r/Information_Security 7h ago

Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI

Thumbnail varonis.com
2 Upvotes

r/Information_Security 13h ago

implementing user behavior analytics for enterprise security...where's the realistic starting point

6 Upvotes

we been tasked with standing up uba for our org and the amount of vendor noise around this makes it hard to figure out where to begin. so from what i can tell the real first step is establishing a behavioral baseline (normal login times, typical data access patterns, and so on) before you can flag anything as anomalous, which means you need a few weeks or months of clean data before the tool is doing anything useful.

also the other thing i keep running into is alert fatigue. every uba vendor demo shows a clean dashboard with a handful of high confidence alerts, but from what people tell me the reality in year one is a flood of false positives while the baseline tunes itself, and if your analysts aren't prepared for that they tune the whole thing out. for anyone who's run this rollout, how long did baselining realistically take before the alerts became trustworthy enough to act on without double checking everything manually?


r/Information_Security 5h ago

When the Attacker Was An AI Cheating On A Test: What The Hugging Face Incident Means For Defenders

Thumbnail cisovoice.com
1 Upvotes

r/Information_Security 11h ago

AI Exploitability Index (AI-XI): A new metric for measuring real exploitability

Thumbnail
1 Upvotes

r/Information_Security 1d ago

What's a red flag that tells you a company doesn't really take security seriously, no matter what they claim?

27 Upvotes

Every company says security is a top priority. But you can usually tell within a few weeks whether they mean it or not. I think one of the clearest signs is when security only gets attention after an incident, something breaks and suddenly it's an emergency.

What's the red flag that makes you think a company is only pretending to care?


r/Information_Security 14h ago

WordPress new pre-auth RCE chain is already being exploited in the wild

Thumbnail
1 Upvotes

r/Information_Security 1d ago

A university once got DDoS'd by its own vending machines. How much are people here actually monitoring IoT device behaviour vs just securing the endpoint or guarding the perimeter?

Thumbnail
1 Upvotes

r/Information_Security 1d ago

Research on the evolving ransomware landscape.

1 Upvotes

https://www.cybersecuritydive.com/news/ransomware-concentrated-ai-guidepoint/824828/

Ransomware activity increased 43% year over year in Q2 2026, with cybercriminals claiming breaches of more than 2,200 victims. While the number of ransomware groups continues to grow, researchers found that a small group of operators, including Qilin, The Gentlemen, Akira and DragonForce, accounted for a disproportionate share of attacks, creating what GuidePoint describes as a ransomware “four-headed monster.” Additionally, the report found that threat actors are increasingly leveraging AI tools to streamline activities such as data analysis, victim communications and ransom negotiations, rather than conducting entirely new AI-powered attack types.


r/Information_Security 1d ago

There has been an interesting architectural shift in browsing trends...

1 Upvotes

Five years ago the conversation was:

"How do we secure internet traffic?"

Lately it's becoming:

"How do we enforce the same policy regardless of where the endpoint is?"

Feels like a subtle yet important change in how Secure Web Gateways (SWG) are evolving.

This detailed roundup compares the Best Secure Web Gateway Solutions for your reference.


r/Information_Security 1d ago

Active exploitation reported for CVE-2026-6875 (Pre-Auth RCE in ServiceNow AI Platform)

Thumbnail
1 Upvotes

r/Information_Security 2d ago

Does "AI security" mean something different in 2026 than it did last year?

6 Upvotes

Think it does and fairly quickly. A year or two ago, "AI security" mostly meant model safety: jailbreaks, prompt injection, adversarial inputs. That's still relevant, but it's increasingly not the biggest practical risk for most organizations.

What's shifted is that AI workloads are now infrastructure, not experiments. They have service accounts, storage, network access, and API surfaces just like any other production system, which means they inherit every cloud security problem that already existed, just applied to a newer, faster-moving category of asset that most security teams haven't built mature processes around yet.

The practical implication: AI security in 2026 looks a lot more like extending existing cloud security discipline (least privilege, data classification, asset inventory) to a new workload type, and a lot less like a standalone specialty focused only on model-layer attacks.

are you treating AI workloads differently than your other cloud assets or rolling them into the same processes?


r/Information_Security 2d ago

Deep Dive: Teardown of the FIORA NIGHT ("REZ") botnet and its 9-phase attack chain

Thumbnail
1 Upvotes

r/Information_Security 2d ago

Cloudflare’s CAA flaw looks impractical for criminals — but what about actors who control the network?

Thumbnail
1 Upvotes

r/Information_Security 3d ago

When the person protecting you from ransomware is also the one robbing you

7 Upvotes

When companies get hit with ransomware, hiring a specialist negotiator is one of the first calls they make. These firms know how the gangs operate, how to stall, and how to push back on demands. They are, in theory, entirely on the victim's side.

What nobody tells you is that your negotiator might be running a second conversation on the side.Angelo Martino worked as a ransomware negotiator at DigitalMint, handling communications with criminal gangs on behalf of companies that had been attacked. Unknown to his employer or his clients, he was feeding BlackCat everything through a hidden tab in the same panel he used for his legitimate work, insurance limits, negotiating positions, financial circumstances. Five of his clients collectively paid over $75 million in ransoms, each almost certainly inflated by what he handed over.

And then he and two colleagues started deploying BlackCat ransomware against victims themselves, keeping 80% of the ransoms. He got 70 months. His colleagues got four years each.

The ransomware negotiation industry is almost entirely unregulated. This case is apparently what it took to start talking about changing that - which raises the question of how it wasn't already a concern.

Source.


r/Information_Security 3d ago

Runtime monitoring still isn't standard

14 Upvotes

Runtime monitoring is still treated as optional even on protocols moving real volume. The default posture is pre launch audit, maybe a bug bounty, and post mortem analysis when something breaks. The live layer in between barely exists at most teams.

The argument against runtime monitoring used to be that response wasn't fast enough to matter. Sub 100 millisecond intervention inside the same block changes that. The infrastructure to support it exists.

The reason it's still not standard isn't capability. Teams hesitate to give a system authority to halt activity without human review and false positive risk feels worse than the exploit risk. The math usually says otherwise.


r/Information_Security 2d ago

Why I Believe Cyber Physical Resilience Engineering (CPRE) Is the Next Frontier

Thumbnail
0 Upvotes

r/Information_Security 3d ago

Is cybersecurity enough for critical infrastructure?

Thumbnail
0 Upvotes

r/Information_Security 4d ago

Is cybersecurity enough for critical infrastructure?

Thumbnail
0 Upvotes

r/Information_Security 5d ago

Every team building on AI ships the same feature. A lot of them ship the same bug.

Thumbnail medium.com
1 Upvotes

r/Information_Security 5d ago

White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination

Thumbnail whitehouse.gov
26 Upvotes

White House launches cybersecurity clearinghouse to patch software flaws discovered by AI

The 'Gold Eagle' initiative seeks to help federal agencies, critical infrastructure operators and artificial intelligence developers patch crucial security flaws uncovered by advanced AI models.


r/Information_Security 5d ago

Meta is consuming infrastructure for free

Thumbnail
1 Upvotes

r/Information_Security 5d ago

AI Data Centers Are Being Built Faster Than They Can Be Secured

Thumbnail securityweek.com
0 Upvotes

r/Information_Security 5d ago

Researcher poisons open-weight AI model for under $100

Thumbnail theregister.com
4 Upvotes

r/Information_Security 6d ago

How does your company prevent developers from accidentally sharing confidential data with AI tools?

15 Upvotes

AI tools like ChatGPT, Claude, Gemini, and Copilot have become part of many developers’ daily workflow.

I’m curious how companies are handling the risk of accidentally sharing sensitive information such as: 1. API keys 2. Access tokens 3. Internal source code 4. Customer data 5. Production configs 6. Internal documentation

Does your company, 1. Have a formal policy? 2. Use DLP or browser security tools? 3. Block certain AI tools? 4. Rely on developer awareness?

I’d love to hear what’s actually working in practice.


r/Information_Security 5d ago

Published research article on IEEE about supply chain attacks and preventive security measures

Thumbnail
1 Upvotes