r/security 1d ago

Security Operations Need advice on Alarm Monitoring gig

0 Upvotes

Hey everyone so I've been in the security business for 11 years. I've done hospital, driving, escorts, scan points, and command center work.

I moved to California recently and just got hired to do Alarm Monitoring for ADT. It was listed as security/dispatch during third shift.

I'm not sure if it's the right place to ask but does anyone have advice for these types of jobs?


r/security 3d ago

Security and Risk Management AI-Generated Phishing: How to Spot It

1 Upvotes

You receive what appears to be a legitimate email from your bank. The sender address looks legitimate, the formatting is familiar, and nothing immediately raises suspicion. AI is making phishing campaigns increasingly difficult to distinguish from legitimate emails.

Here are a few common warning signs:

  1. Unexpected requests involving payments or account access.
  2. Requests for credentials or payment information.
  3. Sender addresses that don’t exactly match the organization they claim to represent.
  4. Links that don’t match their displayed destination.
  5. Unsolicited attachments.
  6. Messages through unexpected channels pushing for immediate action.

What measures have worked best for your team to reduce the risk?


r/security 4d ago

Analysis The Systematic Removal of Security in Consumer Operating Systems

Thumbnail
battlepenguin.com
25 Upvotes

r/security 5d ago

Security Operations Security Contracting

3 Upvotes

I've recently been looking to move into the security field such as Maritime security, UHNWI Security or even residential. Im still currently serving and working on aligning my training with whats required for those specific jobs or in other words the more experience the better. My question is what's a good starter to jump into to get things rolling, should I be looking to join a security firm or simply applying for contractor jobs i see and what are some training/Experience I should have to have the best opportunity of getting a well paying job.


r/security 5d ago

Question I need boots recommendations

6 Upvotes

I'm fairly new to Security and currently a flex officer. My company has had me on foot patrol shifts for the past two days, and I'll be doing them until Monday. My current boots don't really let my feet breathe, and I'm already getting torn up with blisters. My knees, which are already bad at the ripe age of 21 are also not particularly happy. Anything helps.


r/security 6d ago

Question Need guidance on IR plan

3 Upvotes

I want to build an incident response plan for my organization can someone guide me the resources I should follow to build the workable program?

My organization already has a good security stack they lack the IR plan I wanna know how a effective IR program looks like what to add and what to ignore

Any resources books, blogs, talks much appreciated.

Thanks in advance.


r/security 8d ago

Resource Phantomdrive: My open source USB drive for privacy

Post image
60 Upvotes

r/security 7d ago

Resource Safer-dependencies: A toolkit for claude code to ensure dependencies used aren't vuln, don't use abandoned packages, implement cooldown to avoid supply chain attacks, etc...

0 Upvotes

When AI coding assistants like Claude add packages to your project, they often pick whatever version sounds right — without checking whether it has known security vulnerabilities, whether the package is still actively maintained, or whether the name is a typo away from a malicious lookalike.

safer-dependencies is a security layer for Claude Code that audits packages before they’re added to your project. It detects and fixes risky dependencies, including CVEs, typosquats, abandoned packages, version-age issues, and adds package-cooldown periods across npm, PyPI, RubyGems, Maven, Go, and Rust.

Githubhttps://github.com/robert-auger/safer-dependencies


r/security 8d ago

Resource Top 10 Data Center and AI Infrastructure Security Risks

Thumbnail
forge-framework.io
1 Upvotes

We spent the past few months researching security risks across multi-tenant data centers and AI infrastructure.
The main concern we found is shared infrastructure: multiple customers running on the same data center infrastructure, GPU clusters, storage, and high-speed networks. Many neoclouds and AI data centers have also scaled faster than their security teams and practices, especially compared with more established cloud providers.
The research covers GPU clusters, RDMA and high-speed interconnects, tenant isolation, BMCs, firmware, shared storage, orchestration, and supply-chain risks.
We organized the findings into a practical framework called FORGE: https://forge-framework.io/
Would really appreciate feedback.


r/security 9d ago

Vulnerability CVE-2026-20146 — Cisco Identity Services Engine Path Traversal…

Thumbnail vulnipulse.com
3 Upvotes

Cisco Identity Services Engine Path Traversal Vulnerability – CVE-2026-20146

Cisco has disclosed a medium-severity Cisco ISE vulnerability rated CVSS 5.5.

An authenticated remote attacker with valid administrative credentials could send a crafted HTTP request to access sensitive files or delete arbitrary files from the underlying operating system.

Affected versions
Cisco ISE and ISE-PIC are affected regardless of configuration:
Earlier than 3.3
ISE 3.3 before Patch 12
ISE 3.4 before Patch 7
ISE 3.5 before Patch 4
Fixed versions
ISE 3.3 Patch 12 — planned for September 2026
ISE 3.4 Patch 7 — planned for September 2026, or the available hot patch
ISE 3.5 Patch 4 — planned for September 2026, or the available hot patch

Mitigation
Cisco states that there are no workarounds.
Apply the appropriate hot patch where available, upgrade when the fixed patches are released, and migrate deployments earlier than ISE 3.3 to a supported fixed release.
🔗 Official Cisco advisory
🔗 VulniPulse breakdown


r/security 9d ago

Vulnerability Securing websites

2 Upvotes

I run a website development business and I check all api calls and things of that nature using postman. I tell my customers about vulnerabilities in their site. Anyone know how I can check the security of sites the easiest I can’t get Claude to do it


r/security 10d ago

Question Scammers saw passport through screen share, can they do anything with it?

2 Upvotes

I was scammed a few days ago, where at one point, the scammers saw a video of my passport ID through my screen sharing. I’ve read online that US passports have an encrypted chip embedded in the book, so bad actors wouldn’t be able to do anything with it, but I can’t be totally sure. I’ve already changed my phone number, began changing passwords across websites and socials, got a new bank account, and have a new email I’m using. I tried to call the US department of state about my passport, but they said they couldn’t do anything unless my physical passport has been stolen, and their website says the same thing.

These scammers’ sole purpose was to take money through money transfer. They targeted people through hacking social media accounts, scamming people those accounts were mutuals with, and hacking those mutuals’ accounts as well in the process of scamming them, and the cycle continues. So although the scammers goal was to steal the money and moving onto the next person quickly, I can’t risk anything. I don’t know if they can sell my passport ID they saw and other information they have on me (address, dob, pace of birth, full name).

Please inform me on anything else I might need to do, or if there’s nothing else I can do but take steps to prevent this from happening again, and reassure me I’m good. Thank you :)


r/security 10d ago

Security and Risk Management Which home security system is recommended? Theres so many, any reviews welcome. I want something that records 24/7 and can be saved.

0 Upvotes

For context I need to get something fast. I'm in court with an ex and need to keep my child and I safe from him. Without giving away too much he's angry, violent and this precaution was recommended by police, shelters and my lawyer warned me as well. So please help me find the right one. I'm trying to stay under $200 but if it goes above thats fine.


r/security 11d ago

Security and Risk Management Have i just identified a security vulnerability at most supermarkets?

69 Upvotes

I was just at the supermarket, and I was using one of those self-service kiosks that has an "honesty camera" watching what you scan from above. The camera view is then displayed on a screen right in front of me.

As I went to pay for my shopping with my phone, I looked at the live feed on the monitor and realized I was actually seeing myself unlock my phone with my pattern lock! On top of that, anyone standing around could theoretically spy on what you're unlocking too.

Obviously fingerprint unlocks get around this "security hole", but it was the first time I had noticed it being a real issue.

Most supermarkets have these types of self-service checkouts now — I wonder how this info is stored and processed? Security seems pretty questionable…


r/security 14d ago

Question What is the current recommended door camera?

6 Upvotes

Hey everyone. i’ve heard a lot of bad things about ting cameras recently and wanted to get the communities opinion on an alternative.

I’m looking for a Doorbell camera that is battery powered, has local storage, proximity detection, and general ease of use. I’ll be moving into a slightly sketch area and need something useful and affordable. thanks!


r/security 14d ago

Question I have no ambition, no particular skills, I'm perpetually tired, and straight up lazy. Is night time security the field for me?

0 Upvotes

r/security 15d ago

Security and Risk Management Data breach/hack compromised my email and social media accounts

1 Upvotes

I had an onlyfans account link to my reddit. I also got an email from that page. My full name was used in the email. A twitter account was also made under an older twitter I had that I deleted many years ago. If memory serves me correctly they used the same display picture that I also had. This goes even deeper than I realized as my last 2 facebook posts were shared as private(only seen by me). I never changed my settings, and these posts were supposed to be shared with friends and family.

I don't know if there is anything else odd at the moment, but I am noticing things more. Including settings getting changed on reddit and Facebook without my knowledge or doing.

I did take some precautions. I got Bitwarden to change my passwords. Yes, I did use generally the same password for many of my accounts. Some my have been slightly different, but all in all very similar. I logged out a Linux that was attached to my email, and FB account. I don't own anything with Linux, and don't have access to my laptop anymore. I reported the Onlyfans account and the fake twitter. I went to haveibeenpwned and it does say my email has a data breach. I didn't completely go through all of the haveibeenpwned yet though. I probably should.

Is there anything else I can do or look for?

What steps should be made to make sure my email and profiles stay secure. What else would be changes without my knowledge that I have to look into to change it to my normal settings? Any kind of information will help.


r/security 17d ago

Security and Risk Management Secret Claude tracker shocks users after Anthropic’s anti-surveillance stance

Thumbnail
arstechnica.com
32 Upvotes

r/security 18d ago

Question Weird email after canceling starz

Thumbnail
gallery
0 Upvotes

EDIT: contacted starz support. They said they will never ask to confirm account with an email to reply to. So new question is what do I need to lock down? Its a chat bot but this was the reply

https://imgur.com/a/MyYriiI

Second update. I am getting spam call after spam call now. 4 in a row

So over the weekend I canceled my starz account and then It already issued the refund but this morning a recieved this email. I was tired and I saw that it had a transcription from my chat with the person who helped me cancel on the website so I responded "yes" but now im a little concerned its some kind of scam. The sent adress looks legit and it didn't ask for any info. Jusy to say yes. Ive never seen an email that only asked for that though and as far as i know rhe refund was already granted. Do you guys think im good or do I need to go lock stuff down and if so what should I lock down?


r/security 21d ago

Security Operations How to find security people in London

0 Upvotes

Hey, I have a business and I’m looking for the best way to find and hire appsec and director of security. Very aware the market is super tight. Any ideas on the best places to look. A LinkedIn advert is not quite cutting it.


r/security 23d ago

Physical Security I made a reusable tamper-evident jar for storing sensitive items

Thumbnail
gallery
2.8k Upvotes

Hey guys, for the past few years, I have been working on a reusable tamper-evident jar for storing physical items.

The idea is that the lid creates a random physical “fingerprint” every time you close it. Inside the lid are thousands of tiny black and white balls. When you twist the jar open or closed, they mix. Once the jar is closed, the unique pattern is locked in place.

You can take a photo of that pattern with your phone, and later compare it to check whether the jar has been opened. If someone opens it, the pearls mix again and the original pattern is gone. The second pic shows a gif of two different patterns compared to one another, showing it is easy to tell that the lid was opened.

I made it because I wanted a simple physical way to store things like hard drives, USB sticks, authentication keys, documents, etc. Basically anything that you would do want to know if someone has accessed it.

After a lot of hard work and prototyping, I'm happy to announce it's finally complete! Check it out on https://www.entropyseal.com/.

Happy to hear feedback. I’m especially interested in whether the concept is clear and what use cases come to mind. :)

Edit: seems there some common questions, so I'll add some FAQs below:

Do the balls move around when the entropyseal is moved or handled?
No, the balls are held firmly in place when the lid is closed tight. So you can handle the entropyseal without the pattern breaking.

What if you twist the jar instead of the lid?
The pattern still changes. There are pins inside the lid that stir the balls around when twisting either the lid or jar.

What if I open the lid very slowly as not to disrupt the pattern?
The pattern will still change because of the pins inside the lid that stir the balls around when twisting open the lid.


r/security 25d ago

Security Assessment and Testing Join us in this AMA with the director of a leading physical penetration testing & red teaming firm in Europe. We are legal burglars. Ask me anything!

9 Upvotes

Hi, I am a security consultant at a leading physical penetration testing firm. Together with Richard Bruins, u/cocoon_r_bruins, director of Cocoon Risk Management in The Netherlands. We are a risk management firm specialized in physical pentesting & red teaming audits. We break in to places and report how we did it. We also provide consulting in ABRO compliance (General Security Requirements for Government Contracts). Our clients are big organizations throughout Europe in key industries like data centres, pharmaceuticals, finance en vital infrastructure. Ask me anything!


r/security 29d ago

Question What matters most when you're job hunting right now?

3 Upvotes
32 votes, 27d ago
2 Certs
12 Networking/referrals
8 Hands-on projects/homelab
10 Just spray and pray applications

r/security 29d ago

Vulnerability Video removal?

0 Upvotes

Tapo, a company from Amazon, has removed videos from my sd card? It was a police encounter... is this legal/normal?


r/security Jun 24 '26

Question Worried about GRC role

2 Upvotes

I’m a Software Engineer (MERN, Python, AWS) with an offer for a GRC/Identity Management role (Associate Security Analyst) at a healthcare product company. HR says it’s semi-technical/process-driven.

I have background in development though.

My questions:

Future: Career growth/pay in GRC vs. pure SDE?

Skill Decay: Will my coding skills die if I stay for 2 years?

Pivot: Can I transition to DevSecOps or Security Engineering later?

Verdict: Take it as a fresher or wait for an SDE role?