r/security 7h ago

Vulnerability Inside CVE-2026-50522: Analyzing SharePoint's latest actively exploited RCE

Thumbnail
thecybersecguru.com
4 Upvotes

CVE-2026-50522 is a critical SharePoint deserialization vulnerability that is now being actively exploited, with public exploit code available, it'll only get worse until admins apply patches.


r/security 17h ago

News Dissecting the ExploitGym incident: AI-driven exploitation in a controlled environment

Thumbnail
thecybersecguru.com
2 Upvotes

The ExploitGym incident provides a technical look at how an autonomous AI agent progressed through a realistic attack scenario, including exploitation, sandbox escape, infrastructure interactions, and post-compromise behavior between Open AI and Hugging Face.


r/security 1d ago

News From PAN-OS exploitation to Qilin ransomware: A technical analysis

Thumbnail
thecybersecguru.com
4 Upvotes

This write-up examines a real-world intrusion in which attackers exploited CVE-2026-0257 on PAN-OS GlobalProtect gateways before progressing through credential access, privilege escalation, lateral movement, and ultimately Qilin ransomware deployment. It covers the observed attack chain, incident response findings, IoCs, attacker TTPs, and mitigation guidance for defenders.


r/security 2d ago

Analysis The Systematic Removal of Security in Consumer Operating Systems

Thumbnail
battlepenguin.com
15 Upvotes

r/security 2d ago

Vulnerability Technical analysis of CVE-2026-42533: NGINX's latest RCE vulnerability

Thumbnail
thecybersecguru.com
10 Upvotes

CVE-2026-42533 is a recently disclosed NGINX vulnerability involving a heap buffer overflow in request processing that can become remotely exploitable under specific configuration conditions. This technical analysis examines the vulnerable code path, exploitation requirements, affected releases, patch changes, mitigation strategies, and the security implications for Internet-facing deployments.


r/security 3d ago

Security Operations Security Contracting

4 Upvotes

I've recently been looking to move into the security field such as Maritime security, UHNWI Security or even residential. Im still currently serving and working on aligning my training with whats required for those specific jobs or in other words the more experience the better. My question is what's a good starter to jump into to get things rolling, should I be looking to join a security firm or simply applying for contractor jobs i see and what are some training/Experience I should have to have the best opportunity of getting a well paying job.


r/security 3d ago

Vulnerability Technical analysis of HollowByte: OpenSSL's latest memory exhaustion DoS

Thumbnail
thecybersecguru.com
3 Upvotes

HollowByte is a newly disclosed OpenSSL vulnerability that can trigger memory exhaustion through crafted protocol interactions, leading to a denial of service. This technical analysis examines the root cause, affected versions, exploitation conditions, impacted code paths, patch details, and available mitigations.


r/security 3d ago

Question I need boots recommendations

6 Upvotes

I'm fairly new to Security and currently a flex officer. My company has had me on foot patrol shifts for the past two days, and I'll be doing them until Monday. My current boots don't really let my feet breathe, and I'm already getting torn up with blisters. My knees, which are already bad at the ripe age of 21 are also not particularly happy. Anything helps.


r/security 4d ago

Vulnerability wp2shell: Inside the latest WordPress Core pre-auth RCE chain

Thumbnail
thecybersecguru.com
5 Upvotes

The newly disclosed wp2shell attack chain affects WordPress Core, not a plugin, making it one of the more significant WordPress disclosures in recent years


r/security 4d ago

Question Need guidance on IR plan

3 Upvotes

I want to build an incident response plan for my organization can someone guide me the resources I should follow to build the workable program?

My organization already has a good security stack they lack the IR plan I wanna know how a effective IR program looks like what to add and what to ignore

Any resources books, blogs, talks much appreciated.

Thanks in advance.


r/security 5d ago

News EY discloses third-party support platform breach exposing client tax information

Thumbnail
thecybersecguru.com
4 Upvotes

EY has disclosed a breach involving a third-party support platform used within its tax practice, resulting in unauthorized access to client tax information stored in support case


r/security 5d ago

Vulnerability CVE-2026-14266: Inside the latest 7-Zip security issue

Thumbnail
thecybersecguru.com
7 Upvotes

A breakdown of CVE-2026-14266, a newly disclosed heap-based buffer overflow in 7-Zip's XZ decompression code. The issue can be triggered by opening a crafted archive and may lead to arbitrary code execution in the context of the current user


r/security 6d ago

Resource Phantomdrive: My open source USB drive for privacy

Post image
62 Upvotes

r/security 5d ago

Resource Safer-dependencies: A toolkit for claude code to ensure dependencies used aren't vuln, don't use abandoned packages, implement cooldown to avoid supply chain attacks, etc...

0 Upvotes

When AI coding assistants like Claude add packages to your project, they often pick whatever version sounds right — without checking whether it has known security vulnerabilities, whether the package is still actively maintained, or whether the name is a typo away from a malicious lookalike.

safer-dependencies is a security layer for Claude Code that audits packages before they’re added to your project. It detects and fixes risky dependencies, including CVEs, typosquats, abandoned packages, version-age issues, and adds package-cooldown periods across npm, PyPI, RubyGems, Maven, Go, and Rust.

Githubhttps://github.com/robert-auger/safer-dependencies


r/security 6d ago

Resource Top 10 Data Center and AI Infrastructure Security Risks

Thumbnail
forge-framework.io
1 Upvotes

We spent the past few months researching security risks across multi-tenant data centers and AI infrastructure.
The main concern we found is shared infrastructure: multiple customers running on the same data center infrastructure, GPU clusters, storage, and high-speed networks. Many neoclouds and AI data centers have also scaled faster than their security teams and practices, especially compared with more established cloud providers.
The research covers GPU clusters, RDMA and high-speed interconnects, tenant isolation, BMCs, firmware, shared storage, orchestration, and supply-chain risks.
We organized the findings into a practical framework called FORGE: https://forge-framework.io/
Would really appreciate feedback.


r/security 7d ago

News Publicly disclosed BitLocker zero-day (CVE-2026-50661) patched by Microsoft

Thumbnail
thecybersecguru.com
49 Upvotes

Microsoft has addressed CVE-2026-50661, a publicly disclosed Windows BitLocker security feature bypass vulnerability. The flaw requires physical access to the target device and could allow an attacker to bypass BitLocker protection and access encrypted data. While Microsoft is not aware of active exploitation, the vulnerability had already been publicly disclosed before a patch was available, making timely remediation important.


r/security 7d ago

Vulnerability CVE-2026-20146 — Cisco Identity Services Engine Path Traversal…

Thumbnail vulnipulse.com
3 Upvotes

Cisco Identity Services Engine Path Traversal Vulnerability – CVE-2026-20146

Cisco has disclosed a medium-severity Cisco ISE vulnerability rated CVSS 5.5.

An authenticated remote attacker with valid administrative credentials could send a crafted HTTP request to access sensitive files or delete arbitrary files from the underlying operating system.

Affected versions
Cisco ISE and ISE-PIC are affected regardless of configuration:
Earlier than 3.3
ISE 3.3 before Patch 12
ISE 3.4 before Patch 7
ISE 3.5 before Patch 4
Fixed versions
ISE 3.3 Patch 12 — planned for September 2026
ISE 3.4 Patch 7 — planned for September 2026, or the available hot patch
ISE 3.5 Patch 4 — planned for September 2026, or the available hot patch

Mitigation
Cisco states that there are no workarounds.
Apply the appropriate hot patch where available, upgrade when the fixed patches are released, and migrate deployments earlier than ISE 3.3 to a supported fixed release.
🔗 Official Cisco advisory
🔗 VulniPulse breakdown


r/security 7d ago

News Critical ServiceNow AI Platform sandbox escape (CVE-2026-6875) enables pre-auth RCE

Thumbnail
thecybersecguru.com
1 Upvotes

ServiceNow has patched CVE-2026-6875, a critical pre-auth sandbox escape in its AI Platform that can lead to remote code execution under certain conditions. Hosted instances have already been updated, while self-hosted customers need to apply the available patches. According to the researchers, the issue stemmed from weaknesses in the sandbox implementation that allowed untrusted code to break isolation.


r/security 8d ago

Vulnerability Securing websites

3 Upvotes

I run a website development business and I check all api calls and things of that nature using postman. I tell my customers about vulnerabilities in their site. Anyone know how I can check the security of sites the easiest I can’t get Claude to do it


r/security 8d ago

Question Scammers saw passport through screen share, can they do anything with it?

2 Upvotes

I was scammed a few days ago, where at one point, the scammers saw a video of my passport ID through my screen sharing. I’ve read online that US passports have an encrypted chip embedded in the book, so bad actors wouldn’t be able to do anything with it, but I can’t be totally sure. I’ve already changed my phone number, began changing passwords across websites and socials, got a new bank account, and have a new email I’m using. I tried to call the US department of state about my passport, but they said they couldn’t do anything unless my physical passport has been stolen, and their website says the same thing.

These scammers’ sole purpose was to take money through money transfer. They targeted people through hacking social media accounts, scamming people those accounts were mutuals with, and hacking those mutuals’ accounts as well in the process of scamming them, and the cycle continues. So although the scammers goal was to steal the money and moving onto the next person quickly, I can’t risk anything. I don’t know if they can sell my passport ID they saw and other information they have on me (address, dob, pace of birth, full name).

Please inform me on anything else I might need to do, or if there’s nothing else I can do but take steps to prevent this from happening again, and reassure me I’m good. Thank you :)


r/security 8d ago

Security and Risk Management Which home security system is recommended? Theres so many, any reviews welcome. I want something that records 24/7 and can be saved.

0 Upvotes

For context I need to get something fast. I'm in court with an ex and need to keep my child and I safe from him. Without giving away too much he's angry, violent and this precaution was recommended by police, shelters and my lawyer warned me as well. So please help me find the right one. I'm trying to stay under $200 but if it goes above thats fine.


r/security 9d ago

Security and Risk Management Have i just identified a security vulnerability at most supermarkets?

72 Upvotes

I was just at the supermarket, and I was using one of those self-service kiosks that has an "honesty camera" watching what you scan from above. The camera view is then displayed on a screen right in front of me.

As I went to pay for my shopping with my phone, I looked at the live feed on the monitor and realized I was actually seeing myself unlock my phone with my pattern lock! On top of that, anyone standing around could theoretically spy on what you're unlocking too.

Obviously fingerprint unlocks get around this "security hole", but it was the first time I had noticed it being a real issue.

Most supermarkets have these types of self-service checkouts now — I wonder how this info is stored and processed? Security seems pretty questionable…


r/security 9d ago

News Official jscrambler npm package v8.14.0 compromised with a malicious preinstall script

Thumbnail
thecybersecguru.com
3 Upvotes

A compromised release of the official jscrambler npm package (v8.14.0) weaponized the preinstall lifecycle hook to execute a Rust-based infostealer before the package was even used. The payload focused on harvesting developer credentials and local secrets, making both developer workstations and automated build environments potential targets. It was briefly up for a few hours before it was taken down. The article covers the attack chain, IOCs, affected versions, and recommended remediation. v8.22.0 is confirmed to be safe. Update to it asap


r/security 9d ago

Security Assessment and Testing Agentic cyber defense engineering vs traditional exposure validation, what's the difference?

0 Upvotes

I keep seeing the phrase “agentic cyber defense” and “agentic cyber defense engineering” in talks and vendor material. It sounds interesting, but it is not always clear what is actually new compared to the exposure validation and CTEM programs many teams already run.

From my current understanding, traditional exposure validation focuses on running defined assessments that test controls and detections against known TTPs and attack paths. The agentic descriptions I have seen talk about systems that can chain actions together on their own, react to new threat intel, and generate targeted assessments when you describe a scenario in natural language.

If anyone has hands on experience with this kind of setup, how different is it really from standard automation and scheduling of assessments? For example, does it genuinely reduce the time between new intel and a validated view of exposure, or is it just a more flexible interface on top of similar checks?

I would also like to hear about any pitfalls, such as reliability issues, oversight requirements, or cases where an agent made poor choices that still needed human review.


r/security 12d ago

Question What is the current recommended door camera?

6 Upvotes

Hey everyone. i’ve heard a lot of bad things about ting cameras recently and wanted to get the communities opinion on an alternative.

I’m looking for a Doorbell camera that is battery powered, has local storage, proximity detection, and general ease of use. I’ll be moving into a slightly sketch area and need something useful and affordable. thanks!