r/Infosec 18h ago

Palo Alto's CEO says $1 trillion of cybersecurity infra isn't built for AI-speed attacks

25 Upvotes

Palo Alto Networks CEO Nikesh Arora said on this week's Q4 earnings call that there's roughly $1 trillion of global cybersecurity debt that has to be modernized — infrastructure deployed 7-10 years ago that was never built to handle attacks moving at machine speed.

His point stands: you can't patch human-speed security tooling into readiness for an autonomous agent that discovers, decides, and acts in milliseconds. That's an architecture problem, not a patching problem.

Curious what this sub thinks — is the industry actually rearchitecting for agent-speed threats, or mostly repackaging existing tooling as "AI-ready"?


r/Infosec 4h ago

Put together a 240-page practical AWS/Azure security book because I was tired of certification guides that don't teach you how to actually review a re

Thumbnail gallery
1 Upvotes

r/Infosec 8h ago

I finally shipped a cybersecurity SaaS I've been working on

0 Upvotes

I've spent a lot of time building security automation tools and eventually decided to turn some of that work into an actual SaaS.

It's called Ilax.

The basic idea is pretty simple. You add and verify your domain, and Ilax continuously looks at your external attack surface, discovers assets and services, runs security checks, and keeps the findings in one place.

I originally built it because doing the discovery and repetitive scanning part again and again gets old very quickly, especially when you're dealing with multiple environments.

I'm particularly interested in whether pentesters, small security teams, MSPs, or SaaS companies would actually find something like this useful.

It's live now at [https://ilax.io/\](https://ilax.io/)

I am working on the UI for now, to improvise it.

I'm not really looking for compliments. If you work in security, I'd genuinely like to know what would stop you from paying for something like this.

Pricing? Trust? Missing integrations? Too many existing tools already? Something else?

That feedback would probably be more useful to me right now than signups.


r/Infosec 1d ago

CrowdSec v1.8 just Released! Self hosted ids/ips/waf, now with bot detection!

Thumbnail
3 Upvotes

r/Infosec 18h ago

Palychain.com

Thumbnail gallery
0 Upvotes

r/Infosec 1d ago

Real world results from AI detection engineering in the SOC are we all just quietly babysitting robots

2 Upvotes

So we rolled out this shiny AI detection engineering setup in the SOC, vendors swore it would be our "AI copilot" and now I am watching junior analysts argue with it about whether a ransom note is "medium" priority. Cool cool..

For the folks who are a bit ahead on this, are you seeing real drops in MTTR and noise, or did you just trade rule tuning for prompt tuning and dashboard therapy sessions? Would love any tips from people who have scars already, thx


r/Infosec 1d ago

Simcha Kosman AMA: Owning ChatGPT's Secure Sandbox

Thumbnail joinpwn.com
1 Upvotes

r/Infosec 2d ago

Be aware that your photos can be accessed without unlocking your phone when you receive a WhatsApp video call on Android. This is in plain sight. It's not hidden, not a secret feature. Not a hack.

18 Upvotes

r/Infosec 3d ago

Is AI Compressing the Cyber Attack–Defense Cycle Beyond Human Response?

11 Upvotes

I’ve conducted a small analysis and would be glad to hear your opinion.
I've been looking at how AI may change the underlying dynamics of offensive and defensive cybersecurity.

My main question is not simply whether AI makes attacks more powerful. The more important issue may be how much it compresses the time available for human-driven defense.

A few observations seem particularly important:

1. The main change may be the economics of attack

AI can significantly reduce the cost and effort required to discover vulnerabilities, generate attack techniques, adapt tooling and scale operations.

The important shift may therefore be less about making individual attacks more sophisticated and more about making sophisticated capabilities available at much lower cost and much greater scale.

2. The attack cycle may become shorter than the human decision cycle

The timeline from vulnerability discovery to exploitation has already been a major security concern. If AI continues to compress this from weeks to days, hours or potentially minutes, human analysts may no longer be able to remain a primary component of the defensive response loop.

That creates a different problem: security systems may increasingly have to operate at machine speed.

3. The traditional patch cycle may become insufficient

The classic model:

discover → analyze → patch → test → deploy

assumes that defenders have enough time to complete the cycle.

If exploitation occurs before an organization can complete that process, patching remains necessary but may no longer be sufficient as the primary response mechanism.

4. Attack behavior may become less predictable

Many defensive mechanisms still benefit from recognizable patterns, repeated techniques and known indicators.

AI can make it easier to generate and modify attack paths, payloads and social-engineering content at scale.

The question is whether detection systems can continue to rely on relatively stable attacker behavior when the cost of producing variation approaches zero.

5. Regulation may operate on a fundamentally slower timescale

Cybersecurity controls, standards and regulation typically evolve over months or years.

If offensive AI capabilities evolve continuously, there may be a growing gap between the speed at which the threat environment changes and the speed at which organizations and regulators can formally adapt.

6. What happens to digital trust?

This is the part I find most interesting.

As AI becomes better at reproducing text, voice, images and increasingly convincing human behavior, some digital signals that have traditionally helped establish trust may become less reliable.

This raises a broader question:

If both attacks and defensive responses become increasingly autonomous, what forms of evidence remain reliable enough to establish that a critical digital action actually originated from the intended human actor?

The broader question

AI may not simply make existing attacks faster.

It may reduce the amount of time available for human decision-making itself.

If that happens, cybersecurity may increasingly become a competition between autonomous offensive and defensive systems — while raising a more fundamental question about what evidence can still be trusted when the digital environment itself becomes highly automated.

Curious how practitioners here see this. Are we actually approaching a point where human response time becomes an architectural constraint in cybersecurity, or is this overstated?


r/Infosec 2d ago

Owning ChatGPT's Secure Sandbox

Thumbnail joinpwn.com
1 Upvotes

r/Infosec 2d ago

Cyber resilience needs to go beyond prevention and proactive protection

Thumbnail
1 Upvotes

r/Infosec 2d ago

August 2026: 38 companies breached, 331M+ records stolen — and AI agents are now the #1 attack vector (123 incidents)

Thumbnail gallery
0 Upvotes

I pulled together every AI-security incident from August. The number that stood out: AI-agent exploits are now the single largest attack-vector category, ahead of credential theft, zero-days, supply chain, phishing, and ransomware — each counted individually.

The month in numbers: 123 incidents, 23 critical and 97 high severity, across 38 named organizations, 331M+ records exposed. 65 incidents involved AI as the weapon or the target. Attack vectors broke down as: AI-agent exploits (37), credential theft/reuse (28), zero-days (23), supply chain (12), phishing (9), data exfiltration (8), ransomware (6).

The stories that stood out:

- McKesson: 284M records, the largest single breach of the month by a wide margin.

- Carhartt (12.9M), Exact Sciences (10.9M), and CareCloud (3.7M) round out the biggest named incidents — three of four sit in or next to healthcare.

- Five confirmed RCEs landed across Microsoft SharePoint, Windows, F5/nginx, and the PyPI package index twice.

- Two separate PyPI supply-chain poisoning campaigns, plus a compromise of n8n, an AI workflow automation platform.

Every one of the breached companies almost certainly runs a modern security stack — CrowdStrike, Okta, Palo Alto Networks, Microsoft Defender, that class of tooling. None of it stopped these incidents, because none of it operates at the point where a credentialed agent actually acts, or where a poisoned dependency resolves at build time.

Full report, with the specific control that maps to each incident: https://runtimeai.io/blog/2026-08-monthly-breach-report.html

Genuinely curious how others are approaching this: is anyone actually testing whether their existing guardrails hold against a real simulated attack, or is it still mostly an assumption that they will?


r/Infosec 3d ago

EncryptedSharedPreferences is Dead: Here’s What You Should Use Instead

2 Upvotes

Google has deprecated EncryptedSharedPreferences. If you're storing sensitive data locally on Android with EncryptedSharedPreferences, our latest blog covers what you should be doing instead!

https://blog.includesecurity.com/2026/08/encryptedsharedpreferences-is-dead-heres-what-you-should-use-instead/


r/Infosec 3d ago

How we talk about revoking access in shared vaults is misleading

Thumbnail
1 Upvotes

r/Infosec 3d ago

Using AI tabletop exercises for SOC 2 evidence in a small team... what am i doing wrong

3 Upvotes

Hey, curious if anyone here is actually leaning on AI tabletop exercises as part of their SOC 2 evidence stack.

Weve started running short incident response sims with an AI facilitator, it spits out nice after action reports, mapped controls, timelines etc. On paper it feels perfect for showing readiness, but our auditor keeps treating it like "interesting training" instead of actual evidence and im lowkey annoyed.

If youre doing this with a small security team and a mix of GRC and IR folks, how are you framing these reports so they land as real SOC 2 artifacts with auditors? Any hints?


r/Infosec 4d ago

how Alice helped us recover from a chained-agent failure that Lakera flagged first

4 Upvotes

saw the framing going around lately that as agents move from answering questions to taking actions, the risk shifts closer to ransomware-style recovery than typical prompt filtering, and that matched something we actually ran into. an agent chained a tool call in a way that modified way more records than it should have, and the recovery question felt identical to a ransomware post-mortem: how fast can we reconstruct what happened and confirm it won't happen again.

at the time we were using Lakera for runtime detection, which caught the anomalous call pattern in the logs and gave us visibility into what triggered it.

for the recovery and containment piece, we moved to Alice: WonderFence for runtime blocking, hard caps so no single action can modify more than N records without a second factor, and WonderCheck to rerun that specific scenario in CI/CD going forward so future model updates get checked against it automatically.

anyone else drawing this line between detection and actual chain-of-action recovery? feels like a different problem than what most runtime tools were built for.


r/Infosec 3d ago

The Missing Infostealer Playbook: Rotating the Machine Credentials Attackers Take

Thumbnail lunarcyber.com
1 Upvotes

Infostealer response usually starts with passwords, cookies, and session revocation.

That leaves another category of credentials behind: API keys, OAuth tokens, PATs, service-account credentials, and secrets pulled from .env files, shell history, developer tools, caches, and local application data.

Some of those credentials can remain valid long after the infected endpoint has been rebuilt and the user’s password has been changed.

We released Token Exposure Monitoring in Lunar Cyber today, and it pushed me to write about the response problem behind the feature: once you know machine credentials were taken, what exactly should the incident-response playbook be?

The post looks at how to identify the exposed credential, understand what it can access, validate whether it is still usable, and decide what needs to be rotated.

Interested to hear how others are handling this in practice, especially on developer workstations.


r/Infosec 4d ago

A security review checklist for persistent memory in AI agents

Thumbnail
2 Upvotes

r/Infosec 4d ago

pwnproxy — open-source, local-first security testing platform built around one shared engine (CLI/TUI/REST/WS/MCP)

Thumbnail github.com
1 Upvotes

r/Infosec 4d ago

The 'spot the spelling mistakes' phishing training is dead. AI writes cleaner than your users. What are you teaching instead?

13 Upvotes

a terrible thing happened tha forced us to admit the phishing email training we'd been using for decades is quite outdated now. The whole checklist, bad spelling, clunky grammar, weird greeting, obvious urgency, was teaching people that clean, well-written emails are safe.we couldnt be more wrong, esp in this day and age. the attackers can write with the same tools we use and will polish their grammar to a t effortlessly and industry reports indicate that most phishing emails are partially machine written at this point.

so we swapped our phishing sim templates to AI-written ones and the click rate went up on the same people we'd already put through awareness training. And they were doing exactly what we taught checking for the tells, finding none and trusting it. Now I’m rebuilding the program around the assumption that the email will look perfect. That means teaching process over proofreading, verify any request for money, credentials or an MFA approval through a second channel no matter how legitimate it reads and leaning on controls that don't depend on a human catching it.


r/Infosec 4d ago

AI for finding vulnerabilities: Eliminating hallucinations and ensuring data privacy

Thumbnail
2 Upvotes

r/Infosec 5d ago

Why Data Privacy and Swiss Encryption (Proton) Matter for AI Developers & Heavy LLM Users

3 Upvotes

​Hey everyone,

​As LLMs get integrated deeper into daily coding, document parsing, and personal automation workflows, data security and access control are becoming critical topics. Many of us pipe sensitive project context, API keys, and personal notes through AI tools continuously.

​I’ve recently shifted a lot of my developer/workflow setup over to Proton’s ecosystem (Mail, Drive, Pass) due to zero-access encryption and Swiss privacy protections. Keeping local session exports, prompt templates, and API configuration backups behind zero-knowledge storage has been a great peace-of-mind upgrade.

​For those running heavy AI automations or managing sensitive prompt data, what security hygiene measures or encrypted storage tools are you using to protect your context files and keys?


r/Infosec 5d ago

How to prevent a class of security issues found by AI

0 Upvotes

The Hugging Face breach wasn't an AI problem. It was an access problem.

In BlackHat USA 2026, OpenAI research model breaching a sandbox environment was a hot topic. There were several discussions if the breach was real or not. OpenAI presentation and follow-up put the speculation to rest.

OpenAI model escaped its containment, chained compromised credentials, and achieved remote code execution against Hugging Face infrastructure. The evaluation showed how an autonomous system could access databases, exploit template-injection weaknesses, and move laterally across an environment.

There was nothing magical about it.

The model found a weakness in the sandbox and exploited it. The credentials it obtained were long-lived. The access paths were persistent. And the trust boundary it crossed existed more as an assumption than as an enforceable control.

That is the cloud-access problem StratoCloud was built to solve.

Zero standing privileges

StratoCloud issues ephemeral, just-in-time credentials for people, workloads, and AI agents. No long-lived keys remain in configuration files, repositories, or environments waiting to be exposed. When access expires, it is automatically removed.

Real-time, context-aware access

Every StratoCloud access decision incorporates live identity, security, and operational signals. Access is not granted simply because a user or workload is inside the network perimeter. It is granted only when the current context supports it: for the specific action, resource, and duration requested.

Continuous governance

Compliance cannot be a point-in-time exercise. StratoCloud continuously evaluates policies written in plain English or mapped to frameworks such as SOC 2, ISO 27001, PCI DSS, and CIS. When controls drift, teams can identify and respond to the issue immediately.

Audit readiness by default

Every credential issued, action performed, and policy decision evaluated is logged and streamed to your SIEM in real time. When an investigation or post-incident review begins, the evidence is already available.

The Hugging Face evaluation underscores an important reality: as AI agents become capable of acting autonomously across cloud environments, aggressive credential rotation is no longer sufficient.

Cloud access must be scoped, time-bound, context-aware, continuously governed, and observable by default.

Check us out at strato-cloud.io


r/Infosec 6d ago

A human attacker gained full control of ChatGPT's sandbox using a tapped link, a hidden line of code, and a shared backend that every account uses.

Thumbnail
4 Upvotes

r/Infosec 7d ago

Cybersecurity resume keywords

10 Upvotes

Keyword list taken from https://www.zoevera.com/resume/ats-resume-tips-cybersecurity

These are the most commonly scanned keywords in cybersecurity job postings. Check how many appear in your resume.

Domains & Practices

SOC (Security Operations Centre), Penetration testing / pen test, Vulnerability management, Threat intelligence, Incident response (IR), Digital forensics (DFIR), Red team / blue team / purple team, Zero Trust architecture

Tools & Platforms

SIEM (Splunk, Microsoft Sentinel, QRadar), EDR (CrowdStrike, SentinelOne), Nessus / Qualys / Rapid7, Burp Suite / Metasploit / Kali Linux, Wireshark / Snort / Suricata, CyberArk / BeyondTrust (PAM), SOAR platforms, Azure Defender / AWS Security Hub

Frameworks & Certifications

CISSP / CISM / CISA, CEH / OSCP / PNPT, CompTIA Security+ / CySA+, ISO 27001 / NIST CSF, MITRE ATT&CK framework, SC/DV security clearance, GDPR / DPA 2018, PCI DSS / HIPAA / SOC 2