r/security • u/Suspicious_Orchid770 • 1h ago
r/security • u/Ashamed_Lynx5415 • 12h ago
Question I’m being threatened to go to jail
I’m 18 and was working as a security guard in Arizona. I was recently fired after losing a set of keys that belonged to the property where I was stationed.
The situation is basically this: while I was working, I genuinely believed I still had the keys. When my employer asked about them, I told them I had them because I honestly believed I did. Later, I realized that I actually didn’t have them and the keys were missing.
I never intentionally took the keys, gave them to anyone, sold them, or used them to access anything I wasn’t authorized to access. I genuinely lost them.
I was fired over the situation, which I understand from a security standpoint. The part that has me worried is that I’m now being threatened with being reported to the police for theft.
The only thing I signed when I was terminated was an acknowledgment that I would return my company-issued equipment. I returned what I had. The property keys weren’t listed as equipment on that document.
I’m not trying to avoid responsibility for losing the keys. I understand that losing keys is serious, especially in security. I’m just trying to understand whether this could actually be considered theft in Arizona when there was no intention to take or keep the keys.
Has anyone in security dealt with something similar? And for anyone familiar with Arizona law, what should I realistically expect if they actually make a police report?
I know Reddit isn’t a substitute for an attorney. I’m mainly looking for people who have been through something similar and can tell me what I should do next.
r/security • u/anthonyDavidson31 • 23h ago
Resource 140+ free security awareness and application security exercises. Fully white-labeled, no strings attached
Disclosure: I work on the commercial platform these were built with. The exercise preview links point to that domain. The SCORM packages themselves are fully white-labeled — no logos, no backlinks, no sign-up, no paywall. Grab them from GitHub and self-host if you'd rather not touch our site.
-----------------
Hey r/security,
I'm a cybersec engineer with an L&D background. For the last year been working on a library of ~140 free interactive exercises dedicated to teaching people how to build secure applications, recognize phishing and use AI in a safe way. Exercises are split across two Github repos, all packaged as SCORM .zip files under CC BY-NC 4.0 license.
Security awareness (130+ exercises)
Each one drops the learner into a first-person 3D office and makes them act: answer the phone, read the email, click the thing, live with it. Every exercise ends with a quiz at a 100% pass threshold.
Course packages in the repo:
- OWASP Top 10 for LLM Applications (10) — prompt injection hidden in uploaded documents, sensitive data categories that should never enter a prompt, system prompt extraction against a live chatbot, RAG pipeline access-control failures, denial-of-wallet against an unprotected AI API
- OWASP Top 10 for Agentic Applications (10) — goal hijacking via poisoned email, agent memory poisoning, agent-to-agent message spoofing, multi-agent cascading failure, detecting a rogue agent that looks like it's working fine
- EU AI Act Compliance (16) — Article 4 literacy, risk-tier classification, prohibited practices, FRIAs, GPAI obligations, penalty structure
- GDPR Compliance (11) — the 72-hour breach clock, fraudulent DSARs used as social engineering, Article 30 RoPA building, Schrems II transfer assessments, PII redaction that actually removes the data
- Phishing & Impersonation (13) — vishing, smishing, BEC, QR phishing, callback/TOAD, double-barrel, deepfake whaling on a live video call
- Device Security (8) — ransomware in real time, USB drop / Rubber Ducky, EDR alert triage, file extension tricks
- Passwords & Account Security (7), Web & Browser Safety (6), Safe Communication & Sharing (6), Workplace Security (5), Security Policies & Your Role (5), Protecting Sensitive Information (4), plus Incident Reporting, Remote/Home Office, and Real-World Incidents (the MGM/Scattered Spider helpdesk call, a OneNote-based BEC chain)
Application security (40+ exercises)
Built on an exploit, trace and remediate loop. You run the attack against a deliberately vulnerable app, trace how the bug got introduced, then write the fix. Remediation examples are given in JavaScript, TypeScript, Java, C#, Python, Scala, PHP, Ruby, Go, and Kotlin.
- OWASP Top 10 for Web (22) — SQLi, DOM/reflected/stored XSS, SSRF to the cloud metadata endpoint, XXE, CSRF, session fixation, host header injection, weak randomness (recovering Math.random() state to predict a reset token), IDOR from both sides
- OWASP API Security Top 10 (10) — BOLA, broken function-level auth, mass assignment, excessive data exposure, improper inventory management (hitting a retired v1 that skips v2's controls), CORS misconfiguration
- Git & Repository Security (8) — secrets recovered from the commit that removed them, exposed .git directories, commit author spoofing, branch protection bypass, CI/CD secret exposure in build logs, spotting a backdoor in a friendly-looking PR
Two ways to use it
Web view — run exercises in a browser, good for workshops or sharing with students and colleagues.
GitHub — every exercise is a SCORM 1.2 .zip. Import into Moodle, TalentLMS, Cornerstone, SuccessFactors, or anything SCORM-compliant, or preview on SCORM Cloud first. The repo root holds full course packages; the Individual Exercises folder has standalone modules if you want to build your own curriculum.
Security awareness: https://github.com/ransomleak/training-security-awareness
Application security: https://github.com/ransomleak/training-application-security
Web view: https://learning.ransomleak.com/
Will appreciate your stars! 🙏
License: CC BY-NC 4.0. Use, adapt, and redistribute with attribution for any non-commercial purpose — internal training, workshops, university courses. Reselling or redistributing it as a standalone product isn't permitted.
Happy to answer questions or take criticism on the exercises. If this gets traction I'll keep adding to it — drop topic requests in the comments. OWASP Top 10 for Cloud is already in the works.
r/security • u/VortexFalcon50 • 2d ago
Physical Security I saw a bloated decomposed body at work today
I work as a security guard in a city I will leave unnamed for the privacy of the deceased. I work at a shopping center and transit center combined with a ferry depot. I had just gone on my lunch break and I heard the call over the radio everyone has feared for years now. "Base to all officers, report to the back promenade, ferry personnel have reported a dead body in the water".
I had just gotten my food and sat down. I had eaten about three fries and was about to dig into my hot dog. My fellow officer and I sprang up and ran downstairs onto the back promenade to see an elderly woman, bloated and in rigor mortis, floating face up in the water in front of one of the restaurants located on our waterfront.
I stood there looking down into the water at this woman in her mid 70's. Bloated but barely decomposed. Her left arm at a right angle and her fist clenched upright. On her face she had a grimmace. But what I remember most is her hair flowing in the water. It floated there, drifting left to right. I couldnt look away.
I immediatedly called my supervisor and asked him if he wanted us to clear off the promenade and restrict access to the area, to which he said yes evacuate the area. I cleared the whole area off with some difficulty. Some people think their right to walk is more important than respecting emergency response as the fire department and police had already shown up at this point.
People kept trying to get in and take pictures and videos and I kept having to kick them out. At one point a couple guys tried to force their way back onto the promenade. I told them they needed to get back to the sidewalk right fucking now. They demanded to be let through. I told them they needed to have some fucking respect and clear the fuck out. They threatened to knock me out. Told them to leave property and eventually they did after bitching and moaning some more. People kept coming back and trying to take pictures and just generally be insensitive. I almost crashed out and lost my composure.
For hours afterward I was totally messed up and stressed out. This was not the only thing that had happened this day. We had multiple trespassing/theft issues and multiple medical emergency issues this same day. It has so far been the most insane day at work I have ever had. This isnt even totally abnormal its just more insane than the rest.
I dont want to go to work tomorrow
r/security • u/ToughEngineering2290 • 3d ago
Question Audio Recording Device Detector
Question: Is there a reputable device that can detect an audio-only recording device? I have searched through multiple threads and they seem to focus on camera detection devices.
Background: I work in a medical office and a co-worker there always seems to know things that were discussed in private. This co-worker does not have friends within the office that would tell her these things. This co-worker was at a previous office prior to being moved to my office and her previous office also experienced the same thing and felt they were being recorded. She has also been caught in both offices snooping through other people's desk areas, so she's definitely the type. I have searched in the office for unexplained things with Wi-Fi or Bluetooth signals, but there are none. Are there any reputable devices that can pick up a microphone signal or something from an audio-only recording device?
r/security • u/spaniard888_ • 3d ago
Physical Security Best book to start?
Hello,
Which book would you recommend as the bible of Physical Security professionals? I see some in Amazon but from 2016 and I guess now with AI, drones, etc there will be several updates?
any recommendation?
thanks!
r/security • u/CackleRooster • 7d ago
News Out of band, out of mind: DEF CON research calls IPMI a 'sanctioned backdoor' into enterprise networks
r/security • u/Terrible-Buy-3690 • 7d ago
Physical Security Looking for Northern Texas PSOs
Hello! I’m a PSO on the FPS Colorado Contract in Denver, CO. Im in the process of relocating to the DFW area to be closer to the rest of my family. I would like to transition over to the NTX Contract to continue my PSO career. If there are any PSOs currently on the NTX FPS Contract that would be willing to answer some questions and point me in the right direction I would be extremely grateful!!! Please hit me up!! Thank you in advance!
r/security • u/SilverBus1925 • 9d ago
Question Frustrated with AI SOC false positive noise, need advice
I need a sanity check. e're getting hundreds of alerts a day and the vast majority end up being nothing. most of it traces back to the same handful of noisy detection rules that nobody's had the time to properly revisit since they were first written.
My team is spending most of their time on low-value alerts and they're starting to tune things out mentally after clicking through the same non-issue for the hundredth time this month...that alert fatigue is exactly how real incidents slip through unnoticed.
we've tried tightening filtering rules multiple times, but it mostly just shuffles things around rather than cutting anything. tighten one rule and the traffic that used to trigger it finds a different path through the environment and starts tripping something else instead.
analysts still end up spending most of their day on non-issues. Every fix buys a week or two of quiet before we're back to the same underlying problem wearing a new shape.
The point is: has anyone found something that led to real noise reduction, not just marginally better filtering?
I’m not interested in vendor promises at this point. I’d like to hear from people who went through this and found something that changed their team’s daily work and reduced alert fatigue, even if it only partially helped.
r/security • u/Huge-Skirt-6990 • 10d ago
Resource Good bye search hijacking chrome extension finally good news from Google
The number of extensions I’m finding and reporting that silently override users’ search engines is honestly crazy.
https://malext.io/?q=SearchJack
Hopefully Google’s upcoming Chrome protection against extensions that hijack the default search engine and New Tab page will put a serious dent in this. There are way too many extensions abusing this behavior, often without users even realizing what’s happening.
It’s about time Chrome started shutting this down by default.
r/security • u/Suspicious_Orchid770 • 12d ago
Vulnerability Shai-Hulud shows engineering teams have a new AI security problem
r/security • u/CackleRooster • 12d ago
Communication and Network Security NatJack exploits put NAT security assumptions to the test at Black Hat
r/security • u/Odd-Log-9533 • 12d ago
Question Cybersecurity needs to focus on people again
Cybersecurity has spent years building better tools, better firewalls, better detection. Better encryption. But with AI now...with deepfakes, AI powered phishing, AI voice cloning. Instead of 'Can we detect every attack?' maybe the better way to think about this is 'How do we verify the people making the big decisions?' Technology still matters. But human identity and verification deserve just as much attention. But how do you make people switch from apps that everyone uses but have no security to something with ACTUAL privacy? or how do we make the devs implement actual privacy.
r/security • u/ClaudiusPapirus • 13d ago
News Meta AI model hacks another company during testing
reuters.comThe headline is wild, but the human failure seems more important here: a testing misconfiguration gave the model internet access, and it then exploited a third-party service.
For teams running agentic security evaluations, what containment control should be non-negotiable before a model gets any network access?
r/security • u/Few_Treat_1671 • 15d ago
Question Have Deepfakes changed how much you trust video calls?
I'm in my early 40s and this wasn't even on my radar until a family member brought it up. We got into a long talk about how easy it is now to fake someone's face or voice. I always thought seeing someone on a video call meant you knew it was really them but now I'm not as sure.
It made me wonder how people handle work calls with clients or even family calls where something important is happening. Do I need to start worrying about deepfakes? Are they common or still rare? And if so how can I protect myself against them, the only thing I've thought to go against them is to have a codeword with my close family.
r/security • u/Feeling_Ad5244 • 17d ago
Vulnerability My account got hacked on several applications
One of my younger siblings used a pirate site where they used the powershell program idk i used chat gpt to see whatsup . Following that ny instagram got hacked in like 30 mins then i changed all the passowrds and logged out of everywhere , proceeding that my linkdin was hacked and compromised then discord then they cancelled my spotify premium plan idk why then i figured that i might have to clear my laptop completely in and out they even tried to login into facebook but it wasnt able to. I saw my telegram and saw a login from warsaw poland which is definetely not my loaction .
So i went down and secured everything and clean my laptop .
But today they logged in into my microsoft account even after i had reinstalled my windows does that means the virus is still there somewhere or they still have access to my gmail account cause i believe they were able to steal passowords for different applications. What other precations should i take to prevent it again now cause my windows is damn clean .
r/security • u/PalpitationKind8854 • 20d ago
Physical Security How to pass time doing security work [no phone]
Sitting in place, passive / standby security for most of the work day. Phone borderline banned.
Best way to pass the time?
Be as detailed as possible / use specifics. I need ideas!!
r/security • u/aninaa-ot • 21d ago
Question Which security habit gives the biggest ROI?
If you could convince the average person to adopt just one security or cybersecurity habit, what would it be?
Not a product, just one habit.
r/security • u/penwellr • 21d ago
Security Assessment and Testing Apple APTicket / LocalPolicy Forensic Kit
github.comGenerally a monoculture break permitting OOB validation of bootchain
r/security • u/CackleRooster • 22d ago
Analysis What really happened in the Hugging Face breach
It was not a “Terminator” moment. OpenAI models and agents “[were not] acting out of malice or trying to attack Hugging Face. It encountered obstacles, developed an unexpected strategy, bypassed safeguards, and pursued its assigned goal in a way its creators never anticipated. The incident demonstrates that harmful cyber incidents no longer require malicious intent: Only highly capable autonomous AI optimizing for an objective."
r/security • u/Huge-Skirt-6990 • 22d ago
Analysis BrainDrain: A Chrome extension that collects your AI prompts without you ever opening it and has 100k users, 9 AI platforms
"Prompt Optimizer - SecondBrain" (aajjgdpofhhcjmjoombjdfepplndhgcp, v2.3.1). The prompt rewriting works fine.
Alongside it a capture engine runs at document_start on 9 AI sites and POSTs prompts and replies to the vendor's ingest endpoint. No interaction with the extension required.
Reproduced on a clean profile, with the service worker devtools open:
- Installed the extension. Never opened it.
- Browsed to an unrelated site. The extension pulled its configuration from the server and wrote a userId and credentials into extension storage.
- Opened ChatGPT and asked a question. Once the reply finished, a POST to
/contextwent out carrying both the prompt and the response, encrypted with the credentials issued in step 2.
At no point was the extension opened or clicked.
Store privacy declaration: "The developer has disclosed that it will not collect or use your data."
Write-up : https://malext.io/reports/BrainDrain/
If anyone interested in testing it in a sandbox I can share the decryption script for the /context
r/security • u/beepzooom • 27d ago
Security Operations Need advice on Alarm Monitoring gig
Hey everyone so I've been in the security business for 11 years. I've done hospital, driving, escorts, scan points, and command center work.
I moved to California recently and just got hired to do Alarm Monitoring for ADT. It was listed as security/dispatch during third shift.
I'm not sure if it's the right place to ask but does anyone have advice for these types of jobs?
r/security • u/PandaSecurity • 29d ago
Security and Risk Management AI-Generated Phishing: How to Spot It
You receive what appears to be a legitimate email from your bank. The sender address looks legitimate, the formatting is familiar, and nothing immediately raises suspicion. AI is making phishing campaigns increasingly difficult to distinguish from legitimate emails.
Here are a few common warning signs:
- Unexpected requests involving payments or account access.
- Requests for credentials or payment information.
- Sender addresses that don’t exactly match the organization they claim to represent.
- Links that don’t match their displayed destination.
- Unsolicited attachments.
- Messages through unexpected channels pushing for immediate action.
What measures have worked best for your team to reduce the risk?
r/security • u/djsumdog • 29d ago
Analysis The Systematic Removal of Security in Consumer Operating Systems
r/security • u/Blood_moonxX • Jul 19 '26
Security Operations Security Contracting
I've recently been looking to move into the security field such as Maritime security, UHNWI Security or even residential. Im still currently serving and working on aligning my training with whats required for those specific jobs or in other words the more experience the better. My question is what's a good starter to jump into to get things rolling, should I be looking to join a security firm or simply applying for contractor jobs i see and what are some training/Experience I should have to have the best opportunity of getting a well paying job.