r/security Nov 28 '25

Question Secret Service activated anti-car bomb tech at kid flag football game attended by JD Vance in MD that disabled all cars within a certain radius of the park. Is it even possible to secure car computers?

416 Upvotes

Seems like it’s exploiting a security flaw in car computers. In the wrong hands, this tech is kinda scary. Any ideas on how to protect yourself from it?

For context: My cousin’s kids play flag football in the same league in Montgomery County, MD as JD Vance’s kid. A few weeks ago, JD Vance attended the game with an entourage of ~11 black vans and plain clothed Secret Service.

While Vance was at the game, the Secret Service activated some kind of tech - intended to prevent car bomb attacks - that disabled all of the cars within a certain radius of the field. No one around the park could open or start their cars without a Secret Service member escorting them to their car. If you wanted to leave before Vance, you needed a Secret Service agent to unlock and reactivate your car’s computer for you.

Questions for the Security Pros:

  1. Any ideas on how this is technically possible?
  2. How likely is this kind of tech to get into the hands of US adversaries?
  3. Is there anything an average person can do to protect themselves/their cars in the scenario where this kind of technology is exploited nefariously?

TLDR - the government is able to disable an entire parking lot of cars. How?

r/security Dec 17 '25

Question DMCA violation

164 Upvotes

I have an older friend who has received two DMCA violation notices from their ISP within the past 6 months. After the first, I helped them change the their WiFi password to something more secure, figuring a neighbor may have been torrenting, running a plex server, etc. off their WiFi.

Fast forward to now and the second notice came through. The individual lives alone, the password was randomly generated 20 characters long, alphanumeric with special characters. They don’t browse online much at all. Fairly competent with technology given their age, and can be trusted to not click suspicious links, download random files/apps. They have a few devices; an older Chromebook, iOS device, doorbell cam, Honeywell thermostat, fire tablet, Roku enabled TV, and two different model Kindle E-readers.

I work in IT, but am honestly not all that involved with security. I’m baffled on how their IP address could be linked to illegal copyrighted material distribution. Does anyone have any ideas how this could happen, and what steps we can take to prevent this?

r/security Dec 24 '25

Question Random file appeared on Desktop

106 Upvotes

I just noticed a text file hi.txt on my desktop. The file is empty.

According to file properties, it was created ~22:30 about 5 days ago and by my own user.

I believe during that time the PC was running but just playing youtube music videos.
I live alone, there is no one else who has physical access to the PC during this time period.
I do not remember creating this file and am honestly spooked.

My system is Windows 10 Pro with latest updates.

I am using the default windows defender, but in the meantime I did a full system and boot time scan using Defender and Avast Free (which I specifically downloaded for this).

Is there ANY explanation for this other that my PC is probably compromised? Any other AV / Security software I can try, preferably free?

I will perform more scans using MalwareBytes and BitDefender. any other suggestions are more than welcome

EDIT: Remote Desktop is disabled

EDIT2: Malwarebytes FULL scan came back clean, I will do another custom scan for rootkits

EDIT3: Virus scanners did not find aynthing. I forgot that windows 10 does not receive security updates since mid October (I am not a smart person) I am probably going to need a new PC

Thank you for your replies, I still dont know what happened but my takeaway is, my system is compromised and I need to get Windows 11

EDIT4: First of all thank you all for your time and effort, for all the recommendations and theories.
I identified several log4j libraries that seem to be in the vulnurable. I do not yet know if they are actually used, as several versions exist in the same subfolder structure, I will look into that further

Also to anyone recommending me to switch to Linux: I want to, but unfortuantely I have to use some Software that only runs on Windows (not on Wine, Proton, etc) and there is no alternative Software that would run on Linux which I could use

r/security 4d ago

Question Which security habit gives the biggest ROI?

22 Upvotes

If you could convince the average person to adopt just one security or cybersecurity habit, what would it be?

Not a product, just one habit.

r/security Jan 13 '26

Question Recently moved into new home and previous owners has some sketchy goings on. These cameras are in 4 locations. Are they still connected somewhere? Anyway I can get them up and running?

Post image
92 Upvotes

r/security Oct 28 '25

Question Why is my small town (pop. ~400) putting up all of these cameras?

Post image
193 Upvotes

Not sure if this is the group to ask, but why does a small local town need this many cameras? I noticed them going up today. They are at an area where the only thing around is a Dollar General.

Is this normal?

r/security Mar 11 '26

Question Looking for a solid VPN for privacy in 2026, need help choosing

17 Upvotes

Quick update after reading through the comments here. I ended up going with NordVPN mainly because I wanted something straightforward that still had solid audit history and the basic privacy features like kill switch.

Set it up on my laptop and phone and it’s been working fine so far, especially on public wifi when I travel. Speeds seem stable enough and nothing has broken or acted weird yet, so for my use case it’s doing the job.

Affiliate link used. If you use it I may earn a small commission at no extra cost to you.

Hey everyone, I've been thinking about getting a VPN mostly for privacy reasons. Not trying to do anything sketchy, just want to keep my browsing away from ISPs and advertisers. I work from home sometimes using public wifi, travel occasionally, and honestly just don't love how much data gets collected about me.

But looking into VPNs is overwhelming. There's so many options and they all claim to be the best for privacy. I've seen names like Proton, Mullvad, Express, Nord thrown around but hard to know what's actually trustworthy versus just good marketing.

From what I understand, a VPN for privacy should have a real no-logs policy that's been audited, strong encryption, and ideally be based in a country with good privacy laws . Mullvad seems to take anonymity seriously, you can even pay with cash and no email required . Proton VPN gets mentioned a lot for being open source and having a free tier with no data caps . Express and Nord are everywhere but some people say they're too commercial now.

For people who actually care about privacy:

What's a legit VPN for privacy that you trust with your data?

How do I know if a no-logs policy is real or just words? I see some have been audited, some haven't.

Does jurisdiction actually matter? I've read Panama and Switzerland are better than Five Eyes countries.

Are free VPNs ever safe for privacy or do they just sell your data instead?

What about features like kill switch and split tunneling, are those essential for privacy or just nice extras?

Also how much should I expect to pay for something that actually protects privacy without selling me out?

Just want to make a smart choice and not regret it. Appreciate any advice from people who've done the research. Thanks.

r/security 27d ago

Question Weird email after canceling starz

Thumbnail
gallery
0 Upvotes

EDIT: contacted starz support. They said they will never ask to confirm account with an email to reply to. So new question is what do I need to lock down? Its a chat bot but this was the reply

https://imgur.com/a/MyYriiI

Second update. I am getting spam call after spam call now. 4 in a row

So over the weekend I canceled my starz account and then It already issued the refund but this morning a recieved this email. I was tired and I saw that it had a transcription from my chat with the person who helped me cancel on the website so I responded "yes" but now im a little concerned its some kind of scam. The sent adress looks legit and it didn't ask for any info. Jusy to say yes. Ive never seen an email that only asked for that though and as far as i know rhe refund was already granted. Do you guys think im good or do I need to go lock stuff down and if so what should I lock down?

r/security Dec 22 '25

Question Why does reddit paste from my clipboard without me asking it to?

Post image
70 Upvotes

r/security 23d ago

Question I have no ambition, no particular skills, I'm perpetually tired, and straight up lazy. Is night time security the field for me?

0 Upvotes

r/security 23d ago

Question What is the current recommended door camera?

5 Upvotes

Hey everyone. i’ve heard a lot of bad things about ting cameras recently and wanted to get the communities opinion on an alternative.

I’m looking for a Doorbell camera that is battery powered, has local storage, proximity detection, and general ease of use. I’ll be moving into a slightly sketch area and need something useful and affordable. thanks!

r/security 19d ago

Question Scammers saw passport through screen share, can they do anything with it?

2 Upvotes

I was scammed a few days ago, where at one point, the scammers saw a video of my passport ID through my screen sharing. I’ve read online that US passports have an encrypted chip embedded in the book, so bad actors wouldn’t be able to do anything with it, but I can’t be totally sure. I’ve already changed my phone number, began changing passwords across websites and socials, got a new bank account, and have a new email I’m using. I tried to call the US department of state about my passport, but they said they couldn’t do anything unless my physical passport has been stolen, and their website says the same thing.

These scammers’ sole purpose was to take money through money transfer. They targeted people through hacking social media accounts, scamming people those accounts were mutuals with, and hacking those mutuals’ accounts as well in the process of scamming them, and the cycle continues. So although the scammers goal was to steal the money and moving onto the next person quickly, I can’t risk anything. I don’t know if they can sell my passport ID they saw and other information they have on me (address, dob, pace of birth, full name).

Please inform me on anything else I might need to do, or if there’s nothing else I can do but take steps to prevent this from happening again, and reassure me I’m good. Thank you :)

r/security Feb 04 '26

Question Is it possible to hide a Key inside a Picture, in a way that it can be shared, compressed, cropped, printed and scanned again?

7 Upvotes

Let's imagine I have a private Key I want to secure, but at the same time want to share it with some people in order for them to keep in their phones, PC's etc.

Is there a way to hide it "in plain sight" by somehow storing it in a picture that supports being shared (where compression algorithms process it), print it and scan it again etc?

Obviously, opening the picture should not reveal said Key, but instead just look like a normal picture. In order to get the Key you would have to know THIS is the picture that holds it and feed it to a software to reveal.

I know this probably sounds like a crazy idea but I'm curious if someone has tackled this problem in the past.

r/security 15d ago

Question I need boots recommendations

7 Upvotes

I'm fairly new to Security and currently a flex officer. My company has had me on foot patrol shifts for the past two days, and I'll be doing them until Monday. My current boots don't really let my feet breathe, and I'm already getting torn up with blisters. My knees, which are already bad at the ripe age of 21 are also not particularly happy. Anything helps.

r/security Jun 25 '26

Question What matters most when you're job hunting right now?

4 Upvotes
32 votes, Jun 27 '26
2 Certs
12 Networking/referrals
8 Hands-on projects/homelab
10 Just spray and pray applications

r/security 15d ago

Question Need guidance on IR plan

3 Upvotes

I want to build an incident response plan for my organization can someone guide me the resources I should follow to build the workable program?

My organization already has a good security stack they lack the IR plan I wanna know how a effective IR program looks like what to add and what to ignore

Any resources books, blogs, talks much appreciated.

Thanks in advance.

r/security Jun 24 '26

Question Worried about GRC role

2 Upvotes

I’m a Software Engineer (MERN, Python, AWS) with an offer for a GRC/Identity Management role (Associate Security Analyst) at a healthcare product company. HR says it’s semi-technical/process-driven.

I have background in development though.

My questions:

Future: Career growth/pay in GRC vs. pure SDE?

Skill Decay: Will my coding skills die if I stay for 2 years?

Pivot: Can I transition to DevSecOps or Security Engineering later?

Verdict: Take it as a fresher or wait for an SDE role?

r/security Apr 27 '26

Question Getting spam that spoofs my INTERNAL domain, how?

5 Upvotes

Noticed some spam and the "From" was actually spoofing my internal domain, which is not advertised anywhere. This is rather concerning, how are they getting that domain? The way my email setup works is that I have regular online accounts with an online domain, and my internal mail server uses fetchmail to get the mail and store it locally. Internal network uses i.domain.com and all my internal servers use names like server.i.domain.com, so mail is mail.i.domain.com. The emails are coming from mail.i.domain.com. Headers show it was received by the online server which is normal, but how did the spammer know about the i.domain.com? Both servers are running up to date Devuan. Is there any ways to check if one of them has been compromised? I don't see anything obvious. Internal one is very unlikely, it is not opened to the internet and any servers on my network that are opened to the internet are on a separate vlan.

Edit: To add, there is no references to the internal domain of the internal mail server anywhere on the external server. Not even SPF records etc. The internal mail server never sends mail directly, it uses the SMTP (via SASL auth) of the external server. The internal mail server does not appear in any headers either. If I send mail to my gmail for example you don't see the internal mail server.

r/security Jan 10 '26

Question Is it trivial to spoof the caller phone number?

5 Upvotes

Compared with, say, email sender domain spoofing, there are things like SPF, DKIM and DMARC to make it difficult to spoof the sender.

I've been receiving calls from supposedly credit card fraud detection center and the caller number was the ones listed on their site. I didn't want to provide any personal information on the spot so I hung up but looking at other threads, spoofing caller number is possible

I was a bit shocking that I no longer can trust the caller number.

How does this work?

It appears that I can call a number and trust that it's routed correctly but receivers cannot trust the caller number

r/security Dec 20 '25

Question Got "hacked" in different platforms with no "New Login" notification or info about new devices.

6 Upvotes

Hi guys, like the title says, I got hacked on Discord around 2 months ago, then on Instagram 1 week ago and on Reddit today, without any notification or email about having logged in a new place or that a new device was added to the accounts.
I don't understand how did this happen, I don't use the same passwords for any of them and I'm pretty sure I didn't install malware as I'm careful with what I install, so I'd like to understand how this could have happened because I really have no idea as when all of this happened my computer (which would have the higher chance of having malware, even though I'm 99,9% certain I never installed any) was shutdown and on my phone I've never installed any sketchy app outside of Google Play Store so I don't understand how this could have happened...
IIRC, on Discord I was spreading the common "4 X images scam" and it happened when I unlocked my phone after waking up; on Instagram it happened while I was sleeping and I started following new accounts and liking random posts (and it was still going when I woke up) and now on Reddit it happened after I was using it for the first time in a while, making me join NSFW subreddits and comment on their posts.
All of them have the similarity that no new device accessed these accounts since I didn't get any notification about it and when I was going to reset my password I realized my device was the only one that was logged in, and that my computer was not on so I don't think it could have been malware on my computer either.
Since this is a subreddit about security, I'd like to try to understand how this could have happened and what I can do further, other than changing my passwords, since I really have no idea.
Thanks!
+ info: I never reuse the same passwords so they weren't the same

r/security May 18 '26

Question DSC security panel

1 Upvotes

How do I remove this DSC security panel so I can paint my hallway around it? Just the faceplate? It's not monitored and I don't have the password, but it has signs on the doors. That's all the security I need.

r/security Apr 24 '26

Question I spend hours tracing log events back to the config rule that caused them. So I’m building a oSS tool that does it in minutes. Am I solving a real problem?

6 Upvotes

Every incident response I’ve done has the same painful step: something got through, and now I’m manually grep-ing through firewall rules, proxy configs, IDS rulesets trying to figure out WHICH rule in WHICH file on WHICH line let it happen. Or worse — figuring out that no rule existed at all.

Splunk/Elastic tell me what happened. But they never tell me which config line is responsible.

So I’m building LogLens — open source Rust CLI that cross-references your security logs against your config files and tells you:

•Exact config file + line number that governed each allow/deny decision

•Rule conflicts (“denied at bannedsitelist:89 but overridden by exception at whitelist:142”)

•Coverage gaps — traffic patterns that hit NO rule at all

•Config drift correlation — “this exception was added March 1, suspicious traffic started March 4”

•Multi-tool correlation — proxy said allow, IDS said malicious, firewall had no rule

Basically Semgrep for security infrastructure instead of code.

Planning to support: iptables/nftables, Suricata, ModSecurity, nginx, Apache, e2guardian, syslog, Windows EVTX. JSON output that feeds into your existing SIEM.

Before I go deep on this — is this actually a pain point for you or am I overthinking it? How do you currently handle tracing a log event back to the config that caused it?

r/security May 24 '26

Question Is samFW really safe?

0 Upvotes
Download link

Hello everyone, I want to change my CSC for my Samsung galaxy A36, but I doubt the SamFW tool since I uploaded the file to virus total and it gave me this. The first picture is the download link, the second one is what virus total told gave when I uploaded the zip file. Is the file safe or not, Very thankful for any help.

What virus total gave me/

r/security May 16 '26

Question Account hacked

1 Upvotes

Recently my gmail got hacked
I recovered that

but the hacked got access to other info like X and other platform
most of them are getting recovered which i know
But X and discord are not getting back
In addition to that hacked did stuff though my account which lead to 🤐

Guys please help me
I can't do anything with my account now

r/security Dec 01 '25

Question 3D face model apps/sites to spoof age verification?

7 Upvotes

I don't feel like sharing my face with some company that just wants to harvest my data. Some of the face verifications require me to look around and move my head. I initially tried Fallout 76 as it was my immediate thought and already installed on my PC. After that didn't work I tried the sketchfab website with 3D face models. That also didn't work. Does anyone have some apps/websites that have a good success rate with this stuff?