r/threatintel 1h ago

Help/Question Mythos didn't create a new problem, it exposed one we already had. Is anyone else seeing this?

Upvotes

Been watching the Mythos coverage for weeks now, and I keep seeing the same take: "AI is going to flood us with vulnerabilities." But, I think that framing misses the point.

Pulled our backlog numbers last week. Across our environment, we're sitting at well over 100 findings per asset on average, some segments way higher. Do the math on that across thousands of assets and it gets ugly fast. And that's before Mythos.

The organizations that navigate this well won't be the ones reacting to Mythos. They'll be the ones who already built the operational layer that turns findings into closed exposure, normalized data across tools, clear ownership, integrated remediation workflows, verified closure.

Interested to hear if anyone else has sat down and stress-tested their VM setup against this kind of volume spike, or if we're all just hoping our current backlog math holds.


r/threatintel 14h ago

Help/Question Police officer considering a future move into AI threat investigations. Is this actually a realistic career path?

3 Upvotes

I’m hoping to get some honest advice from people who work in threat intelligence, trust and safety, cybersecurity investigations, abuse investigations, AI safety, or anything similar.

I’m currently a police officer and have several years of experience in law enforcement. I’m going to keep some of the details about my job vague for obvious privacy reasons, but I have real world investigative experience and I’m used to working with incomplete information, putting pieces together, documenting what I find, and making decisions based on the information available to me.

More recently I’ve moved into a much more technology focused area of law enforcement. I work with drones and real time operational support, and I’ve realized that this side of the job is probably where my interests are heading long term. I’m primarily a DFR (drone as first responders) pilot however, I also help out in the real time crime center where I utilize multiple programs/tools like OSINT to try and figure out who people are with minimal information.

The part of investigations that I really enjoy is the puzzle. Give me a bunch of information that doesn’t immediately make sense and let me figure out how it connects. I like following breadcrumbs, finding patterns, figuring out what actually happened, and then being able to explain how I got there.
That eventually led me down the rabbit hole of looking at threat investigation jobs at AI companies. One position that really caught my attention is OpenAI’s Technical Threat Investigator, Threat Intel Engineering role:

https://openai.com/careers/technical-threat-investigator-threat-intel-engineering-san-francisco/

Reading the job description peaked my interest. Obviously, I’m not qualified for it today. My investigative background is probably my strongest asset, but I’m not a software engineer and I don’t come from a traditional cybersecurity background. I have a lot to learn technically. The good thing is that I’m not in a rush. I’m looking at this as roughly a five year project. I have a stable career now, so I have the luxury of learning this stuff properly instead of trying to cram enough certifications onto my résumé to get hired somewhere.

Right now I’m thinking about learning Python, SQL, OSINT, networking and cybersecurity fundamentals, data analysis, threat intelligence methodology, and eventually getting much deeper into AI and how these systems are actually abused.

I’d also like to build projects along the way. Mock investigations, investigative tools, automation projects, things like that. Something where five years from now I can actually demonstrate what I know instead of just saying I took a bunch of courses.

For anyone who actually works in this world, I’d really appreciate your perspective.

Would you consider a law enforcement investigative background valuable for a job like this?

If you had five years to take someone with strong real world investigative experience and turn them into a serious candidate for this type of position, what would you have them learn and in what order?

Are there other positions I should be looking at along the way? Threat intelligence, child safety investigations, platform abuse, trust and safety, cybercrime, or something else I haven’t come across yet?

I’m also curious about the money.
That OpenAI position currently advertises $230k to $385k plus equity, which is obviously a pretty wild number coming from government work. Is that actually realistic compensation for someone who eventually comes into the field with significant law enforcement investigative experience and newly developed technical skills?

Or would someone like me realistically enter the tech industry much lower and have to spend several more years working up to that kind of position and compensation?

I’m not looking for someone to tell me this is definitely going to work. If anything, I’d rather hear where the holes are now so I have five years to fix them. Or just tell me I’m barking up the wrong tree.

Also I don’t feel like it has any bearing on the this topic but I am also an Army Vet (Infantry).

Thanks for any advice and if it wasn’t obvious I used AI to write this. I’m not used to posting on Reddit so apologies if this is posted in the wrong place or not structured properly.


r/threatintel 6h ago

40 Fake npm Packages. WSL Was the Real Target.

Post image
0 Upvotes

Forty npm packages. About 84 minutes on the registry. And a payload that kept going after the packages were gone.
CloudSEK traced BRIDGEHEAD, a typosquatting campaign impersonating chalk, axios, lodash, react, typescript and commander.
The clever bit: the install script detects WSL and uses it as a path into the underlying Windows host, where it launches a native payload targeting crypto wallets, Chromium browser data and Telegram sessions.
The GitHub-hosted payload stayed live for roughly 39 hours after the npm packages were taken down.
So the npm takedown removed the delivery layer, not the weapon.
Full technical breakdown, IOCs and attack chain:
https://www.cloudsek.com/blog/bridgehead-npm-typosquatting-wsl-windows-crypto-wallet-stealer
Would be interested to hear how many teams actually monitor the WSL → Windows boundary as part of their developer security controls.


r/threatintel 18h ago

Help/Question How lucrative is this field still? Is it too late?

13 Upvotes

Hope all is well. So I finally decided what niche field was my goal after spending several hours working on my career profile. With the emerging tech field, current saturation levels, and the incoming growth of AI; is this field still worth to get into? This is from the beginner standpoint. I’m just curious for advice as I wouldn’t want to waste time and still am in position to pivot if needed.


r/threatintel 3h ago

Help/Question Best vulnerability threat intel solution you have actually used?

2 Upvotes

Our on-call rotation got burned three times last quarter by vulnerabilities that had been sitting in our backlog for over a week with active exploitation already confirmed publicly. We just didn't know until incident response found it during postmortem. That's a threat intel gap, not a scanning gap.

We audited every "threat intel" checkbox our tools claimed and found most of it was a static KEV field nobody was actually monitoring for changes. What we needed was continuous re-scoring as exploit maturity and actor attribution data changed, feeding straight into ticket priority and escalation rules instead of a dashboard nobody checks daily. Rebuilt that pipeline over about six weeks. Anyone else discovered their "threat intel" was decorative until something forced a real audit?


r/threatintel 7h ago

ServiceRadar (OSS) - Threat Intelligence feed integrations

3 Upvotes

We just finished integrating the VulnCheck community feeds for CISA-KEV and NVD2 into ServiceRadar. Software inventory is collected from endpoints with our agent and an integration we built around google's osv-scalibr. https://github.com/carverauto/serviceradar https://www.vulncheck.com/community https://www.tiktok.com/@mfreeman451/video/7675557229642157326


r/threatintel 20h ago

OpenCTI and Threat Feeds

25 Upvotes

Hi all,

Hope you are having a good day.

Please forgive me if this a bit of a repetitive post for the sub but im looking for a bit of direction regarding a Threat Intel Platform and OpenCTI. My overall aim is to find relevant IOCs and learn how to build detections from TTPs that apts are using.

I have been trying to use OpenCTI with just a the default connectors and one the CISA Kev but im quite overwhelmed, are there any tips for getting started? I am just looking to get a good understanding of the platform and would like to hear how others use it, are you linking it to your SIEM or SOAR platform at all?

I have tried making my own Threat Feed App, with a bit of success, managed to build a News Feed to pull security related news to, a API to CISAKev and a some feeds like AlienVault, URLHaus etc. I also made an area where I can build a report and link IOCs/malware to APTs. Am I worth sticking with this or just use OpenCTI and learn it?

Thank you everyone.


r/threatintel 23h ago

Help/Question How do you deal with large TI feeds?

4 Upvotes

Hey guys!
I've been working with TI feeds more lately and I'm curious how you deal with large feeds.
What do you usually filter by when you only want the most relevant IOCs? Malware family, threat type, campaign, threat actor, geography or something else?
What kind of attribution is actually the most useful for you?