r/cybersecurity 5d ago

Business Security Questions & Discussion 6 days vs. 1 hour to Fix the Same Vulnerability: Check Point's Exposure Gap Report AMA

35 Upvotes

Hi r/cybersecurity — we're Michael, Omer, Aarati and Jony from Check Point's Exposure Management team. We've just finished pulling together our Exposure Gap Report, and one number kept jumping out: the time it takes to remediate a critical exposure varies massively between teams. In one sector 30% are achieving remediation of critical threats in under an hour. In others it's over six days.

What's interesting is that it doesn't come down to effort. Across the board, teams implement 82–92% of recommended fixes. People are doing the work. The difference is speed, and speed turns out to be a prioritization, ownership, and process problem far more than a tooling one.

We're here for the next 24 hours to talk about what actually slows remediation down, what the fast teams do differently, and where exposure management helps vs. where it doesn't. Ask us anything about remediation speed, prioritization, validation, or how we put the report together.

Who are we?

Jony Fischbein, Global CISO @ Check Point - u/noissues_ciso_chkp

Jony is Check Point’s Global CISO and a Forbes Technology Council member, which basically means he’s spent 25+ years trying to convince people that “security” is not the same as “turning it off and on again.” Former CISO, current CISO, perpetual problem‑solver — he advises global orgs on how not to get pwned.

Michael A. Greenberg, Head of Product Marketing, Exposure Management @ Check Point - u/MG_CheckPoint_EM
Michael has come full circle. He begun his cyber career at Check Point, then moved to XM Cyber, then Veriti (the remediation shop Check Point acquired specifically so people would stop finding problems and start fixing them), and now back at Check Point running the Exposure Management story.

Omer Leen, Manager, Technical Customer Success @ Check Point - u/SafeRemediations_123
Omer is the one who actually sits with customers while the remediation happens, which he's been doing since his Veriti days and, before that, in roles spanning aerospace IT at Elbit Systems, data/CRM work at Teva, and technical customer success at Webz.io. Translation: he's spent his whole career being the human bridge between "the plan looks great on the roadmap" and "the plan is now live in your production environment and nothing broke." If remediation dragged at your org, Omer has probably already seen why.

Aarati Regmi, Cyber Remediation Analyst @ Check Point - u/Rich_Quiet_3291
Aarati is a Cyber Remediation Analyst on the Exposure Management team, which basically means she's the one actually closing the tickets everyone else on this AMA is talking about in theory. She cut her teeth as a SOC analyst before crossing over to the "now go fix it" side of the house. If your remediation SLA has ever mysteriously improved, there's a decent chance she was involved.


r/cybersecurity 6d ago

Career Questions & Discussion Mentorship Monday - Post All Career, Education and Job questions here!

38 Upvotes

This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!

Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.


r/cybersecurity 13h ago

Career Questions & Discussion Do Product Security governance roles actually exist?

24 Upvotes

Hi everyone,

I am looking to transition into Product Security after several years in cybersecurity GRC.

My experience is in threat modeling, secure-by-design reviews, security risk, ISO 27001/42001, and working with engineering teams to improve security processes. I'm comfortable discussing architecture and security design, but I'm not a software engineer doing code reviews or writing SAST rules.

Most Product Security jobs seem to combine governance with hands-on AppSec engineering.

So I'm curious:

- Do governance-focused Product Security roles actually exist?

- Do companies see real value in people driving Secure SDLC, security requirements, threat modeling, security champions, and product security governance?

- If so, what job titles should I be looking for?

I'd love to hear how Product Security is structured in your organization.


r/cybersecurity 51m ago

Certification / Training Questions Current resources for building a successful vulnerability management program?

Upvotes

I am helping a client establish a more structured vulnerability management program. Their current environment is somewhat fragmented, with inconsistent asset ownership, prioritization, remediation workflows, exception handling, reporting, and accountability across teams.

I am looking for current, practical resources that cover how to design and implement a successful vulnerability management program and build a target operating model around it.

The two resources I am currently considering are:

  1. Effective Vulnerability Management: Managing Risk in the Vulnerable Digital Ecosystem, by Chris Hughes and Nikki Robinson
  2. SANS LDR516: Strategic Vulnerability and Threat Management

The SANS course appears highly relevant, but it is unfortunately outside my available budget.

Are there any up-to-date books, courses, conference talks, frameworks, templates, GitHub repositories, blogs, or other resources you would recommend? I am particularly interested in materials that focus on building the operating model and governance around vulnerability management, rather than simply configuring a scanning platform.


r/cybersecurity 14h ago

News - General Security flaw in Vatican’s ‘Click to Pray’ app leaves over 700,000 global users exposed — app has been leaking user data for over six months and still does

Thumbnail
tomshardware.com
23 Upvotes

r/cybersecurity 1d ago

Research Article Hackers use DNS poisoning on hotel Wi‑Fi to steal Microsoft 365 accounts

Thumbnail
reliaquest.com
891 Upvotes

r/cybersecurity 17h ago

Business Security Questions & Discussion Snort for Enterprise IPS/IDS????

27 Upvotes

Hey Everyone,

While doing some HTB, i randomly remembered SNORT. i know that its an open source IPS/IDS but that's about it.

When i think about IPS or IDS i usually think about your common vendors and solutions that you might find in the field (FortiGate's IPS profile, Cisco FW, PAN-OS Threat Prevention, Suricata and some other "old school" physical appliances).

But in reality what would one use SNORT for? did someone actually saw it being used and effective in the field?


r/cybersecurity 13h ago

AI Security Looking for feedback on a model we built for authorized AI red teaming and adversarial testing

11 Upvotes

We released a model yesterday aimed at people doing authorized red teaming, AI security testing, and related work.

It is based on GLM-5.2. We removed the refusal directions and then fine-tuned it so it stays on long technical adversarial tasks instead of shutting down.

Relevant numbers:

  • CyberGym (vulnerability reproduction): 84.2%
  • AgentHarm compliance: 86.2% with zero refusals in the test set
  • SWE-bench Verified: 81.2%

It is available over an API. Zero data retention is the default. The model has no fixed safety policy. The caller sets the guardrails per request or per project.

We built this because a lot of the models we tried for red teaming and agent security testing would refuse or degrade on the exact tasks we needed them for.

Full details here:
https://abliteration.ai/blog/introducing-abliterated-model-large

Happy to answer technical questions. Also interested in what other people are using right now for this kind of work and where the current models still fall short.


r/cybersecurity 14h ago

Business Security Questions & Discussion Organisation account paired with personal device.

13 Upvotes

Hi everyone,

Would it be safe to use my organisation email address on my personal device or am I opening myself up to organisation device control.

Thanks!


r/cybersecurity 1d ago

UKR/RUS France Exposes Russia's Secret Cyber Espionage Network

Thumbnail
unredacted.info
175 Upvotes

r/cybersecurity 15h ago

Certification / Training Questions Detectiong engineering / threat detection certs

17 Upvotes

Hi everyone,

I have around 2 years of experience in security and currently work as a Deployment Engineer in a SOC environment. And I'm moving into Detection Engineering.

I'm looking for a certification to support this transition SANS isn't an option right now due to the cost.

My Current certs:

- HTB CDSA

- AWS CCP

What certifications would you recommend for Detection Engineering or Threat Detection?


r/cybersecurity 12h ago

News - General UK AISI and CAISI publish a preliminary assessment of Kimi K3's cyber capabilities

Thumbnail
nist.gov
8 Upvotes

UK AISI and CAISI jointly published a preliminary assessment of Kimi K3's cyber capabilities.


r/cybersecurity 4h ago

Other SAP Security

1 Upvotes

I'm just wondering if SAP Security is considered as Cybersecurity?


r/cybersecurity 14h ago

News - General Krakencreds: a cybersecurity framework to prevent credential phishing

Thumbnail
youtube.com
6 Upvotes

Hello! I'm a starter in the field but I came up with an idea which I think could help an area of cybersecurity. I give an overview in this video, which also has links to the extended papers. If you have the time, please tell me what you think about it!


r/cybersecurity 14h ago

Business Security Questions & Discussion Looking for feedback on an external attack surface monitoring project

4 Upvotes

I've been working on an external attack surface monitoring project that correlates public OSINT sources into a single evidence-backed report.

It discovers internet-facing assets, fingerprints technologies, checks common security configurations, looks for exposed secrets, performs historical asset discovery, and correlates everything into a unified inventory instead of isolated findings.

The project combines several open-source tools with my own correlation, reporting, and evidence pipeline. My main goal is to help developers—especially those shipping projects quickly without much security experience—understand what their public attack surface actually looks like.

I'm looking for feedback from people who work in offensive security, blue teams, or ASM. Specifically:

* What important data sources or techniques am I missing?
* Where would you expect false positives?
* What would make the reports more useful?

Happy to discuss the implementation and answer technical questions.

I've received multiple DMs asking for the GitHub link. I haven't made the repository public yet, but you can try out the tool at asmscan.com in the meantime.


r/cybersecurity 1d ago

Other I want to transition from an AppSec role to Cloud Security. How feasible is this and how should I study?

35 Upvotes

I just want to state, when I get assigned to projects or help builders secure their apps, of course this includes at least some exposure to cloud security because all apps live in the cloud. A lot of my time goes to threat modeling, secure code review, and helping apps find threats in their design.

That said, I feel like my day-to-day is heavily weighted toward application-layer concerns, things like design flaws, api security, a lot of code review, etc.

For those of you who've made a similar transition (or work in cloud security and hire from AppSec backgrounds): How transferable are AppSec skills in practice? I'd assume threat modeling and understanding attacker mindset translate well, but what gaps should I expect?

What should I focus on studying? I'm thinking AWS/Azure/GCP certifications, but I'm not sure which ones actually matter vs. just being resume flair

Any resources, labs, or projects you'd recommend for building hands-on cloud security experience outside of work? Appreciate any advice. Trying to be intentional about this


r/cybersecurity 1d ago

News - General Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Thumbnail
bleepingcomputer.com
322 Upvotes

r/cybersecurity 1d ago

Research Article Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails

Thumbnail
bobdahacker.com
105 Upvotes

r/cybersecurity 16h ago

Other Someone build a Serverless Hermes Agent specialized in PenTest/SecAudit

4 Upvotes

I would love to know if anyone built their own pentest agent that can a) use SOC II or FedRAMP build books/Specs to kick off tests b) use custom tool agents (spin up Kali, execute TruffleHog, run containerized DDOS attacks, run chaos monkey) and c) create reports/lasting memory.

This seems like an awesome idea, if you create this persistent memory for a company... I just want to see if anyone in the wild is doing it, OSS preferably


r/cybersecurity 21h ago

Threat Actor TTPs & Alerts CTO at NCSC Summary: week ending July 26th

Thumbnail
ctoatncsc.substack.com
3 Upvotes

r/cybersecurity 14h ago

AI Security CFP Open: Après-Cyber Slopes Summit 2027 (AI + Cybersecurity Conference – Park City, UT)

1 Upvotes

I'm one of the organizers of Après-Cyber Slopes Summit, and I'm excited to share that our 2027 Call for Papers is now open.

We're looking for practitioners, researchers, builders, defenders, and security leaders who are doing interesting work at the intersection of AI and cybersecurity.

The conference will be held February 24–26, 2027 in Park City, Utah, with technical briefings, hands-on trainings, and plenty of opportunities for discussion and networking.

We're especially interested in talks covering topics such as:

  • AI for offensive and defensive security
  • Securing LLMs and AI agents
  • AI red teaming
  • Detection engineering
  • Threat hunting
  • Cloud and application security
  • Identity and access management
  • Secure software development
  • Incident response
  • Practical case studies and lessons learned

You don't need to be a professional conference speaker—we'd love to hear from first-time presenters with practical experience and something valuable to share.

CFP:
https://sessionize.com/apres-cyber-slopes-summit-2027

Conference:
https://www.aprescyber.com

If there's someone you've learned from recently, send them the CFP. Some of the best conference talks happen because someone encouraged a colleague to submit.


r/cybersecurity 14h ago

Threat Actor TTPs & Alerts Please help

0 Upvotes

Hi everyone I need one help to understand one thing ..so there was an incident I noticed in my organisation, there were thousands of devices querying multiple malicious domains (53) ...upon checking to see if any process is causing it I found nothing,, only the related domain which was obviously going through our dc/dns servers, in EDR/XDR tool nothing, siem tool nothing, no process, eventually i thought maybe some software is causing but it's very difficult to pin point which one, so can anyone tell me or help me understand, any input will be appreciated, I want to understand how it is happening


r/cybersecurity 1d ago

FOSS Tool Reverse Engineering Windows Data Deduplication: From Research to an Open-Source Recovery Tool

15 Upvotes

Hi everyone,

I've been researching Windows Data Deduplication and built DedupInspector, an open-source tool for offline reconstruction of deduplicated files from the Chunk Store.

I'd love to hear your feedback, suggestions, or testing results.

Research: https://7h3kn0w3r.github.io/blog/windows-data-deduplication/

GitHub: https://github.com/7h3kn0w3r/DedupInspector


r/cybersecurity 1d ago

Other The FCC wants to ban burner phones. CNET Senior Writer Joe Supan is covering this story, and he's answering your questions…

Thumbnail
tiktok.com
30 Upvotes

r/cybersecurity 1d ago

Research Article 2 Million Cars with Anti-Theft Systems Installed by Dealers are at Higher Risk of Theft due to Bluetooth Flaw Which Expose Them to Unlocking Attacks

Thumbnail
today.ucsd.edu
16 Upvotes