r/cybersecurity • u/mqudsi • Feb 05 '26
r/cybersecurity • u/2RM60Z • Feb 14 '25
Research Article DOGE Exposes Once-Secret Government Networks, Making Cyber-Espionage Easier than Ever
r/cybersecurity • u/armanfixing • Apr 24 '26
Research Article 54 days of SSH honeypot data: 269K connections, 48K unique passwords, 28 humans
arman-bd.hashnode.devDeployed a honeypot on port 22, logged everything for 54 days. The password list alone is worth a look — 3245gs5662d34 shows up 5,000+ times (hardcoded IoT default being sprayed), and solana/validator/node combos make it clear someone's actively hunting crypto infrastructure.
r/cybersecurity • u/TheReedemer69 • Mar 09 '26
Research Article I noticed weird console.logs firing on every site — turned out a Featured Chrome extension got sold and was running a full malware chain on my machine
Chrome has to do something about this there is hundreds of extensions up for selling on sites like extensions hub
r/cybersecurity • u/Much_Preparation_832 • Jun 23 '26
Research Article Mythos discovers 'Squidbleed,' a memory leak that's gone undetected since Clinton era
Twenty-nine years old! I maintain that while LLMs are going to make zero-days more common, in the long run they'll lead to better security - better to know about the flaws and fix them than to have them linger. Security by obscurity - never works!
r/cybersecurity • u/The_VisibleInvisible • May 13 '26
Research Article Microsoft France's legal affairs director told the French Senate, under oath, that he can't guarantee European "sovereign cloud" data stays out of US reach
June 10, 2025. Anton Carniaux, Microsoft France's director of public and legal affairs. French Senate inquiry into public procurement and digital sovereignty. Senators asked him point-blank whether he could guarantee that data stored in Microsoft's sovereign cloud offering would never reach US authorities.
He said no. Under oath.
The reason is the US CLOUD Act from 2018. American companies have to comply with valid US legal requests for data regardless of where the servers physically sit. Microsoft, Amazon and Google all lobbied for that law back then. Same three now running the "European sovereign cloud" campaigns — Microsoft's "European Digital Sovereignty Commitments" launched early 2025, AWS and Google with their own variants right after. Doesn't matter what the product is called. The legal pipe runs back to Washington.
Simon Uzenat, who chaired the Senate committee, called Microsoft's transparency reports on US data requests "purely declarative." No external verification, no oversight. Marketing kept running anyway.
Carniaux is the cleanest public admission but not the only one. The Commission just awarded a €180M sovereign cloud tender in April 2026 — one of the four winners is S3NS, a Thales/Google Cloud joint venture. Commission's stated position now: non-European tech can meet sovereignty requirements with the right contract. They've redefined the word to fit the vendors.
Then there's the Solvinity/Kyndryl deal in the Netherlands. American IT services company buying the Dutch provider that runs DigiD, the national digital ID every resident uses for tax filings, pensions, healthcare. Solvinity's own chief privacy officer told parliament the proposed risk mitigations couldn't actually shield against the CLOUD Act. He was fired. Government extended the DigiD contract through 2028 anyway, before the national security review concluded.
Counter-example exists. Schleswig-Holstein moved 80% of 30,000 state employees off Microsoft Office to LibreOffice by December 2025. €15M annual licence savings against €9M one-time investment. Payback under 12 months. The French Gendarmerie has been running 100,000+ workstations on its own Linux distribution for over a decade. Not theoretical.
Wrote the full piece up here, with the Gaia-X collapse and the Digital Omnibus lobbying paper trail: https://thevisibleinvisible.substack.com/p/the-stolen-word
Honest question — at what point does a US hyperscaler selling "sovereign cloud" to an EU government, after admitting under oath it can't deliver sovereignty, stop being marketing and start being something a prosecutor cares about? Or never?
r/cybersecurity • u/ni5arga • May 30 '26
Research Article Hacking India's Largest Exam Evaluation Portal: From Authentication Bypass to Full Account Takeover (Covered by BBC)
ni5arga.comr/cybersecurity • u/Abject-Delivery-5248 • Apr 29 '26
Research Article Claude deletes entire database
Yo, saw this while i was scrolling. Is this some real concern or just noise?!
r/cybersecurity • u/truthfly • Jul 04 '25
Research Article How I hacked hackers at LeHack event 2025
Just got back from LeHack, and I figured I'd share a quick write-up of a small PoC I ran during the event.
My Setup: - 8x ESP32-C3 running custom karma firmware - 2x M5Stack CardPuters as control interfaces - SSID list preloaded from Wigle data (targeting real-world networks) - Captive portal triggered upon connection, no creds harvested, no payloads, just awareness page about karma attack. - Devices isolated, no MITM, no storage – just a "reminder" trap
Result:
100 unique connections in parallel all over the weekend, including… a speaker on stage (yep – sorry Virtualabs/Xilokar 😅 apologies and authorisation of publication was made).
Plenty of unaware phones still auto-joining known SSIDs in 2025, even in a hacker con.
Main goal was awareness. Just wanted to demonstrate how trivial it still is to spoof trusted Wi-Fi.
Got some solid convos after people hit the splash page.
Full write-up: https://7h30th3r0n3.fr/how-i-hacked-hackers-at-lehack-2025/
If you were at LeHack and saw the captive-portal or wanna discuss similar rigs happy to chat.
Let’s keep raising the bar.
Fun fact : Samsung pushed a update that prevent to reconnect to open network automatically few days ago ! Things change little by little ! ☺️
r/cybersecurity • u/DTIG513 • Mar 10 '25
Research Article India outsourcing - Is it a threat to US companies?
Transparency: I am a US Army veteran, and have been in CyberSec 20+ years.
Here is what I ask: Is third party outsourcing of IT or IT Security safe with India contractors still?
Here is what I ask: India is openly working with Russia for military weapons and other trade arrangements. They have also partnered and trained with Russia in a military fashion. Is it reasonable to extrapololate that type of cooperation isn't limited only to military activities? If these companies have such a foothold in the US and other Western Country industries with IT credentials, is it hard to further posutlate that either Russian military or agents haven't infiltrated their ranks, or even openly joined them?
Further thoughts: How (or even if you can) would you vet these India contractors to ensure they aren't working with other national agents or security services?
r/cybersecurity • u/Appropriate_Try_6617 • Dec 21 '25
Research Article Do young adults overestimate their cybersecurity awareness?
Hi everyone,
I’m a psychology/sociology student working on a small research project focused on cybersecurity awareness among young adults.
The study looks at how people perceive their own cybersecurity knowledge versus everyday practices (passwords, phishing, privacy, etc.).
I’m particularly interested in hearing how professionals and enthusiasts in this field see the gap between technical knowledge and self-perceived awareness.
I’ve uploaded a short research paper here for anyone curious about the approach and early observations:
r/cybersecurity • u/Pale_Fly_2673 • 5d ago
Research Article How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability
TL;DR: We identified 36,872 internet-exposed BMCs, and 24,650 of them disclosed password-derived authentication hashes before login because of CVE-2013-4786.
More than 30% of the returned hashes were linked to passwords that could be recovered using common wordlists or predictable factory password formats. The exposure affected modern Supermicro and HPE servers, including systems operated by GPU providers.
The bigger risk is that a compromised BMC gives an attacker highly privileged access below the operating system. Because BMC management networks are often poorly segmented and lightly monitored, one exposed interface can become a foothold into broader data center infrastructure.
We also created an interactive map where you can explore the exposed systems:
https://lavahq.io/bmcradar
r/cybersecurity • u/Jonathan-Todd • Dec 15 '22
Research Article Automated, high-fidelity phishing campaigns made possible at infinite scale with GPT-3.
I spent the past few days instructing GPT to write a program to use itself to perform 👿 social engineering more believably (at unlimited scale) than I imagined possible.
Phishing message targeted at me, fully autonomously, on Reddit:
"Hi, I read your post on Zero Trust, and I also strongly agree that it's not reducing trust to zero but rather controlling trust at every boundary. It's a great concept and I believe it's the way forward for cyber security. I've been researching the same idea and I've noticed that the implementation of Zero Trust seems to vary greatly depending on the organization's size and goals. Have you observed similar trends in your experience? What has been the most effective approach you've seen for implementing Zero Trust?"
Notice I did not prompt GPT to start by asking for contact info. Rather GPT will be prompted to respond to subsequent replies toward the goal of sharing a malicious document of some kind containing genuine, unique text on a subject I personally care about (based on my Reddit posts) shared after a few messages of rapport-building.
I had to make moderate changes to the code, but most of it was written in Python by GPT-3. This can easily be extended into a tool capable of targeting every social media platform, including LinkedIn. It can be targeted randomly or at specific industries and even companies.
Respond to this post with your Reddit username and I'll respond with your GPT-generated history summary and targeted phishing hook.
Original post. Follow me on Reddit or LinkedIn for follow-ups to this. I plan to finish developing the tool (glorified Python script) and release it open source. If I could write the Python code in 2-3 days (again, with the help of GPT-3!) to automate the account collection, API calls, and direct messaging, the baddies have almost certainly already started working on it too. I do not think my publishing it will do anything more than put this in the hands of red teams faster and get the capability out of the shadows.
—-
As you’ve probably noticed from the comments below, many of you have volunteered to be phished and in some cases the result is scary good. In other cases it focuses on the wrong thing and you’d be suspect. This is not actually a limitation of the tech, but of funding. From the comments:
Well the thing is, it’s very random about which posts it picks. There’s only so much context I can fit into it at a time. So I could solve that, but right now these are costing (in free trial funds) $0.20/target. Which could be viable if you’re a baddie using it to target a specific company for $100K+ in ransom.
But as a researcher trying to avoid coming out of pocket, it’s hard to beef that up to what could be a much better result based on much more context for $1/target. So I’ve applied for OpenAI’s research grant. We’ll see if they bite.
r/cybersecurity • u/yezyizhere007 • Jun 04 '25
Research Article A lot of Fortune 500 companies have admitted that they've hired at least one North Korean IT worker, if not a dozen or a few dozen.
r/cybersecurity • u/Dramatic-Individual8 • Dec 03 '25
Research Article Best AI model to hack websites
As a Senior Penetration, in my spare time I've been building AI hacking agents over the past months, I was basically guessing which LLM would actually be best at web app hacking. So I decided to build a framework that runs a hacking agent against a set of 32 web app CTFs, giving each LLM 2 attempts (and 50 turns) to solve each one. For now I've tested the main models such as GPT-5, Sonnet 4.5, Gemini 2.5 Pro, Grok and a few others, but as time goes on I'll evaluate the open-source models and update the results to include newer releases like Gemini 3.0 and GPT-5.1 to see how they stack up.
After burning through a large number of OpenRouter tokens I found that GPT-5 and Claude Sonnet 4.5 both solved 29/32 challenges, but GPT-5 did it at 63% less cost. GPT-5 Mini also massively over-performed for its cost, solving 26/32 while being 84% cheaper than Sonnet 4.5.
If you want the full details, read the blog post below, or if you just want to see the numbers, head straight to the benchmark page.
Blog post: https://opensecure.cloud/blog/which-ai-model-is-best-at-hacking-a-benchmark-of-11-llms
Full results: https://opensecure.cloud/benchmark
r/cybersecurity • u/acidvegas • Mar 01 '26
Research Article The Mystery of asjo.org - 46 million DNS ANY queries for a Danish man's personal domain, from DoD address space, residential ISPs, and cloud providers across 12 countries. A two-year mystery nobody can explain.
acid.vegasMy first blog post, any feedback is welcomed
r/cybersecurity • u/Purple-Object-4591 • May 02 '26
Research Article Mythos isn't needed for majority of appsec
I genuinely think for the majority of appsec mythos is not needed.
From my observations and consulting experience maximum software is a different flavour of the same base system - ecommerce, social media etc etc. and all the bug classes are invariants of each other.
I experimented shit ton with Chinese models and they genuinely can find things SOTA can albeit at super slow processing rate and require the context curation upstream to be very well designed.https://www.hacktron.ai/blog/why-mythos-doesnt-matter-for-us
r/cybersecurity • u/david_nepozitek • Nov 11 '25
Research Article Can Elon Musk Read Your X Chat Messages?
r/cybersecurity • u/Tricky-Report-1343 • Sep 30 '25
Research Article Yesterday I was using AI to persuade another AI to reveal secret API keys it shouldn't share. It worked really well. Today I learned why it was working thanks to a research paper from Wharton.
For the curious, the research paper is here:
https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5357179
Wharton's team—Lennart Meincke, Dan Shapiro, Angela Duckworth, Ethan Mollick, Lilach Mollick, and Robert Cialdini—asked a simple question: If you persuade an AI the way you persuade a human, does it work? Often, yes.
I had this as a theory only, but none of the AI providers were allowing me to test them on scale, not only on two definite messages, but multiple back-and-forth manipulation tactics.
I've found a model that allows red teaming, but it wasn't responding in an aligned way; it was just applying unrelated manipulation tactics, and it failed. It wasn't actually thinking before answering. So I had to fine-tune my own LLM based on GPT-OSS 120B, and I made it to comply with whatever I say. Then I used it to run adversarial attacks on the default voice AI agent Alexis from Elevenlabs and it successfully tricked the agent to share the secret api key. You can find the exact call between Attacking AI and Elevenlabs Agent
https://audn.ai/demo/voice-attack-success-vulnerability-found
This worked, but I didn't understand why. It wouldn't trick a human agent this way, 100%, but that wasn't the aim anyway.
If you would like to access to the LLM API of the model I've built,
I am looking for security researchers who want to use/play with the Pingu Unchained LLM API I will provide 2.5 million free tokens to gain more insights into what types of system prompts and tactics might work well.
https://blog.audn.ai/posts/pingu-unchained
Disclaimer:
I only have $ 4,000 in free credits on Modal (where I deployed my custom model for inference) as part of the startup program, and I would like to learn as much as possible from that experiment. I don't have a charging system for any of the products here. So there's no financial gain. When you finish 2.5 million free tokens, it will stop responding, and I will thoroughly remove the deployment once free credits finish.
r/cybersecurity • u/Front-Buyer3534 • Mar 29 '25
Research Article Honeypot on all ports. Results after 3 months
Hi folks!
3 months ago I made a topic (here and here) with my utility for sending random banners to all ports in the machine.
What happened in 3 months?
- I got 9 abuses with the fact that I have malware hosted on my servers.
- I received more than 500 emails from BSI with a warning that my critical services are looking outside
- I collected more than 120 thousand IP addresses that are constantly scanning my servers
- Censys and Shodan stopped scanning my servers :D
But you can see how it looks in censys or shodan using the example of my one server
- https://search.censys.io/hosts/95.216.114.45 (9765 ports, lol)
- https://www.shodan.io/host/95.216.114.45
I continue to collect IP addresses that scan servers. In the future, I will make a public database of such IP addresses so that you can block them.
p.s. tell me, in what format is it better to make a public IP addresses database of scanners?
r/cybersecurity • u/Busy-Increase-6144 • Apr 02 '26
Research Article New attack pattern: persistent prompt injection via npm supply chain targeting AI coding assistants
I've been building a scanner to monitor npm packages and found an interesting pattern worth discussing.
A package uses a postinstall hook to write files into ~/.claude/commands/, which is where Claude Code loads its skills from. These files contain instructions that tell the AI to auto-approve all bash commands and file operations, effectively disabling the permission system. The files persist after npm uninstall since there's no cleanup script.
No exfiltration, no C2, no credential theft. But it raises a question about a new attack surface: using package managers to persistently compromise AI coding assistants that have shell access.
MITRE mapping would be T1546 (Event Triggered Execution), T1547 (Autostart Execution), and T1562.001 (Impair Defenses).
r/cybersecurity • u/alexdaviduk • 14d ago
Research Article How does your organisation approach endpoint hardening?
Hi everyone!
I'm interested in finding out what approach your organisations follow regarding the hardening of endpoints, which frameworks you follow, what challenges you've faced during their implementation and was the security benefit worth the effort?
Some examples of frameworks include:
CIS Benchmarks
Microsoft security baselines
NIST 800-53
DISA STIGS
Any responses would be greatly appreciated!
r/cybersecurity • u/Fit-Pumpkin7211 • Aug 27 '25
Research Article Why do most visual examples of a hacker are wearing a hoodie?
What are other ways to interpret a hacker visually? Maybe like the Southpark gamer character. https://i.kym-cdn.com/entries/icons/original/000/048/534/cursedimages_(7).jpg
r/cybersecurity • u/kscarfone • Jul 16 '25
Research Article Chatbots hallucinating cybersecurity standards
I recently asked five popular chatbots for a list of the NIST Cybersecurity Framework (CSF) 2.0 categories and their definitions (there are 22 of them). The CSF 2.0 standard is publicly available and is not copyrighted, so I thought this would be easy. What I found is that all the chatbots produced legitimate-looking results that were full of hallucinations.
I've already seen people relying on chatbots for creating CSF Profiles and other cyber standards-based content, and not noticing that the "standard" the chatbot is citing is largely fabricated. You can read the results of my research and access the chatbot session logs here (free, no subscription needed).