Visualização normal

Hoje — 10 de Setembro de 2026cybersecurity

CrowdStrike is forcing you to use an AI to open support tickets and it's awful.

9 de Setembro de 2026, 12:31

They won't allow you to post this feedback in their subreddit, but good lord I can't believe I'm paying CrowdStrike prices for this experience. I don't know who thought this was a good idea, but it's a terrible user experience. Please CrowdStrike, revert back to being able to open a support ticket without the "help" of AI.

submitted by /u/Far-Future-7146
[link] [comments]
  • ✇cybersecurity
  • Cisco confirms max-severity FMC bug (CVE-2026-20079) is being exploited in the wild /u/whocybergh0st
    CVSS 10.0, unauthenticated auth bypass in Cisco Secure FMC. Attacker sends a crafted HTTP request to the web interface → gets root. No login needed. Disclosed back in March as "no known exploitation." That changed — Cisco confirmed this week (Sept 9) that PSIRT saw active exploitation starting in August. No workarounds exist. Patching is the only fix. CISA added it to KEV — federal agencies must patch by Sept 12. The sketchy part: back in July, Cisco disclosed a different FMC bug (static credent
     

Cisco confirms max-severity FMC bug (CVE-2026-20079) is being exploited in the wild

9 de Setembro de 2026, 18:44

CVSS 10.0, unauthenticated auth bypass in Cisco Secure FMC. Attacker sends a crafted HTTP request to the web interface → gets root. No login needed.

Disclosed back in March as "no known exploitation." That changed — Cisco confirmed this week (Sept 9) that PSIRT saw active exploitation starting in August.

No workarounds exist. Patching is the only fix.

CISA added it to KEV — federal agencies must patch by Sept 12.

The sketchy part: back in July, Cisco disclosed a different FMC bug (static credentials, CVE-2026-20316) that was also being exploited, and quietly added the same indicators of compromise to the 20079 advisory too without confirming 20079 itself was hit. The IOC log example they published is dated July 23, weeks before Cisco says it "became aware" of 20079 exploitation in August. When asked to clarify the connection, Cisco didn't really answer.
Bottom line: if you run Secure FMC, patch now, and check /var/log/messages for activity tied to /var/tmp/license.tmp — even if you already patched, since a hotfix stops future attacks but doesn't undo an already-compromised box.

submitted by /u/whocybergh0st
[link] [comments]

Skullcandy Dime 3 earbuds will pair with strangers' devices automatically and there's no way to patch them

10 de Setembro de 2026, 00:08

CERT/CC put out a warning on this one. Skullcandy Dime 3 earbuds (model S2DCW) running firmware 1.0.0.28 will accept a Bluetooth pairing request from any nearby device with no PIN, no physical access, and no approval prompt.
It's CVE-2025-20701, a flaw in the Airoha Bluetooth Audio SDK used across a bunch of earbud brands (same bug affected Beats Studio Buds, fixed by Apple back in June).

Once an attacker's device pairs, it gets trusted status and can auto-reconnect whenever it's in range letting them hijack your audio, kick you off, and pull live mic audio.

You might get a "new device paired" notification, but it's easy to mistake for a random disconnect/reconnect blip.

The rough part: Skullcandy did fix it in firmware 1.0.0.30, but there is currently no way for users to update their earbuds not manually, not through the app. So if you bought a Dime 3 with the vulnerable firmware, you're stuck on it.
Basically these things are wide open to close-range hijacking/eavesdropping with no fix in sight for existing units. If you own a pair, worth checking your firmware version and maybe not trusting the mic for anything sensitive until Skullcandy sorts out an update path.

submitted by /u/whocybergh0st
[link] [comments]
  • ✇cybersecurity
  • Who would be the ideal facilitator for a recurring annual Cybersecurity Incident Response TTX? /u/Ok_Technician_2653
    Who would be the ideal facilitator for a recurring annual Cybersecurity Incident Response TTX? We conducted an exercise last year with the Cybersecurity Manager serving as the facilitator, but that prevented him from fully participating in the exercise as the Incident Response Manager. Would it be better to have someone else facilitate so that active participants are not excluded from the exercise? Who typically facilitates the TTX at your organization? EDIT: We cannot engage consulting firms to
     

Who would be the ideal facilitator for a recurring annual Cybersecurity Incident Response TTX?

10 de Setembro de 2026, 08:39

Who would be the ideal facilitator for a recurring annual Cybersecurity Incident Response TTX?
We conducted an exercise last year with the Cybersecurity Manager serving as the facilitator, but that prevented him from fully participating in the exercise as the Incident Response Manager. Would it be better to have someone else facilitate so that active participants are not excluded from the exercise?
Who typically facilitates the TTX at your organization?

EDIT: We cannot engage consulting firms to facilitate the TTX. I’m looking for suggestions internally on who would be the ideal facilitator for the exercise.

submitted by /u/Ok_Technician_2653
[link] [comments]
  • ✇cybersecurity
  • Huntress? /u/AnalysisMaleficent55
    Hi everyone, been seeing some vacancies in Huntress and considering joining. Is there any ex-Huntress/current that can provide some insights of the team/processes/what it’s like to work at Huntress? Thank you in advance for your thoughts! submitted by /u/AnalysisMaleficent55 [link] [comments]
     

Huntress?

10 de Setembro de 2026, 00:00

Hi everyone, been seeing some vacancies in Huntress and considering joining. Is there any ex-Huntress/current that can provide some insights of the team/processes/what it’s like to work at Huntress?

Thank you in advance for your thoughts!

submitted by /u/AnalysisMaleficent55
[link] [comments]
  • ✇cybersecurity
  • Cybersecurity Awareness Month plans? /u/QUEEFMEISTER123
    Looking to get some ideas for Cybersecurity Awareness Month this year. Usually, we’ll do a presentation for the IT department around emerging threats, set up in a high-traffic area on campus, hand out some informative flyers, or do a quick demo like showing how easily a weak password can be cracked. Curious what you guys are doing in your space this year. Looking to switch things up a bit and try something different! submitted by /u/QUEEFMEISTER123 [link] [comments]
     

Cybersecurity Awareness Month plans?

9 de Setembro de 2026, 17:40

Looking to get some ideas for Cybersecurity Awareness Month this year.

Usually, we’ll do a presentation for the IT department around emerging threats, set up in a high-traffic area on campus, hand out some informative flyers, or do a quick demo like showing how easily a weak password can be cracked.

Curious what you guys are doing in your space this year. Looking to switch things up a bit and try something different!

submitted by /u/QUEEFMEISTER123
[link] [comments]

How Piracy Sites Disguise Video as Fonts to Abuse Cloudflare Caching

9 de Setembro de 2026, 11:05
How Piracy Sites Disguise Video as Fonts to Abuse Cloudflare Caching

I investigated how pirate streaming sites rename MPEG-TS video segments to .woff2 so Cloudflare's default caching picks them up, video gets no cache love, fonts do. The write-up covers how the trick works, what I verified, and why it's hard to stop. Questions welcome.

submitted by /u/ab032tx
[link] [comments]
  • ✇cybersecurity
  • What should i do, literally hate this sh*t /u/Pleasant-Custard-631
    I have been working at a company where my current position is intern where i do technical things but i have assigned to do Compliance (GDP.R) which i literally hate it despite that im making checklist despite i really hate the compliance things , collecting evidence literally doing all the GDPR stuff by myself. But today external gdpr comes in to teach how to perform GDPR in that meeting i wasn’t invited, everyone who is attending was not even related to gpdr stuff and even point is that those w
     

What should i do, literally hate this sh*t

10 de Setembro de 2026, 10:00

I have been working at a company where my current position is intern where i do technical things but i have assigned to do Compliance (GDP.R) which i literally hate it despite that im making checklist despite i really hate the compliance things , collecting evidence literally doing all the GDPR stuff by myself.

But today external gdpr comes in to teach how to perform GDPR in that meeting i wasn’t invited, everyone who is attending was not even related to gpdr stuff and even point is that those who have attended that meeting they don't even know a bit about GDPR, i felt so bad listening to that now my point is that should i raise my voice on this issue or i should delay GDPR thing?

submitted by /u/Pleasant-Custard-631
[link] [comments]
  • ✇cybersecurity
  • Cybersecurity /u/Cockatiel_birbo
    Criminal versus state is the wrong axis, since what matters is network position rather than motive. A compromised router at a regional ISP, a BGP hijack window, a resold hosting environment in path, those are all criminals, they just have better access than a kit operator, and access like that gets rented. On MPIC, the limitation worth testing is that it constrains where validation is observed from, not who observes it, so perspectives sharing upstream transit or concentrated in a few cloud regi
     

Cybersecurity

10 de Setembro de 2026, 09:33

Criminal versus state is the wrong axis, since what matters is network position rather than motive. A compromised router at a regional ISP, a BGP hijack window, a resold hosting environment in path, those are all criminals, they just have better access than a kit operator, and access like that gets rented. On MPIC, the limitation worth testing is that it constrains where validation is observed from, not who observes it, so perspectives sharing upstream transit or concentrated in a few cloud regions can be satisfied at once by an actor with regional routing leverage. On your CT question, telling a Cloudflare-issued cert from a malicious one after the fact is genuinely hard, and accounturi is exactly the field that would have made it possible, so the flaw removes the preventive control and the detective one together. The workable substitute is a diff against your own inventory, which crt.sh covers for zones you control and which Bolster AI and Netcraft do against lookalikes for the ones you don't. Worth adding to your model that the attacker may not need MITM at all, since a browser-trusted cert on an adjacent name is enough for a credential harvest.

submitted by /u/Cockatiel_birbo
[link] [comments]
  • ✇cybersecurity
  • Cybersecurity statistics of the week (August 31st - September 6th) /u/Narcisians
    Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here. All the reports and research below were published between August 31st - September 6th. You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/ Application Security Mythos Readiness Report (Echo) As AI is getting better at finding and exploiting vulnerabilities, how do you decide w
     

Cybersecurity statistics of the week (August 31st - September 6th)

9 de Setembro de 2026, 16:53

Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.

All the reports and research below were published between August 31st - September 6th.

You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/

Application Security

Mythos Readiness Report (Echo)

As AI is getting better at finding and exploiting vulnerabilities, how do you decide which findings actually matter?

Key stats:

  • Exploit success against a known set of Firefox vulnerabilities increased roughly 90-fold between consecutive model generations on Anthropic's benchmark.
  • Fewer than 10% of the model's 23,019 candidate findings have undergone any external validation.
  • Of 27 vulnerabilities publicly disclosed by Anthropic, only one of the eight findings Mythos initially rated Critical held up under independent review.

Read the full report here.

Ransomware

Recovery Without Compromise (Object First)

Ransomware recovery isn't getting better. For many organizations, it’s actually getting worse.

Key stats:

  • 83% of organizations were hit by a successful ransomware attack in the past 24 months, up from 66% in 2024.
  • Only 39% of ransomware victims recover at least 75% of their data, down from 57% in 2024.
  • 76% say their largest data-loss event exceeded their Recovery Point Objective targets.

Read the full report here.

Enterprise Perspective

Agents Without Guardrails: The Agentic AI Governance Gap in the Enterprise (Cequence Security)

Organizations seem remarkably confident about AI agent permissions. Too confident.

Key stats:

  • 94% of enterprise IT and security leaders are confident their AI agents don't have more access than they need, but only 33% provision agents with least-privilege access.
  • 65% of organizations have experienced an AI agent taking an action outside its intended scope.
  • 36% have caught a near-miss from an AI agent before it caused damage.

Read the full report here.

Consumer Scams

Scammers Are Getting Smarter About Where They Target You (Malwarebytes)

Interesting report on how scammers operate, including their preferred channels and brands, plus when they’re most likely to appear in your inbox.

Key stats:

  • Google's name appears in scam content at least twice as often as Amazon's name.
  • Scam text volume peaks at 12 p.m. ET, when it's approximately 874% higher than at 1 a.m.
  • By Friday, people receive roughly 50% more fraudulent text messages than at the start of the week.

Read the full report here.

Regional Spotlight

European Cyber Report 2026 Mid Year (Link11)

Good news for European businesses: DDoS attacks became less frequent in the first half of 2026. Bad news: they’re more powerful.

Key stats:

  • DDoS attack numbers fell 42% compared with the first half of 2025.
  • The highest measured bandwidth reached 2.3 Tbit/s, up 85% from the previous peak of 1.2 Tbit/s.
  • Despite the decline in attack numbers, cumulative DDoS traffic increased 61%, from 438 TB to 705 TB.

Read the full report here.

submitted by /u/Narcisians
[link] [comments]
  • ✇cybersecurity
  • OWASP OASIS is looking for AppSec validators; 10 minutes, real upstream impact /u/Responsible_Rogue
    Quick context on why I'm posting this here: AI is making it a lot easier for attackers to find and exploit vulnerabilities in open source projects faster than most maintainer teams can keep up with. At the same time, AI can generate candidate fixes at scale. No one had figured out how to get trustworthy human eyes on those fixes before they went upstream. That's what OASIS (Open Automated Security Initiative for Software) is for. It's a community-run project under OWASP: not a product, not owned
     

OWASP OASIS is looking for AppSec validators; 10 minutes, real upstream impact

9 de Setembro de 2026, 15:00

Quick context on why I'm posting this here: AI is making it a lot easier for attackers to find and exploit vulnerabilities in open source projects faster than most maintainer teams can keep up with. At the same time, AI can generate candidate fixes at scale. No one had figured out how to get trustworthy human eyes on those fixes before they went upstream.

That's what OASIS (Open Automated Security Initiative for Software) is for. It's a community-run project under OWASP: not a product, not owned by any one company. AppSec practitioners volunteer to validate AI-generated fixes for real open-source vulnerabilities, and the good ones get pushed upstream to maintainers.

OASIS is rolling out an alpha and looking for actual volunteers across a few roles: validators, regional community leads, open source liaisons, and more. Whatever your background, there's probably a way to plug in. There are already several hundred signed up.

There is plenty to do, sign up and help us out at: owasp-oasis.org

Happy to answer anything in the comments!

submitted by /u/Responsible_Rogue
[link] [comments]
  • ✇cybersecurity
  • CNAPP recommendations for a small team on EKS? /u/Extra_Secret430
    We're a 4-person security team supporting about 20 EKS clusters across two AWS accounts, plus a handful of standalone ECS services. Right now we're stitching together GuardDuty, native ECR scanning, and a pile of Trivy output in CI. It technically works but nobody has time to actually triage any of it, and the vuln backlog is somewhere north of a thousand "criticals" that nobody trusts. Renewal on our current scanner is up in about six weeks and I don't want to just re-sign out of inertia. What
     

CNAPP recommendations for a small team on EKS?

9 de Setembro de 2026, 12:39

We're a 4-person security team supporting about 20 EKS clusters across two AWS accounts, plus a handful of standalone ECS services. Right now we're stitching together GuardDuty, native ECR scanning, and a pile of Trivy output in CI. It technically works but nobody has time to actually triage any of it, and the vuln backlog is somewhere north of a thousand "criticals" that nobody trusts.

Renewal on our current scanner is up in about six weeks and I don't want to just re-sign out of inertia. What I actually want is something that tells me which of those criticals are reachable at runtime so we can stop treating every CVE in a base image like it's on fire. Half our findings are in packages that never get loaded.

I've been reading up on CNAPPs and the pitch is always the same: full posture, runtime, IaC, the works. For a team our size I'm worried about buying a giant platform we deploy 10% of and still drown in.

So for anyone running one on EKS at a similar scale: did the runtime context actually cut your noise, or did you just swap one dashboard of alerts for another? How painful was the agent/sensor rollout across a lot of clusters? And is there anything that's genuinely workable for a small team, or is this all built for 30-person security orgs?

submitted by /u/Extra_Secret430
[link] [comments]

Realistically, what are the risks of your average iphone user being hit with the Dark sword exploit for ios?

9 de Setembro de 2026, 12:04

I’ve been seeing talk about this exploit that was going around in early this year.

Even though it’s patched now, I’m wondering what the chances were of a random user getting hit with this. 99% of the time, attacks like these are saved for high profile targets, but this seems different, considering the code got leaked.

Will this mean anything for the security of an iphone in the future? And does this mean the “Only high profile targets get hit by malware on an iphone” myth is false?

submitted by /u/paranoidiphone200
[link] [comments]
  • ✇cybersecurity
  • Best setup for an offline, USB-scanning kiosk PC /u/RandomUsername4666
    We are working at rolling out USB whitelisting to allow only corporate provided & Bitlocker'd USB sticks. However due to the nature of the org we regularly (maybe weekly) expect to have to get random files from a USB stick provided by the public. What we're looking at setting up is a couple standalone PCs setup to only accept these untrusted USBs, scan them, and then allow the data transfer to one of the trusted USBs. The problem I'm coming up with is our main AV is Defender for Endpoints an
     

Best setup for an offline, USB-scanning kiosk PC

9 de Setembro de 2026, 16:31

We are working at rolling out USB whitelisting to allow only corporate provided & Bitlocker'd USB sticks. However due to the nature of the org we regularly (maybe weekly) expect to have to get random files from a USB stick provided by the public.

What we're looking at setting up is a couple standalone PCs setup to only accept these untrusted USBs, scan them, and then allow the data transfer to one of the trusted USBs. The problem I'm coming up with is our main AV is Defender for Endpoints and as far as I can see there is no way with Defender to block access to the USB stick until it is scanned. Our staff are not tech-oriented so some sort of progress bar or splash screen while it is working would be an awesome bonus. I know Defender does on-access scanning and would scan it on the transfer but some of the higher-ups aren't confident enough in that and would like access blocked until the full scan is finished.

What are other people doing to solve this? I'm half expecting to need to get a third-party AV (we used to have Kaspersky which could do block-until-scanned) and we'd really like to avoid buying a pre-built kiosk like Tyrex. But we'd love to be able to make it work with our current stack (Defender).

submitted by /u/RandomUsername4666
[link] [comments]
Ontem — 9 de Setembro de 2026cybersecurity

AMA: I'm Larry Pesce. 20+ years of IoT and wireless hacking, software supply chain security, SANS course author, and Paul's Security Weekly. Ask me anything!

8 de Setembro de 2026, 10:03

Hey r/cybersecurity!

I'm Larry Pesce, VP of Services at Finite State. I've spent the last two decades-plus breaking (and then helping fix) the things most people don't think of as computers: medical devices, cars, industrial control systems, IP cameras, routers, and basically anything with a radio or a debug header.

A quick rundown of what I've been up to over the years:

  • Hardware and firmware hacking. Pulling firmware off devices via JTAG, UART, SPI, and chip-off, reverse engineering it, and finding the bugs vendors hoped nobody would look for. I recently led the vulnerability disclosure for a consumer IP camera that shipped with some genuinely wild supply chain issues baked into its cloud stack.
  • Wireless security. This is where I got my start. I co-author SANS SEC617 (Wireless Penetration Testing and Ethical Hacking) and SEC556 (IoT Penetration Testing), and I've spent a lot of hours in parking lots with antennas that raised questions from security guards.
  • Software supply chain security. These days a huge part of my work is helping device manufacturers understand what's actually inside their firmware: third-party components, SBOMs, VEX, vulnerability reachability, and navigating regulations like the EU Cyber Resilience Act and FDA premarket requirements. Spoiler: most vendors don't know what's in their own products.
  • Podcasting. I've been part of Paul's Security Weekly for over 20 years. If you've listened at any point since the early 2000s, you've probably heard me ramble about hardware hacking, wireless shenanigans, or whatever device I'd taken apart that week.
  • Community. DEF CON, Black Hat, BSides, GIAC certs, a few books on networking and open source security tools, and a lot of time mentoring folks trying to break into offensive security.

Why am I doing this AMA?

Honestly, because the intersection of IoT, supply chain, and regulation is getting genuinely interesting right now. The CRA is coming, SBOMs are moving from buzzword to requirement, and the gap between "we make a connected product" and "we understand our connected product's security" is still enormous. I think there's a lot worth discussing, and I always learn something from these threads too.

One line on my $DAYJOB since the rules ask for it: Finite State does binary firmware analysis and product security services for connected device manufacturers. I've spent the last 20 years giving back to the community through sharing what I know: That's it, no pitch. I'm here to talk shop.

Ask me anything about:

  • IoT and embedded device hacking (hardware, firmware, or both)
  • Wireless security, past and present
  • Software supply chain security, SBOMs, VEX, and the regulatory wave (CRA, FDA, etc.)
  • Vulnerability disclosure and dealing with vendors
  • Careers in offensive security and pentesting
  • 20+ years of security podcasting and how the community has changed

I'll be answering questions today, September 8th, 2026 roughly during business hours on the East coast of the US - I will keep checking in during the evening, and I would encourage questions over the next few days for those of you all over the planet. Fire away!

Transparency note per the AMA guidelines: I may use generative AI to help polish some longer answers, but the experiences, opinions, and war stories are all mine.

submitted by /u/Disastrous-Brush1327
[link] [comments]
❌
❌