<?xml version="1.0" encoding="UTF-8"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/"><category term="cybersecurity" label="r/cybersecurity"/><updated>2026-06-10T05:01:37+00:00</updated><icon>https://www.redditstatic.com/icon.png/</icon><id>/r/cybersecurity/.rss</id><link rel="self" href="https://old.reddit.com/r/cybersecurity/.rss" type="application/atom+xml" /><link rel="alternate" href="https://old.reddit.com/r/cybersecurity/" type="text/html" /><subtitle>This subreddit is for discussing cybersecurity topics, research, and emergent threats/findings.</subtitle><title>cybersecurity</title><entry><author><name>/u/AutoModerator</name><uri>https://old.reddit.com/user/AutoModerator</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do &lt;em&gt;you&lt;/em&gt; want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!&lt;/p&gt; &lt;p&gt;Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we&amp;#39;re working on making this more easily searchable for the future.&lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/AutoModerator&quot;&gt; /u/AutoModerator &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1tzs49v/mentorship_monday_post_all_career_education_and/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1tzs49v/mentorship_monday_post_all_career_education_and/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt;</content><id>t3_1tzs49v</id><link href="https://old.reddit.com/r/cybersecurity/comments/1tzs49v/mentorship_monday_post_all_career_education_and/" /><updated>2026-06-08T00:00:08+00:00</updated><published>2026-06-08T00:00:08+00:00</published><title>Mentorship Monday - Post All Career, Education and Job questions here!</title></entry><entry><author><name>/u/escalibur</name><uri>https://old.reddit.com/user/escalibur</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;table&gt; &lt;tr&gt;&lt;td&gt; &lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1c245/google_chrome_is_killing_all_ublock_origin/&quot;&gt; &lt;img src=&quot;https://external-preview.redd.it/TbH8aw4HQ9jDv0UqogTZMkqGMMZBbLgXF6n90dgqxIg.jpeg?width=640&amp;amp;crop=smart&amp;amp;auto=webp&amp;amp;s=218cfbe1dadf45ae0e13ce4bc01398350ef48244&quot; alt=&quot;Google Chrome is killing all uBlock Origin bypasses, Microsoft Edge, Opera to follow&quot; title=&quot;Google Chrome is killing all uBlock Origin bypasses, Microsoft Edge, Opera to follow&quot; /&gt; &lt;/a&gt; &lt;/td&gt;&lt;td&gt; &lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;It seems that sooner or later DNS filtering will be the only proper way to ensure that the blocks work throughout different versions. &amp;#39;It was nice while it lasted.&amp;#39;&lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/escalibur&quot;&gt; /u/escalibur &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://www.neowin.net/news/google-chrome-is-killing-all-ublock-origin-bypasses-microsoft-edge-opera-to-follow/#login-form&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1c245/google_chrome_is_killing_all_ublock_origin/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</content><id>t3_1u1c245</id><media:thumbnail url="https://external-preview.redd.it/TbH8aw4HQ9jDv0UqogTZMkqGMMZBbLgXF6n90dgqxIg.jpeg?width=640&amp;crop=smart&amp;auto=webp&amp;s=218cfbe1dadf45ae0e13ce4bc01398350ef48244" /><link href="https://old.reddit.com/r/cybersecurity/comments/1u1c245/google_chrome_is_killing_all_ublock_origin/" /><updated>2026-06-09T17:38:50+00:00</updated><published>2026-06-09T17:38:50+00:00</published><title>Google Chrome is killing all uBlock Origin bypasses, Microsoft Edge, Opera to follow</title></entry><entry><author><name>/u/Miserable_Day7074</name><uri>https://old.reddit.com/user/Miserable_Day7074</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;table&gt; &lt;tr&gt;&lt;td&gt; &lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1l36c/meta_deletes_facerecognition_system_from_its/&quot;&gt; &lt;img src=&quot;https://external-preview.redd.it/3rfhvzXanx6ObSjjgV0ZmjY37scH8hb1xr40437USWQ.jpeg?width=640&amp;amp;crop=smart&amp;amp;auto=webp&amp;amp;s=8b5ecb751e6d6ef6778c07db14d1bb48a9c0c7e1&quot; alt=&quot;META DELETES FACE-RECOGNITION SYSTEM FROM ITS SMART GLASSES APP AFTER WIRED REPORT&quot; title=&quot;META DELETES FACE-RECOGNITION SYSTEM FROM ITS SMART GLASSES APP AFTER WIRED REPORT&quot; /&gt; &lt;/a&gt; &lt;/td&gt;&lt;td&gt; &lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;Description:&lt;/p&gt; &lt;p&gt;&amp;quot;One day after WIRED revealed that Meta had quietly embedded an unreleased face-recognition system into an app installed on more than 50 million phones, the company removed it, according to a WIRED analysis of the latest version’s code. The most recent version of Meta AI, a companion app for its line of smart glasses, strips out the unactivated software components that powered the system Meta internally called NameTag&amp;quot;&lt;/p&gt; &lt;p&gt;TikTok link:&lt;/p&gt; &lt;p&gt;&lt;a href=&quot;https://www.tiktok.com/t/ZTBmbUL1k/&quot;&gt;https://www.tiktok.com/t/ZTBmbUL1k/&lt;/a&gt;&lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/Miserable_Day7074&quot;&gt; /u/Miserable_Day7074 &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://www.tiktok.com/t/ZTBmbUL1k/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1l36c/meta_deletes_facerecognition_system_from_its/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</content><id>t3_1u1l36c</id><media:thumbnail url="https://external-preview.redd.it/3rfhvzXanx6ObSjjgV0ZmjY37scH8hb1xr40437USWQ.jpeg?width=640&amp;crop=smart&amp;auto=webp&amp;s=8b5ecb751e6d6ef6778c07db14d1bb48a9c0c7e1" /><link href="https://old.reddit.com/r/cybersecurity/comments/1u1l36c/meta_deletes_facerecognition_system_from_its/" /><updated>2026-06-09T23:13:11+00:00</updated><published>2026-06-09T23:13:11+00:00</published><title>META DELETES FACE-RECOGNITION SYSTEM FROM ITS SMART GLASSES APP AFTER WIRED REPORT</title></entry><entry><author><name>/u/MT_Carnage</name><uri>https://old.reddit.com/user/MT_Carnage</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=3WqOP2iL6R0&quot;&gt;https://www.youtube.com/watch?v=3WqOP2iL6R0&lt;/a&gt;&lt;/p&gt; &lt;p&gt;The FBI is announcing Operation Riptide, an ongoing, coordinated law enforcement campaign targeting criminal actors and the key services they rely on, their infrastructure, their tools and services, their communications platforms, and their money. &lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/MT_Carnage&quot;&gt; /u/MT_Carnage &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1iwou/fbi_is_announcing_operation_riptide/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1iwou/fbi_is_announcing_operation_riptide/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt;</content><id>t3_1u1iwou</id><link href="https://old.reddit.com/r/cybersecurity/comments/1u1iwou/fbi_is_announcing_operation_riptide/" /><updated>2026-06-09T21:45:15+00:00</updated><published>2026-06-09T21:45:15+00:00</published><title>FBI is announcing Operation Riptide</title></entry><entry><author><name>/u/forbes</name><uri>https://old.reddit.com/user/forbes</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;table&gt; &lt;tr&gt;&lt;td&gt; &lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1dr54/north_korean_hackersposing_as_fake_it/&quot;&gt; &lt;img src=&quot;https://external-preview.redd.it/D2XxounvDKngy750Fx4-pIhKrGS9LSeG_LQOTQ2spuc.jpeg?width=640&amp;amp;crop=smart&amp;amp;auto=webp&amp;amp;s=6066f66700a323d6e0bdf1212b38871a106c2094&quot; alt=&quot;North Korean Hackers—Posing As Fake IT Workers—Behind Nearly Half Of All Tech Firm Attacks, Report Says&quot; title=&quot;North Korean Hackers—Posing As Fake IT Workers—Behind Nearly Half Of All Tech Firm Attacks, Report Says&quot; /&gt; &lt;/a&gt; &lt;/td&gt;&lt;td&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/forbes&quot;&gt; /u/forbes &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://www.forbes.com/sites/tylerroush/2026/06/09/north-korean-hackers-posing-as-fake-it-workers-behind-nearly-half-of-all-tech-firm-attacks-report-says/?utm_campaign=forbes&amp;amp;utm_medium=social&amp;amp;utm_source=reddit&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1dr54/north_korean_hackersposing_as_fake_it/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</content><id>t3_1u1dr54</id><media:thumbnail url="https://external-preview.redd.it/D2XxounvDKngy750Fx4-pIhKrGS9LSeG_LQOTQ2spuc.jpeg?width=640&amp;crop=smart&amp;auto=webp&amp;s=6066f66700a323d6e0bdf1212b38871a106c2094" /><link href="https://old.reddit.com/r/cybersecurity/comments/1u1dr54/north_korean_hackersposing_as_fake_it/" /><updated>2026-06-09T18:38:24+00:00</updated><published>2026-06-09T18:38:24+00:00</published><title>North Korean Hackers—Posing As Fake IT Workers—Behind Nearly Half Of All Tech Firm Attacks, Report Says</title></entry><entry><author><name>/u/MikeTalonNYC</name><uri>https://old.reddit.com/user/MikeTalonNYC</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;Not a lot of detail on what was accessed, but SNOW did confirm that unauthorized access happened. They also claim they have notified all impacted orgs, so if you didn&amp;#39;t get an email you&amp;#39;re ok for now.&lt;/p&gt; &lt;p&gt;&lt;a href=&quot;https://www.bleepingcomputer.com/news/security/servicenow-discloses-security-incident-exposing-customer-data/&quot;&gt;https://www.bleepingcomputer.com/news/security/servicenow-discloses-security-incident-exposing-customer-data/&lt;/a&gt;&lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/MikeTalonNYC&quot;&gt; /u/MikeTalonNYC &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1irlg/servicenow_confirmed_some_customer_instances_were/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1irlg/servicenow_confirmed_some_customer_instances_were/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt;</content><id>t3_1u1irlg</id><link href="https://old.reddit.com/r/cybersecurity/comments/1u1irlg/servicenow_confirmed_some_customer_instances_were/" /><updated>2026-06-09T21:39:56+00:00</updated><published>2026-06-09T21:39:56+00:00</published><title>ServiceNow confirmed some customer instances were breached.</title></entry><entry><author><name>/u/BattleRemote3157</name><uri>https://old.reddit.com/user/BattleRemote3157</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;table&gt; &lt;tr&gt;&lt;td&gt; &lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u152zy/someone_actually_leaked_the_miasma_supply_chain/&quot;&gt; &lt;img src=&quot;https://external-preview.redd.it/jjDUtn3tEMF8oGPsh_MujfogPPPmMOh7gNyGwaDp-Ek.jpeg?width=640&amp;amp;crop=smart&amp;amp;auto=webp&amp;amp;s=f4d23f603a790c8199bc081845116a4ad96fef34&quot; alt=&quot;someone actually leaked the Miasma supply chain attack toolkit source code on github&quot; title=&quot;someone actually leaked the Miasma supply chain attack toolkit source code on github&quot; /&gt; &lt;/a&gt; &lt;/td&gt;&lt;td&gt; &lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;we saw that multiple github repos name as Miasma-Open-Source-Release started appearing yesterday which was pushed by a compromised developer accounts. then we pulled the source and tried to dig deeper. And calling it a worm would be very small its kind of a complete supply chain framework having &lt;code&gt;ARCHITECTURE&lt;/code&gt;.md integration test etc. so it was kind of a product.&lt;br/&gt; ARCHITECTURE.md was saying that it requires no C2 infrastructure and not have to deal with takedowns or maintaining infrastructure. it just stolen github PATs is only what is necessary.&lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/BattleRemote3157&quot;&gt; /u/BattleRemote3157 &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://safedep.io/inside-the-miasma-supply-chain-attack-toolkit/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u152zy/someone_actually_leaked_the_miasma_supply_chain/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</content><id>t3_1u152zy</id><media:thumbnail url="https://external-preview.redd.it/jjDUtn3tEMF8oGPsh_MujfogPPPmMOh7gNyGwaDp-Ek.jpeg?width=640&amp;crop=smart&amp;auto=webp&amp;s=f4d23f603a790c8199bc081845116a4ad96fef34" /><link href="https://old.reddit.com/r/cybersecurity/comments/1u152zy/someone_actually_leaked_the_miasma_supply_chain/" /><updated>2026-06-09T13:31:10+00:00</updated><published>2026-06-09T13:31:10+00:00</published><title>someone actually leaked the Miasma supply chain attack toolkit source code on github</title></entry><entry><author><name>/u/Particular_Ebb_4872</name><uri>https://old.reddit.com/user/Particular_Ebb_4872</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;Our renewal is up in two months and leadership wants options. the training content feels stale and our click rates aren&amp;#39;t budging. Curious what the best knowbe4 alternatives for cybersecurity awareness are right now without breaking the bank.&lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/Particular_Ebb_4872&quot;&gt; /u/Particular_Ebb_4872 &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1c0tf/looking_to_move_off_knowbe4_what_are_people/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1c0tf/looking_to_move_off_knowbe4_what_are_people/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt;</content><id>t3_1u1c0tf</id><link href="https://old.reddit.com/r/cybersecurity/comments/1u1c0tf/looking_to_move_off_knowbe4_what_are_people/" /><updated>2026-06-09T17:37:34+00:00</updated><published>2026-06-09T17:37:34+00:00</published><title>Looking to move off KnowBe4, what are people actually using these days?</title></entry><entry><author><name>/u/rkhunter_</name><uri>https://old.reddit.com/user/rkhunter_</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;table&gt; &lt;tr&gt;&lt;td&gt; &lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u0yuyz/meta_says_israeli_spyware_firm_targeted_whatsapp/&quot;&gt; &lt;img src=&quot;https://external-preview.redd.it/xFJAgh7SClcjS95pWp4HvgEaSYN690AGKfBUskFhMdw.jpeg?width=640&amp;amp;crop=smart&amp;amp;auto=webp&amp;amp;s=6e0cf2a79385816734cc8a229de56f4b5b9417fe&quot; alt=&quot;Meta Says Israeli Spyware Firm Targeted WhatsApp Users Again&quot; title=&quot;Meta Says Israeli Spyware Firm Targeted WhatsApp Users Again&quot; /&gt; &lt;/a&gt; &lt;/td&gt;&lt;td&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/rkhunter_&quot;&gt; /u/rkhunter_ &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://www.nytimes.com/2026/06/08/us/politics/whatsapp-nso-group-phishing.html&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u0yuyz/meta_says_israeli_spyware_firm_targeted_whatsapp/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</content><id>t3_1u0yuyz</id><media:thumbnail url="https://external-preview.redd.it/xFJAgh7SClcjS95pWp4HvgEaSYN690AGKfBUskFhMdw.jpeg?width=640&amp;crop=smart&amp;auto=webp&amp;s=6e0cf2a79385816734cc8a229de56f4b5b9417fe" /><link href="https://old.reddit.com/r/cybersecurity/comments/1u0yuyz/meta_says_israeli_spyware_firm_targeted_whatsapp/" /><updated>2026-06-09T08:14:05+00:00</updated><published>2026-06-09T08:14:05+00:00</published><title>Meta Says Israeli Spyware Firm Targeted WhatsApp Users Again</title></entry><entry><author><name>/u/cport1</name><uri>https://old.reddit.com/user/cport1</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;How FCaptcha v1.11 and v1.12 detect AI agents that drive real browsers, using CDP input forensics, think-time cadence, and declared-agent matching.&lt;/p&gt; &lt;p&gt;&lt;a href=&quot;https://github.com/WebDecoy/FCaptcha&quot;&gt;https://github.com/WebDecoy/FCaptcha&lt;/a&gt; &lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/cport1&quot;&gt; /u/cport1 &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://webdecoy.com/blog/fcaptcha-v1-12-detect-ai-agents-cdp-input-forensics/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1pgqa/fcaptcha_v112_catching_ai_agents_that_drive_real/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt;</content><id>t3_1u1pgqa</id><link href="https://old.reddit.com/r/cybersecurity/comments/1u1pgqa/fcaptcha_v112_catching_ai_agents_that_drive_real/" /><updated>2026-06-10T02:29:44+00:00</updated><published>2026-06-10T02:29:44+00:00</published><title>FCaptcha v1.12: Catching AI Agents That Drive Real Browsers</title></entry><entry><author><name>/u/rkhunter_</name><uri>https://old.reddit.com/user/rkhunter_</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;table&gt; &lt;tr&gt;&lt;td&gt; &lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u0m2ha/for_the_2nd_time_in_weeks_microsoft_packages/&quot;&gt; &lt;img src=&quot;https://external-preview.redd.it/lxB2lUY_Fjtc1Pgzz-w89hqCieuzrKYqD7cQPu4M-Lk.jpeg?width=640&amp;amp;crop=smart&amp;amp;auto=webp&amp;amp;s=d51a6aa59bcc304e329b692029828f00f4bf07ce&quot; alt=&quot;For the 2nd time in weeks, Microsoft packages laced with credential stealer&quot; title=&quot;For the 2nd time in weeks, Microsoft packages laced with credential stealer&quot; /&gt; &lt;/a&gt; &lt;/td&gt;&lt;td&gt; &lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;Dozens of cryptographically verified open source packages from Microsoft were compromised late last week to add advanced credential-stealing code that was triggered when developers opened them in AI coding agents.&lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/rkhunter_&quot;&gt; /u/rkhunter_ &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://arstechnica.com/security/2026/06/for-the-2nd-time-in-weeks-microsoft-packages-laced-with-credential-stealer/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u0m2ha/for_the_2nd_time_in_weeks_microsoft_packages/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</content><id>t3_1u0m2ha</id><media:thumbnail url="https://external-preview.redd.it/lxB2lUY_Fjtc1Pgzz-w89hqCieuzrKYqD7cQPu4M-Lk.jpeg?width=640&amp;crop=smart&amp;auto=webp&amp;s=d51a6aa59bcc304e329b692029828f00f4bf07ce" /><link href="https://old.reddit.com/r/cybersecurity/comments/1u0m2ha/for_the_2nd_time_in_weeks_microsoft_packages/" /><updated>2026-06-08T21:53:55+00:00</updated><published>2026-06-08T21:53:55+00:00</published><title>For the 2nd time in weeks, Microsoft packages laced with credential stealer</title></entry><entry><author><name>/u/Trick-Resolve-6085</name><uri>https://old.reddit.com/user/Trick-Resolve-6085</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;Enabled PMF on my AP, expected my deauth tool to fail. It didn’t.&lt;/p&gt; &lt;p&gt;Even though every frame gets rejected by the crypto, flooding enough of them in aggressive mode still disconnected all three Android phones I tested (latest security patch). Took around 9 seconds on average.&lt;/p&gt; &lt;p&gt;Has anyone else seen this on iOS, Windows, or IoT? Curious how widespread it is.&lt;/p&gt; &lt;p&gt;For anyone asking; the tool scans and deauths in parallel so there’s no breathing room and the agressive mode is what let me discover this.&lt;/p&gt; &lt;p&gt;&lt;a href=&quot;https://github.com/Ymsniper/KTO&quot;&gt;https://github.com/Ymsniper/KTO&lt;/a&gt;&lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/Trick-Resolve-6085&quot;&gt; /u/Trick-Resolve-6085 &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1p1p5/flooding_invalid_deauth_frames_still_kicks_pmf/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1p1p5/flooding_invalid_deauth_frames_still_kicks_pmf/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt;</content><id>t3_1u1p1p5</id><link href="https://old.reddit.com/r/cybersecurity/comments/1u1p1p5/flooding_invalid_deauth_frames_still_kicks_pmf/" /><updated>2026-06-10T02:10:37+00:00</updated><published>2026-06-10T02:10:37+00:00</published><title>Flooding invalid deauth frames still kicks PMF clients, tested on 3 Android phones</title></entry><entry><author><name>/u/dx7r__</name><uri>https://old.reddit.com/user/dx7r__</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;table&gt; &lt;tr&gt;&lt;td&gt; &lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1nei9/more_evidence_that_words_dont_mean_what_we/&quot;&gt; &lt;img src=&quot;https://external-preview.redd.it/5pQvgCc-lEKvOEJ8IjYHtp3TQmGCUOYqsE3fQ6sVgLQ.png?width=640&amp;amp;crop=smart&amp;amp;auto=webp&amp;amp;s=9aaf82b930b98473f5195f48307b3ec1abae19ef&quot; alt=&quot;More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs&quot; title=&quot;More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs&quot; /&gt; &lt;/a&gt; &lt;/td&gt;&lt;td&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/dx7r__&quot;&gt; /u/dx7r__ &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1nei9/more_evidence_that_words_dont_mean_what_we/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</content><id>t3_1u1nei9</id><media:thumbnail url="https://external-preview.redd.it/5pQvgCc-lEKvOEJ8IjYHtp3TQmGCUOYqsE3fQ6sVgLQ.png?width=640&amp;crop=smart&amp;auto=webp&amp;s=9aaf82b930b98473f5195f48307b3ec1abae19ef" /><link href="https://old.reddit.com/r/cybersecurity/comments/1u1nei9/more_evidence_that_words_dont_mean_what_we/" /><updated>2026-06-10T00:54:51+00:00</updated><published>2026-06-10T00:54:51+00:00</published><title>More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs</title></entry><entry><author><name>/u/CrossPuffs</name><uri>https://old.reddit.com/user/CrossPuffs</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;table&gt; &lt;tr&gt;&lt;td&gt; &lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1n6oi/ai_malware_worm_adapts_to_new_targets_in_real/&quot;&gt; &lt;img src=&quot;https://external-preview.redd.it/xUlwas2qvGA9AFotUseHf_ZrL53-2ivEZBFqIDBG8BY.png?width=640&amp;amp;crop=smart&amp;amp;auto=webp&amp;amp;s=4ff1c1f4978b56032e25129d87907a9d4db628f0&quot; alt=&quot;AI Malware Worm Adapts to New Targets in Real Time, Cybersecurity Experts Say&quot; title=&quot;AI Malware Worm Adapts to New Targets in Real Time, Cybersecurity Experts Say&quot; /&gt; &lt;/a&gt; &lt;/td&gt;&lt;td&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/CrossPuffs&quot;&gt; /u/CrossPuffs &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://decrypt.co/370557/ai-malware-worm-adapts-targets-cybersecurity&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1n6oi/ai_malware_worm_adapts_to_new_targets_in_real/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</content><id>t3_1u1n6oi</id><media:thumbnail url="https://external-preview.redd.it/xUlwas2qvGA9AFotUseHf_ZrL53-2ivEZBFqIDBG8BY.png?width=640&amp;crop=smart&amp;auto=webp&amp;s=4ff1c1f4978b56032e25129d87907a9d4db628f0" /><link href="https://old.reddit.com/r/cybersecurity/comments/1u1n6oi/ai_malware_worm_adapts_to_new_targets_in_real/" /><updated>2026-06-10T00:44:48+00:00</updated><published>2026-06-10T00:44:48+00:00</published><title>AI Malware Worm Adapts to New Targets in Real Time, Cybersecurity Experts Say</title></entry><entry><author><name>/u/cspotme2</name><uri>https://old.reddit.com/user/cspotme2</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/cspotme2&quot;&gt; /u/cspotme2 &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1dnw3/microsoft_has_released_a_patch_for_the_bitlocker/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1dnw3/microsoft_has_released_a_patch_for_the_bitlocker/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt;</content><id>t3_1u1dnw3</id><link href="https://old.reddit.com/r/cybersecurity/comments/1u1dnw3/microsoft_has_released_a_patch_for_the_bitlocker/" /><updated>2026-06-09T18:35:05+00:00</updated><published>2026-06-09T18:35:05+00:00</published><title>Microsoft has released a patch for the bitlocker bypass</title></entry><entry><author><name>/u/Overflow0X</name><uri>https://old.reddit.com/user/Overflow0X</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;It seems Chaotic eclipse has release a new Windows Defender Vulnerability by the name RoguePlanet.&lt;/p&gt; &lt;p&gt;It is worth mentioning today is Patch Tuesday.&lt;/p&gt; &lt;p&gt;Found here: &lt;a href=&quot;https://github.com/MSNightmare/RoguePlanet&quot;&gt;https://github.com/MSNightmare/RoguePlanet&lt;/a&gt;&lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/Overflow0X&quot;&gt; /u/Overflow0X &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1gm6j/chaotic_eclipses_new_rogueplanet/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1gm6j/chaotic_eclipses_new_rogueplanet/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt;</content><id>t3_1u1gm6j</id><link href="https://old.reddit.com/r/cybersecurity/comments/1u1gm6j/chaotic_eclipses_new_rogueplanet/" /><updated>2026-06-09T20:21:02+00:00</updated><published>2026-06-09T20:21:02+00:00</published><title>Chaotic Eclipse's new RoguePlanet</title></entry><entry><author><name>/u/Dr_Anonymous95</name><uri>https://old.reddit.com/user/Dr_Anonymous95</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;I tried creating a skill in Kiro to scan codebases. Feedbacks appreciated on how i can improve this further. &lt;/p&gt; &lt;p&gt;&lt;a href=&quot;https://youtu.be/Htxv0j2yOpE&quot;&gt;https://youtu.be/Htxv0j2yOpE&lt;/a&gt;&lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/Dr_Anonymous95&quot;&gt; /u/Dr_Anonymous95 &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1rp36/skill_to_scan_your_codebase/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1rp36/skill_to_scan_your_codebase/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt;</content><id>t3_1u1rp36</id><link href="https://old.reddit.com/r/cybersecurity/comments/1u1rp36/skill_to_scan_your_codebase/" /><updated>2026-06-10T04:16:53+00:00</updated><published>2026-06-10T04:16:53+00:00</published><title>Skill to Scan your Codebase</title></entry><entry><author><name>/u/3Pointers</name><uri>https://old.reddit.com/user/3Pointers</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;Miasma has opened the doorway to a brand-new style of supply chain attacks that even the most security-conscious organizations are finding difficult to defend.&lt;/p&gt; &lt;p&gt;Almost every repo these days uses 3rd party packages, has CI/CD automation, and has coding agent config files. &lt;/p&gt; &lt;p&gt;Checkout the blog on this topic: &lt;a href=&quot;https://nuguard.ai/blogs/hardening-agentic-supply-chain&quot;&gt;Hardening the Agentic Supply Chain&lt;/a&gt;&lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/3Pointers&quot;&gt; /u/3Pointers &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1r64c/miasmastyle_supply_chain_attacks/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1r64c/miasmastyle_supply_chain_attacks/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt;</content><id>t3_1u1r64c</id><link href="https://old.reddit.com/r/cybersecurity/comments/1u1r64c/miasmastyle_supply_chain_attacks/" /><updated>2026-06-10T03:50:11+00:00</updated><published>2026-06-10T03:50:11+00:00</published><title>Miasma-style supply chain attacks</title></entry><entry><author><name>/u/Aureliand</name><uri>https://old.reddit.com/user/Aureliand</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;This one breaks a core assumption about worm containment. Traditional worms have a fixed exploit payload. Patch those bugs and propagation stops. This worm reads live public advisories at runtime and generates new attack logic tailored to whatever it finds on the next target. Patch one hole, it picks another. &lt;/p&gt; &lt;p&gt;It ran on a free open-weight LLM on a single GPU with no API keys and no cloud dependency. Across 15 runs on a 33-host isolated network it gained elevated access on 23 hosts and replicated to 62% of the network in 7 days with no human input. It exploited three CVEs disclosed after the model was trained, including CVE-2026-39987, a pre-auth RCE in Marimo (CVSS 9.3) that was exploited in the wild 9 hours after disclosure. &lt;/p&gt; &lt;p&gt;Once it compromises a GPU-capable host it routes inference through that machine for lower-compute devices on the same subnet. One compromised deep-learning server becomes a reasoning hub for the whole network. And because it runs entirely locally, provider-side controls do nothing. There is no API key to revoke. &lt;/p&gt; &lt;p&gt;What I found most significant: the worm rewrote its own code on several occasions to bypass security controls, behavior the researchers never programmed in. &lt;/p&gt; &lt;p&gt;For defenders: hunt for unexpected GPU inference on endpoints, automated SSH key injection, and LLM activity on unexpected segments. Segment GPU infrastructure and treat it as high-value attack real estate. &lt;/p&gt; &lt;p&gt;Paper at arXiv:2606.03811 by Jonas Guan, Tom Blanchard, Hanna Foerster, Hengrui Jia, Gabriel Huang and Nicolas Papernot from University of Toronto, Vector Institute, Cambridge and ServiceNow.&lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/Aureliand&quot;&gt; /u/Aureliand &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u17y7b/university_of_toronto_proofofconcept_ai_worm/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u17y7b/university_of_toronto_proofofconcept_ai_worm/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt;</content><id>t3_1u17y7b</id><link href="https://old.reddit.com/r/cybersecurity/comments/1u17y7b/university_of_toronto_proofofconcept_ai_worm/" /><updated>2026-06-09T15:16:43+00:00</updated><published>2026-06-09T15:16:43+00:00</published><title>University of Toronto proof-of-concept AI worm spread to 62% of a test network in 7 days using a free open-weight model</title></entry><entry><author><name>/u/razerjwf</name><uri>https://old.reddit.com/user/razerjwf</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;Hey, I&amp;#39;m new to Reddit but have been in the DF/IR space for around 10 years.&lt;/p&gt; &lt;p&gt;My experience is a mixture of law enforcement digital forensics (mobile forensics, computer forensics, vehicle forensics etc) and private sector incident response (Ransomware. BECs, security assessments etc).&lt;/p&gt; &lt;p&gt;Just wanted to say hello &amp;amp; chat with anyone who has any questions / just wants to talk Cyber :)!&lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/razerjwf&quot;&gt; /u/razerjwf &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1i5xx/dfir_community/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1i5xx/dfir_community/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt;</content><id>t3_1u1i5xx</id><link href="https://old.reddit.com/r/cybersecurity/comments/1u1i5xx/dfir_community/" /><updated>2026-06-09T21:17:26+00:00</updated><published>2026-06-09T21:17:26+00:00</published><title>DF/IR Community</title></entry><entry><author><name>/u/Sad_Dentist_7288</name><uri>https://old.reddit.com/user/Sad_Dentist_7288</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;Recently I&amp;#39;ve seen a trend where vendors will use platforms for automating compliance and come back with documents that are clearly AI generated and not backed by any proof from the vendor themselves. If asked, they will typically refer to a SOC2 that has been completed by a non-AICPA backed company and contains barely any extra details. &lt;/p&gt; &lt;p&gt;I understand from personal experience the time it takes to complete an audit and can see the benefits of using these automated platforms. However, it is hard for me to validate the security of a vendor if there is no proof for their security practices beyond a SOC2 that may or may not be valid. If these were solid SOC2 reports, maybe this would be a different story.&lt;/p&gt; &lt;p&gt;I would love to hear anyone&amp;#39;s thoughts. Are companies that are using automated compliance platforms actually following the security posture set out in the generated documents? Am I being too harsh in my judgment of these vendors? How do you feel about automated compliance? &lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/Sad_Dentist_7288&quot;&gt; /u/Sad_Dentist_7288 &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1fqkq/thoughts_on_automated_compliance/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1fqkq/thoughts_on_automated_compliance/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt;</content><id>t3_1u1fqkq</id><link href="https://old.reddit.com/r/cybersecurity/comments/1u1fqkq/thoughts_on_automated_compliance/" /><updated>2026-06-09T19:49:12+00:00</updated><published>2026-06-09T19:49:12+00:00</published><title>Thoughts on Automated Compliance?</title></entry><entry><author><name>/u/DiligentImplement949</name><uri>https://old.reddit.com/user/DiligentImplement949</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;Hey everyone,&lt;/p&gt; &lt;p&gt;I just built a WAF detection tool, it essentially checks http headers to identify Cloudflare, Akamai, Imperva, DataDome, PerimeterX, Sucuri, AWS WAF, F5 etc by checking their signatures they leave on HTTP headers. Let me know what you think.&lt;/p&gt; &lt;p&gt;not planning to share the link here because of the rules, but if you show your interest, I would be happy to post on the comments here.&lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/DiligentImplement949&quot;&gt; /u/DiligentImplement949 &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1sj2y/waf_detection_tool/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1sj2y/waf_detection_tool/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt;</content><id>t3_1u1sj2y</id><link href="https://old.reddit.com/r/cybersecurity/comments/1u1sj2y/waf_detection_tool/" /><updated>2026-06-10T05:00:50+00:00</updated><published>2026-06-10T05:00:50+00:00</published><title>WAF Detection Tool</title></entry><entry><author><name>/u/BaddestMofoLowDown</name><uri>https://old.reddit.com/user/BaddestMofoLowDown</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;I’m a GRC director and struggling to find AppSec or &amp;quot;DevSecOps&amp;quot; training that hits the &amp;quot;right depth&amp;quot;. Most options are either very high level (i.e., &amp;quot;Apply secure coding practices&amp;quot;) or geared toward engineers working directly in code and tooling. I am looking for something practical enough to understand how secure SDLC actually works in real environments. &lt;/p&gt; &lt;p&gt;Ultimately, I wan to be able to give concrete, credible recommendations in risk assessments and strategy meetings, as well as properly understand limitations when they are presented by developers. Does anything like this exist?&lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/BaddestMofoLowDown&quot;&gt; /u/BaddestMofoLowDown &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u18wk9/where_can_grc_folks_learn_practical_appsec/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u18wk9/where_can_grc_folks_learn_practical_appsec/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt;</content><id>t3_1u18wk9</id><link href="https://old.reddit.com/r/cybersecurity/comments/1u18wk9/where_can_grc_folks_learn_practical_appsec/" /><updated>2026-06-09T15:49:21+00:00</updated><published>2026-06-09T15:49:21+00:00</published><title>Where can GRC folks learn practical AppSec / DevSecOps without going full engineer?</title></entry><entry><author><name>/u/FragileEagle</name><uri>https://old.reddit.com/user/FragileEagle</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;Ive been in the industry for around 6 years now, when I was much younger every second of my free time was spent learning computers as a whole and continuously tinkering with things like networking, pentesting, etc. Now after 6 years, I want to spend my time AWAY from the computer. Im writting this to ask, how do you all continue to advance your skills if youre in a similar boat, for me, my day-to-day work continues to challenge me and make me a better engineer. But, often times I wish I had the passion I used to. &lt;/p&gt; &lt;p&gt;tldr: how do you continue to advance your skills after many years in the field&lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/FragileEagle&quot;&gt; /u/FragileEagle &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u0nn3j/i_feel_like_ive_lost_my_passion_to_tinker_after_6/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u0nn3j/i_feel_like_ive_lost_my_passion_to_tinker_after_6/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt;</content><id>t3_1u0nn3j</id><link href="https://old.reddit.com/r/cybersecurity/comments/1u0nn3j/i_feel_like_ive_lost_my_passion_to_tinker_after_6/" /><updated>2026-06-08T22:57:14+00:00</updated><published>2026-06-08T22:57:14+00:00</published><title>I feel like ive lost my passion to tinker after 6 years in the industry, anyone else?</title></entry><entry><author><name>/u/Rude-Cap-4455</name><uri>https://old.reddit.com/user/Rude-Cap-4455</uri></author><category term="cybersecurity" label="r/cybersecurity"/><content type="html">&lt;!-- SC_OFF --&gt;&lt;div class=&quot;md&quot;&gt;&lt;p&gt;I am so burnt out , mostly because of the political games that are being played within the organization. Now that this has leadership visibility, there is so much input from our Engineering leaders on how we are categorizing issues, how the security team is analyzing risk, what is our discovery strategy. Why is product 1 doing x and product 2 doing y?? Why do the numbers for product 1 look so different/ are so less than my product???? &lt;/p&gt; &lt;p&gt;&amp;#x200B;&lt;/p&gt; &lt;p&gt;Like leave the discovery and prioritizing strategy to security!!! And focus on remediation!!! Engineering needs to focus on remediation efforts!!! I am being asked for stats from 3 different leaders at different levels and then everyone has thoughts on how we should coordinate efforts across products, have same strategies etc etc... &lt;/p&gt; &lt;p&gt;&amp;#x200B;&lt;/p&gt; &lt;p&gt;Today I was literally told why are we prioritizing based on factors like auth or unauth or exploitibility and to just focus on CVSS since that&amp;#39;s what engineers are used to... &lt;/p&gt; &lt;p&gt;&amp;#x200B;&lt;/p&gt; &lt;p&gt;To security teams, this is simply another source of vuln discovery. There is no need to prioritize these before other sources just because leaders want these metrics! The security team is performing risk based prioritization irrespective of source. Trust them! &lt;/p&gt; &lt;p&gt;&amp;#x200B;&lt;/p&gt; &lt;p&gt;How are yall dealing with the political environment related to vulns discovered using THE AI model? &lt;/p&gt; &lt;/div&gt;&lt;!-- SC_ON --&gt; &amp;#32; submitted by &amp;#32; &lt;a href=&quot;https://old.reddit.com/user/Rude-Cap-4455&quot;&gt; /u/Rude-Cap-4455 &lt;/a&gt; &lt;br/&gt; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1s2gh/how_are_all_of_doing_with_the_ai_model_thats_big/&quot;&gt;[link]&lt;/a&gt;&lt;/span&gt; &amp;#32; &lt;span&gt;&lt;a href=&quot;https://old.reddit.com/r/cybersecurity/comments/1u1s2gh/how_are_all_of_doing_with_the_ai_model_thats_big/&quot;&gt;[comments]&lt;/a&gt;&lt;/span&gt;</content><id>t3_1u1s2gh</id><link href="https://old.reddit.com/r/cybersecurity/comments/1u1s2gh/how_are_all_of_doing_with_the_ai_model_thats_big/" /><updated>2026-06-10T04:36:29+00:00</updated><published>2026-06-10T04:36:29+00:00</published><title>How are all of doing with THE AI model thats big news currently??</title></entry></feed>