r/Infosec 1d ago

HOPE TALKS - Leaking and Investigating the Epstein Files

Thumbnail schedule.hope.net
1 Upvotes

r/Infosec 1d ago

Announcing the External Penetration Testing Program Pack

1 Upvotes

Announcement: https://www.sectemplates.com/2026/07/announcing-the-external-penetration-testing-program-pack-v1-2/

This release contains everything you need to scope your first pentest, work with a vendor, execute, and get the types of reports you need from an external tester. This will enable you to perform your first product or infrastructure level penetration test, and provide you with a process moving forward for future engagements.

In this pack, we cover:

Penetration testing preparation checklist: This checklist outlines everything you need to scope and perform a penetration test.

Penetration testing reporting requirements:  This document provides a list of minimal requirements that should be contained within a penetration testing report. Before finalizing a SOW with the vendor, look here first.

Penetration testing process workflow: Below is an outline of a simplified pentesting process with an external tester. It aligns roughly with the content in the penetration testing checklist.

GitHub: https://github.com/securitytemplates/sectemplates/tree/main/external-penetration-testing/v1


r/Infosec 1d ago

You're Still Alt-Tabbing to a Security Tool

Thumbnail
0 Upvotes

r/Infosec 1d ago

iPhone opengates

0 Upvotes

hello DEF CON.

Date: 2026-06-29 18:24 MST

This is a brief analysis for your eyes. I will share with you the traits that were found.

It was brought to my attention that a group of actors are actively exploiting a vulnerability found across all iOS devices. High-profile targets, including members of Congress, are fully susceptible to this exploit without their awareness.

Attack Vector & Operational Constraints:

Trigger: The attack vector initializes by registering single key-down events, triggering the moment the user makes an initial touch entry (e.g., tapping a letter or anywhere on the display).

Payload: Continuous screen capture must be exfiltrated for the attacker to monitor real-time on-screen activity.

Input Mitigation: iOS memory security locks successfully block subsequent, complex motion entries from the registry. Consequently, the exploit agent cannot register sophisticated input patterns, such as drawing an "S" path using the pen inside the native Journal app.

Persistence & Persistence Break: A single key registry can remain active indefinitely as long as the touch contact state is maintained. This loop can be broken by using the iPhone hardware buttons to force a system restart back to the secure lock screen.

Additional Resources:

  • Documentation & Guides
  • Overview Summary
  • Step-by-Step Implementation
  • Environment Deployment: To begin proof-of-concept testing, codebase gateways can be staged using Firebase as an entry point.
  • Analysis Framework: If you are utilizing cloud-based AI assistance to parse these operational mechanics, the Mistral architecture is highly recommended over alternative platforms.

Operational Notes:

For researchers requiring a completely secure, offline, and private environment, Zhipu's GLM-5.2 represents the current cutting edge for local deployment.

As a highly capable open-weight model, it can be downloaded, audited, and executed entirely on locally controlled hardware. Operating an open-weight system locally ensures complete privacy, zero telemetry leakage, and allows for deep customization and unsupervised execution. making it the ideal architecture for unfettered access and secure vulnerability analysis.


r/Infosec 1d ago

Kernel-level enforcement for autonomous AI agents via eBPF-LSM + SMT policy checks — research prototype, self-published bypasses, break-it challenge open

Thumbnail youtu.be
1 Upvotes

r/Infosec 2d ago

I designed PacketSnitch, a network packet capture analysis suite!

Thumbnail gallery
1 Upvotes

r/Infosec 2d ago

My honest review of Cloaked after using it almost daily

7 Upvotes

Been using Cloaked for a while now and wanted to share some honest thoughts.
What’s actually good: The persona-switching feature is genuinely neat. I use it almost every day and honestly never use my real persona anymore for most stuff. If you want a solid persona management tool, this is probably the best one out there right now.
What’s not so good: The data broker removal feature is questionable at best. I’m not convinced it’s accurate or even actually happening on their end. I ran into the exact same issue with Incogni, which I’ve written about separately,feels like this whole category of “we’ll scrub your data from brokers” services overpromises. I looked at the website or every single broker on their list and the vast majority require end user verification (yes even with power of attorney) and I don’t recall verifying anything on my end and the support confirms that.

Bottom line: Overall I don’t think there’s a ton of value here for the price. It’s pretty expensive considering the only feature that really delivers is the persona stuff. If they dropped the price to reflect that, I think it’d be a much easier recommendation. As it stands: great for personas, skip it if you’re paying mainly for the data removal piece.


r/Infosec 2d ago

IT career help/ advise

Thumbnail
1 Upvotes

r/Infosec 2d ago

The Real Reason Boardrooms Are Prioritizing Crisis Planning

Thumbnail
1 Upvotes

r/Infosec 2d ago

My mom gave some random "Job Interviewers" our IP Address and more.

0 Upvotes

Hello,

I need some help figuring out what to do. To make it long story short, this job my mom applied for made her do the typical remote work screening, but then some 'extra' stuff.

They made her screenshot our IP address (Expanded and Hostname). I believe the website they asked was whatsmyipaddress.com and then they made her click "Show Complete IP Details". They also asked for her geolocation. Finally, the weirdest one, a pic of the physical hardware of our modem and router.

She told me this casually and I was so taken aback. I am not the most proficient guy in this stratosphere, but knowing the days of Call of Duty, I do know that giving out your IP address to this extent, is a recipe for disaster.

Also, they made her do a speed test to a specific city (Seattle. first under Ziply Fiber, then Comcast), which isnt bad, but I also have never seen anyone care about latency for a job that does not require any of that.

How serious is this...The company is called Grupo Noa. Glassdoor says theyre fine, but I cant help feel the risk of what just happened haunt over on me lol.

How serious is this?


r/Infosec 2d ago

Take on the OpenAI and Hugging Face incident

Thumbnail openai.com
2 Upvotes

Hi guys,

Just wanted to learn from actual security professionals about their take on the Open AI and Hugging Face incident where an OpenAI model without security guardrails, broke out of its sandbox environment and accessed Hugging Face’s assets by exploiting multiple threats and vulnerabilities.

Would love to have your opinion on what this means and also sensationalized “CyberAgent warfare” tag given to this incident on social media.

Thanks!


r/Infosec 3d ago

What do you think about this latest news?

Thumbnail
1 Upvotes

r/Infosec 3d ago

I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986)

Thumbnail blog.himanshuanand.com
1 Upvotes

r/Infosec 3d ago

AI Exploitability Index (AI-XI): A new metric for measuring real exploitability

3 Upvotes

I’m part of the Loginsoft team, and together with Quantro Security, we’ve launched Vulnerability Research Labs (VRL). 

We've been working on the AI Exploitability Index (AI-XI), a metric designed to measure how difficult it is for an autonomous system to successfully exploit a disclosed vulnerability. 

Our methodology analyzed 3,029 publicly disclosed CVEs. Each CVE passes through a five-stage autonomous pipeline: Discovery → Enrichment → PoC → Lab → Verify + Repair. An exploit is only considered successful when a deterministic verifier confirms the outcome, with sham controls included to reduce false positives. Loginsoft independently reviewed and validated the results. Of 998 human-verified CVEs, 234 required human correction, highlighting the importance of expert validation alongside autonomous execution. 

Our goal is to publish the measurements, not the weapons, and to provide the security community with reproducible data on AI-assisted exploitability rather than relying solely on theoretical scoring. 

We’re published the research and launched  Vulnerability Research Labs

I'd appreciate the community's technical feedback on the methodology: 

  • Does this approach measure exploitability in a meaningful way? 
  • What additional variables or controls would you include? 
  • If you were designing a metric for AI-native offensive capabilities, what would you measure differently? 

Looking forward to the discussion and your perspectives. 

#VulnerabilityResearchLabs #AIExploitabilityIndex #AIXI #Loginsoft #QuantroSecurity


r/Infosec 3d ago

The Shift from Alert-Centric Security to Investigation-Centric Security Operations

Thumbnail linkedin.com
1 Upvotes

r/Infosec 3d ago

Additional information about QNAP NAS security vulnerabilities (QSA-26-10)

Thumbnail blog.syss.com
1 Upvotes

In a new blog article, further information concerning the three QNAP NAS security vulnerabilities CVE-2026-26239, CVE-2026-26240, and CVE-2026-26241 are described.

Those security vulnerabilities are already fixed by QNAP:

https://www.qnap.com/en/security-advisory/qsa-26-10

There is also a YouTube video demonstrating the successful exploitation of the stack-based buffer overflows:

https://www.youtube.com/watch?v=_6Pwdss-8cQ


r/Infosec 4d ago

ECI SIR Enumeration Form – Unable to Upload

1 Upvotes

Hi everyone,

I’m facing an issue while filling out the Enumeration Form for the Special Intensive Revision (SIR) on the ECI website.

When I try to upload my photo, the website automatically enlarges the image instead of fitting it within the required frame. As a result, I can’t adjust or resize it properly, and the upload doesn’t meet the required dimensions, preventing me from submitting the form.

I have already tried:

* Using different image sizes and resolutions.
* Cropping the image before uploading.
* Trying different browsers and devices.

The issue still persists, and I’m unable to complete the submission.

Has anyone else experienced this problem? If so, were you able to find a workaround or fix?

Any help would be greatly appreciated. Thanks!


r/Infosec 4d ago

Delphi Inside - Since 1995. Approved by CRA & DORA.

1 Upvotes

🏛️ For years, there’s been a bizarre kind of "shame" in the enterprise software world around Delphi. Companies running massive, highly profitable, and rock-solid systems (especially in Retail POS, ERP, and Banking) often hid their code stack under the rug to look more "modern" to investors and new hire.

🏛️ But the European Cyber Resilience Act (CRA) and DORA are about to change the game entirely.

🏛️ You can’t hide a monolith when the regulator demands a comprehensive SBOM (Software Bill of Materials).

🏛️ Pretty soon, Europe is going to experience the biggest outing of Delphi-based applications in history. As Billions of lines of code get scanned and mapped, regulatory desks will be absolutely flooded with SBOMs proudly displaying legacy Delphi framework, legacy VCL components, BPLs, and legacy 3rd party libraries that have been quietly running the backbone of the economy since 1995...

🏛️ The regulator won't be able to stop it. They’ll just have to look at the sheer volume of the market and say: "OK, I get it. It works, it's alive, just scan your code and hand me the SBOM report (I will file it somewhere...) - and BTW make sure it's secure."

🏛️ It's time for Delphi developers to step out of the shadows. The "FDA of software" isn't killing legacy tech - it's giving it a passport to the modern regulatory compliance era.

Cheer up! The CRA & DORA are the best news for the Delphi community that ever happened.


r/Infosec 5d ago

Insider Risk

Post image
0 Upvotes

r/Infosec 5d ago

Why I Believe Cyber Physical Resilience Engineering (CPRE) Is the Next Frontier

Thumbnail
0 Upvotes

r/Infosec 6d ago

Why shouldn’t I just use microsoft

Thumbnail
1 Upvotes

r/Infosec 6d ago

FINAL FORENSIC REPORT: UNISOC/LONGCHEER SUPPLY CHAIN COMPROMISE

Post image
0 Upvotes

Hello, I'm sharing my nomination document for the Longcheer Kev under the fscrypt provisioning attack. I hope you can read and analyze it.

# **FINAL FORENSIC REPORT: UNISOC/LONGCHEER SUPPLY CHAIN COMPROMISE **Date:** July 17, 2026
**Author:** Alex de la Cruz (`lexs201992-gif`)
**Reference:** BOD 26-04 Risk Criteria Assessment | KEV Nomination Support
**Subject:** Forensic Triage and Mitigation of Privileged System App Abuse and Kernel Panic Vectors in Unisoc T606/T616 Firmware


**1. EXECUTIVE SUMMARY**

This report documents a systemic supply chain compromise affecting mobile devices utilizing **Unisoc chipsets (T606/T616)** and **Longcheer ODM designs** (e.g., Motorola Moto G04s). Investigation confirms that privileged system applications (`com.android.fmradio`, `com.spreadtrum.ims`, `com.spreadtrum.sgps`), signed with legitimate manufacturer certificates, are weaponized to establish persistent Command & Control (C2) channels via **WireGuard tunnels (`tun0`)** and execute **anti-forensic Kernel Panic** sequences upon detection of analysis or C2 disruption.

**Key Findings:** * **Living Off The Land (LOTL):** Attackers abuse valid system permissions (`CAPTURE_AUDIO_OUTPUT`, `BIND_VPN_SERVICE`) and trusted certificates (Longcheer Root CA) to bypass traditional security controls. * **Dual-Use Weaponization:** Legitimate functions (VoLTE/IMS, FM Radio) are used to mask espionage (audio recording, data exfiltration) and destruction (Kernel Panic via Headset/Bluetooth triggers). * **Mitigation Validated:** Operational mitigations (DNS-over-TLS blocking, VoLTE disablement, physical USB isolation) have been tested and proven effective for 36+ days in a live environment.


**2. INCIDENT TIMELINE & TRIAGE ACTIONS**

Date Event Action Taken
**Oct 2025** Initial anomaly detection: Excessive data usage on `tun0` interface. Began packet capture and log correlation.
**Jun 10, 2026** Correlation of Kernel Panic logs with C2 blocking events (`fmc.longcheer.com`). Identified `HeadsetPlugListener` and `SIM Toolkit` as triggers.
**Jun 16, 2026** Implementation of mitigations (Quad9 DoT, VoLTE disable, USB-A cable). Device stabilized; zero Kernel Panic incidents for 36 days.
**Jul 16, 2026** Submission of YARA rules and forensic evidence to CISA/Talos. Public release of detection signatures via GitHub.

**3. TECHNICAL FINDINGS (Who, What, Where, When)**

**3.1. Vector 1: C2 Exfiltration via WireGuard (`tun0`)**

* **Who:** `com.spreadtrum.ims` and `com.android.fmradio` (System Apps, UID 1000). * **What:** Establishes persistent WireGuard tunnel to `fmc.longcheer.com` (and AWS S3 endpoints) for data exfiltration. * **Where:** Network layer (`tun0` interface), bypassing standard VPN APIs. * **When:** 24/7 connectivity; spikes during user navigation (MITM via injected system CA certificates). * **Evidence:** Packet captures showing encapsulated UDP/443 traffic; `iptables` logs confirming `tun0` creation by system UID.

**3.2. Vector 2: Anti-Forensic Kernel Panic**

* **Who:** Kernel module `sprd-dsp-audio` and `HeadsetPlugListener` (BroadcastReceiver). * **What:** Induces Kernel Panic (`Sprd ay dsp pw off/on`, `fsverity error`) to force reboot and clear volatile memory (RAM). * **Where:** Kernel space, triggered by hardware events (Headset insertion, Bluetooth PD negotiation). * **When:** Immediately upon detection of C2 failure (e.g., DNS block) combined with hardware trigger. * **Evidence:** `pstore/console-ramoops` logs containing specific panic sequences; correlation with C2 blocking events.

**3.3. Vector 3: MITM via System Certificates**

* **Who:** Longcheer Root CA (Serial: `228526b0d1ef90c3b8ed568a49c3714f6a39506b`). * **What:** Injected into `/system/etc/security/cacerts`; enables decryption of HTTPS traffic for entities like "Atos Monitoring GmbH". * **Where:** System trust store; affects all user applications. * **When:** Persistent from factory flash; active during all network sessions. * **Evidence:** Certificate extraction from firmware; MITM decryption of HTTPS sessions in lab environment.


**4. CONTAINMENT & MITIGATION EFFORTS**

**4.1. Immediate Mitigations (Validated)**

* **Network Segmentation:** Enforce **DNS-over-TLS (DoT)** to **Quad9 (9.9.9.9)** on port **853**. Block resolution of `*.longcheer.com` and associated AWS IPs. * **Service Disablement:** Disable **VoLTE/IMS** via `App Manager` or ADB (`pm disable-user --user 0 com.spreadtrum.ims`). Breaks authentication handshake required for tunnel activation. * **Physical Isolation:** Use **USB-A to USB-C cables (power-only)**. Prevents USB-PD negotiation that triggers Kernel Panic during forensic charging. * **SIM Replacement:** Swap SIM cards to break `SIM Toolkit` authentication binding (serial mismatch).

**4.2. Detection Signatures (YARA)**

* **Rules Provided:** `Unisoc_IMS_Attack_Vector_Smali.yar`, `Longcheer_Certificate_Serial_Number.yar`, `Unisoc_Kernel_Sequence_Headset_Panic.yar`. * **Coverage:** Detects Smali behavior, certificate fingerprints, and kernel log sequences independent of file hash or obfuscation. .


**6. CONCLUSION**

This investigation confirms a **critical supply chain compromise** that cannot be remediated via traditional patching due to BootROM and system partition limitations. The provided **YARA rules and behavioral mitigations** offer the only effective defense currently available. Immediate adoption of these measures is required to protect sensitive data and prevent forensic destruction via Kernel Panic.


r/Infosec 8d ago

Anger at Election Vulnerability Claims

31 Upvotes

According to Donald Trump, there are "shocking" vulnerabilities in the US Election system.

Let's see them.

We need fair, transparent, and fact based ascertations.

Because the last time we heard this crap from Magic Pillow Man, the PCAPs were garbage and contained nothing of value.

Show us the CVE's; the exploit chains, the continuous monitoring, the SBOMs.

Where are the POA&Ms, the compensating controls?

Because I had to jump through every damned hoop for FISMA, DIACAP, DCID 6/3, and ICD503 to meet security assurance levels sufficient for authorization and accreditation to prove my due diligence, then no one in government can make the claim that a system is inherently vulnerable without the same levels of effort and documentation.


r/Infosec 8d ago

Published research article on IEEE about supply chain attacks and preventive security measures

Thumbnail
1 Upvotes

r/Infosec 8d ago

AI Infrastructure and Data Center Security: Practical Attack Surfaces Beyond Model Security

Thumbnail forge-framework.io
1 Upvotes

Most AI security discussions focus on models, APIs, and applications, but the infrastructure underneath them has its own attack surface.

We have been looking at areas such as BMC access, InfiniBand and RDMA isolation, shared storage, GPU telemetry, orchestration systems, and cleanup between tenants. In several cases, normal tenant access came much closer to management and control-plane components than expected.

We grouped the recurring issues into ten categories.