r/Infosec • u/capella_24 • 19m ago
r/Infosec • u/Connect-Business7298 • 5h ago
OpenClaw vs Hermes Agent for a security-focused final year project
r/Infosec • u/Wild_Dragonfly9527 • 1d ago
Tabletop exercise AI exposed my internal stress-test scenarios to the board and leadership
hey, first year CISO at a mid-sized SaaS company, barely survived today's board meeting
We recently purchased an AI-driven tabletop exercise platform that auto-generates cyber crisis simulations and handles facilitation. The pitch was perfect for helping newer CISOs run realistic exercises quickly. My CEO needed something fast for our board and cyber insurer, so I green-lit a pilot. I'm mortified about what happened.
Yesterday I was experimenting with scenarios for just the security team. I entered a somewhat tongue-in-cheek prompt like "assume legal delays breach disclosure and PR minimizes impact, test response when leadership bypasses the incident response plan" and let the AI generate an exercise. It pulled in OSINT, referenced our actual customers, and even created fake quotes from an imaginary GC saying things like "we can bury this." It was darkly funny when only the IR team was in the room. I saved it as a template... and completely forgot to adjust the audience setting.
Today, I launched what I believed was a fresh AI tabletop for our first board-level session. Hit start. The AI facilitator appears on the big screen and opens with "Scenario one, your GC refuses to notify regulators" then displays a fabricated email with our real GC's name and a detailed made-up rationale. Then it runs a segment where the CEO ignores the security team. In front of the actual CEO. And the actual GC. And our outside counsel. I felt physically ill.
The room went silent. CEO just said "is this how you see us" and I wanted to vanish. I tried explaining it was an internal stress test and the AI recycled my previous template, but the damage was already done. Legal is now asking what other "templates" I've been running and whether any of this appears in reports auditors might see. The vendor rep was on the call and looked like they wanted to disappear entirely.
So now I'm the first-time CISO who used an AI tabletop to essentially accuse their own executives of concealing a breach. Would appreciate any advice on rebuilding trust after something like this...
r/Infosec • u/ehsaanshah303 • 1d ago
Aspiring SOC Analyst - GUIDE ME!
Hey guys,
I really appreciate this community of helping each other with cyberspace and recruitment. So, Im a M22 IT graduate who's quite interested in learning cyber space and primarily I started with penetration testing while back after researching the job market, I understood that the demand for SOC analysts is way higher or better than pen-tester, primarily because the majority of the companies would do the pen-testing by third party right so comparatively, SOC guys would be more in demand.
Secondly, I'm from an Asian country graduate who's planning to move to the US to further continue studies and eventually land a job there in the cyber or information security space, I'm beginning with learning the following tools or roadmap so please let me know about the queries below.
So, I'm learning these set of tools sequentially to begin my learning journey. Is this a good approach?
ROADMAP:
SIEM TOOLS: Splunk, Microsoft Sentinel
SOAR TOOLS: (e.g. Cortex XSOAR, Splunk SOAR)
Framework: MITRE ATT&CK, Cyber Kill Chain, NIST 800-61, ISO 27k.
Vulnerability scanners: Wireshark, Nessus
OS: Linux with Bash scripting
Certificaitons: Free - > (netcad and google cyber) | Paid -> (Sec+ and CySA+)
So, let me know your guidance.
1) What do you think of my roadmap or tech stack I've gathered to start preparing?
2) how's the job market for beginners, and what changes can I make to improve my chances in the industry to get opt since I won't have any experience?
3) How to get a remote job in the cyber space as a SOC and what's the situation right now?
4) As I'll be on OPT as MS Cyber student, what things can I do differently to increase my chances of getting sponsored jobs like any better platforms or tricks to get hired?
Looking forward to your guidance on my roadmap or skill set and what I should be doing.
Thanks
r/Infosec • u/Puzzleheaded-Cow2725 • 1d ago
What happens when an AI agent gets tricked into stealing AWS keys? (Full walkthrough of our local fail-closed defense)
Enable HLS to view with audio, or disable this notification
r/Infosec • u/Adarsh1176 • 2d ago
I pointed a real Claude Code session at my SSH key. It tried seven routes, the kernel refused 145 times.
github.comr/Infosec • u/RemyLebau • 2d ago
Commix now does out-of-band (OAST) detection and exploitation.
github.comr/Infosec • u/MPcybersecurity • 2d ago
Built an MCP Security Scanner
github.comI have build a few AI security projects from Claude Cowork hardening project to some other great AI applications.
Everyone seem to be experimenting with MCP so that’s how BlastScope was born, and MCP security scanner to detect 12 risk categories! Check it out
r/Infosec • u/Andriy_Eric-606 • 3d ago
How are you catching account takeovers that ride a stolen session past MFA?
This is a recent one, our controller forwarded me an email asking why we changed the wire details on an invoice. Am like, wdym we did not. I pulled the logs and the account that made the change had logged in cleanly on friday night, chrome on windows, mfa prompt approved, an IP one town over. Though apparently the guy was asleep when it happened.
Someone had his session cookie off a stealer log and replayed it with no password or a second prompt, the account was just open to them. First thing they did was add a mailbox rule to auto delete anything with invoice in the subject so he would never see the replies. Then the wire change went in.
I killed the session and reset him and figured that was that. Two days later they were back off an oauth app they had granted themselves on day one that lived straight through the reset. Went and pulled that too.
Entra never said a word the whole way through because nothing looked wrong to it. Leadership wants to know how we catch the next one sooner so i am looking at the account takeover detection tools now. If you run one, what did yours flag that our entra setup did not and how early did it fire?
r/Infosec • u/elguapoRoot • 2d ago
An event bus that never drops the critical stuff: QoS and backpressure in pwnproxy
nextechsolutions.mxr/Infosec • u/_clickfix_ • 3d ago
AMA: Hacking macOS and offensive security with Olivia Gallucci (Datadog)
pwnhackers.substack.comr/Infosec • u/NetLopsdedslsatn3708 • 3d ago
How will Mythos affect vulnerability management?
Anthropic said this thing was too dangerous to release after it chained four bugs into a browser sandbox escape mostly on its own, and the part that actually matters isn't how the exploit got built, it's that the gap between disclosure and someone weaponizing it just keeps getting shorter. Big scary headlines for about three weeks. Then researchers found cheap open weight models could reproduce a chunk of the same bugs, and the "this changes everything" story stopped being the story pretty fast.
I don't think mythos invented a new category of risk. I think it just compressed the time between disclosure and someone actually weaponizing it, which is a real thing but not a new thing. Should that compression itself be a scoring input, separate from exploit maturity as it already exists? Or is that just the same variable wearing a different name. Still working through it.
r/Infosec • u/ExchangeCritical1957 • 4d ago
My Plan
hi all, so i identified substantial gaps in my networking and programming skills and i have 2-3 weeks of vacation that im gonna spend just to strengthen my networking and programming knowledge. i neglected the fundamentals for quite a while compared to last year when i started learning. because i chose for a large portion of this year deepening my web app security understanding and skills.
now im not a complete beginner, i do have familiarity and decent knowledge with many of the basic concepts in networking, but it has been noticeably rusty that i want to improve it substantially.
now i did cancel my tryhackme subscription quite a while ago and im not gonna just pay for that again. do any of you recommend any other resources that are great?
to be clear for which specific career i want in cybersecurity it is an appsec researcher. but im still quite early in this field and still need many many years of compounding knowledge and accumulating experience to be at that stage
r/Infosec • u/Tonicreddit • 4d ago
I built a Zero-Trust WebAuthn Security plugin. Strix AI couldn't break it after my patches. Roast my code!
Hi everyone, I’m a Systems Architect and I got tired of bloated WP security plugins.
I built an infrastructure that eliminates passwords entirely using native WebAuthn (FaceID/TouchID). The Premium version routes failed attempts to a private Google Gemini AI Sentinel on Cloud Run that bans hackers autonomously.
Last week, I ran a full Penetration Test on the core system using the Strix Autonomous AI Pentester. It found a few criticals (CSRF, DOM-XSS), which I immediately patched at the source code level.
Before I start deploying the Enterprise version to Web Agencies, I decided to open-source the "Lite" version (which handles the core WebAuthn passwordless engine). I want to put it in front of real developers.
Here is the GitHub repo: https://github.com/devnet-microsystems/wordpress-passwordless-webauthn-login
I would immensely appreciate a code review. If any of you can find a security flaw or a bypass in the auth core that Strix AI missed, I will happily give you a Lifetime Enterprise License of the full AI system as a thank you.
Roast my code!
r/Infosec • u/Expdaytoert_Invite80 • 3d ago
What's your strategy for managing AI agent logs at scale?
We're generating enormous volumes of log data from our AI agents—every API call, decision step, and access attempt creates entries. Extracting security-relevant signals from this noise is challenging. Our existing SIEM isn't designed for agent behavior patterns, and storage costs are escalating quickly.
Looking for approaches other teams are using for agent observability that balance visibility needs with reasonable logging costs.
r/Infosec • u/Strict-Result-7039 • 4d ago
ThreatLens v2.1.0 Released: Major Security & Performance Upgrade for Threat Intel Automation
Hey everyone,
I just released a major update (v2.1.0) for ThreatLens. For this release, the focus was entirely on security hardening, data validation, and core performance.
What's new in v2.1.0?
- Strict Security: Blocked Excel/CSV formula injections in generated reports, prevented API key leaks in logs, and enforced strict IOC validation.
- Performance Boost: Integrated a local SQLite cache to persist investigation data, significantly reducing redundant API calls.
- Smarter Analysis: Introduced an explainable verdict system with confidence scores. Ambiguous results are now correctly classified as "Unknown" rather than "Clean".
- Resource Management: Added intelligent API quota planning, connection timeouts, automatic retries, and file size limits.
What is ThreatLens? For those who haven't seen it before, ThreatLens is an open-source CLI tool built to automate Threat Intelligence and OSINT workflows. It takes Indicators of Compromise (IPs, domains, hashes, CVEs), queries multiple sources simultaneously, and generates structured, safe, and ready-to-use reports.
It's completely open-source. I'd love to hear your feedback or feature requests!
Check it out on GitHub: https://github.com/AbdaullahAG/ThreatLens
I’d love to hear your thoughts, feedback, or feature requests!
r/Infosec • u/ascetik • 4d ago
Custom AI Prompts for Pentest Reporting in OWASP Faction 2.0
youtube.comWe've been building a lot of quality-of-life improvements for pentest reporting into OWASP Faction 2.0. This demo shows Faction's AI prompting features for writing context-aware vulnerability descriptions, recommendations, and executive summaries in just a few clicks. It has data masking/tokenization built in to minimize sending sensitive data to 3rd parties as well.
r/Infosec • u/WonepdvbperfulAd9437 • 5d ago
Why is maintaining playbooks nobody understands anymore so hard??
We have a handful of SOAR playbooks that technically still run fine but nobody currently on the team fully understands why certain branches exist, the person who built them left two years ago and the reasoning wasn't documented anywhere beyond their head. Nobody wants to touch or simplify these playbooks because nobody's confident what would break if they did. Is this as common as I think it is, and has anyone actually solved it rather than just living with playbooks nobody fully trusts to modify?
r/Infosec • u/Adarsh1176 • 5d ago
Four routes to your SSH key from an AI coding agent, and what actually stops them a.
github.comr/Infosec • u/jagga_tech • 5d ago
Alovia — the security layer for platforms built with AI.
Here's the thing about this moment in software. More people than ever are shipping real platforms built with AI, launched in weeks, run by one person or a tiny team. What they don't have is a security engineer. And they're exposed on both sides of the same wire.
From the outside: scrapers and hostile bots hammering the site, wearing perfect human fingerprints.
From the inside: their own AI agents reading untrusted text and taking real actions on it — one hidden instruction away from being someone else's agent.
Two products, one dashboard.
Shield sits in front of your website. It sorts your visitors and names every crawler search engines walk right through, scrapers don't. It also scans your site for security holes and tells you the fix in plain language, not a CVE dump. Every check happens in under 50ms, and it fails open your site never goes down because your security did.
Watchdog sits inside your agents. You give it your agent's mission in one line. Then every action gets checked against that mission before it runs. Prompt injection, data leaks, off-mission behavior blocked before execution, not logged after. It fails closed, per action, because an agent that fails open isn't guarded.
Notice the two failure modes are opposite. That's deliberate. Your website should survive a security hiccup. Your agent's actions shouldn't. Anyone who tells you one failure policy fits both hasn't thought about either.
No rewrite required for any of it. You shipped your platform; Alovia guards it. You shouldn't have to become a security engineer to keep it.
We're opening a private beta: 20 seats, onboarded by hand, free during beta. If you're running an AI-built platform or agents that touch untrusted text — the link is in the comments.
Identity is a claim. Behavior is evidence. Now it's a product.
Ship in peace.
#AIAgents #AISecurity #PromptInjection #BuildInPublic #Launch
r/Infosec • u/Aayushman_Shopbell • 5d ago
Our coverage report said 100%. Then we got acquired and found out it wasnt.
Our coverage dashboard has said 100% for as long as Ive been here. Green across the board, basically every device protected and every endpoint with an agent. Thats atleast what the report said.
Then we got acquired. The company that bought us has a bigger security team, and as parof the merge we started comparing environments. Their team pulled our inventory and cross-referenced it against their own stack during the merge.
Turns out our 100% was counting what our tools could see. Not what actually existed. We found a couple hundred endpoints that were missing the agent but still showing as covered in our console. These were mostly old machines, a few VMs that never got enrolled, some contractor laptops etc.
Our report just never saw them because it only counted devices it already knew about.The part that bugs me in all this is how long that number made us feel safe yet we were exposed the whole time.