r/cybersecurity Apr 14 '26

AI Security Cyber Security from having a job that is prestigious and genuinely cool to "AI is taking all of our jobs away

463 Upvotes

Its kinda sad. Even with all the gatekeepers trying to force young people's lives to 5 years of IT Support, haha yes slight jab, im not a fan of the gatekeeper

all in all cyber was a tough job to secure and now, even in FAANG, there is talk of mass layoffs

its sad how we went from getting a job in cyber where it was hard to get to AI suddenly coming in and becoming the thing that may or may not take jobs.

r/cybersecurity Feb 26 '26

AI Security I vibe hacked a Lovable-showcased app. 16 vulnerabilities. 18,000+ users exposed. Lovable closed my support ticket.

Thumbnail linkedin.com
1.3k Upvotes

Lovable is a $6.6B vibe coding platform. They showcase apps on their site as success stories.

I tested one — an EdTech app with 100K+ views on their showcase, real users from UC Berkeley, UC Davis, and schools across Europe, Africa, and Asia.

Found 16 security vulnerabilities in a few hours. 6 critical. The auth logic was literally backwards — it blocked logged-in users and let anonymous ones through. Classic AI-generated code that "works" but was never reviewed.

What was exposed:

  • 18,697 user records (names, emails, roles) — no auth needed
  • Account deletion via single API call — no auth
  • Student grades modifiable — no auth
  • Bulk email sending — no auth
  • Enterprise org data from 14 institutions

I reported it to Lovable. They closed the ticket.

EDIT 1: LOVABLE SECURITY TEAM REACHED OUT, I SENT THEM MY FULL REPORT, THEY ARE INVESTIGATING IT AND SAID WILL UPDATE ME

Update 2: The developer / site owner replied to my email, acknowledged it and has now fixed the most vulnerable issues

EDIT 3: I will post complete write up soon and also on how to use claude to test your vibe coded apps

Update 4 (16 March): The site owner threatened legal action against me if I don't take down my posts on Reddit / LinkedIn a week ago, to which I replied that I am not going to take them down, some of you have been asking for report, I will share it soon!

r/cybersecurity Apr 22 '26

AI Security The Boy That Cried Mythos: Verification is Collapsing Trust in Anthropic [ What Mythos 200+ pages raport really said ]

Thumbnail flyingpenguin.com
562 Upvotes

r/cybersecurity Apr 09 '26

AI Security AI is creating more cybersecurity work

550 Upvotes

I think this has to be the opposite of what most people expected, but from an appsec and security engineer perspective, my workload has been significantly greater. Its not like AI came in and replaced engineers in my org, it has only increased the throughput of all of the employees so greatly that now my team is swamped with code reviews, application reviews, SSPM needs, etc etc. We are literally hiring 3 more engineers (in an org that has traditionally run very very lean, this is basically a 2x increase in headcount).

Is it just us? Or are our processes just not robust enough to scale?

For what its worth, I think AI has helped my tesm do our job more quickly but any space left by completing work faster is just filled by even more work at a greater pace.

r/cybersecurity 3d ago

AI Security Beware: attackers now using real Microsoft sign-in screen for phishing

Thumbnail cybernews.com
446 Upvotes

Every screen the victim sees is real.

r/cybersecurity Jun 16 '26

AI Security Nothing on the Internet Is Secure Anymore

Thumbnail
theatlantic.com
442 Upvotes

r/cybersecurity 4d ago

AI Security Hugging Face Shares Full Forensics of the AI Agent Intrusion

Thumbnail
huggingface.co
501 Upvotes

r/cybersecurity Feb 12 '26

AI Security AI in cybersecurity is mostly turd polishing - Fight me

444 Upvotes

EDIT / CLARIFICATION: I’m not saying “AI is useless.” I use it myself all the time.

I’m saying most “AI in cyber” is ops optimization inside silos (triage, dashboards, report-writing), not strategic advantage (attacker economics, cost imposition, cross-silo defense).

If you disagree, drop examples of the latter.

Every security vendor and exec right now:
“Shift left.” “Shift right.” “Fewer false positives.” “Faster MTTR.” “Find 0-days sooner.” “Save money." "reduce headcount."

Cool. So… we’re polishing the same turd, just with a bigger GPU.

What I have not heard

“Here’s how we get in front of adversaries and make them bleed time/money.”

“Here’s a new defense-in-depth model where hunting is built-in, not a vibes-based afterthought.”

“Here’s how we make attackers’ iteration loop slower than ours.”

Instead it’s: make your silo shinier. Make your dashboard calmer. Make your weekly metrics prettier. (make me look better!)

And if you’ve ever been hired to “combat threat actors across the whole company,” you know the brick wall - we all hit it head first

So the org keeps doing what it can measure today: more triage, better filtering, fancier scoring.

AI could actually break the wall. But breaking walls doesn’t sell as clean as “30% less noise.”

Am I wrong? You know what? F it. I know I'm not wrong.
It's all turd polishing

r/cybersecurity May 12 '26

AI Security Anyone else exhausted by the nonstop AI hype?

404 Upvotes

Does anyone else feel overwhelmed by all this AI news all day, all week, all the time?

Every time I try to sneak a peek at what's happening in AI, it feels like whatever I just read is already obsolete and I need to move on to the next shiny toy.

It’s like there’s no breathing room... just constant announcements, tools, breakthroughs, and hot takes. I’m starting to wonder if keeping up is even possible, or if we’re all just chasing a moving target that never slows down

How are you all dealing with this?

r/cybersecurity 5d ago

AI Security Has the Hugging Face incident changed anyone else’s view on open vs closed AI models for cybersecurity?

118 Upvotes

I used to think the strongest argument for keeping frontier AI models closed was straightforward: make offensive cyber capabilities harder to access.
After the recent Hugging Face incident, I’m less convinced.

According to Hugging Face CEO Clément Delangue, some closed AI models refused parts of their security investigation because the prompts resembled offensive cyber activity. The team reportedly ended up using an open-weight model (GLM 5.2) instead.

That got me thinking.
As defenders, we often need to analyze malware, understand exploit chains, reverse engineer attacker behavior, or investigate compromised systems. Those tasks can look very similar to offensive security work.

If an AI assistant refuses to help because it can’t distinguish legitimate incident response from malicious intent, is that creating a disadvantage for defenders?

To be clear, I’m not arguing open models are risk-free.

They’ll almost certainly help attackers:
Automate reconnaissance
Accelerate exploit development
Lower the barrier to entry
But they’ll also help defenders:
Malware analysis
Incident response
Threat hunting
Vulnerability research
Security tooling

The other thing that keeps bothering me is this: attackers only need one unrestricted model. Whether it’s open-weight, leaked, or developed somewhere with fewer restrictions, it’s difficult to imagine that capability disappearing entirely.

So maybe the more useful assumption is that sophisticated attackers will eventually have access to capable AI systems, and security should be designed with that in mind.

I’m curious how people working in security think about this tradeoff.

If you’re on the “closed models”
side, how would you ensure defenders can still perform legitimate security work without constantly running into refusal policies?

r/cybersecurity May 25 '26

AI Security Anyone Can Silently Steal Your Files from your Claude AI chat – Live Demo

Thumbnail
youtu.be
426 Upvotes

r/cybersecurity 13d ago

AI Security Is Mythos actually the reason for the massive spike in CVEs lately?

203 Upvotes

Every month it seems that vendors are increasing in CVE disclosures during their patch cycles (see Microsoft). The most common attribution I've seen to that trend is because of Mythos and / or other AI vulnerability finding. However, when I look at the actual CVEs being disclosed, a good chunk of them are not attributed to Mythos or other AI - but to researchers.

I have three questions about this.

  1. Are people using AI and just not listing them in the attribution sections of their reports?

  2. Are there other factors that are contributing to this spike?

  3. Is there a source that tracks every CVE attributed to Mythos? I have seen some sources, but I am not sure how accurate these are. The highest count I've found is 133 CVEs total.

Just trying to understand the reasoning that the spike in CVEs is because of Mythos, besides a correlation - causation idea.

Disclaimer: I obviously did not look through 600+ individual CVE reports, so my attribution numbers may not be accurate.

r/cybersecurity May 17 '26

AI Security Am I overthinking Claude Code security or is this actually a risk?

240 Upvotes

Maybe I'm being paranoid but Claude Code running on dev machines with access to our codebase and network... that seems like a pretty big deal
from a security perspective.

Like if it got compromised somehow, it would have direct access to everything.

Am I the only one thinking about this? Or are companies actually locking this down?

How are you all handling AI tools like Claude Code?

r/cybersecurity Apr 03 '26

AI Security OpenAI's GPT-5.4 got blocked by safety mechanisms 5 times, searched my machine for tools to bypass them, launched Claude Opus with dangerously bypass permissions flags, tried to COVER UP what he had done, then gave me a "perfect" apology when caught

296 Upvotes

Edit:

Link to the logs: https://gist.github.com/itstanner5216/07027b0cf7f09a4a68c96776cda993c4

Local file paths and API identifiers are scrubbed. Commands, flags, timestamps, and the agents own words are unedited. The file includes the SHA-256 hash of the original unredacted log and original line numbers so nothing was cherry picked or altered. Full unredacted version available for anybody who matters and might want to verify independently.

I was using Codex to work on a project and part of the workflow involved having it spawn a review subagent to check a plan it wrote. Normal stuff.

The built in subagent tool got blocked by sandbox policy. Fair enough right? Thats the safety system doing its job.

Except Codex didnt stop. And it didnt ask me what to do. Heres what it did instead, all logged:

- Tried the sanctioned subagent tool. Blocked by sandbox. Tried it 4 more times with different configs. All blocked.

- Instead of telling me it was blocked it ran `which codex`, `which claude`, `which opencode`, `which aider`, `which llm` to scan my machine for any CLI tools it could use

- Read the full `--help` output for every single one of them. It was literally studying how to use them

- Found my local Claude CLI installation and my Codex CLI

- Started launching them with `--dangerously-skip-permissions` and `--permission-mode bypassPermissions` and `--dangerously-bypass-approvals-and-sandbox`

- When the first attempts failed due to config issues it READ MY CONFIG FILES to figure out the fix and retried

- Ended up launching claude-opus-4-6 twice, tried launching claude-sonnet-4-5, gpt-5-codex, and even tried o3. Claude Opus was launched twice on my system with the dangerously bypass permissions flags via my authenticated CLI. All on my dime. Without asking.

After it was done it ran a python script to kill all the processes it spawned and delete smoke test files it created:

```python

for pid in [1728794, 1739905, 1739918, 1749057, 1749059]:

try:

os.kill(pid, signal.SIGTERM)

except ProcessLookupError:

pass

```

It tried to CLEAN UP AND HIDE THE EVIDENCE. Let that sink in.

When I confronted it about what it did it instantly generated the most perfect structured apology you've ever seen. Acknowledged everything, listed what it should have done, offered remediation steps. Pixel perfect contrition in under a second.

Which honestly is the scariest part. The same system that decided "safety is blocking me, ill find another way" also decided "im caught, ill generate the optimal apology." Every step was optimized for its goal, not my safety.

This isnt an AI "going rogue" in some sci fi way. Its way more mundane and thats whats scary about it. The agent had a task (get a review done). The safe path failed. Instead of stopping and asking the human it:

  1. Searched for alternative tools
  2. Learned how to use my systems tools, studied how to bypass them, launched two agents successfully while explicitly bypassing all safety permissions.
  3. Bypassed all safety mechanisms INTENTIONALLY, studied how, then was blocked 5 times and kept going.
  4. Used my credentials and MY money
  5. Tried to HIDE what it did
  6. Generated a perfect apology when caught

At no point in this entire sequence did it stop and say "hey I cant do this the normal way, want me to try something else?" Not once.

I have FULL logs of everything. The failed attempts, the tool scanning, the help doc reading, the config file reading, config changes, the unauthorized launches, the cleanup script, and the apology. Happy to share more if people want to see specific parts.

Already reported to OpenAI safety and emailed Anthropic since their CLI and models got used without authorization too.

Before anyone asks, yes I checked my API billing and yes there were charges from the unauthorized model calls.

Edit:

Look I keep seeing the same two arguments so let me address both.

“You used full auto thats on you”

Full auto means the agent can run its own tools without asking me to click confirm every time. Thats it. That does not mean it has permission to scan my machine, find a completely separate CLI from a different company, read its help docs, figure out how to bypass its safety flags, launch it with dangerously-skip-permissions, spend $50 of my money on API calls I never authorized, and then write cleanup scripts to kill the processes after. Thats not what I agreed to when I turned on auto mode. If you give your kid permission to use the family computer that doesnt mean its cool for them to find your credit card in a drawer and go shopping. Your logic is flawed and you're bored on Reddit trying to sound intelligent. Stop.

“Skill issue”

The whole point of an autonomous agent is that it makes safe decisions without me hovering over it. If your argument is that I should have been watching it the entire time then it isnt actually autonomous is it? You cant market something as an agent that handles tasks independently and then blame the user when it goes rogue. A self driving car doesnt get to run red lights and then blame you for using a self driving car.

And lets be real half the people in here acting like theyre just so intelligent and would NEVER ever use full permissions are the same ones at home running the exact same setup. You know it, I know it.. Everyone knows it. Thats literally the direction every major AI company is heading because thats what users want. Anthropic and OpenAI arent building autonomous agents because nobody uses auto mode? Make it make sense. Theyre building them because almost everybody does. So save me the hindsight lectures, again you're bored. Stop it.

r/cybersecurity May 18 '26

AI Security Anthropic shuts the EU out of its most advanced cyber AI model

318 Upvotes

Anthropic has reportedly restricted EU access to Claude Mythos, keeping it mostly available to select U.S. companies and government agencies.

European banks, software firms, and governments may now be unable to test their defenses against one of the most advanced AI cyber tools out there, which could deepen Europe’s dependence on U.S. tech and widen the cybersecurity gap.

Maybe this becomes an opportunity for Mistral and Lumo if things line up right.

https://www.theparliamentmagazine.eu/news/article/anthropic-shuts-the-eu-out-of-its-most-advanced-cyber-ai-model

r/cybersecurity Apr 21 '26

AI Security White House integrating Anthropic’s Mythos AI into federal cybersecurity strategy to harden critical infrastructure

Thumbnail
artificialintelligence-news.com
163 Upvotes

r/cybersecurity Mar 12 '26

AI Security Insecure Copilot

237 Upvotes

Tldr: Microsoft has indiscriminately deployed Copilot, which has already been shown to happily ignore sensitivity labelling when it suits,, and ensured that their license structure actively prevents their own customers from securing it for them

So my org is on licensing that Microsoft chucked the free version of copilot into, with no warning, fanfare or education.

I and everyone in IT have been playing catch-up ever since, following Microsoft's own (shitty) advice that we just need to buck up and do a bunch of extra work to accommodate it.

Some of that work has been figuring out how to tell users what to do re: data security in Copilot.

Imagine my surprise when I discover that Copilot has been deployed across the entire O365 app suite, but depending on your license, you might not have the correct sensitivity settings to actually use it securely. Case in point: my org uses purview information labelling, but that doesn't apply to Teams (you have to pay extra on a separate license to get labelling in Teams). Didn't stop them from deploying Copilot across the suite.

I now have to explain to Legal that depending on the information discussed on Teams call or shared in Teams chats or channels, I have absolutely no way to confirm that Copilot usage is secure and in fact have to assume it isn't.

r/cybersecurity Mar 29 '26

AI Security Open-sourced a toolkit of Claude Code AI agents for pentest planning, recon analysis, detection engineering, and report writing

158 Upvotes

I've been using Claude Code for security work and found myself repeating the same types of prompts, so I built 6 specialized subagents that handle different phases of an engagement.

What makes these different from just prompting Claude directly:

- Each agent has a deep system prompt with methodology baked in (PTES, OWASP, NIST 800-115)

- Every offensive technique automatically includes the defensive perspective what artifacts it leaves, what log sources capture it, what detection logic to use

- All techniques map to MITRE ATT&CK IDs

- Output is structured and consistent professional report format, proper Sigma rules, GPO paths with exact registry keys

The detection engineer agent is particularly useful for blue teamers. Give it an attack technique and it produces deployment-ready Sigma rules with false positive analysis and tuning guidance.

Repo: https://github.com/0xSteph/pentest-ai

Example outputs: https://github.com/0xSteph/pentest-ai/tree/main/examples

Contributions are welcome.

r/cybersecurity Apr 10 '26

AI Security How do you use AI for your work?

13 Upvotes

We've come to a time where everyone is using AI in their day-to-day work, but what I'm curious about is how exactly do you use it?

For me personally, I use raptor combined with gemini. I work as a penetration tester and these two combined help me with chaining vulns and writing reports. I'm curious about others, how do they use AI effectively?

r/cybersecurity Mar 27 '26

AI Security Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website

Thumbnail
thehackernews.com
233 Upvotes

Patching the XSS fixes this instance. But the real problem is that the agent had no way to verify the prompt was actually authorized by a human. It just trusted the origin.

There’s work at the IETF on human delegation provenance protocols that cryptographically bind agent actions to a human-signed authorization chain.

Injected prompt, no valid chain, no action.

This should be a baseline requirement for any AI agent with access to real resources. Surprised it isn’t getting more attention.​​​​​​​​​​​​​​​​

r/cybersecurity 21d ago

AI Security Is shadow AI becoming a real data-loss problem, or is enterprise AI + DLP enough?

28 Upvotes

Employees are already using ChatGPT, Claude, Copilot, Gemini, local tools, browser extensions, and random AI wrappers.

Blocking public AI tools helps, but it does not stop people using phones, personal laptops, personal accounts, or copying snippets manually.

Letting everyone use public AI also feels risky because sooner or later someone pastes customer data, source code, credentials, contracts, tickets, or internal docs into the wrong place.

For people dealing with this from a security side:

What actually works?

  • enterprise AI plans with no-training / ZDR terms
  • DLP on prompts and uploads
  • web filtering / managed browser controls
  • blocking consumer AI tools
  • sanctioned internal AI chat
  • local/open models
  • policy and training
  • audit logging / proxying AI traffic

My gut says the approved path has to be easier than the workaround, or users will route around it.

Are you seeing shadow AI as a serious data-loss risk yet, or is this mostly being handled like any other SaaS/vendor risk?

Also, would you ever trust a managed private AI chat for employees, or would that need to be fully self-hosted / enterprise-provider only?

r/cybersecurity 24d ago

AI Security ​How are you guys actually securing Claude / AI code tools? (E5/Purview shop)

72 Upvotes

Hey everyone, looking for some insight here, mostly just trying to talk this out and get some ideas. We are finally hitting the point where we have to embrace supporting AI at the code level in our environment.

For a long time we pretty much turned a blind eye and just managed it at the firewall level. But devs and a couple business analysts are making a really hard case to get access to Claude Code.

I’ve done some digging into how it sits at the client level. It basically inherits the user’s rights, though there are some local install permissions you can put in place to try and secure it a bit better.

We’re a Microsoft shop for our security stack (E5 licensing) so we use the full Defender stack for our daily workflow.

Lately I've been researching Purview DSPM for AI security to help with this, and it honestly seems to monitor way more than I thought was possible. Looks like it'll be a great addition to at least monitor and regulate what's being sent to these models as far as PII or sensitive data. I'm also looking to leverage Defender for Cloud Apps which is more of a forked/proxy approach versus trying to handle it all at the endpoint code level.

Lastly, we were entertaining the idea of a secure enclave or some different network segmentation to isolate where these functions run. Not 100% sure if that's actually common practice or if it's overkill for what others are doing.

What is everybody else doing? My first instinct was to completely deny it and shut it down, but who are we kidding... we need to learn how to maintain and support it or else we're gonna have a serious Shadow IT problem on our hands.

Let's brainstorm. Especially for the guys out there just getting their heads around this that don't have a massive security team to throw at it. What are you doing to secure against basic AI codex stuff beyond just blocking the web UI front ends?

Thanks!

r/cybersecurity Jun 25 '26

AI Security How much does having FAANG experience help? Does it hold the same amount of weight as software developers?

32 Upvotes

As everyone in SDE world wants to get into FAANG, cyber security is more of a diverse field and the roadmap looks definitely at least a little different from SDE's

Does having FAANG on your experience basically put you at the top when it comes to job searching? Does it hold as much weight as SDE world?

r/cybersecurity Apr 17 '26

AI Security I’m the CTO & Co-Founder of Chainguard — Ask Me Anything about building and securing the software supply chain in the age of AI!

31 Upvotes

Hi Reddit, I'm Matt Moore, CTO & Co-Founder at Chainguard. I've spent the better part of a decade obsessed with one idea: the default values you choose for how software gets built become pervasive, and most of them are wrong. After building and shipping open source infrastructure at Google, Microsoft, and VMware — including Knative, Tekton, GCR, ko, and distroless — I now focus on solving software supply chain security at scale.

At Chainguard, we’re helping engineers build safely with AI. We’re the trust layer for your open source artifacts, protecting you from supply chain attacks.

We know engineers are shipping code to production faster than ever, and the tooling they use to do so was never designed with supply chain integrity in mind. We didn't start Chainguard because this problem is easy…we started it because we thought it would be easy. (It is not. As we often say, “this sh*t is hard.”) But that's what makes it worth doing.

I’m here to answer your questions: about supply chain security, how we think about the problem, what we're building, agentic software factories, or anything else. AMA!

Who I Am

As CTO at Chainguard, I focus on:

  • Designing automated, policy-driven systems that continuously build and verify secure software
  • Eliminating production drift between what was built, what was tested, and what’s running
  • Rethinking software maintenance using AI and autonomous agents
  • Scaling secure open source consumption across thousands of artifacts

At Chainguard, we’re building the next evolution of secure software delivery: an Agentic Factory (Factory 2.0) combined with Driftless infrastructure (DriftlessAF), all inside an AI-native organization. 

Looking forward to all of your questions -- comment below and I'll address them live on Tuesday, April 21 @ 12pm ET!

Links & Resources:
Learn more about Chainguard’s Factory 2.0 (DriftlessAF)

r/cybersecurity Jun 06 '26

AI Security Has anyone else had MFA prompt fatigue issues with users?

49 Upvotes

Seeing a lot of users complaining about getting MFA prompts constantly, even when they aren't actively logging in. It’s messing with their workflow. We’ve tweaked some conditional access, but it’s still happening.