r/Information_Security • u/expert-insights • 7h ago
r/Information_Security • u/varonis-threat-labs • 9h ago
Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI
varonis.comr/Information_Security • u/loginsoft • 14h ago
AI Exploitability Index (AI-XI): A new metric for measuring real exploitability
r/Information_Security • u/Severe_Part_5120 • 15h ago
implementing user behavior analytics for enterprise security...where's the realistic starting point
we been tasked with standing up uba for our org and the amount of vendor noise around this makes it hard to figure out where to begin. so from what i can tell the real first step is establishing a behavioral baseline (normal login times, typical data access patterns, and so on) before you can flag anything as anomalous, which means you need a few weeks or months of clean data before the tool is doing anything useful.
also the other thing i keep running into is alert fatigue. every uba vendor demo shows a clean dashboard with a handful of high confidence alerts, but from what people tell me the reality in year one is a flood of false positives while the baseline tunes itself, and if your analysts aren't prepared for that they tune the whole thing out. for anyone who's run this rollout, how long did baselining realistically take before the alerts became trustworthy enough to act on without double checking everything manually?
r/Information_Security • u/No-Suggestion-4083 • 16h ago
WordPress new pre-auth RCE chain is already being exploited in the wild
r/Information_Security • u/Seahawker-One-2599 • 1d ago
A university once got DDoS'd by its own vending machines. How much are people here actually monitoring IoT device behaviour vs just securing the endpoint or guarding the perimeter?
r/Information_Security • u/OfficialLastPass • 1d ago
Research on the evolving ransomware landscape.
https://www.cybersecuritydive.com/news/ransomware-concentrated-ai-guidepoint/824828/
Ransomware activity increased 43% year over year in Q2 2026, with cybercriminals claiming breaches of more than 2,200 victims. While the number of ransomware groups continues to grow, researchers found that a small group of operators, including Qilin, The Gentlemen, Akira and DragonForce, accounted for a disproportionate share of attacks, creating what GuidePoint describes as a ransomware “four-headed monster.” Additionally, the report found that threat actors are increasingly leveraging AI tools to streamline activities such as data analysis, victim communications and ransom negotiations, rather than conducting entirely new AI-powered attack types.
r/Information_Security • u/VegetablesProof • 1d ago
What's a red flag that tells you a company doesn't really take security seriously, no matter what they claim?
Every company says security is a top priority. But you can usually tell within a few weeks whether they mean it or not. I think one of the clearest signs is when security only gets attention after an incident, something breaks and suddenly it's an emergency.
What's the red flag that makes you think a company is only pretending to care?
r/Information_Security • u/Academic-Soup2604 • 1d ago
There has been an interesting architectural shift in browsing trends...
Five years ago the conversation was:
"How do we secure internet traffic?"
Lately it's becoming:
"How do we enforce the same policy regardless of where the endpoint is?"
Feels like a subtle yet important change in how Secure Web Gateways (SWG) are evolving.
This detailed roundup compares the Best Secure Web Gateway Solutions for your reference.
r/Information_Security • u/socradario • 1d ago
Active exploitation reported for CVE-2026-6875 (Pre-Auth RCE in ServiceNow AI Platform)
r/Information_Security • u/Own_Mortgage2792 • 2d ago
Does "AI security" mean something different in 2026 than it did last year?
Think it does and fairly quickly. A year or two ago, "AI security" mostly meant model safety: jailbreaks, prompt injection, adversarial inputs. That's still relevant, but it's increasingly not the biggest practical risk for most organizations.
What's shifted is that AI workloads are now infrastructure, not experiments. They have service accounts, storage, network access, and API surfaces just like any other production system, which means they inherit every cloud security problem that already existed, just applied to a newer, faster-moving category of asset that most security teams haven't built mature processes around yet.
The practical implication: AI security in 2026 looks a lot more like extending existing cloud security discipline (least privilege, data classification, asset inventory) to a new workload type, and a lot less like a standalone specialty focused only on model-layer attacks.
are you treating AI workloads differently than your other cloud assets or rolling them into the same processes?
r/Information_Security • u/socradario • 2d ago
Deep Dive: Teardown of the FIORA NIGHT ("REZ") botnet and its 9-phase attack chain
r/Information_Security • u/David_Osipov • 2d ago
Cloudflare’s CAA flaw looks impractical for criminals — but what about actors who control the network?
r/Information_Security • u/kukap_ • 2d ago
Why I Believe Cyber Physical Resilience Engineering (CPRE) Is the Next Frontier
r/Information_Security • u/Syncplify • 3d ago
When the person protecting you from ransomware is also the one robbing you
When companies get hit with ransomware, hiring a specialist negotiator is one of the first calls they make. These firms know how the gangs operate, how to stall, and how to push back on demands. They are, in theory, entirely on the victim's side.
What nobody tells you is that your negotiator might be running a second conversation on the side.Angelo Martino worked as a ransomware negotiator at DigitalMint, handling communications with criminal gangs on behalf of companies that had been attacked. Unknown to his employer or his clients, he was feeding BlackCat everything through a hidden tab in the same panel he used for his legitimate work, insurance limits, negotiating positions, financial circumstances. Five of his clients collectively paid over $75 million in ransoms, each almost certainly inflated by what he handed over.
And then he and two colleagues started deploying BlackCat ransomware against victims themselves, keeping 80% of the ransoms. He got 70 months. His colleagues got four years each.
The ransomware negotiation industry is almost entirely unregulated. This case is apparently what it took to start talking about changing that - which raises the question of how it wasn't already a concern.
r/Information_Security • u/Soft_Goat_8749 • 3d ago
Runtime monitoring still isn't standard
Runtime monitoring is still treated as optional even on protocols moving real volume. The default posture is pre launch audit, maybe a bug bounty, and post mortem analysis when something breaks. The live layer in between barely exists at most teams.
The argument against runtime monitoring used to be that response wasn't fast enough to matter. Sub 100 millisecond intervention inside the same block changes that. The infrastructure to support it exists.
The reason it's still not standard isn't capability. Teams hesitate to give a system authority to halt activity without human review and false positive risk feels worse than the exploit risk. The math usually says otherwise.
r/Information_Security • u/kukap_ • 3d ago
Is cybersecurity enough for critical infrastructure?
r/Information_Security • u/kukap_ • 5d ago
Is cybersecurity enough for critical infrastructure?
r/Information_Security • u/rutoca • 5d ago
Every team building on AI ships the same feature. A lot of them ship the same bug.
medium.comr/Information_Security • u/threat_researcher • 5d ago
Meta is consuming infrastructure for free
r/Information_Security • u/cjacobs0001 • 5d ago
AI Data Centers Are Being Built Faster Than They Can Be Secured
securityweek.comr/Information_Security • u/Confident-Bluebird21 • 5d ago
Published research article on IEEE about supply chain attacks and preventive security measures
r/Information_Security • u/EchoOfOppenheimer • 5d ago
Researcher poisons open-weight AI model for under $100
theregister.comr/Information_Security • u/chota-kaka • 5d ago
White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination
whitehouse.govWhite House launches cybersecurity clearinghouse to patch software flaws discovered by AI
The 'Gold Eagle' initiative seeks to help federal agencies, critical infrastructure operators and artificial intelligence developers patch crucial security flaws uncovered by advanced AI models.
r/Information_Security • u/ranjith_snifty1 • 6d ago
How does your company prevent developers from accidentally sharing confidential data with AI tools?
AI tools like ChatGPT, Claude, Gemini, and Copilot have become part of many developers’ daily workflow.
I’m curious how companies are handling the risk of accidentally sharing sensitive information such as: 1. API keys 2. Access tokens 3. Internal source code 4. Customer data 5. Production configs 6. Internal documentation
Does your company, 1. Have a formal policy? 2. Use DLP or browser security tools? 3. Block certain AI tools? 4. Rely on developer awareness?
I’d love to hear what’s actually working in practice.