r/Information_Security 8h ago

When the Attacker Was An AI Cheating On A Test: What The Hugging Face Incident Means For Defenders

Thumbnail cisovoice.com
0 Upvotes

r/Information_Security 10h ago

Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI

Thumbnail varonis.com
2 Upvotes

r/Information_Security 16h ago

implementing user behavior analytics for enterprise security...where's the realistic starting point

6 Upvotes

we been tasked with standing up uba for our org and the amount of vendor noise around this makes it hard to figure out where to begin. so from what i can tell the real first step is establishing a behavioral baseline (normal login times, typical data access patterns, and so on) before you can flag anything as anomalous, which means you need a few weeks or months of clean data before the tool is doing anything useful.

also the other thing i keep running into is alert fatigue. every uba vendor demo shows a clean dashboard with a handful of high confidence alerts, but from what people tell me the reality in year one is a flood of false positives while the baseline tunes itself, and if your analysts aren't prepared for that they tune the whole thing out. for anyone who's run this rollout, how long did baselining realistically take before the alerts became trustworthy enough to act on without double checking everything manually?