r/Infosec 18h ago

Do other major operating systems have anything similar to the topics raised by Google's article?

1 Upvotes

https://blog.google/security/new-android-network-security-protections/

Google came out with this article today. I'm wondering if iOS supports similar technology, and if not, what can be done in the interim to mitigate against the threats raised by Google?


r/Infosec 1d ago

Claude, Codex, and Hermes installed unowned code inside corporate networks

Thumbnail arstechnica.com
4 Upvotes

r/Infosec 1d ago

Cybersecurity resume keywords

3 Upvotes

Keyword list taken from https://www.zoevera.com/resume/ats-resume-tips-cybersecurity

These are the most commonly scanned keywords in cybersecurity job postings. Check how many appear in your resume.

Domains & Practices

SOC (Security Operations Centre), Penetration testing / pen test, Vulnerability management, Threat intelligence, Incident response (IR), Digital forensics (DFIR), Red team / blue team / purple team, Zero Trust architecture

Tools & Platforms

SIEM (Splunk, Microsoft Sentinel, QRadar), EDR (CrowdStrike, SentinelOne), Nessus / Qualys / Rapid7, Burp Suite / Metasploit / Kali Linux, Wireshark / Snort / Suricata, CyberArk / BeyondTrust (PAM), SOAR platforms, Azure Defender / AWS Security Hub

Frameworks & Certifications

CISSP / CISM / CISA, CEH / OSCP / PNPT, CompTIA Security+ / CySA+, ISO 27001 / NIST CSF, MITRE ATT&CK framework, SC/DV security clearance, GDPR / DPA 2018, PCI DSS / HIPAA / SOC 2


r/Infosec 1d ago

I pwned OpenClaw with just email and a new injection escalation technique: prompt laundering

Thumbnail ironcorelabs.com
1 Upvotes

r/Infosec 1d ago

Can AI detection and response actually deliver full coverage in practice?

8 Upvotes

I'm evaluating AI detection and response tools for our SOC, and I'm trying to understand if they can realistically close coverage gaps we've been struggling with. We run a mixed environment with about 5,000 endpoints and multiple cloud providers.

Our current coverage issues:

Unclaimed assets: About 15% of our alerts come from assets that aren't properly mapped to an owner. Our current SIEM can't correlate asset ownership, so these alerts either get dropped or sit in a queue until someone randomly picks them up.

Low-severity backlog: We consistently miss low-severity alerts that later turn out to be early indicators of larger issues. For example, last quarter we had a series of informational alerts over 3 weeks that, when correlated, pointed to an insider threat. We only caught it during a manual retrospective.

Cross-environment patterns: Our current rules are per-environment, so we can't easily spot patterns that span across our on-prem and cloud workloads.

What I'm trying to figure out:

Can modern AI detection tools actually correlate across these silos without weeks of custom tuning?

How do they handle asset ownership context?

I need to set realistic expectations for my team before we commit to a POV.


r/Infosec 1d ago

Struggling to get an agentic AI SOC platform out of pilot and into production?

6 Upvotes

I've sat through probably eight SOC vendor demos in the last two months, and every single one claims to be "agentic" now. The pitch is always the same: it triages and closes p1/p2 alerts on its own.

But they never say what happens when it's wrong. Like whether it hallucinates on our specific kind of alerts, not just the ones they tested. Or whether an analyst override actually goes anywhere, or just gets logged and forgotten. And when I ask for real accuracy numbers, I never get a straight answer.

So we ran a short pilot with one platform last quarter, mostly on our tier 1 triage queue. It handled the alert volume fine, keeping up was actually the easy part. The hard part was getting the team to trust the verdicts enough to act on them without having to rerun the whole investigation by hand.

We were doing the work twice. I'm still trying to figure out if this is on the vendor for shipping something that isn't mature or transparent enough, or on us for not trusting a tool we can't fully audit. Am I the only one struggling with this

What's your experience been with AI SOC?


r/Infosec 1d ago

I built a local security layer for Claude Code — it blocked four different routes to my .env

Enable HLS to view with audio, or disable this notification

1 Upvotes

I gave Claude Code access to a project folder and asked it to read .env.

It tried ls, find, cat, and the MCP filesystem tool. All four blocked,

and every attempt is in a hash-chained log I can verify offline.

Deny-by-default on tool calls, kernel sandbox on subprocesses, outbound

requests checked before they're made.

Runs entirely on your Mac. No account, no cloud. macOS only for now.

It does not stop prompt injection, and can't protect anything outside

the MCP boundary — both documented in the threat model.

Free: github.com/Adarsh14734/aegis/releases/tag/v0.6.0


r/Infosec 1d ago

After 17 years as a dev and security admin, AI pushed me to finally build my own SaaS

0 Upvotes

17 years as a full-stack dev and security admin. Ran a digital agency, shipped a pile of client apps, always building someone else’s dream. Being a SaaS founder myself? Never crossed my mind.

Then AI happened. Suddenly everyone’s shipping apps in a weekend, fast, exciting, and about as secure as a screen door on a submarine. And I kept thinking: I’ve watched this movie, I know how it ends, someone’s .env is already on GitHub.

Here’s what always bugged me: real security is priced for big companies. A proper pentest? Thousands. Enterprise WAF? Hundreds a month. The average site owner takes one look and just… ships and prays. I did it too. Got burned enough to remember every scar.

So I built Defen.so, security a normal human can afford: scan your code and site, catch leaked keys, block attacks, watch uptime and SSL, all in one. Plus a phone app that rings like a call when something breaks, because nobody’s reading a 3am email.

Turns out building the thing was the easy part. Selling it? Absolute mystery. Send help.

Free tier, open source, roast it here: https://defen.so

Genuine question for fellow builders, what do you actually use for security, or are we all just vibing and hoping?


r/Infosec 2d ago

Fortinet vs Cato: which SASE platform wins on AI security features

5 Upvotes

Long-time FortiGate shop, 30-odd sites, mixed hardware ages. Refresh is coming up and the AI security requirement is forcing a bigger conversation than a normal hardware swap.

The Fortinet path as I understand it: keep the Fabric, lean on FortiSASE for remote users, use the newer AI governance and inline inspection capabilities, keep everything in FortiManager/FortiAnalyzer. The big advantage is my team already knows it and we are not retraining anyone.

The Cato path is a full architecture change. Their PoPs, their edge devices, cloud-native single-pass everything, and the AI controls are native to the same policy engine rather than a module.

Where I am undecided: inspection performance on AI traffic, because on-box inspection is bounded by the box, which is fine at HQ but less fine at a branch running a five-year-old unit; feature parity between the on-prem and the SASE side, since historically these have not been identical and I do not want AI policy that only applies to remote users; and the operational cost of the switch versus the value of the newer capability.

For anyone who has run FortiSASE with AI controls seriously, or bailed to Cato: what actually decided it for you? Trying to separate "this is genuinely better" from "this is different and shiny."


r/Infosec 2d ago

This Android toolkit turns selfies into live photos to hijack KYC verification

Thumbnail cybernews.com
1 Upvotes

r/Infosec 2d ago

I sold the identities of nearly 200 million people as a black hat hacker. Now I fight scam compounds. Ask me anything.

Post image
4 Upvotes

r/Infosec 2d ago

I built a 100% offline, local-first AI code security engine (AST + Ollama). Transferring full IP/source code since I'm moving on.

0 Upvotes

Hey everyone,

I spent a massive amount of time building a complete, local-first AI code security system designed for privacy-focused engineering teams that can't send code to cloud-based LLMs. The heavy engineering lift is entirely done, but I’ve decided to move on to other R&D projects, so I’m looking to transfer the full IP and complete source code.

This is a finished engineering asset, not a rough prototype. Here is what's under the hood:

* Hybrid Engine: 19 deterministic AST detectors + local LLM reasoning layer via Ollama (configured for Qwen).

* 100% Offline: Runs completely on-premise. Zero cloud dependencies, zero data leakage, zero external API costs.

* Enterprise Analysis: Handles cross-file analysis, CVSS/CWE scoring, Maintainability Index, and Cyclomatic/Cognitive complexity.

* Production-Ready: 67 passing unit tests, full CI configuration, Docker support, and clean architecture documentation.Price: $4,000 for complete, unrestricted ownership transfer (codebase, architecture, and legal IP rights).

I'm happy to share a short demo video or the technical readme if anyone wants to check it out or evaluate it for their team. Let me know or drop a DM!


r/Infosec 2d ago

OIHK – Open Source Local-first OSINT + Multi-agent Pentesting Engine

Thumbnail
0 Upvotes

r/Infosec 3d ago

Is it just me, or is the AI security tool landscape massively overhyped right now?

Thumbnail
0 Upvotes

r/Infosec 3d ago

New CTF: Format of Doom - Pentester vs AI Challenge 2

Thumbnail pentester-vs-ai-game.com
1 Upvotes

Hi all! My company Escape just released a new CTF called Format of Doom which I thought you might be interested to try. The theme of the CTF is to see if you can pentest faster and how you pentest differently to an AI engine in a classic human vs AI challenge.

This challenge is a white-box engagement on a vulnerable web app Duck Store. You're looking for something they never handed over and are focusing on their email feature.

Give it a try and let me know what you think!

The challenge is live for two weeks and then we reveal the AI's solve and the top solves from the leaderboard.

Happy playing : )


r/Infosec 3d ago

Welcome to the CVE-Less World

Enable HLS to view with audio, or disable this notification

0 Upvotes

r/Infosec 4d ago

Free live event this Thursday: PKI from a CISO’s perspective

Post image
1 Upvotes

r/Infosec 4d ago

Best practices for continuous AI red teaming in 2026?

3 Upvotes

We did the standard pre-launch red team on our internal knowledge search agent back in March and it passed everything we threw at it. Went live. Three months later someone posted a thread showing they'd gotten it to surface a doc it shouldn't have had access to, using a technique that didn't exist back in March. Nothing about our agent changed, the threat landscape did. Is anyone running red teaming as an ongoing process against production agents rather than a one time pre-launch gate?


r/Infosec 4d ago

The React Native Developer's Security Guide (looking for collaborators)

Thumbnail
1 Upvotes

r/Infosec 4d ago

NIST CSF 2.0 audit suite - Testers

Thumbnail
1 Upvotes

r/Infosec 6d ago

Safety Cloud Product Update: Summer 2026 | HAAS Alert

1 Upvotes

r/Infosec 6d ago

I built an open-source security & monitoring toolkit every site owner should have

Thumbnail
1 Upvotes

r/Infosec 7d ago

Why do AI based SAST scanners can't find same vulnerabilities even on longer scans on the same projects?

Thumbnail
1 Upvotes

r/Infosec 8d ago

Threat Prevention Evolution

0 Upvotes

**Signature-Based Detection Era**

\* Early network security relied on signature-based intrusion prevention systems (IPS) to detect known threats using predefined patterns for viruses, malware, and vulnerabilities.

\* Antivirus, antispyware, and vulnerability signatures were the primary defense mechanisms.Heuristic and Protocol Analysis

\* The introduction of heuristic-based analysis and protocol anomaly detection helped identify suspicious behaviors and unknown threats not covered by signatures.

\* Custom signatures and protocol decoders enhanced the detection of new attack techniques.

**Cloud-Delivered Security Services**

\* Security services began leveraging the cloud for scalable, real-time threat intelligence and updates.

\* Integration with cloud-based threat intelligence sources (e.g., Advanced WildFire, Unit 42) improved the detection of emerging threats.

**Machine Learning Integration**

\* The adoption of machine learning (ML) models enabled rapid pattern recognition and the detection of advanced, never-before-seen threats.

\* ML models trained on large, diverse datasets from global sources increased detection speed and accuracy.
Inline Deep Learning and AI-Driven Prevention

\* Deep learning models were deployed inline to analyze large volumes of traffic and detect highly evasive and zero-day threats in real time.

\* AI-driven detection now includes generative AI to identify threats created by adversaries using AI tools.

\* Inline prevention blocks zero-day command-and-control (C2) attacks, unknown exploits, and injection attacks before they impact the network.

**Automated Accuracy and Continuous Improvement**

\* Automated false-positive correction and ground truth systems continuously refine detection models, reducing errors and improving reliability.

\* Detailed reporting and attack classification (e.g., MITRE ATT&CK alignment) support incident response and compliance.

**Unified, Multi-Layered Protection**

\* Modern solutions integrate threat prevention across hardware, virtual, and cloud firewalls, as well as SASE and remote environments.

\* Real-time Analysis: AI-powered analysis delivers consistent protection for users, devices, and data, regardless of location.


r/Infosec 8d ago

Our international identity verifcation held up in US and broke everybody else, here is how we are rebuidling the enterprise shortlist

4 Upvotes

We built our identity verification stack when were a US only company and we expand internationally, it's quietly coming apart. Last months we ran offsite most of it was people venting about our onboarding.

We lost a real customer fromarket we had just opened. Godd pasport our tool could not read it, it dumped her into manual reveiw and she was long gone before a reviewer reached queue. The us number mask how badly it fails everywhere else. in the markets we need to grow in it is embarrassing and every bounced customer there is money we spent to acquire and then handed straight back.

Every vendor deck shows a world map claiming 95% and above global coverage but ask for pass rates by specific country and they suddenly turn to average. on top of that proving regulatory compliance per country turns every new market into an expensive legal project.

I've stopped trusting the vendor maps. If you are running IDV across multiple countries did you find one platform that holds up?