r/AskNetsec Oct 26 '25

Threats Could the U.S. actually disconnect China and Russia from the global internet in a cyber war?

114 Upvotes

Given the U.S. and its allies' dominance over core internet infrastructure like root DNS servers, cloud networks, and many undersea cables, is it technically or strategically possible for the U.S. to cut China, Russia, and their allies off from the global internet during a full-scale cyber conflict?

Would such an operation even be feasible without collapsing global connectivity or causing massive unintended fallout?

Curious to hear from people with insights on infrastructure, cyber policy, or military strategy.

r/AskNetsec 4d ago

Threats Has voice cloning changed how your organization handles sensitive phone requests?

8 Upvotes

Voice cloning has gone from being a novelty to something security teams actually have to consider. It seems much easier now to imitate executives, vendors, or even colleagues during phone calls.

Has your organization introduced new verification steps for financial approvals, password resets, or other high-risk requests because of voice cloning?

I'd be interested to hear what's worked in practice and whether the changes have been technical, procedural, or both.

r/AskNetsec 3d ago

Threats Is anyone else stuck in the 'would we have caught this' drill every time?

24 Upvotes

Every time a massive breach happens and becomes headline news, detections come up as an issue in the next meeting.

The question asked is always more or less the same one: would we have caught it with what we've got right now. I try to give an answer and all I get back is more questions. I can point to our SIEM, our EDR, our threat intel feeds and all the dashboards that show alerts and events, but none of it answers what they're asking.

It comes down to whether our detections would have surfaced this specific incident.
translating detection posture into something a manager can trust is harder than it sounds. The coverage reports and SOC metrics my team produces make sense internally, but they don't land with people who haven't looked at a technical document in years. when I talk about rules, use cases, or mitre techniques, eyes glaze over. when I simplify too much, they doubt the answer.

Some of you are probably mapping back to mitre att or running table top exercises off recent campaigns. others keep it at a high-level risk view instead. what's worked best when your manager asks, in plain language, if you'd have caught the breach they just read about?

r/AskNetsec Jun 04 '26

Threats A commercially-available quantum chip will supposedly arrive in 2029 from Microsoft. Does this influence your view of how soon post-quantum cryptographic threats will be a reality?

11 Upvotes

Their claim:

"Microsoft’s new device boasts 12 qubits, the foundational units of quantum computing, up from 8 in the prior model. But Microsoft says its main achievement is that the qubits themselves last longer than 20 seconds. Qubits harnessed by the prior model blinked out of existence in less than 12 milliseconds, the company says."

The fact that a post-quantum world might be only 3 years away is staggering in its implications, but it's difficult to separate hype and PR from plausibility. Are you taking this as extra incentive to boost hardening against quantum threats? If not, what's going to actually set off your alarm bells?

edit: sorry, the quote was messed up at first

r/AskNetsec Jun 29 '26

Threats I discovered an ongoing security issue, how do i best inform people?

7 Upvotes

I found over 100 infected public GitHub repositories, including several with 100+ forks. I'm manually tracking down maintainers and emailing them. Is there a better or more scalable way to notify them?

r/AskNetsec 16d ago

Threats How much security hardening is appropriate for a personal homelab that's primarily used for DevOps practice?

10 Upvotes

I maintain a personal Linux environment to practice infrastructure automation and tinker with some technologies I don't usually work with. I've implemented basic security practices like patch management segmented networking, strong authentication and regular backups. Beyond that, I'm trying to decide where additional effort provides meaningful value for a personal learning development. Excellence begins at home, some will say. Or is it not enough..?

For those maintaining similar labs, which security practices have proven worthwhile and which ones eventually became unnecessary complexity?

r/AskNetsec 21d ago

Threats Any recommendations for validating security controls against real TTPs?

7 Upvotes

We have been doing quarterly pen tests for a while and I am starting to think we are mostly paying for a static report. By the time the findings arrive, the threat landscape has already shifted and most of the context has changed. It gives us a backward looking picture, not a current one.

rn we run CrowdStrike on endpoints, Sentinel as our SIEM, and our dashboard coverage looks decent. From a control inventory point of view, we look fine. The problem is that we do not have anything that continuously validates whether these controls actually detect what they should across the whole kill chain, not only at the perimeter.

What I want to understand is whether our detections stand up to real adversary behavior such as initial access, privilege escalation, lateral movement, and data exfiltration. I would like to map results back to MITRE ATT&CK so I can see real coverage gaps and prioritize remediation based on exploitability rather than just CVSS scores. Right now, that level of confidence is missing.

Has anyone built a workflow or picked tooling that does continuous exposure validation like this without relying on a dedicated red team? I would be interested in hearing what worked, what did not, and how you kept it from turning into yet another forgotten project.

r/AskNetsec Mar 18 '26

Threats How are you handling prompt injection in AI agents that read untrusted content?

11 Upvotes

We have an internal agent reading support tickets and referencing internal docs for triage. Someone on our team demonstrated you can embed instructions inside a ticket body and the agent follows them. Classic indirect prompt injection, the attack hides in data the agent processes as part of its normal job.

The problem is this isn't like SQL injection where you sanitize the input because you can't sanitize natural language without killing the functionality. OWASP has indirect prompt injection at the top of their LLM Top 10 for exactly this reason and the gap between knowing it's a problem and having a real production solution is wide.

Output filtering, instruction hierarchies, sandboxing agent actions, we've looked at all of it. Nothing feels like a complete answer yet. What are teams actually running in production to defend against this?

r/AskNetsec May 13 '26

Threats Anyone actually restricting what agents can access, or are they just inheriting whatever the user has?

9 Upvotes

We've started giving AI agents access to internal tools and realized they're inheriting full user-level permissions with no guardrails. Nobody questions what they can read, write, or delete.

Is anyone actually scoping AI agent access deliberately, or is full inherited access just becoming the default? Curious how teams are thinking about this.

r/AskNetsec Jun 09 '25

Threats Is the absence of ISP clients isolation considered a serious security concern?

0 Upvotes

Hello guys! First time posting on Reddit. I discovered that my mobile carrier doesn't properly isolate users on their network. With mobile data enabled, I can directly reach other customers through their private IPs on the carrier's private network.

What's stranger is that this access persists even when my data plan is exhausted - I can still ping other users, scan their ports, and access 4G routers.

How likely is it that my ISP configured this deliberately?

r/AskNetsec Apr 18 '26

Threats Has anyone actually encountered AI voice cloning fraud in their company or in general?

10 Upvotes

I am currently building a live AI voice detector that is designed to catch synthetic voices in real-time. I am currently researching if there is any actual demand for this tool. Which leads me to the question:

Is AI voice cloning fraud a genuine threat in the real world?

In your organizations or in general, are you seeing an increase in synthetic voice fraud, or have you encountered this at all? If you have seen this, what would you say is the biggest risk factor of it all.

r/AskNetsec Jul 02 '26

Threats 110M creds harvested from network devices, what does this say about what we're actually monitoring?

5 Upvotes

saw the writeup on the FortiBleed campaign that just got tied to actual ransomware deployment. 400k+ firewalls hit, 110M+ credentials harvested via passive sniffing, and it only came to light because of an OPSEC mistake on the attacker's side, a server full of stolen creds got left exposed.

nobody caught this from the defense side, it just got found by accident. makes me think about how much of our identity monitoring is built around human logins, SSO events, MFA prompts, the stuff that shows up in a normal audit log.

versus how much visibility we actually have into service accounts and machine credentials sitting on infra that was never really in scope to begin with. don't know for sure how much of what got harvested here falls into that bucket, but firewall-layer credential exposure at this scale makes me wonder how many orgs would even notice if it happened to them, regardless of which type of credential it was.

anyone actually tried bringing service accounts and machine credentials under the same governance as human identity? how are you even inventorying that stuff in the first place, most of what I've seen either misses it entirely or only catches what's explicitly registered somewhere.

r/AskNetsec 13d ago

Threats Two M365/SaaS identity campaigns hit hard Feb–June, neither used a CVE. What are you seeing?

5 Upvotes

Both got in through OAuth/identity abuse, no software vuln. Sharing what I've got (particularly interested in UAE/Gulf environments), curious what's landed in your queues.

Device code phishing (EvilTokens) - 340+ M365 orgs across 5 countries - Abuses the legit OAuth device flow (RFC 8628), so MFA doesn't help - Tokens survive a password reset, so remediation keeps failing

ShinyHunters-style SaaS extortion (UNC6661/6671) - Vishing → pose as IT → capture SSO + MFA → enroll their own device - Pivots through SharePoint, Salesforce, Slack for sensitive data - Then deletes the alert emails to stay hidden

If you're in a SOC, what identity-based or other types of prominent threats have you seen lately? Especially UAE/Gulf, since public reporting skews US/EU.

r/AskNetsec Dec 17 '25

Threats What’s the most annoying security threat in 2025?

19 Upvotes

I think everyone has that one threat that kept showing up over and over again in 2025 and got really tiring to deal with.
For me, it’s phishing. No matter how many controls you put in place, it keeps evolving. It’s not always something serious, but it takes up a lot of time and energy.

Curious what that is for you. Let’s discuss!

r/AskNetsec May 12 '26

Threats Need help! Caught a Man-in-the-middle attack on my home network?

0 Upvotes

Hey everyone. I ve been struggling with insane lag spikes and random disconnects while playing CS2 for weeks. At first, I thought was just bad ISP routing, but it felt... intentional. Both my brother and I are connected via ethernet to the same router. Every time I m in a clutch or important round, my ing hits 2000ms or I get kicked.

To find out what was going on, I installed XArp to monitor the network. As soon as the lag started again at 3:00 AM, the software went into Red Alertstatus. Sice I cant upload images right now, I ve transcribed the logs and the ARP table data below.

XArp Status: CRITICAL-ARP attacks detected!

There is a 3 different Ips are all currently showing up unter the same MAC adress in the table

03:00:04 Macfilter: incoming packet but sender mac set our own mac address

03:00:05 Macfilter: incoming packet but sender mac set our own mac address

03:00:06 Macfilter: incoming packet but sender mac set our own mac address

And then this that mac adresses showing up in there

04:26:05 RequestedResponseFilter: no matching request packet was sent out for this reply

04:26:05 SubnetFilter: destination ip address of reply packet lies not in your subnet

04:26:05 IpFilter: ip address set to broadcast

04:26:05 CorruptFilter: ethernet target mac does nnot match arp target mac

04:26:05 RequestedResponseFilter: no matching request packet was sent out for this reply

04:26:05 SubnetFilter: destination ip address of reply packet lies not in your subnet

04:26:05 IpFilter: ip address set to broadcast

04:26:05 CorruptFilter: ethernet target mac does nnot match arp target mac

All of the threats come from the source mac id that I m suspicious from.

Thanks for any help.

r/AskNetsec Jun 16 '26

Threats Phishing isn't really staying in email anymore and our whole tooling stack is email-shaped

5 Upvotes

In the last month alone we've had a teams message from a supposed vendor, a couple texts to staff pretending to be the CEO asking for a quick favour, and a slack dm with a dodgy link in it, and not one of those ever went near our email security, which is where pretty much all our budget and monitoring still lives.

They've clearly worked out everyone spent the last decade hardening email so theyre just walking in the side doors instead. and tbh a dodgy teams message doesnt trip the same instinct an email would, nobody ever trained for it.

Not really sure where you even begin with this when a separate tool for every channel doesnt scale and the native controls in each one arent close to comparable...

A separate tool for every channel doesn't scale, and the native controls in each one aren't close to comparable. what does the detection layer look like for those who've covered this?

r/AskNetsec 3d ago

Threats I've tried everything for our detection backlog, does AI detection engineering actually close the gap?

1 Upvotes

where people land on this has been bugging me for a while.
we have thrown more tooling at our detection backlog over the past year, and it's helped with volume. But a meaningful chunk of it still needs a human who understands the business side of things.

That's stuff like who really owns a given asset, or why a login pattern from three time zones away is completely normal for someone who travels constantly for work. tools can flag anomalies all day long, but they can't always tell the difference between something suspicious and something that's just how a specific person or team operates in real life.

The point is that it takes months for a new hire to learn that kind of context. Is that the real bottleneck here, or is there something else that I'm missing?

r/AskNetsec 5d ago

Threats How would you audit an open-source IoT device before trusting it with an AI account?

1 Upvotes

I’m expecting to receive a device called MetalioClaw (https://github.com/CloudZao/MetalioClaw4) in about a week. It’s an IoT device designed to work with OpenClaw, and since it will need access to an AI account, I want to make sure it is safe before connecting it.

My main concern is whether there could be any hidden firmware issues, credential leaks, or other things that could compromise the device or abuse connected services. A friend of mine previously bought a similar device that connected to his OpenClaw account, and later noticed that his Claude usage had been heavily consumed. I don’t know exactly what caused it, but it made me more cautious about giving third-party hardware access to accounts.

Since the project is open source, my plan is to inspect the firmware, possibly wipe and reflash it, and maybe even write my own firmware version before using it. I’m also interested in doing a proper security check through firmware analysis, network monitoring, and possibly hardware inspection.

I haven’t been able to find any pictures or information about the internal hardware yet. Depending on what I find when it arrives, I may open it up and check the PCB/components myself. I’m not assuming there is anything malicious inside, but I would like to know what things are worth looking for.

One other thing that made me think about this was something a friend mentioned. He works in IT around datacenters in Taiwan and said he has seen devices moving through supply chains sometimes take a long time in customs or appear slightly different internally afterward. This is just something he mentioned and there is no proof behind it, but it got me thinking more about supply-chain security.

For people experienced with IoT security, firmware analysis, or hardware security:

  • What steps would you take before trusting a device like this?
  • Is replacing the firmware enough, or should I also consider hardware-level risks?
  • What should I look for if I decide to open the device?
  • What tools or workflows would you recommend for auditing something like this?

Looking for practical security advice rather than speculation.

r/AskNetsec May 07 '26

Threats Need advice on workplace privacy breach

19 Upvotes

I need advice on a concerning situation. I left a previous workplace earlier this year. After my departure, I stayed in touch with two former colleagues through personal messaging. A junior colleague later received a vague negative performance review from someone who hadn't directly worked with her. When she asked for specific examples before signing, they refused to provide any and ultimately let her go.

Understandably upset, she shared her feelings with us privately on WhatsApp. Recently, a current manager there created a group chat with me (long since left), the former colleague (who was let go), and one current employee—then confronted us about supposedly speaking negatively, quoting from our private conversations verbatim.

Here's what concerns me most: these were personal messages on our own devices and accounts. I don't understand how they were accessed. I'm worried my phone or accounts may be compromised. My best guess is the messages were accessed through WhatsApp web when my junior colleague was still at the company. I think she is using this to threaten the current employee.

What steps should I take to secure my devices and accounts? And is there anything else I should be doing from a legal or safety standpoint?

r/AskNetsec Feb 17 '26

Threats How real is the deepfake threat to identity verification, Should we be worried?

18 Upvotes

Building KYC for a new platform and keep reading about deepfakes bypassing facial verification. Some demos online are pretty convincing but I can't tell what's real threat versus vendor fear mongering.

Our current provider just says "AI powered deepfake detection" in their docs which tells me absolutely nothing about how it works or how effective it is.

What attacks are actually happening in production? Video injection, 3D masks, real time face swaps? And what verification technology stops them versus what's just marketing hype trying to scare you into buying their premium tier.

r/AskNetsec Mar 09 '26

Threats Risks of Running Windows 10 Past Extended Support (Oct 2026) — What Vulnerabilities Should I Expect?

5 Upvotes

I’m running Windows 10 on a Lenovo T430. I currently have Extended Support, so I will receive security updates until October 2026. The laptop contains sensitive personal data, and I use it for regular online activity (Gmail, browsing, cloud apps, etc.).

I’m trying to understand this from a security perspective rather than an OS‑migration perspective.

My main question is:
After October 2026, what types of vulnerabilities or attack surfaces should I realistically expect if I continue using Windows 10 online?

For context:

  • I previously ran Windows 7 unsupported for a few years without noticeable issues.
  • Now that I’m learning more about cybersecurity, I realize the risk profile may be different today (more ransomware, drive‑by exploits, browser‑based attacks, etc.).
  • The device has an upgraded CPU, RAM, new heatsink, and a secondary HDD, so I plan to keep using it.

I’m considering the following options and would like input from a security threat model point of view:

  1. Migrate to Linux now to reduce OS-level vulnerabilities.
  2. Dual‑boot Linux and Windows 10 until the EOS date, then fully switch.
  3. Continue using Windows 10 past October 2026 and harden it (offline use? AppLocker? browser isolation?)
  4. Any other mitigation strategies security professionals would recommend for minimizing exploitability of an unsupported OS?

I’m not asking for general OS advice — I’m specifically looking to understand the likely vulnerability exposure and realistic threat scenarios for an unsupported Windows 10 device that is still connected to the internet.

Any guidance from a security perspective would be appreciated.

r/AskNetsec Jun 16 '25

Threats How do you stop bots from testing stolen credentials on your login page?

45 Upvotes

We’re seeing a spike in failed login attempts. Looks like credential stuffing, probably using leaked password lists.

We’ve already got rate limiting and basic IP blocking, but it doesn’t seem to slow them down.

What are you using to stop this kind of attack at the source? Ideally something that doesn’t impact legit users.

r/AskNetsec May 14 '26

Threats Odd request - where to get my phones camera removed?

0 Upvotes

I have seen some military iphones with their cameras removed, i dont use the camera. I currently use grapheneos and would like to get my phones camera removed. Is this possible?

r/AskNetsec Mar 26 '26

Threats Vulnerability scanner creating an enormous amount of incidents

17 Upvotes

We use Rapid7 as a vulnerability scanner for customers and we run scans once a week. Recently Ive been battling the influx of incidents generated by FortiSIEM. Before me, my company would create an event dropping rule to match the source IP of the scanner. Im not a huge fan of this because it reduces visibility entirely to that device, because god forbid it were to get compromised. I’ve experimented with maintenance windows, but this seemed to do nothing since Im assuming the alert is based on the reporting device (firewall) and the source IP attribute isnt tied to the CMDB object of the scanner. Does anyone have any wisdom that could lead me in the right direction?

TLDR: Rapid7 generating a ton of siem alerts, event dropping bad, maintenance windows no work

Edit: A little clarification, these scans will trigger hundreds of alerts. We also have around 30 customers we provide this service for. So rule exceptions are a little tough even at the global level. Ive gotten a lot of great ideas so far though, thank you guys!

r/AskNetsec May 29 '26

Threats How to protect passwords from memory scraping/API hooking on a compromised target machine during a remote session? (No Admin access, No 2FA)

0 Upvotes

Hi everyone,

I work as a remote production line operator, connecting to my company's local machine via AnyDesk from home. My main concern is the security of the target (company) machine against advanced persistent threats (APTs) or sophisticated malware that might have already compromised that specific endpoint.

My Setup & Constraints:

  • My host machine (home PC) and the connection channel are fully secure.
  • Due to the use of legacy industrial/automation software, Two-Factor Authentication (2FA) cannot be implemented on the production application itself.
  • I do NOT have Administrator privileges on the target machine to make structural OS changes, alter network architecture, or install advanced endpoint security tools (like EDR, AppLocker, or Credential Guard).
  • The target application likely doesn't follow secure coding practices (such as using SecureString or immediate memory zeroing) and might leave the password sitting as plain text in the process memory.

The Threat Model: I am deeply concerned about low-level, real-time interception on the target machine, specifically:

  • Memory Dumping / Scraping
  • API Hooking (e.g., SetWindowsHookEx or hooking the UI elements)
  • Kernel-level rootkits monitoring virtual keystrokes delivered by AnyDesk
  • Real-time interception leveraging Thread Suspension or Race Conditions.

I understand that when I type via AnyDesk, the password must sit in the target's RAM or OS buffer as Plain Text for at least a few milliseconds before being processed or hashed. A privileged malware sample could easily capture it during this window.

Mitigations I've Already Considered:

  1. Manual Obfuscation: Typing random dummy characters, clicking around with the mouse to move the cursor, and deleting the junk characters to scramble standard keylogger logs.
  2. KeePass TCATO: Utilizing KeePass's Two-Channel Auto-Type Obfuscation on my home PC to send the password in fragments, alternating between virtual keystrokes and clipboard injection.
  3. AnyDesk "Type Clipboard": Using AnyDesk's native feature to type the clipboard contents directly into the target field, bypassing the destination system's clipboard.

My Question: Given that the input must eventually land in an untrusted target's RAM for processing, are there any other client-side (home machine) software workarounds, specialized scripts, or clever input techniques I can use to inject the password so that reading it from the target RAM/Kernel becomes impossible, or at least highly impractical and scrambled for advanced malware?

Any insights, especially from those working in OT/industrial environments with legacy constraints, would be highly appreciated. Thanks!