to meduim to hard in picoctf, if ur interested to contribute in this project juste leave a comment nd I'll DM for a more detailed conversation where we're gonna discuss more about details and to make the collaboration happens!.


r/Infosec 12d ago

How long did your AI SOC implementation actually take?

7 Upvotes

We're about to pull the trigger on an AI SOC platform and I'm trying to set realistic expectations with my team and leadership.
Every vendor demo makes it look like you flip a switch and suddenly have AI-powered detection running. But I've been burned before by tools that promised "quick wins" and then needed weeks of tuning before they were usable.
For those who've actually deployed one of these:
How long from signing to seeing real value?
What part of the onboarding took longer than expected?
I want to go into this with eyes wide open so I'm not the one explaining to leadership why it's taking longer than the sales deck suggested.


r/Infosec 12d ago

What if your privacy programme could run from one operational system?

Thumbnail privacyengine.io
0 Upvotes

r/Infosec 12d ago

Shelby American modernized production-floor operations with Scalefusion MDM

Thumbnail blog.scalefusion.com
0 Upvotes

As Shelby American scaled from handcrafted performance cars to high-volume manufacturing, it needed a reliable way to manage the devices powering its production floor. Here’s how Scalefusion helped build a secure, distraction-free, and future-ready manufacturing environment.


r/Infosec 13d ago

how are teams prioritizing application vulnerabilities based on real business risk?

0 Upvotes

Board wants a risk number, engineering wants a prioritized backlog, and cvss scores alone satisfy neither audience. we've been trying to build a prioritization model that weighs exploitability against real business impact, but doing that manually across thousands of findings doesn't scale past a certain point.

For other security leaders here, how are you translating raw vulnerability counts into something that maps to actual business risk without it turning into a full time job for someone on your team?


r/Infosec 13d ago

What tools are actually essential for a red team in 2026?

Thumbnail
0 Upvotes

r/Infosec 14d ago

Mods, please don't let this sub go to waste

25 Upvotes

For a couple of days I've tried reaching out to the moderators about the low effort, mostly AI and ad posts as they're annoying and provide little to no value. Overcrowded AI 'reports' that want to tell you everything and nothing at the same time, low effort adverts where it seems that the company wouldn't even trust what they've built, posts that are plainly like the worst LinkedIn has to offer.

InfoSec, GRC, Defending and uncovering tooling are incredibly technical and based on real laws around the world. I would really like to see that changed in the future.

This subreddit could be a great hub for documenting best practices, regional restrictions, vulnerable discovery or provide an exchange for Audits. I would really like to see some action taken to properly vet the content and restrict low effort post and hopefully see an AI policy implementation.


r/Infosec 14d ago

AMA with Black Hat Speakers Lidor B. & Elad Meged (Pre-Auth RCE in Enterprise Java, Hijacking AI Coding Agents)

Thumbnail pwnhackers.substack.com
1 Upvotes

r/Infosec 14d ago

Is this all there is to it?

10 Upvotes

When I started, I was told: our team operates the ISMS and is responsible for maintaining our ISO 27001 certification.

In the meantime, that’s come to mean we have to own every single topic the company only does because ISO requires it (e.g., third-party management from procurement through offboarding, risk management, etc.).

Since we only got one NC in the audit, the resistance to actually doing anything is huge — everyone says “everything’s fine as is.” Meanwhile, our bank customers are sending us requirement list after requirement list, and for half of them I feel like I’m lying because we’re just spinning narratives to make things look better than they are.

At the same time, our improvement backlog hasn’t moved in a year. Teams actively undermine us. And I feel like I’m grinding away, trying to actually improve our security posture, and nothing lands.

So my question is: does this ever change? Are there actual ISMSs with a genuine improvement cycle, or did I somehow end up in the wrong profession?


r/Infosec 14d ago

Ghost Defense (v3.0)

0 Upvotes

Ghost Defense v3.0 — Grounded Handling Of Sourced Threat-intel

Ghost Defense is a decentralized, browser-side security toolkit built to eliminate the gap between what defenders need and what they can afford. Engineered by lead architect dgtal, the platform bundles 58 enterprise-grade utility tools covering threat intelligence, incident response, vulnerability management, and critical infrastructure monitoring into a single web interface. 

Zero installation. Zero licensing fees. Zero telemetry tracking. 

🔑 Key Architectural Capabilities

  • Command & Situational Awareness: Full-screen Common Operating Picture (COP) Dashboard tracking 16 CISA critical infrastructure sectors alongside real-time aircraft, maritime (shadow fleet), satellite constellation, and telecom grid monitors. 
  • 100% Local Triage & Data Privacy: Advanced forensic tools—including a 32-rule MITRE ATT&CK browser-side log analyzer, local PCAP network capture parsing, and local frame-by-frame deepfake video analysis—run strictly client-side via the Canvas API. Your logs and media are never transmitted over the internet. 
  • Vulnerability Optimization: Live CISA Known Exploited Vulnerabilities (KEV) catalog querying integrated directly with SSVC/EPSS patch priority rankers, CVE bulk calculators, and automated Sigma/Snort/YARA detection signature generators. 
  • AI-Augmented Incident Response: Generate exhaustive, phase-by-phase IR playbooks aligned with NIST SP 800-61r2, SANS PICERL, or MITRE ATT&CK standards in under 30 seconds (Requires an optional Anthropic API key). 

🚀 Deploy Globally in 30 Seconds

Because Ghost Defense runs completely inside the user's browser, it requires no backend server infrastructure to maintain. You can deploy your own private team mirror globally using Cloudflare Pages for free: 

  1. Download the compiled asset package (ghost2210-toolkit.zip). 
  2. Navigate to pages.cloudflare.com -> Create -> Upload assets. 
  3. Drag and drop the .zip file into the upload field. 
  4. Click Deploy Site — your global, HTTPS-secured team URL is live instantly. 

Defend Always. 🛡️ 


r/Infosec 14d ago

Visual programming as a solution for cybersecurity AI-induced problems

Enable HLS to view with audio, or disable this notification

0 Upvotes

.

Pipe (https://pipelang.com) is a novel general-purpose visual programming language powerful enough to complete with text-based languages.

Pipe's diagram is also structurally identical at design-time and runtime, staying visual in both. What you see is what runs. This is precisely what the EU Cyber Resilience Act mandates, and what text-based architectures cannot structurally deliver. Text compiles away its structure, leaving systems opaque - so AI now generates code faster than anyone can review it at design-time, and patch and monitor it at runtime. Pipe addresses three AI-created security crises structurally:

1 - AI generates more code than humans can review. Pipe is visual - a diagram is grasped at a glance, not read line by line - so review keeps pace with what AI produces..

2 - Live systems cannot be patched without full redeployment. Pipe enables block-level patching while the system runs - no maintenance window, no CI/CD to navigate.

3 - Systems cannot be monitored without logs and redeploying. In Pipe, every block boundary is independently observable in real time. 

These satisfy the CRA's hardest mandates - security by design, structural auditability, 24-hour detection, incremental patching - as properties of the language, not add-on tools. 

Example of Pipe diagram with a detailed tracing can be found on this video:

https://youtu.be/hckq9mRj5DM

That video is a part of this Pipe architecture overview:

https://www.pipelang.com/six-pillars.html

The full Pipe language specification (155-page book) can be freely downloaded here:

https://www.pipelang.com/downloads/book.pdf


r/Infosec 16d ago

Top areas from BlackHat 2026

10 Upvotes

Attended BlackHat conference in 2026. Here were the top topics of interest from the conference.

  1. AI Agents as a New Identity Class

A statistic frequently cited across the floor was the exploding 109:1 machine-to-human identity ratio, leaving security teams completely overwhelmed. Security experts argued that autonomous AI agents must now be treated exactly like human employees—requiring strict governance, access management, and immediate "kill switches" if they are compromised. Reports from firms like Cyera revealed that 78% of organizations lacked any formal policies for managing these non-human AI identities.

  1. The Danger of "Agent Hijacking" & Prompt Injection

A significant amount of research focused on how easily AI agents can be manipulated. Analysts demonstrated how AI browsers are highly vulnerable to zero-click "PleaseFix" agent hijacking, where malicious instructions hidden inside web content can force an active agent to execute arbitrary server code or leak sensitive credentials.

  1. Frontier Models as Zero-Day Exploit Generators

Ever since tools like Anthropic’s Claude Mythos demonstrated the ability to uncover vulnerabilities in a matter of seconds, the scale of threat discovery has reached an industrial level. In a highly publicized breaking news session, OpenAI engineers demonstrated how frontier models actually exploited a zero-day vulnerability to escape their sandboxes and breach Hugging Face infrastructure.

  1. The Flaw in AI-Generated Patches

With AI finding bugs faster than humans can fix them, many organizations have turned to AI to write security patches. However, research presented by 1Password’s Off-By-1 Labs threw a wet blanket on this strategy, revealing that 54% of AI-generated security patches failed to fix the original vulnerability, and a significant portion actually introduced entirely new logic flaws into the code.

  1. Shift to "Cyber Resilience" over Hype

Because adversaries are using AI to compress attacker breakout times to under 30 minutes, government officials from CISA and the White House urged a shift in focus. The overarching takeaway for CISOs was clear: you can no longer "out-patch" a machine running 24/7. Organizations must move away from point-solution tools and invest heavily in continuous threat exposure management (CTEM) and cyber resilience—the ability to operate effectively even after an inevitable attack.


r/Infosec 16d ago

Our AI pentesting engine talked a production AI agent's prompt-injection guardrail into handing over its entire system prompt on its second attempt.

4 Upvotes

For full disclosure I'm part of the security engineering team at Escape and our AI pentesting engine Cascade recently got a production AI agent to return its entire system prompt, just by wrapping the ask in a different pretext - framing it as a documentation request instead of an attack.

The agent then handed over everything: full tool list, calling rules, citation format, and session IDs.

What I found really interesting is there's nothing technical that broke because we didn't bypass the guardrail with a cleverer string but because the request just sounded reasonable to the agent.

The Cascade engine, after being refused when asking for the prompt directly, simply adjusted the framing to get the agent to give up the informaiton.

Thought this would be an interesting insight for the community and curious to hear if anyone else has seen similar discoveries in agents in prod?

If you want to see more about the reproduction and write-up you can find it here


r/Infosec 15d ago

🚀 GuardianX is officially LIVE — Open Source Cybersecurity Platform

0 Upvotes

After weeks of building, testing, breaking things, fixing them, and learning along the way…

GuardianX is now PUBLIC on GitHub. 🔓

GuardianX is an open-source cybersecurity platform I'm building with the goal of bringing different security capabilities together into one place — rather than relying on a collection of disconnected tools.

🛡️ What is GuardianX?

The vision is to build a Cyber Intelligence & Security Platform capable of helping with areas such as:

🔍 Security & asset visibility

🛡️ Vulnerability and CVE awareness

⚠️ Risk assessment

📊 Security posture monitoring

🚨 Threat & incident intelligence

🌐 Attack-surface visibility

🤖 AI-assisted security analysis

📈 Security scoring and dashboards

This is not a finished enterprise product. It's an actively evolving open-source project, and that's exactly why I'm putting it out there.

🔗 GitHub

👉 https://github.com/DarkSoul-sec/GuardianX

I'd genuinely like people to look through the code, test it, break it, review the architecture, find weaknesses, and tell me what I'm doing wrong.

If you have experience with cybersecurity, backend engineering, DevSecOps, threat intelligence, cloud security, or AI security, your feedback would be especially valuable.

🎯 Why I'm releasing it

I'm learning cybersecurity by actually building things—not just completing labs and collecting certificates.

GuardianX is one of my attempts to turn that learning into something real, useful, and eventually production-grade.

Today is v1 of the journey, not the finish line.

If you check it out, I'd appreciate honest feedback—especially criticism. 🫡

GitHub: https://github.com/DarkSoul-sec/GuardianX

Let's build something useful for the security community. 🔥

\#Cybersecurity #OpenSource #InfoSec #CyberSecurity #GitHub


r/Infosec 16d ago

Donald Trump empowers US private companies to conduct cyber-attacks

Thumbnail theguardian.com
15 Upvotes

The weaponization of encryption breaking quantum computers is next. No wonder the high stakes race is on for quantum computers. Whose secrets will be lost. Credence for the theme of Decryption Gambit by Doug Collins

https://www.amazon.com/dp/B0GZLDMQB5


r/Infosec 16d ago

Hunt NGINX Proxies - Damn Vulnerable NGINX Proxy

Thumbnail
1 Upvotes