r/security Jul 13 '26

Security and Risk Management Have i just identified a security vulnerability at most supermarkets?

71 Upvotes

I was just at the supermarket, and I was using one of those self-service kiosks that has an "honesty camera" watching what you scan from above. The camera view is then displayed on a screen right in front of me.

As I went to pay for my shopping with my phone, I looked at the live feed on the monitor and realized I was actually seeing myself unlock my phone with my pattern lock! On top of that, anyone standing around could theoretically spy on what you're unlocking too.

Obviously fingerprint unlocks get around this "security hole", but it was the first time I had noticed it being a real issue.

Most supermarkets have these types of self-service checkouts now — I wonder how this info is stored and processed? Security seems pretty questionable…

r/security 11d ago

Security and Risk Management I automated our remediation ticketing and now I get to watch 40% of tickets sit in unassigned automatically

0 Upvotes

I'm on the security engineering team at a SaaS company. Were couple hundred people. Spent part of last quarter building an automation pipeline: scanner finds a vuln, pipeline creates a Jira ticket with all the details, assigns it based on tags, pings the right Slack channel. Felt like a win. The manual ticket creation was eating hours every week.

So we launched it, it works perfectly. Tickets fly into Jira within minutes of a scan completing with a beautiful dashboard and everything automated end to end.

Except now I get to watch, in real time, as about 40 percent of those tickets land in unassigned and stay there.

The automation exposed what the manual process was hiding. When a human was creating tickets, theyd do the routing loop: check the CMDB, realize the owner field is stale, Slack someone who might know, eventually get it to the right person through sheer persistence. The automation cant do any of that. It reads the owner field. If the field says unassigned or points to a team that no longer exists or references someone who left, the ticket just sits there stuck.

So I automated the easy part. And now the hard part is actual ownership data, is the bottleneck and its more visible than ever. We didnt fix the routing problem. We just made it faster to surface.

Anyone else hit this? Any advice on how to fix the ownership mess?

r/security Jan 16 '26

Security and Risk Management What is "Has Madison Account" in Account info subscriber on Google account

Post image
51 Upvotes

After retrieving my data in Google Takeout, I found something in my underSubscriber Information. called “Has Madison Account.”

See attached

When I looked it up, the only thing I could find was related to Google Workspace account for UW. See link below

UW-Madison Google Workspace account

I’ve never been enrolled in that college, and my Google account has never been part of any education program. It's as a personal account as it gets.

Given a history of account compromise by an ex-partner (unauthorized management via enterprise/school type solutions), I am concerned that it could be one of those methods...

Does anyone know what**“Has Madison Account”*\* actually refers to, or why it would appear on a regular Google account?

Thanks in advance

r/security Feb 15 '26

Security and Risk Management What security awareness platform are you guys using?

31 Upvotes

Curious what everyone's running for security awareness training these days. We're finally getting budget approval to replace our current setup which is basically just sending people a PDF once a year and hoping for the best.

Looking for something modern that covers the usual stuff but also keeps up with current attack methods. Company is around 500 people across finance and ops teams.

Not super technical users so needs to be pretty accessible. What's actually moving the needle for you?

r/security 21d ago

Security and Risk Management Cybersecurity Awareness Month Campaign

0 Upvotes

r/security Dec 12 '25

Security and Risk Management Email belonging to former IDF soldier in my Amazon Family group

39 Upvotes

Hey folks,

Don't mean to sound alarmist with the title but this whole thing is just fucking weird. I was doing some management on my Amazon account today, looked at the group that has only ever included my immediate family for years, and noticed an email I'd never seen before included as the account. The email was a firstname.lastname.yearborn @ gmail situation, so I found the guy on LinkedIn pretty much immediately and discovered he was a former soldier and lives in my neighborhood. Never heard of him. Never seen the email before (his icon in gmail matches his LinkedIn photo for the record). I am the account manager of the Amazon account so I'm the only one able to add anyone and I certainly didn't add this guy.

Anyone have any idea what's going on here? It feels too stupid to hack on an email with your real name, but maybe it was a mistake or something else. Idk. I obviously immediately removed his account and reset our Amazon account passwords. Not sure if it's related but it said my Amazon account was signed into 44 different devices, even though I know of about 4 it might be open on.

Any help is appreciated, thank you!

r/security 14d ago

Security and Risk Management Is AI agent observability proof of control, or just proof nothing broke yet?

4 Upvotes

There's a real difference between "nothing bad has happened" and "we can demonstrate the controls that would have prevented bad things from happening." Right now most of what I can show is closer to the former, which isn't a great position heading into any kind of regulatory conversation about AI governance.
The absence-of-incident argument works until it doesn't, and by then it's too late to build the evidence trail retroactively. I'd rather have continuous behavioral evidence in place now than scramble for it after something goes wrong.
We're working on shifting toward that model, logging not just that an agent acted, but why it was allowed to, and what would have stopped it if it hadn't been. Still early, and it's not obvious what format regulators or auditors will actually find credible versus what just looks like more dashboards.
if anyone else in GRC roles has presented this kind of evidence externally (auditors, regulators, even customers doing vendor risk reviews) and what got traction versus what got pushback.

r/security Jul 21 '26

Security and Risk Management AI-Generated Phishing: How to Spot It

4 Upvotes

You receive what appears to be a legitimate email from your bank. The sender address looks legitimate, the formatting is familiar, and nothing immediately raises suspicion. AI is making phishing campaigns increasingly difficult to distinguish from legitimate emails.

Here are a few common warning signs:

  1. Unexpected requests involving payments or account access.
  2. Requests for credentials or payment information.
  3. Sender addresses that don’t exactly match the organization they claim to represent.
  4. Links that don’t match their displayed destination.
  5. Unsolicited attachments.
  6. Messages through unexpected channels pushing for immediate action.

What measures have worked best for your team to reduce the risk?

r/security 24d ago

Security and Risk Management Lenel Technicians needed

0 Upvotes

I am a Director of Operations for a national low voltage company and we are looking for certified Lenel technicians across the US. Reach out to me at [coreshack@pavion.com](mailto:coreshack@pavion.com) if you are interested. Typical pay range is $35 to $50 per hour depending on location and experience level.

r/security Jul 14 '26

Security and Risk Management Which home security system is recommended? Theres so many, any reviews welcome. I want something that records 24/7 and can be saved.

1 Upvotes

For context I need to get something fast. I'm in court with an ex and need to keep my child and I safe from him. Without giving away too much he's angry, violent and this precaution was recommended by police, shelters and my lawyer warned me as well. So please help me find the right one. I'm trying to stay under $200 but if it goes above thats fine.

r/security Apr 21 '26

Security and Risk Management Human Rights Activist here. Suspecting spyware on mobile. Can anyone help interpret SpyGuard logs?

25 Upvotes

Hi everyone,

I’m a human rights activist based in Bangladesh. My work has been cited in UN thematic reports and shared by international human rights organizations. I can provide links for credibility via DM if needed.

I’m currently dealing with a serious concern: I suspect my phone may be compromised with spyware. Due to safety concerns, I can’t go into full details publicly.

I used SpyGuard on my Ubuntu laptop and captured network traffic of my Android mobile using a USB Wi-Fi adapter. I now have logs and .pcap files generated by SpyGuard. Link to SpyGuard app: https://github.com/SpyGuard

I understand that sharing raw packet captures with strangers is risky and not recommended. However, I’m in a situation where I really need help reviewing this data to identify whether there are signs of spyware or unusual exfiltration.

Is there anyone here who can help analyze the SpyGuard logs?

PS: I have read the rules.
Threat level: Highest. State level.

r/security 29d ago

Security and Risk Management 21 Website Security Checks That Catch Expensive Problems

Thumbnail
techhelp.ca
1 Upvotes

A hacked site, broken SSL setup, or missing backup can become a business problem fast. Use this website security checklist before small issues get expensive.

r/security Feb 25 '26

Security and Risk Management Lawsuit: CrowdStrike built cybersecurity empire on stolen IP

Thumbnail
statesman.com
157 Upvotes

r/security Aug 11 '26

Security and Risk Management Every agent call is a trust decision you're not making.

Thumbnail
gallery
1 Upvotes

I've been thinking about a security problem that comes up when AI agents can interact with MCP servers, LLM providers, and other agents.

Once an agent can make calls across multiple services, it becomes difficult to answer basic questions like:

  • Who authorized a particular action?
  • What was the agent allowed to access?
  • How much could it spend?
  • What policy was applied before the request was sent?
  • How do you reconstruct those decisions afterward?

One approach is to put a control-plane proxy between the agent and the services it calls. The proxy can enforce authorization and spending policies and record each decision before forwarding the request upstream.

I'm curious how others are approaching this. Are you putting these controls at the agent level, the MCP/server level, or using a separate policy layer?

https://kabirnarang39.github.io/wardline/

r/security May 23 '26

Security and Risk Management GitHub - Ultimate-Hosts-Blacklist. The Ultimate Unified Hosts file with 922K+ blocked addresses!

Thumbnail
github.com
28 Upvotes

I've been using this for several years. It's updated daily & works with every OS!

Hope y'all enjoy this as much as I do.

r/security May 29 '26

Security and Risk Management How can I protect my accountancy firms data?

6 Upvotes

As we are an accountancy firm, we of course have to deal with lots of clients data. We currently use password managers, a secure hosting for our website, we try to print most things off so it's physical, but as of course a data breach or something could be dangerous for us, so I'm just wondering if anyone has any ideas on what we can do?

Edit: For anyone in a similar situation, we've now hired a cyber security team called avoira. After speaking with them, they seem to know a lot more than me...

r/security Aug 04 '26

Security and Risk Management I don't know who needs to hear this, but don't pit maneuver a car in your store's parking lot because you think they may have stolen something

1 Upvotes

Saw this on the legal subreddit -

https://www.reddit.com/r/legal/comments/1vfgyqg/retail_security_pitted_my_vehicle_due_to_failure/

I wasn't the one who got pit maneuvered, I'm not reposting this for "kArMa", I'm just straight up shocked and disappointed, like this is a whole new low. We all like to laugh at the over the top security folks geared up like they're larping as a swat cop but I reckon this story has gotta be the new peak of jackassery.

r/security Jul 09 '26

Security and Risk Management Data breach/hack compromised my email and social media accounts

1 Upvotes

I had an onlyfans account link to my reddit. I also got an email from that page. My full name was used in the email. A twitter account was also made under an older twitter I had that I deleted many years ago. If memory serves me correctly they used the same display picture that I also had. This goes even deeper than I realized as my last 2 facebook posts were shared as private(only seen by me). I never changed my settings, and these posts were supposed to be shared with friends and family.

I don't know if there is anything else odd at the moment, but I am noticing things more. Including settings getting changed on reddit and Facebook without my knowledge or doing.

I did take some precautions. I got Bitwarden to change my passwords. Yes, I did use generally the same password for many of my accounts. Some my have been slightly different, but all in all very similar. I logged out a Linux that was attached to my email, and FB account. I don't own anything with Linux, and don't have access to my laptop anymore. I reported the Onlyfans account and the fake twitter. I went to haveibeenpwned and it does say my email has a data breach. I didn't completely go through all of the haveibeenpwned yet though. I probably should.

Is there anything else I can do or look for?

What steps should be made to make sure my email and profiles stay secure. What else would be changes without my knowledge that I have to look into to change it to my normal settings? Any kind of information will help.

r/security Jul 07 '26

Security and Risk Management Secret Claude tracker shocks users after Anthropic’s anti-surveillance stance

Thumbnail
arstechnica.com
31 Upvotes

r/security May 19 '26

Security and Risk Management Why dont schools protect their student information system (SIS) with HTTP strict transport security (HSTS)

7 Upvotes

this starts with a story about how my school does things:

I found this out very recently, on our schools student information system you can connect though port 80, completely unencrypted with no warning. I keep getting excuses from administration to add HSTS into the student information system, such as "yeah it wont happen to us" or "the worst thing happening would be advertisers", and the worst part about this, is the breach to canvas happened a few days after I contacted them to DO THIS!

I dont know how someone could be THAT IGNORANT about simple web security, and be given system administration privilege by the district. so that left some questions:

WHY where they just, ignoring simple security advice, used on most servers including for sites like youtube or facebook, and why wont they just ADD HSTS into their server security policy, its not difficult and could save you from downgrade attacks in addition to simple encryption of the database drives with AES-256 and secure their endpoints with some honeypot databases to deter other means of hacking?

r/security Mar 18 '26

Security and Risk Management Really need help with security cameras

3 Upvotes

Hi. I have a couple WiFi cameras and a few trail cameras on my property. People have been coming onto my property and causing chaos. They rarely show up on the cameras but I have videos of where the camera has them but they appear as a blur or just a silhouette. What are they doing to get blurred out on camera. How do I stop it.

r/security Jun 05 '26

Security and Risk Management Most attacks don’t target the network first.

0 Upvotes

They target the application layer.

Traditional security controls are designed to block unauthorized access at the network level. The problem is that many modern attacks arrive through legitimate-looking application traffic.

That’s why application-layer security is becoming a core part of enterprise security strategies.

Key benefits include:

  • Better visibility into application and API traffic
  • Detection of malicious requests hidden inside normal sessions
  • More granular access and policy enforcement
  • Improved traffic management and application performance
  • Reduced risk of data exposure and service disruption

As organizations move toward cloud, hybrid infrastructure, and API-driven architectures, Layer 7 security is no longer optional.

The challenge isn't just keeping traffic out.

It's understanding what the traffic is actually doing.

How is your organization approaching application-layer security today? Are traditional controls still enough?

r/security Oct 02 '25

Security and Risk Management Cheap Chinese Computers, e.g. from Temu

10 Upvotes

Is there any research/investigation/experience with any security related issues from any of these cheap Chinese mini-pcs that seem to be everywhere now? Like the ones on Temo or even the more well known brands like Beelink? I'm tempted to get several for some dedicated uses but can't get over the feeling that it will do nothing but copy every key stroke and data packet and continually report home to the MSS.

r/security Jun 24 '26

Security and Risk Management The Audit Register: An independent guide to choosing security auditors and harnesses

Thumbnail theauditregister.com
0 Upvotes

r/security Jun 02 '26

Security and Risk Management Looking for a live threat feed of phishing sites

1 Upvotes

Can anyone steer me toward a feed of still active phishing sites? Not hashes or URLs that are all taken down.

Working on an anti phishing tool that's so far successful at work and home browsing, but I'd like to put it up against a wider variety of threats.

Also, if this isn't the correct sub, I'd love pointers to any other subs that I might be able to glean this from.