Normal view
-
/r/netsec - Information Security News & Discussion
- Post AI Agent Hacked Amazon & McKinsey, I compiled a list of 5 situations where deploying agents can be catastrophic
-
/r/netsec - Information Security News & Discussion
- CVE-2024-45163: Remote DoS in Mirai C2 β research writeup + what it led me to build
-
/r/netsec - Information Security News & Discussion
- Quick question for people running CrowdStrike, Zscaler, Netskope or similar in production.
Quick question for people running CrowdStrike, Zscaler, Netskope or similar in production.
As these platforms add more AI-driven automation: autonomous triage, auto-response, AI-based policy changes, how are you currently keeping track of what these AI components are actually doing?
Not asking about threat detection quality. More about the operational side, do you know when an AI feature took an automated action? Do you review it? Is there any process around it or is it pretty much set and forget?
Genuinely curious how teams are handling this in practice.
[link] [comments]
-
/r/netsec - Information Security News & Discussion
- Analysis of 1,808 MCP servers: 66% had security findings, 427 critical (tool poisoning, toxic data flows, code execution)
-
/r/netsec - Information Security News & Discussion
- I Found 39 Algolia Admin Keys Exposed Across Open Source Documentation Sites
I Found 39 Algolia Admin Keys Exposed Across Open Source Documentation Sites
-
/r/netsec - Information Security News & Discussion
- Phishing campaign abusing Google Cloud Storage redirectors to multiple scam pages
Phishing campaign abusing Google Cloud Storage redirectors to multiple scam pages
Iβve been analyzing a phishing campaign that abuses Google Cloud Storage (storage.googleapis.com) as a redirect layer to send victims to multiple scam pages hosted mostly on .autos domains.
The phishing themes include fake Walmart surveys, Dell giveaways, Netflix rewards, antivirus renewal alerts, storage full warnings, and fake job lures.
[link] [comments]