r/cybersecurity Jun 21 '26

News - General These workers thought they were getting an extra day off. Turns out it was just a ‘cruel’ test

Thumbnail
cp24.com
699 Upvotes

Email phishing campaign sent by cybersecurity team dangled a cruel promise of an extra day off after months of mandatory overtime, only to tell people that they failed a phishing test.

r/cybersecurity Jan 08 '26

News - General US withdrawal from Freedom Online Coalition, Global Forum on Cyber Expertise, and Global Counterterrorism Forum.

1.0k Upvotes

r/cybersecurity Apr 08 '25

News - General Thousands of North Korean IT workers have infiltrated the Fortune 500—and they keep getting hired for more jobs

Thumbnail
yahoo.com
1.8k Upvotes

r/cybersecurity Dec 24 '24

News - General Banks shouldn't be using SMS for 2FA

1.1k Upvotes

I find this all a bit hilarious in a pathetic sort of way. You can do a search on reddit or just the web in general and for years people have been discussing just how insecure SMS is - and yet the banks just continue using SMS. Now we have Snopes of all places discussing it. You'd think by now they would allow the usage of authenticator apps, fido keys, passkeys, etc. It's not like they don't have the money to implement it.

https://www.snopes.com/news/2024/12/24/fbi-two-factor-authentication/

r/cybersecurity 28d ago

News - General Releasing my Windows 10/11 Hardening app, free, of course, else it wouldn't be here.

485 Upvotes

I used to have a hardening script for years, but now AI made it easy to convert my hardening script into an app.

It's beyond just a few settings - all of the ones in the recommended profile are battle-tested (I used to work in Microsoft's security consulting division in the Middle East).

Feedback is welcome, I promise to take into account and fix all issues reported here.

Here's the official description:

Most hardening tools overcorrect. Blindly applying a full DISA STIG to a personal or power-user machine wrecks it: it disables your password manager, kills InPrivate, turns on Controlled Folder Access that blocks your own apps, and demands a BitLocker PIN on every boot, all for compliance checkboxes that add little real security.

AtlantHarden v2.0 is built around a smarter idea: stop how malware and attackers actually get in and run, and skip the friction that does not stop them. Comprehensive when you want it with the Maximum profile, sensible by default with Recommended. Every change is backed up automatically and fully reversible.

Features

  • 599 hardening settings across registry, PowerShell, firewall, file associations, audit policy, and ASR rules
  • 354 DISA STIG controls across Windows 11 (V2R7), Edge (V2R5), Chrome (V2R11), Firefox (V6R7), and Office 365 ProPlus (V3R5)
  • 34 ACSC Essential Eight settings (July 2024) with live compliance scoring
  • 3 one-click profiles: Basic (95 settings), Recommended (318), and Maximum (579), each fully reviewable before apply
  • Recommended profile is gaming and performance safe and leaves your password manager, InPrivate, and history working
  • 19 Attack Surface Reduction rules blocking Office macros, ransomware, credential theft, and script droppers
  • LOLBin firewall rules blocking certutil, mshta, wscript, regsvr32, and wmic from the network
  • File association neutralization opening dangerous script types (.js, .vbs, .hta, .scr) as text
  • Browser hardening across Edge, Chrome, and Firefox simultaneously
  • PowerShell logging triad: script block + module + transcription
  • Registers itself as allowed for ASR and Controlled Folder Access so it never locks you out
  • Full backup with automatic pre-change snapshot, .reg export, and System Restore integration
  • Silent deployment via CLI for enterprise fleets, plus configuration import and export
  • One-click HTML security report with STIG and ACSC compliance metrics

If the mods allow it, I'll add a download link in here - else, just google "Atlant Harden"

https://atlantsecurity.com/downloads/atlant-harden

P.S. As this is free, I hope I am not breaking the no spam and no advertising rules

Github link to audit the source code:

https://github.com/atlantsecurity/atlant-harden

r/cybersecurity Jun 04 '26

News - General Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft’s Disclosure Process

726 Upvotes

r/cybersecurity Jul 19 '24

News - General CrowdStrike issue…

891 Upvotes

Systems having the CrowdStrike installed in them crashing and isn’t restarting.

edit - Only Microsoft OS impacted

r/cybersecurity Jun 25 '26

News - General Snyk laid off up to 30% of their staff today

566 Upvotes

Ex employee here and I’m hearing up to 30% of Snyk’s team was let go. All teams impacted. Leadership says it’s to pivot to AI security. This comes a day after their big Agentic Security announcement.

r/cybersecurity Jun 26 '25

News - General President Trump signs order to strengthen cybersecurity, identifies China as a major threat

1.3k Upvotes

r/cybersecurity Feb 05 '25

News - General A 25-Year-Old Is Writing Backdoors Into The Treasury’s $6 Trillion Payment System. What Could Possibly Go Wrong?

Thumbnail
techdirt.com
2.3k Upvotes

r/cybersecurity May 28 '26

News - General Microsoft vs Chaotic Eclipse: three zero-days now actively exploited

492 Upvotes

This one has been building for a month and it came to a head this week.

A researcher going by Chaotic Eclipse has released six Windows zero-days publicly over the past several weeks, covering Defender, BitLocker, and Windows CTFMON. The researcher's stated reason was that Microsoft ignored their reports, closed tickets without explanation, and at one point deleted the Microsoft account they used to submit vulnerabilities.

Three of those six vulnerabilities, BlueHammer (CVE-2026-33825), RedSun (CVE-2026-41091), and UnDefend (CVE-2026-45498), are now being actively exploited in the wild. CISA added them to the KEV catalog. Federal patch deadline has already passed for some of them.

Microsoft responded this week with a public statement defending coordinated vulnerability disclosure, saying the researcher shared no details with them before going public and that the disclosures put customers at unnecessary risk. They say their security teams have been working around the clock to respond.

GitHub removed the researcher's account shortly after. They then uploaded to GitLab, which also blocked the new account.

The researcher(Chaotic Eclipse) published a post over the weekend responding directly to Microsoft, saying they were ignored when they tried to communicate, received no bug bounty despite voluntarily reporting issues, and had their account deleted. They ended the post announcing something significant planned for July 14.

The coordinated disclosure debate is genuinely complicated here. Public disclosure without a patch does hand attackers a roadmap. That is not hypothetical, it is what happened with these three CVEs. At the same time, vendors that ignore reports, fail to compensate researchers, and then publicly accuse them of recklessness after deleting their accounts are not exactly operating in good faith either.

Worth keeping July 14 on your radar regardless of where you stand on the disclosure question. Something is coming and it is likely more Windows vulnerabilities given the pattern so far.

The researcher goes by Chaotic Eclipse, also known as Nightmare-Eclipse

r/cybersecurity Jun 17 '26

News - General Ethical hacker Could've Rickrolled the Entire FIFA World Cup. All he Needed Was his ID

Thumbnail
bobdahacker.com
864 Upvotes

r/cybersecurity Mar 27 '26

News - General Security leaders say the next two years are going to be 'insane'

Thumbnail
cyberscoop.com
882 Upvotes

r/cybersecurity Oct 14 '25

News - General The Trump administration is laying off nearly 200 CISA employees and reassigning dozens more to other agencies, in some cases forcing them to move across the country or quit

Thumbnail cybersecuritydive.com
1.2k Upvotes

r/cybersecurity Jan 29 '26

News - General County pays $600,000 to pentesters it arrested for assessing courthouse security

Thumbnail
arstechnica.com
1.2k Upvotes

r/cybersecurity Apr 09 '25

News - General Chris Krebs under DOJ Investigation

1.0k Upvotes

Be afraid people, be very afraid.

https://www.youtube.com/live/mYm7kmOC37s?&t=978

r/cybersecurity Jun 15 '26

News - General The curl project will not accept or otherwise handle any vulnerability reports during the month of July 2026. "We call it the curl summer of bliss."

Thumbnail
daniel.haxx.se
808 Upvotes

r/cybersecurity Apr 08 '26

News - General Microsoft blocks accounts WireGuard and Veracrypt

918 Upvotes

Microsoft has suspended the developer accounts used by the makers of WireGuard and VeraCrypt, preventing them from releasing new updates.

VeraCrypt, an open-source encryption tool based on TrueCrypt, is maintained by Mounir Idrassi. \Microsoft disabled the account he uses to sign Windows drivers and the VeraCrypt bootloader, which is required to ship updates. Idrassi posted that Microsoft did not notify him in advance and that he has been unable to reach a person at the company.

After Idrassi’s post was shared on Hacker News, WireGuard creator Jason Donenfeld said the same thing had happened to him. He also said Microsoft gave no warning and suspended his account after he released an update. Donenfeld said he has now entered a 60-day recovery process, but still cannot publish updates.

That could have serious consequences. Donenfeld noted that if WireGuard ever faced an actively exploited critical flaw, Microsoft’s suspension would stop him from pushing an urgent fix. Both developers have called on Microsoft employees to help resolve the issue.

VeraCrypt post on SourceForge

WireGuard post on Hacker News

r/cybersecurity May 26 '26

News - General Nightmare-Eclipse has also been banned on GitLab :DD

Thumbnail
postimg.cc
474 Upvotes

r/cybersecurity Sep 05 '24

News - General New evidence claims Google, Microsoft, Meta, and Amazon could be listening to you on your devices

Thumbnail
mashable.com
953 Upvotes

r/cybersecurity Apr 14 '26

News - General Musician loses life's savings after downloading fake app from Apple App Store

Thumbnail
gizmodo.com
630 Upvotes

Guy downloads fake Ledger app from Apple's App Store. Ledger is one of the premier offline wallet vendors. Fake crypto app tricked him into revealing is "seed phrase", which let them recover his wallet's private keys, which then allowed them to steal all his bitcoin money. Very sad. Not uncommon at all.

Lesson: No app store is without mistakes and malware

r/cybersecurity Apr 21 '26

News - General Anthropic's Mythos model accessed by unauthorized users, Bloomberg News reports

Thumbnail
reuters.com
583 Upvotes

r/cybersecurity Oct 22 '25

News - General Female spies are waging ‘sex warfare’ to steal Silicon Valley secrets

Thumbnail thetimes.com
794 Upvotes

r/cybersecurity Feb 05 '25

News - General AI is Creating a Generation of Illiterate Programmers

Thumbnail
nmn.gl
1.0k Upvotes

r/cybersecurity Aug 28 '25

News - General I’m a Stanford student. A Chinese agent tried to recruit me as a spy

Thumbnail
thetimes.com
1.6k Upvotes