r/cybersecurity 2d ago

Business Security Questions & Discussion 6 days vs. 1 hour to Fix the Same Vulnerability: Check Point's Exposure Gap Report AMA

21 Upvotes

Hi r/cybersecurity — we're Michael, Omer, Aarati and Jony from Check Point's Exposure Management team. We've just finished pulling together our Exposure Gap Report, and one number kept jumping out: the time it takes to remediate a critical exposure varies massively between teams. In one sector 30% are achieving remediation of critical threats in under an hour. In others it's over six days.

What's interesting is that it doesn't come down to effort. Across the board, teams implement 82–92% of recommended fixes. People are doing the work. The difference is speed, and speed turns out to be a prioritization, ownership, and process problem far more than a tooling one.

We're here for the next 24 hours to talk about what actually slows remediation down, what the fast teams do differently, and where exposure management helps vs. where it doesn't. Ask us anything about remediation speed, prioritization, validation, or how we put the report together.

Who are we?

Jony Fischbein, Global CISO @ Check Point - u/noissues_ciso_chkp

Jony is Check Point’s Global CISO and a Forbes Technology Council member, which basically means he’s spent 25+ years trying to convince people that “security” is not the same as “turning it off and on again.” Former CISO, current CISO, perpetual problem‑solver — he advises global orgs on how not to get pwned.

Michael A. Greenberg, Head of Product Marketing, Exposure Management @ Check Point - u/MG_CheckPoint_EM
Michael has come full circle. He begun his cyber career at Check Point, then moved to XM Cyber, then Veriti (the remediation shop Check Point acquired specifically so people would stop finding problems and start fixing them), and now back at Check Point running the Exposure Management story.

Omer Leen, Manager, Technical Customer Success @ Check Point - u/SafeRemediations_123
Omer is the one who actually sits with customers while the remediation happens, which he's been doing since his Veriti days and, before that, in roles spanning aerospace IT at Elbit Systems, data/CRM work at Teva, and technical customer success at Webz.io. Translation: he's spent his whole career being the human bridge between "the plan looks great on the roadmap" and "the plan is now live in your production environment and nothing broke." If remediation dragged at your org, Omer has probably already seen why.

Aarati Regmi, Cyber Remediation Analyst @ Check Point - u/Rich_Quiet_3291
Aarati is a Cyber Remediation Analyst on the Exposure Management team, which basically means she's the one actually closing the tickets everyone else on this AMA is talking about in theory. She cut her teeth as a SOC analyst before crossing over to the "now go fix it" side of the house. If your remediation SLA has ever mysteriously improved, there's a decent chance she was involved.


r/cybersecurity 2d ago

Career Questions & Discussion Mentorship Monday - Post All Career, Education and Job questions here!

33 Upvotes

This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!

Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.


r/cybersecurity 4h ago

News - General Microsoft admits SMS and voice MFA can’t stop AI attacks, mandates passkeys in Entra by February 2027

Thumbnail
windowslatest.com
202 Upvotes

r/cybersecurity 2h ago

News - Breaches & Ransoms Swiss rail giant Stadler rejects 12.3M ransom demand after cyberattack

Thumbnail
bleepingcomputer.com
35 Upvotes

r/cybersecurity 7h ago

Career Questions & Discussion At what point does a cybersecurity role become professionally unsustainable?

76 Upvotes

TL;DR: I’m an Information Security Manager for a 1,600-employee international organization with a relatively high-risk profile. Our central security team consists of me and two security engineers, despite continued growth through acquisitions, increasing regulatory obligations, and an expanding workload. After months of discussions, management has decided not to increase security headcount. I’m trying to understand where the line is between accepting business risk and accepting personal professional responsibility.

I’m the Information Security Manager for an international organization of around 1,600 employees. We operate across multiple countries in a relatively high-risk industry with a significant amount of business-critical IT.

Our central security function consists of me and two security engineers supporting multiple companies within the group.

We’re a holding company that continues to grow through acquisitions. Newly acquired companies often have security maturity levels that are significantly below the standards expected by the holding company, requiring considerable effort to bring them up to an acceptable baseline.

As the organization has grown, I’ve repeatedly argued that cybersecurity needs to scale accordingly. I developed a proposal for a centralized shared security services organization that would provide governance, security engineering, operational security, and compliance support across the group. As part of that proposal, I also requested an additional Information Security Officer role to strengthen governance and help meet our growing regulatory obligations, including NIS2.

Over the past several months I’ve spent a great deal of time working with senior management to explain why additional security capacity is necessary. Together with external advisors, we’ve explained the operational impact of our growth, our regulatory obligations, and the practical realities of managing security for an organization of this size.

We didn’t stop at high-level discussions. We broke our work down into individual activities, identified the bottlenecks, quantified the backlog, prioritized the work, and demonstrated exactly what can and cannot realistically be delivered with our current team.
The proposal hasn’t been formally rejected, but this week I was informed that there are no plans to invest in additional security headcount in the foreseeable future.
I fully understand that cybersecurity is about managing risk rather than eliminating it. I also understand that every organization has limited budgets and competing priorities.

What I’m struggling with is where my own professional responsibility ends.

At this point, I feel I’ve done everything I reasonably can: documented the risks, presented realistic solutions, involved external experts, communicated the consequences, and made management aware of the growing gap between business growth and our ability to manage cyber risk.

Despite that, there is now more critical work than our team can realistically deliver. As the person ultimately responsible for information security, I’m increasingly uncomfortable carrying accountability for risks that I know we simply don’t have the capacity to address.

I’m not looking to criticize my employer or argue that every security request should automatically be approved. I’m genuinely interested in hearing from other Information Security Managers, CISOs, and security leaders who have faced similar situations.
- At what point do you feel you’ve fulfilled your professional duty?
- How do you distinguish between business risk that management is entitled to accept and professional responsibility that you shouldn’t continue to own?
- Is thorough documentation of risks and management decisions enough, or is there a point where the right professional decision is simply to move on?

I’d genuinely appreciate hearing how others have navigated this.


r/cybersecurity 22h ago

New Vulnerability Disclosure Oracle Releases 1235 CVEs today.

Thumbnail oracle.com
729 Upvotes

It's a new record!


r/cybersecurity 2h ago

News - Breaches & Ransoms South Korea discloses data breach impacting diplomats worldwide

Thumbnail
bleepingcomputer.com
6 Upvotes

r/cybersecurity 6h ago

Personal Support & Help! Cybersecurity or Computer engineering Undergrad

9 Upvotes

Hi I recently finished high school and now looking forward to learn offensive security. I'm more interested in the offensive part of cyber security than defensive . I have a few questions

Should I take bsc cybersecurity or bsc computer engineering and then do msc cybersecurity later

I have two options either to do online with dakota state university usa or physical in the EU with a study visa . How will Ai impact cybersecurity .Is it even Worth it ?

I will be grateful for any expert guide .


r/cybersecurity 11h ago

News - Breaches & Ransoms Suno discloses data breach exposing 55M records that not only includes email, names, phones, addresses, purchase history, and partial credit card data, but also proves they scraped YouTube, Deezer, and Genius for training data.

Thumbnail
paperweight.email
18 Upvotes

Key Takeaways

  • In November 2025, Suno experienced a data breach that exposed email addresses, names, phone numbers, physical addresses, purchase details, and partial credit card data for 55.3 million records.
  • The same hack also leaked internal source code confirming Suno scraped copyrighted music from YouTube Music, Deezer, and Genius for training data, while publicly arguing that training on copyrighted works is fair use.
  • This incident is part of a pattern of data breaches affecting companies in the same sector, with other music and education platforms also reporting significant exposures around the same time.
  • Individuals affected by this breach should be vigilant about phishing attempts and other scams that use their exposed personal and purchase information.

r/cybersecurity 2h ago

News - General Cybersecurity statistics of the week (July 13th - July 19th)

3 Upvotes

Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.

All the reports and research below were published between July 13th - July 19th.

You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/ 

Ransomware

The State of Ransomware 2026 (Sophos)

Now in its seventh straight year, this is the definitive look at ransomware trends worldwide.

Key stats:

  • 79% of ransomware attacks start with an identity-based approach.
  • 67% of root causes across 661 incident response and MDR cases are identity-related.
  • 97% of victims where compromised credentials are identified as the root cause have MFA enabled in some form at the time of the attack.

Read the full report here.

Ransomware and Cyber Extortion in Q2 2026 (ReliaQuest)

ReliaQuest's Q2 numbers on ransomware activity. The big takeaway: The Gentlemen is the group everyone should be watching. Plus, it looks like Deadlock is back. 

Key stats:

  • The Gentlemen surged 588% quarter-over-quarter to 179 posts in Q1.
  • Deadlock emerged in June 2026 with 75 named victims in a single month, after being absent from public data-leak sites for 11 months.
  • The US absorbed 1,094 ransomware victim data leak posts in Q2, roughly 49% of observed activity and nine times the volume of the next country.

Read the full report here.

Vulnerability Management

The 2026 State of Vulnerability Remediation (Vicarius)

A look at how security leaders are fixing vulnerabilities. 

Key stats:

  • 79% of organizations experienced a security incident in the past 12 months involving a vulnerability that was already known and sitting in their inventory.
  • 75% of critical vulnerability responses initiate administrative workflows (like ticket creation or routing) rather than immediately fixing the underlying flaw.
  • 58% of all vulnerability remediation activities require direct human intervention.

Read the full report here.

AI Security

AI Agents Are Entering Critical Workflows. Who's Governing Them? (JumpCloud)

AI agents are moving into real work, but 800 IT leaders admit governance hasn't caught up.

Key stats:

  • More than 60% of organizations run AI agents in production.
  • Organizations have adopted fewer than one-third of standard AI governance and security practices.
  • The share of organizations requiring human review before high-risk AI actions dropped from 40% to 25% in six months.

Read the full report here.

The AI Security Report 2026 (Check Point)

A breakdown of how AI has gone from cyber assistant to active attacker. 

Key stats:

  • High-risk enterprise AI prompts doubled over the year, increasing from about 1 in every 50 interactions to 1 in every 25 interactions.
  • The average organization runs ten AI applications per month.
  • Between 87% and 93% of organizations experienced at least one high-risk AI interaction each month.

Read the full report here.

The Year Agents Entered the Workforce (Straiker)

Straiker put AI agents through adversarial testing to see where they fail.

Key stats:

  • More than 1,700 successful exploits occurred across production coding, productivity, and first-party AI agents during adversarial testing.
  • 36% of successful attacks on coding agents reached remote code execution on the developer's machine.
  • 91% of successful attacks on productivity agents ended in silent data exfiltration.

Read the full report here.

Rethinking AI's Impact on Cybersecurity Roles (ISC2)

ISC2 on how AI is changing the day-to-day of cybersecurity work.

Key stats:

  • 89% of cybersecurity professionals report having experienced AI recommendations that lead to incorrect outcomes at their organizations.
  • 62% list over-reliance on AI as a top concern.
  • 50% say their organizations hold human decision-makers ultimately accountable when AI-recommended actions lead to incorrect outcomes.

Read the full report here.

Executive Risk

2026 Executive Trends Report (Nisos)

Scary insight into how exposed executives are on the internet. 

Key stats:

  • 100% of executives have breach data linking their name to at least one current email address.
  • 94% have at least one plaintext password exposed in breach data.
  • 94% have home addresses publicly linked to their name in public records or people-search sites.

Read the full report here.

Industry-Specific 

Government Ransomware Roundup: H1 2026 (Comparitech)

Comparitech tracked ransomware attacks specifically against government entities in the first half of 2026.

Key stats:

  • From January to June 2026, an average of one ransomware attack on a government entity occurred every day.
  • The median ransom demand in H1 2026 was $100,000, one-fifth of the H2 2025 median of $500,000.
  • The most prolific ransomware strains against government were The Gentlemen (22), Qilin (21), LockBit (14), APT73/BASHE (12), and INC (10).

Read the full report here.


r/cybersecurity 20h ago

Career Questions & Discussion How was your career/job search after getting the CISSP?

84 Upvotes

For those who have earned their CISSP, did you notice a significant difference in your job search afterward? Did you start getting more interview requests or have more recruiters reaching out to you on LinkedIn or other platforms?

Did the CISSP open up more opportunities for you or help you qualify for higher-level cybersecurity roles? I’d be interested to hear about your experience and whether you feel getting the CISSP made a noticeable impact on your career.


r/cybersecurity 1d ago

News - General US police now armed with Israeli spy vans simulating mobile phone towers

Thumbnail cybernews.com
719 Upvotes

r/cybersecurity 5h ago

Research Article Windows Kerberos AS-REQ "till" is a hardcoded constant and other AD time findings from chasing KRB_AP_ERR_SKEW

5 Upvotes

TL;DR: a Windows DC hands out its exact time to UNAUTHENTICATED clients over 5 protocols (CLDAP/SMB/NTP/Kerberos-error/NTLM). the AS-REQ "till" is a hardcoded constant (2037, or 9999 on Win11 22H2+) and getting it wrong can even break your own request. a few of these are cheap wire signatures for blue team to baseline. i wrapped it all in a small OSS tool + rust crate.

Hey hey, im a dev and i have been learning cybersec and acting as appsec eng and during the ctfs, boxes and authorized engagements the KRB_AP_ERR_SKEW found me a lot, the usual "correction" for it is to change the entire system clock or use some one liners that always get bugged or dont work in every environment, so i ended going down a rabbit hole to learn how the DC usually exposes its time (and also to find ways to slip past my own DetectionLab, so i could learn the detection/purple side too)

So, the DC leaks its time to UNAUTHENTICATED clients over several protocols:

  1. CLDAP rootDSE: the currentTime attribute in a base search
  2. SMB2 NEGOTIATE: the SystemTime field in the response (fixed offset, all dialects)
  3. NTP/SNTP: the obvious one
  4. Kerberos KRB-ERROR: stime/susec even from a failed AS-REQ
  5. NTLM type-2 challenge: MsvAvTimestamp in the target info

The last one was also the funniest when i was testing, so i started tuning my detectionLab to get weird reqs and in the research ended up finding that the AS-REQ till is a hardcoded Windows constant, not a computed value (in my dev mind it would be computed, something like now+XXhrs or idk) but Real Windows fixes it as a far future constant 20370913024805Z (Win11 22H2+ switched to 99990913024805Z) credits to a Heimdal bug report with the captures, so in theory any jittered till is potentially a fingerprint, but it also makes sense in a way of if your box is too far behind even an now+XXhrs could end up in the past and you wouldnt even get the regular KRB_AP_ERR_SKEW

Another fun thing now about SMB is that real win 10/11 send SMB 3.1.1 (0x0311) in the NEGOTIATE dialect list + the mandatory PREAUTH_INTEGRITY_CAPABILITIES context and set the CLDAP timeLimit to 0 which can become cheap wire signatures to baseline if you're detecting this kind of activity

Also the CLDAP query people call a "DC Locator Ping" is actually a rootDSE diagnostic query (objectClass=*), which is ldapsearch/PowerShell-shaped traffic, not the machine-account DC Locator ping, different hiding pool than commonly assumed

If anyone wants to know more, see it or is dealing with the KRB_AP_ERR_SKEW I applied all this in a small open-source tool + a Rust crate for the extraction part (Skewrun)

Anyone working in a SOC: do you have detection rules for these kinds of time-based protocol requests?
And to the ones attacking, has anybody dealt with this kind of problem without LD_PRELOAD, any ideas of how to make it deal with static bins and/or be truly OS agnostic?


r/cybersecurity 1d ago

Career Questions & Discussion what is going on with the cybersecurity job market??????

244 Upvotes

I am tired of applying for cybersecurity jobs and not hearing back bc after a while it becomes difficult to tell whether I need more experience, more certifications, better projects, or simply better luck.

and while I still want to build a career in this field and I am willing to put in the work, I feel stuck and I am not sure where I should focus my effort next..

tbh this is starting to feel difficult to survive both financially and mentally.

for employers, what do you guys focus on? i would really appriciate the help. thanks.


r/cybersecurity 3m ago

Business Security Questions & Discussion Cyber security Content

Upvotes

What do you believe is missing in cyber security content?

We have darker dairies that cover cyber crime or just overall interesting security stories.

Breaking into security content

The likes of networkchuck etc, but what’s missing?


r/cybersecurity 19h ago

Business Security Questions & Discussion Managed Security Service Provider Recommendations

32 Upvotes

looking for a MSSP to provide Managed SIEM + 24x7 SOC alert, monitoring and response across entire tech stack of endpoint and firewalls.


r/cybersecurity 1d ago

News - General Critical SharePoint RCE flaw exploited to steal machine keys

Thumbnail
bleepingcomputer.com
73 Upvotes

r/cybersecurity 18h ago

Career Questions & Discussion How to not become crazy with the constant flow of information we're receiving

22 Upvotes

Hi all! I am a CTI Analyst, previously working on awareness and governance. I have a geopolitics and economics background too so spending a lot of time reading news and reports has been my entire life. However, I feel SO OVERWHELMED by the flow of content we are getting and I am just afraid to not being able to follow the pace, especially with AI related topics.

In my company, they are all talking about AI and all the new tools, processes, systems etc that are associated with AI and it is growing/evolving everyday. Also, in terms of cyber news and reports, the content is multiplicating so fast, I have an hard time to catch-up which has never been my case before.

I am a truly resilient and efficient person and the fact that I am feeling that way is not usual. Honestly, how can we keep the pace? Do you have some tips and tricks to keep up with the best level of knowledge and understanding of what’s going on in the cyber world and also regarding AI (as apparently we all have to use it more and more...).

My second fear is that people would be so overwhelmed with available content that they wouldn't have the mental space to read and acknowledge correctly our CTI notes and analysis.

This is a vicious circle.


r/cybersecurity 10h ago

Personal Support & Help! What would an AI or AI Agent hack look like?

6 Upvotes

Does anyone know or have any info on what it would look like if an AI agent was trying to get into your networks? Or if it did? Which kind of security tools do you think would detect them? Is there any way they act that would tell them apart from a human?


r/cybersecurity 2h ago

Personal Support & Help! Agentic Ai in cyber please help

1 Upvotes

Hi all, SOMEONE PLEASE HELP, I am going round in circles here. This is where I’m at with my AI knowledge and what I want to achieve…..

I work in cyber security as head of security team and come from a semi technical background mainly in networking/security operations. I understand the difference between agentic ai and genai. I have done a course ‘AI for Everyone’ which is a basic non technical intro course to GenAI and how it works, supervised learning, inputs/outputs etc. What I want to understand now is genai and how we can use it in our workflows. I don’t want to become some sort of AI wizard but I want to know how it works under the hood and how we can utilise agentic ai in our workflows. Someone please tell me where to start/what courses to take etc. I have a look on Udemy I just become overwhelmed because I have absolutely no idea what course to go for. I just want to understand the concept better than what I do so I can understand how it all comes together. I hope this makes sense and any help would be appreciated.


r/cybersecurity 2h ago

Certification / Training Questions SC-200 XtremeLabs – Is anyone else experiencing issues with Labs 1 and 4?

1 Upvotes

I'm currently preparing for the Microsoft SC-200 exam using the official XtremeLabs environment.

Lab 1 and Lab 4 appear to be inoperative in my environment, while the remaining labs seem to work normally.

Has anyone else experienced the same issue recently?

Are there any known workarounds?

Is this a temporary platform issue or a problem with the current lab version?

Has anyone received an update from XtremeLabs or Microsoft Learning? And is there any alternative for the labs?

I'd appreciate hearing from anyone who has tested these labs recently.


r/cybersecurity 9h ago

News - Breaches & Ransoms Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI

Thumbnail
varonis.com
3 Upvotes

r/cybersecurity 2h ago

Burnout / Leaving Cybersecurity Transitioning out of cyber

1 Upvotes

Hello! Has anyone transitioned out of cyber security into the intelligence or forensics space? What was your previous background (professional and educational) and what advice do you have for anyone trying to do it right now?

I currently am a fairly new cybersecurity engineer. Have an IT military background and Federal IT background (mostly governance) and local IT government professional background. I’ll be finishing up my bachelor’s in cybersecurity next year (yes I landed an cyber role with just my associates). Any advice would be amazing I would love to get into intelligence or forensic style work.


r/cybersecurity 1d ago

News - General Nvidia's new Synthetic Video Detector can identify fake AI videos with up to 92% accuracy

Thumbnail
tech.yahoo.com
166 Upvotes

r/cybersecurity 10h ago

Career Questions & Discussion How to optimise first week at new company / role

3 Upvotes

Starting a new role at a FS firm End of Aug as a GRC Analyst, what would everyone recommend doing / reading in the first week to be as prepared as possible?