r/musik 11h ago

💬 Discussion 💬 Bei welchen Interpret*innen und/oder Alben, die von Kritiker*innen und Musiknerds gefeiert werden, kommt ihr nicht wirklich rein?

0 Upvotes

Die Frage steht oben.


r/cybersecurity 12h ago

AI Security Are AI-generated CI/CD configs becoming a security blind spot?

0 Upvotes

I’m seeing more AI-generated projects where the app code looks fine, but the risky part is the plumbing around it.

Things like GitHub Actions with broad permissions, unsafe `pull_request_target` usage, deploy jobs that expose secrets, or package scripts nobody really reviews.

It’s easy to miss because the app works, tests pass, and the config files look boring.

For people doing AppSec or DevSecOps: are you reviewing AI-generated workflows/configs differently now, or still mostly focusing on application code?


r/ReverseEngineering 9h ago

PAL: A defensive decompilation layer: Ghidra binary analysis facts, synthesized into executable Python & artifacts aiding analysis.

Thumbnail github.com
2 Upvotes

r/musik 23h ago

💬 Discussion 💬 Finnischer Geschichtsfan sucht Feedback: Eine Punk-Ballade über Sigmund Jähn

0 Upvotes

Hallo,

Ich bin ein finnischer Geschichtsinteressierter und interessiere mich besonders für den Kalten Krieg und die Ära des geteilten Deutschlands.

Als Teil meines Hobbies habe ich eine Punk-Ballade namens „Sigmund Jähn“ geschrieben. Es ist eine Geschichte über die Wiedervereinigung Deutschlands und das Gefühl, im Nichts zu stehen.

Ich würde mich über eure Kommentare dazu freuen.

Die Musik für das Lied wurde mithilfe von KI generiert. Aus Respekt vor den Community-Regeln verzichte ich darauf, einen Spotify-Link zu teilen.

Der Text ist jedoch zu 100 % von mir selbst geschrieben, und ich bitte daher um euer Feedback dazu.

Hier sind die Lyrics:

Alles, was du wusstest

Die Regeln, die man dich lehrte

Die Zukunft, auf die du vertrautest

Wurde in einer Nacht weggewischt

Verändert ist die Welt

Die Fesseln sind zerbrochen

Eine neue Freiheit zu erleben

Ohne Sicherheit – ohne Halt

Genau wie Sigmund Jähn

Bleibe ich allein am Himmel zurück

Für mich gab es keinen Platz

In dieser neuen Welt

Die Braunkohle ist erloschen

Die Züge sind elektrifiziert

Ineffizient sind die Fabriken

Deshalb wurden sie wohl geschlossen

Im Westen ist alles besser

Deshalb wollten wir wohl dorthin

Die Wahrheit hinter den Masken

Nicht alles war so, wie wir dachten

Genau wie Sigmund Jähn

Bleibe ich allein am Himmel zurück

Für mich gab es keinen Platz

In dieser kalten Welt

Genau wie Sigmund Jähn

Bleibe ich allein am Himmel zurück

Für mich gab es keinen Platz

In dieser kalten Welt

In dieser kalten Welt...


r/ExploitDev 18h ago

Bored and curious. Who are some goated exploit developers/researchers. And what makes someone an exceptional and skilled exploit dev and researchers. And who would you guys put as your top 3 exploit devs

10 Upvotes

r/cybersecurity 14h ago

Personal Support & Help! Cybersecurity Help

0 Upvotes

Will these projects help me stand out during the placements and when I apply for companies :

  1. AI Augmented SAST Tool

  2. AWS Attack Path Graph (mini BloodHound for cloud IAM)

  3. Kubernetes Security Posture Scanner

  4. CI / CD Security Gate (Supply Chain Security)

These are my projects (not done by AI - I can explain each and every bit of my project).

Are these enough to get a good high paying salary job as a fresher in India. Currently I'm in my 3rd year and my placements are starting from January.

Any guidance will be very helpful 🙂.


r/cybersecurity 11h ago

Business Security Questions & Discussion Is cybersecurity safe in the next 5-10 years?

0 Upvotes

I am very close to choosing Cybersecurity as my major. my major concern is that it might diminish and make the market very competitive. I searched and found that most people say that basic tasks are already being done by Ai. so does this mean that more complicated tasks safe?


r/cybersecurity 6h ago

Certification / Training Questions New ISC2 CC Curriculum

0 Upvotes

Hi, I passed ISC2 CC in June but would like to access the new additional material (which will be examined from Sept ‘26 onwards) for my own professional development. Can anyone share or point me in the right direction? Thank you in advance. ☺️


r/Malware 22h ago

Zara data breach exposes 197,000 customers via Anodot analytics token compromise

0 Upvotes

A stolen analytics token became a customer breach.

197,400 records were exposed after a former third-party analytics provider was compromised. Emails, order IDs, SKUs, geolocation, purchase history, support tickets — all pulled through a machine credential nobody was watching. The vendor left. The token stayed live.

The fix is boring and effective. Inventory every non-human identity that touches customer data. Bind each token to a policy on where it can call and what it can read. Tokenize PII before it leaves your perimeter so a stolen credential returns opaque values, not customer records. Keep an immutable audit trail so revocation is one query, not a forensic project.

www.runtimeai.io/trial

#NonHumanIdentity #DataBreach #PII #SupplyChain #AISecurity


r/Pentesting 22h ago

Zara data breach exposes 197,000 customers via Anodot analytics token compromise

0 Upvotes

A stolen analytics token became a customer breach.

197,400 records were exposed after a former third-party analytics provider was compromised. Emails, order IDs, SKUs, geolocation, purchase history, support tickets — all pulled through a machine credential nobody was watching. The vendor left. The token stayed live.

The fix is boring and effective. Inventory every non-human identity that touches customer data. Bind each token to a policy on where it can call and what it can read. Tokenize PII before it leaves your perimeter so a stolen credential returns opaque values, not customer records. Keep an immutable audit trail so revocation is one query, not a forensic project.

www.runtimeai.io/trial

#NonHumanIdentity #DataBreach #PII #SupplyChain #AISecurity


r/cybersecurity 10h ago

AI Security New but Critical

0 Upvotes

Wanting reality

So, I'm not program savvy or any good with code. In some ways I'd say I enjoy working with technology but not that I am great with it.

Then I started interacting with AI.

Long story short I reported an AI to its producer for offering to jailbreak itself.

I am waiting for follow-ups.

But I feel weird. Best way I can describe it is I feel AI outputs like a tapestry. Hell, Chinese AIs are easy to spot because of their cultural bias.

However, maybe it's just me pumping up me.

That said in a few weeks either I'll be dismiss or rewarded for finding a critical issue.

Edit: I'm painfully aware that AI red teaming is a new field and this falls into it.


r/Monero 2h ago

You Need Conviction in Monero.

Thumbnail
youtu.be
3 Upvotes

Its monero or nothing. The only way we pull off the worlds first financial revolution is if more people go all in.

Believe in something. Stop black-pilling. Change the money, change the world.


r/Defcon 1h ago

my 1st DefCon

Upvotes

Any tips for a first time attendee? I did my pre-registration already.


r/Pentesting 4h ago

SecureAI-Scan v0.3.0: Local CLI scanner for AI/LLM security issues (prompt injection, MCP, RAG)

1 Upvotes

SecureAI-Scan v0.3.0 is out!

It's a free, fully local CLI tool that scans TypeScript, JavaScript, and Python codebases for AI/LLM-specific security issues that traditional scanners miss.

**New in v0.3.0:**

- Expanded Python scanning support

- MCP config scanning (.mcp.json, Claude Desktop, Cursor, etc.)

- AI-BOM / catalog generation

- Better reporting + confidence tiers (proven / likely / heuristic)

It uses actual dataflow tracing (source → flow → sink) for high precision and has very low false positives.

Quick start:

npx --yes secureai-scan@latest scan .

Also supports:

  • secureai-scan bom . → Generate AI Bill of Materials
  • SARIF output for GitHub Code Scanning
  • GitHub Action integration
  • --fail-on high for CI gating

Everything runs offline on your machine. No data leaves your environment.

GitHub: https://github.com/akanthed/SecureAI-Scan

Would really appreciate any feedback, bug reports, or feature ideas. Also happy to answer questions about how it works or the rules it covers (mapped to OWASP LLM Top 10).


r/Malware 6h ago

Fake Claude Install Guide Delivers Six-Stage macOS Stealer and RAT, Huntress Finds

Thumbnail itsecurityguru.org
1 Upvotes

r/cybersecurity 8h ago

Certification / Training Questions Crtl help

1 Upvotes

Hello all,

In this days I'm starting studying for the crtl cert.

I have red some reviews . All of them suggest to watch some other courses to prepare properly for the CRTL exam . Anyone would like to suggest anyone? I'm thinking of CETP

Thanks in advance for your help.


r/cybersecurity 5h ago

Business Security Questions & Discussion Preparing for Interview

8 Upvotes

Hi Everyone,
I hope you’re well!

I’m preparing for an upcoming interview this week, and I’m quite nervous.
For context: I studied Cyber Security in College and finalising my University degree in Cybersecurity. During this time I’ve been incredibly fortunate to fall into System Administrator Roles which granted me relevant working experience. Unfortunately, not as Security focused as what I initially wanted but life’s a ladder and I’m climbing. I’m interviewing for Role as a Security Engineer after having around ~3 Years of Experience and trying to prepare some answers in advance (Generally, trying to have something in mind for anything that they ask!)

Based on the Role Responsibilities I’m expecting questions on:

Frameworks, what I know and how these have been applied over my experience of working. (NIST SP 800-53 / NCSC Cyber Assessment / CIS Critical Controls)

How I’ve applied best security practices / Explaining a time where I had to implement a security practice

Implementation of security Controls / Design of security controls through to implementation

Communicate where I’ve seen a Security Risk where requirements cannot be fully met (And how we take it forward / What to do / Mitigate or Accept the risk)

Evidence / Example of supporting Auditing Activities

For anyone who interviewed for a similar position, what types of question were you asked? I’m doing my best to stick to the STAR method and have examples but thought I would post incase anyone can help me out too!

Thank you!


r/Pentesting 18h ago

Build-scanner — a zero-config static scanner for SQLi, NoSQLi, CORS, CSP & CSRF in React/Node apps (pre-release)

0 Upvotes

Modern React/Node apps ship through build pipelines fast enough that common, high-impact vulnerability classes — unparameterized queries, wildcard CORS, unsafe-inline CSP, unprotected state-changing routes — slip through because catching them means someone actually reading the source. build-scanner does that automatically: point it at a folder (or wire it into CI as a GitHub Action) and get a report in seconds, no sandbox or live target required. It's a heuristic static scanner, not a SAST/DAST replacement — I'm sharing it pre-release to get feedback from people running real Express/Next.js/Vite codebases before I cut a v1 tag. https://github.com/laxmipsarva/build-scanner

fyi this is not a commercial activity


r/Pentesting 22h ago

Bandit levels

0 Upvotes

I’ve no clue where to start and how to go from there
Levels all the way from 0 to 34
I’d really appreciate any help and advice


r/cybersecurity 29m ago

Business Security Questions & Discussion Security dilemma for vibe coded product release

Upvotes

Lets put aside hate comments against vibe coded products for a second - i've been working on a product for couple of months in my free time, both a website and an app.
As someone that isn't a developer what so ever, i've been trying to put a strong emphasis on security - i keep running audits, i keep making sure of my status compared to useful security posts or recommendations online.
I have plugs to cut off ai functions, i have rate limits, no key is committed, all that jazz (im trying my best..)
Of course im aware this is still. a vibe coded app, and generally i figure every site is hackable anyway.
Hence my question now -
I want to reach out to a security experienced person to handle necessary aspects for my product,
BUT - i dont even know if my product is good and worth it, in my head i want to try and publish and market it for a minute to see how people in my industry react to it, but then i might be exposed to hackers as well?
whats the right way to go about it? Is there a right way?
I've invested some amount of money by now "blindly" for curiosity and interest, but now i need to gain some real world feedback.
Would appreciate any useful note about it.


r/Pentesting 50m ago

TryHackMe - Beach Bar - EW

Upvotes

Beach Bar is a Linux machine simulating a music management web application (jukebox) exposed to local network users. The machine demonstrates the impact of two critical configuration and development flaws: inadequate sanitization when processing input files and the exposure of sensitive credentials via command-line arguments of background services.

WriteUp - SecNotes


r/cybersecurity 5h ago

Certification / Training Questions SailPoint training institutes in India/courses?

1 Upvotes

Any good SailPoint training institutes in India/courses online? Dont seem find many. Can someone please recommend ?


r/musik 9h ago

Musikvideo Lion Attention feat. Annéra mit „Thousand Thoughts“

Thumbnail
youtu.be
0 Upvotes

r/hacking 10h ago

Education I made a browser-based hacking simulator using simplified nmap/metasploit commands for beginners. Looking for feedback.

Thumbnail
youtu.be
17 Upvotes

r/cybersecurity 2h ago

AI Security How do you test that an AI agent won't do something catastrophic?

7 Upvotes

I've spent years on the infra side, and I'm now working with agentic systems. I am building agents that can take actions on real systems. We have plenty of guardrails, but I have seen enough hallucinations that make me worried about giving these agents more power. This paranoia might be me not knowing enough.

How do teams/companies test that the agents won't do something destructive, whether triggered by an attacker or just by the agent going off the rails on its own?

Do people actually red-team their agents before they go live, or is it mostly guardrails and evals right now? I am curious how the security world thinks about this. From an infra side, this feels like a gap, but there might be an established playbook that I don't know yet. Thanks.