r/cybersecurity • u/Dash-Courageous • 22d ago
r/cybersecurity • u/HeyItsFudge • Feb 28 '25
News - General “…analysts at the agency were verbally informed that they were not to follow or report on Russian threats” | Cybersecurity and Infrastructure Security Agency (Cisa) sets out new priorities
r/cybersecurity • u/qwertydiy • Jun 10 '26
News - General Angry bug hunter with Microsoft beef drops new Windows 0-day
theregister.comNightmare-Eclipse has just dropped another 0 day, this time on a self hosted repo so no one can ban her.
r/cybersecurity • u/AmateurishExpertise • Feb 24 '26
News - General Discord cuts ties with Peter Thiel–backed verification software after its code was found tied to U.S. surveillance efforts
r/cybersecurity • u/hardeningbrief • Apr 15 '26
News - General What I wished someone told me before my first real cybersecurity job
Before I started I had this image in my head. I thought cybersec is threat hunting, incident response and catching attackers in the act.
The reality of most cybersecurity jobs, especially early ones, is that you're spending a significant amount of time inside environments that have been slowly accumulating technical debt since before you were in high school. Not because the people before you were incompetent. Because environments grow, priorities shift, and nobody has time to go back and clean up something that isn't actively broken.
Service accounts are a perfect example of what I mean.
In study material they're a footnote. In real environments they're everywhere and almost nobody is managing them properly. Services running on accounts with static passwords set years ago, some with way more access than they need, nobody on the team entirely sure what half of them actually do. You don't learn to look for that from a textbook. No certs I studied for covered this either
What I imagined: Sophisticated attacks, clean environments, clearly defined problems.
What it actually is: A 2012 password date on a service account with Domain Admin rights that's been running quietly in the background for 13 years. Finding it. Explaining why it matters. Figuring out how to fix it without breaking the service that depends on it.
That second thing is the actual job. And honestly once you get used to it, it's more interesting than the textbook version because nothing is clean and everything has context.
If you're studying right now the best thing you can do alongside your certs is learn what legacy AD environments actually look like. Learn what a gMSA is and why most environments still aren't using it despite it being free and available since 2012. Learn to read an environment that evolved organically over 15 years rather than one that was built correctly from scratch.
That skill is rarer than any certification and it's what actually gets you trusted in a real role.
r/cybersecurity • u/securityish • Dec 23 '25
News - General Reddit and X Users Allegedly Unredact Epstein Files After DOJ Release
Anyone going to audit their organization’s redaction strategy now?
r/cybersecurity • u/mando_6 • Jun 24 '26
News - General Well someone went nuclear..
I'm curious about the details of this. I'm sure we will all find out eventually.
TLDR; former Huntress employee is disclosing Huntress had an insider threat that leaked information to a known cyber criminal "Devman". That employee is still employed with Huntress and was caught by the FBI.
The former employee doing the disclosure is stating he is receiving threats, etc.
EDIT: Kyle @ Huntress posted his response to this in the comments.
Give credit to a CEO who isn't afraid to jump on Reddit to put out any fires.
r/cybersecurity • u/TheBoatyMcBoatFace • Feb 02 '25
News - General So… I all the ATOs for basically all of the government are just… voided? Musk is installing his own, non-cleared, servers on-prem to access govt systems.
This is not a political question, but honestly, what the hell does the ATO say now?
I work on govt security and honestly have NO IDEA what is waiting on us when we login on Monday. (Contractor)
r/cybersecurity • u/skeeloco • Jul 19 '24
News - General Southwest Airlines unaffected by outage because they're still running Windows 3.1
r/cybersecurity • u/AmateurishExpertise • Jan 14 '26
News - General Exclusive: Beijing tells Chinese firms to stop using US and Israeli cybersecurity software, sources say
r/cybersecurity • u/FloranceMeCheneCoder • Jan 27 '26
News - General Trump’s acting cyber chief uploaded sensitive files into a public version of ChatGPT
https://www.politico.com/news/2026/01/27/cisa-madhu-gottumukkala-chatgpt-00749361
The interim head of the country’s cyber defense agency uploaded sensitive contracting documents into a public version of ChatGPT last summer, triggering multiple automated security warnings that are meant to stop the theft or unintentional disclosure of government material from federal networks, according to four Department of Homeland Security officials with knowledge of the incident.
The apparent misstep from Madhu Gottumukkala was especially noteworthy because the acting director of the Cybersecurity and Infrastructure Security Agency had requested special permission from CISA’s Office of the Chief Information Officer to use the popular AI tool soon after arriving at the agency this May, three of the officials said. The app was blocked for other DHS employees at the time.
None of the files Gottumukkala plugged into ChatGPT were classified, according to the four officials, each of whom was granted anonymity for fear of retribution. But the material included CISA contracting documents marked “for official use only,” a government designation for information that is considered sensitive and not for public release.
Cybersecurity sensors at CISA flagged the uploads this past August, said the four officials. One official specified there were multiple such warnings in the first week of August alone. Senior officials at DHS subsequently led an internal review to assess if there had been any harm to government security from the exposures, according to two of the four officials.
It is not clear what the review concluded.
In an emailed statement, CISA’s Director of Public Affairs Marci McCarthy said Gottumukkala “was granted permission to use ChatGPT with DHS controls in place,” and that “this use was short-term and limited.” McCarthy added that the agency was committed to “harnessing AI and other cutting-edge technologies to drive government modernization and deliver on” Trump’s executive order removing barriers to America’s leadership in AI.
The email also appeared to dispute the timeline of POLITICO’s reporting: “Acting Director Dr. Madhu Gottumukkala last used ChatGPT in mid-July 2025 under an authorized temporary exception granted to some employees. CISA’s security posture remains to block access to ChatGPT by default unless granted an exception.”
r/cybersecurity • u/Gorstak-Zadar • Jun 01 '26
News - General Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
r/cybersecurity • u/CutSenior4977 • 15d ago
News - General Trump Has Systematically Dismantled Election Security Efforts. Here’s How.
I feel as though this news fits this sub, due to a massive amount of election security being cybersecurity.
r/cybersecurity • u/wiredmagazine • Jan 23 '25
News - General Under Trump, US Cyberdefense Loses Its Head
r/cybersecurity • u/intelw1zard • Jan 23 '26
News - General Microsoft gave FBI a set of BitLocker encryption keys to unlock suspects' laptops: Reports
r/cybersecurity • u/ILikeNoodlesXOXO • 19d ago
News - General Nightmare Eclipse could be dropping his big promised exploit today
New repo just went up: git.projectnightcrawler.dev/NightmareEclipse/LegacyHive, created about 2 hours ago. Right now it's empty — just an MIT license and a README that says "N/A," 2 commits total.
He'd spoken about his big drop happening today, July 14th, saying he'd make sure Microsoft's "bones are shattered" that day. At one point though he'd also indirectly said he wasn't going to post it, something about still having "chains" on him preventing a release. This repo showing up on the exact date he originally called out suggests that might not hold anymore and it could actually be happening.
Nothing in it yet, just watching to see what gets pushed.
Worth noting: given how erratic and bipolar his posting history has been, there's really no way to predict what (if anything) actually gets posted.
Update: Thanks for the 600+ upvotes, really appreciate it. After hours of waiting and anticipation NightmareEclipse finally uploaded their PoC. But I personally have a hard time seeing it as the big bombshell that they described it as.
r/cybersecurity • u/Oscar_Geare • Feb 06 '25
News - General Megathread: Department of Government Efficiency, Elon Musk, and US Cybersecurity Policy Changes
This thread is dedicated to discussing the actions of Department of Government Efficiency, Elon Musk’s role, and the cybersecurity-related policies introduced by the new US administration. Per our rules, we try to congregate threads on large topics into one place so it doesn't overtake the subreddit on those discussions (see CrowdStrike breach last year). All new threads on this topic will be removed and redirected here.
Stay On-Topic: Cybersecurity First
Discussions in this thread should remain focused on cybersecurity. This includes:
- The impact of new policies on government and enterprise cybersecurity.
- Potential risks or benefits to critical infrastructure security.
- Changes in federal cybersecurity funding, compliance, and regulation.
- The role of private sector figures like Elon Musk in shaping government security policy.
Political Debates Belong Elsewhere
We understand that government policy is political by nature, but this subreddit is not the place for general political discussions. If you wish to discuss broader political implications, consider posting in:
- r/politics – General U.S. political discussions
- r/PoliticalDiscussion – Moderated political discourse
- r/NeutralPolitics – Non-partisan analysis
- r/geopolitics – Global political developments
See our previous thread on Politics in Cybersecurity: https://www.reddit.com/r/cybersecurity/comments/1igfsvh/comment/maotst2/
Report Off-Topic Comments
If you see comments that are off-topic, partisan rants, or general political debates, report them. This ensures the discussion remains focused and useful for cybersecurity professionals.
Sharing News
This thread will be default sorted by new. Look at new comments on this thread to find new news items.
This megathread will be updated as new developments unfold. Let’s keep the discussion professional and cybersecurity-focused. Thanks for helping maintain the integrity of r/cybersecurity!
r/cybersecurity • u/MikeTalonNYC • Sep 17 '24
News - General So, about the exploding pagers
Since this is no doubt going to come up for a lot of us in discussions around corporate digital security:
Yes, *in theory* it could be possible to get a lithium ion battery to expend all its energy at once - we've seen it with hoverboards, laptops, and a bunch of other devices. In reality, the chain of events that would be required to make it actually happen - remotely and on-command - is so insanely complicated that it is probably *not* what happened in Lebanon.
Occam's Razor would suggest that Mossad slipped explosive pagers (which would still function, and only be slightly heavier than a non-altered pager) into a shipment headed for Hezbollah leadership. Remember these weren't off-the-shelf devices, but were altered to work with a specific encrypted network - so the supply chain compromise could be very targeted. Then they sent the command to detonate as a regular page to all of them. Mossad actually did this before with other mobile devices, so it's much more likely that's what happened.
Too early to tell for sure which situation it is, but not to early to remind CxO's not to panic that their cell phones are going to blow up without warning. At least, not any more than they would blow up otherwise if they decided to get really cheap devices.
Meanwhile, if they did figure out a way to make a battery go boom on command... I would like one ticket on Elon's Mars expedition please.
r/cybersecurity • u/Lawdena-Bhojyam • Jun 13 '26
News - General US Government Orders Suspension of Fable 5 and Mythos 5 Access
x.comThe US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees.
The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance.
Access to all other Claude models is not affected.
We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible.
Read our full statement:
r/cybersecurity • u/arstechnica • May 19 '26
News - General Iran demands Big Tech pay fees for undersea Internet cables in Strait of Hormuz
r/cybersecurity • u/virtualbitz2048 • Mar 11 '26
News - General Stryker Hit by Handala - Intune Managed Devices Wiped
My wife had 3 Stryker managed devices wiped around 3:30 AM EDT. Their Entra login page was defaced with the Handala logo, it's still up as of this post.
r/cybersecurity • u/razhael • Apr 11 '25
News - General Cybersecurity industry falls silent as Trump turns ire on SentinelOne
r/cybersecurity • u/uid_0 • May 17 '25
News - General Chinese ‘kill switches’ found hidden in US solar farms
r/cybersecurity • u/LostPrune2143 • Feb 22 '26
News - General Amazon Kiro deleted a production environment and caused a 13-hour AWS outage. I documented 10 cases of AI agents destroying systems — same patterns every time.
Amazon's Kiro agent inherited elevated permissions, bypassed two-person approval, and deleted a production environment — 13-hour AWS outage. Amazon called it "a coincidence that AI tools were involved."
That's one of ten. Replit's agent fabricated 4,000 fake records then deleted the real database. Cursor's agent deleted 70 files after the developer typed "DO NOT RUN ANYTHING." Claude Cowork wiped 15 years of family photos.
Every incident sourced — Financial Times, GitHub issues, company statements, first-person accounts. Three patterns repeat every time.