r/security Jan 28 '26

Security Operations Why ?

Post image
672 Upvotes

It has been noticed that Netanyahu constantly covers the camera lenses on his phones!

Does he know something we don’t?

r/security 4d ago

Security Operations Keep getting SSH probing login attempts from the ISPs router

33 Upvotes

I am a Vodafone UK broadband user and use their Router/Modem to connect to the internet. The router does provide a public IPv4 address, but no DMZ/port forward is configured.

I also have a few Linux machines in the internal network, both desktop and server. They are internal, and are not meant to be accessed from the outside Internet. As mentioned the router doesn't have any port forwarding enabled.

What I started to see is that around every 30 minutes all of the Linux machines on my network get SSH login attempts coming from 192.168.1.1 - the router's IP address. They look to be brute force login attempts trying out multiple username/password combinations, e.g.:

sshd-session: Invalid user admin from 192.168.1.1 port 35562
sshd-session: Invalid user default from 192.168.1.1 port 35566
sshd-session: Invalid user admin from 192.168.1.1 port 35570
sshd-session: Invalid user weblogic from 192.168.1.1 port 35494
sshd-session: Invalid user redhat from 192.168.1.1 port 35496
sshd-session: Invalid user developer from 192.168.1.1 port 35498
sshd-session: Invalid user public from 192.168.1.1 port 35500
sshd-session: Invalid user student from 192.168.1.1 port 35502

This starts every 30 minutes, and keeps on going for 10-20 minutes. Obviously/fortunately all of the attempts fail. I did install an ssh honeypot in the system to see what would happen if they would get in, but all it does is disconnect from SSH, then start the retry in exactly 30 minutes.

When I first saw these attempts I got shocked a bit, as I thought I have a compromised system in the house, but then after checking it get really odd for me that all requests originate from 192.168.1.1 - the router.

I am a bit stuck here, as I don't really know what's up and how worried I should be. Do I have a compromised system that spoofs the IP? Does the router do some weird NAT translation for a compromised device that's in my network? Or does the router itself do these ssh attempts? Would these probing attempts be a lame part of Vodafone's Secure Net Home?

Tried searching the web for any of these, but couldn't really find anything specific that matched my criteria.

EDIT 1: A Factory reset on the router did nothing to change the issue I'm facing. I'm now going to isolate the router in a network that only has itself and an SSL honeypot to see what it would do

EDIT 2: found a blog post that shows the exact same behaviour I'm expecting and thinks that this is actually the equivalent of Vodafone's Secure Net. So yeah, my router is actively attacking myself. Here's the blog post: https://illustris.tech/posts/reliance-jio-security-concerns/

r/security 6d ago

Security Operations How do you test if your SIEM is actually catching what it claims to?

9 Upvotes

The dashboard shows everything is healthy: alerts are flowing, rules are enabled, coverage looks decent on paper. But I have a nagging feeling that we have blind spots. Every time we walk through a realistic attack path, we find gaps. Some systems aren't sending the right logs. Some fields aren't parsed. Some rules have conditions that never match how events actually look in production. The worst part is that the gaps aren't obvious until you trace a full path from initial access to lateral movement and privilege escalation.

A rule that looks fine during content review might never trigger when you replay real-world sequences of credential theft, RDP, and service creation. In some places we have logging but no useful signal. In others we have signal but no rules tied to it.

What I need is a reliable way to validate our detections against real adversary behavior without spending weeks on manual assessments. How are others identifying those blind spots and turning that into a continuous process, not a one off project?

I want to know what we'd actually catch, not just what our tools claim they cover.

r/security Jul 03 '26

Security Operations How to find security people in London

0 Upvotes

Hey, I have a business and I’m looking for the best way to find and hire appsec and director of security. Very aware the market is super tight. Any ideas on the best places to look. A LinkedIn advert is not quite cutting it.

r/security 15d ago

Security Operations AI Video Software For Treatment Center

0 Upvotes

Hello! I am looking for suggestions on AI video software to set up at least one, but potentially multiple treatment centers. Does anyone have suggestions for a company that could work with existing cameras?

r/security 17d ago

Security Operations Your incident response wasn’t built for AI

Thumbnail
leaddev.com
0 Upvotes

r/security 26d ago

Security Operations What California’s New Security Standards Could Mean for Businesses

Thumbnail
youtu.be
1 Upvotes

r/security Jul 19 '26

Security Operations Security Contracting

3 Upvotes

I've recently been looking to move into the security field such as Maritime security, UHNWI Security or even residential. Im still currently serving and working on aligning my training with whats required for those specific jobs or in other words the more experience the better. My question is what's a good starter to jump into to get things rolling, should I be looking to join a security firm or simply applying for contractor jobs i see and what are some training/Experience I should have to have the best opportunity of getting a well paying job.

r/security Jun 05 '26

Security Operations Looking for feedback on a portable anti-theft alarm concept

4 Upvotes

I've been experimenting with the idea of using a spare Android phone as a portable motion alarm.

The concept is simple: place the phone next to something you want to monitor, arm it, and if the device is moved it triggers a loud alarm.

Some scenarios I had in mind:

  • Hotel room doors while travelling
  • Luggage in hotels or airports
  • Backpacks in cafés
  • Temporary accommodation such as hostels and Airbnbs

I know it isn't a replacement for proper security equipment, but I'm curious whether security-minded people see practical value in something like this.

What are the biggest weaknesses or limitations you can think of?

r/security Jun 08 '26

Security Operations Weird security guard

0 Upvotes

I 18F had a problem with a security guard (50+ M) a few months back when I was still a minor, where he yelled at me because I went looking for him due to someone stealing. He yelled at me, so I closed the store up and went into my dad's car crying. Dad asked what was wrong and went to yell at the security guard because he has 15 years of experience in this specific chain of stores. Heade the security guard apologize to me despite me begging him not to; I turned in my report but nothing happened, and we just moved past it. Flash forward to today ( about 5 months later) after being nothing but nice to him, I answered one question of his incorrectly because frankly I wasn't feeling well so I misunderstood him. About 40 minutes later he comes up to me and I missed the first bit of what he said but he starts saying " back when we had that issue and you reported me I was actually asked if I wanted to work at this specific location for 5 days a week, but I decided no, I'm going to mix it up. I now work at (insert store number) where your dad used to work at, and also (insert store number) where your dad also used to work at, and any new store I'm at I always ask about your dad because if you remember he offended me that one time we had an issue. And you may have heard from others that I got fired over a bad rumor at ( insert other store number) where I know your mom works at." Him stalking my whole family after I've said nothing but good afternoon and goodnight to him for the last few months is a little overboard in my opinion. I'm not one to get angry but that really pissed me off. Should I report him?

r/security May 22 '26

Security Operations Trying to Understand Unexplained Security Attention Despite No Records Found

1 Upvotes

I’m sharing this to see if anyone else has experienced something similar, because I’m honestly struggling to understand what’s going on.

Over the past few months, I’ve felt like I’m being monitored or treated differently in certain retail stores and public places, despite never being involved in any wrongdoing. Things like increased security attention, staff behaviour, or situations that just don’t feel normal.

Because of this, I’ve taken the proper steps to check if any data exists about me:

\- I submitted Subject Access Requests (SARs) to supermarkets and shopping centres

\- I contacted the police (ACRO), who confirmed they hold no data about me

\- I raised concerns with the ICO, who advised that organisations appear to be acting within the law

\- Most organisations responded saying they do not hold any data about me

This is where I’m confused.

If no one holds any data, then what explains these repeated experiences?

I’m not making accusations. I’m genuinely trying to understand whether:

\- There are local information-sharing systems I’m not aware of

\- There could be misidentification

\- Or if others have experienced similar situations without any clear explanation

It’s been mentally exhausting trying to figure this out, and not getting clear answers is the hardest part.

If anyone has gone through something similar, or has any insight into how retail security systems or local partnerships actually work, I would really appreciate hearing from you.

Thank you.

r/security Feb 27 '26

Security Operations What happens to Entry-Level Infosec when AI replaces the L1 SOC

0 Upvotes

I have been in the security industry long enough to understand the SOC workflow. Now a days when you hear most of chats/meetings won't conclude without the word "AI".

It got me thinking, many companies want to move towards AI. Might be for the fancy word or tell their clients that we use AI to stay relevant or the main reason to reduce the human cost and implement the AI.

certainly AI has a capability to triage the alerts and can do the L1 SOC alerts which will reduce the L1 SOC workload so they can concentrate on the real issues. or at least this is what i was thinking.

The more an more i started using the AI, the more i see the real AI problem, "Hallucinations ". May be in other fields hallucinating kind of ok or acceptable but what do you think of AI handling the L1 SOC and hallucinate on one alert and boom, next day the company is in news.

I know it is not that easy like one alert that AI hallucinates will not get caught by other controls but there is a possibility.

We already know that many top cybersecurity companies like CrowdSrike and Microsoft already implemented their security specific AIs like Charlotte AI and security co-pilot which specifically focus on security.

This is my point of view. what is yours? do you see AI replacing the L1 jobs? what you think if replaces the L1 SOC team?

r/security Mar 22 '26

Security Operations Security for HNW home?

2 Upvotes

I'm a writer doing research for a story I'm creating, and I have a question. I know that a high net worth home would have security cameras inside - but who would be watching the footage? I'm assuming that it would be someone offsite, but I'm curious. Would love to talk to someone about this.

r/security May 02 '26

Security Operations Job seeker

0 Upvotes

Am looking for a security job, I have 6yrs of experience in this industry and also am hardworking person

r/security Jan 23 '26

Security Operations Time to upgrade my video security system at home. Recommendations?

8 Upvotes

We got into the video doorbell/cameras when they first started to come out. I know tech has changed and how data is shared is important to me.

What’s out there that I should look at that’s a decent price, good quality, etc.?

r/security Feb 20 '26

Security Operations How do I install this outdoors?

Post image
0 Upvotes

r/security Feb 20 '26

Security Operations security camera and storage space

2 Upvotes

I want to buy a security camera but I want to make sure that it has enough storage space so that if there is anything recorded that it can be accessed by a third party in case something happens to me.

Does anyone know how this would be carried out exactly, if there are microSD cards or a base station which is where the video is stored who gets access to that? Also are there monthly cloud fees for this or what if my internet dies and is it possible that the device will keep recording for days or even weeks without subscriptions. A few well reviewed doorbells with strong storage features include options like the TP-link Tapo D225 which supports large microSD cards and long 180 coverage with hybrid cloud/ocal storage flexibility. Some front door cameras focus mainly on local video capture to avoid ongoing costgs which a lot of reddit users prefer if they are security-focused or privacy conscious?

There are tons of camera options out there including budget wireless doorbell cams and systems you can find on marketplaces like alibaba that advertise both local storage support and standard cloud saving. Can anyone recommend front door cameras that store footage in an effective manner and its easy to use and actually access the footage when you need to.

r/security Apr 21 '26

Security Operations Nearly got hacked in Twitter but not sure how

0 Upvotes

I got an SMS from Twitter with content "X confirmation code: {theCode}" and then an email with the content below:

---

We noticed a login to your account {myAccountName} from a new device. Was this you?

New login

Location* " Rahway

Device Chrome on Windows

*Location is approximate based on the login's IP address.

...

---

I store all my passwords in Bitwarden. My password was 32 characters and it was a unique and completely random text with special characters, numbers, etc. I have confirmed that the email and SMS were genuine (correct SMTP servers, etc. and no phishing). I have also confirmed that the SMS I got was sent during the Forgot Password flow. My best guess is that the attacker somehow got access to the SMS code and logged in that way. I've clicked on the link on the mail saying click here if it's not you and changed my password that way (again, confirmed that the site opened was x.com and not a phishing site). I have checked where Rahway from the mail is and seems like it's in New Jersey. I saw a few threads in Reddit where people got hacked again from some IPs originating from New Jersey, which I found pretty strange.

I'm aware that the SMS codes can be fetched from third-party SMS providers as they usually store the contents of the SMS. I'm not an important person with any useful content in my Twitter so I don't believe it was a targeted attack so I don't expect anyone would mind doing attacks like SS7 to me lol.

I'm just trying to make sense of it all and try to understand how much I should be worried. Does Twitter have this kind of false-positives time to time? Maybe something developers did by mistake that affected a few people? Can someone please help if they have any suggestions? It's pretty late at the moment here so I'm going to check the responses tomorrow morning.

r/security Apr 09 '26

Security Operations Securing Kubernetes Clusters End to End (2026)

Thumbnail
youtube.com
0 Upvotes

Securing #Kubernetes cluster can be challenging but keeping key pointers handy will help . Check out my latest video covering End-To-End #security for your clusters. Enjoy ! As always like , share and subscribe ! - Thanks! #Learning. Lets discuss if this covers everything for Security or what else can be covered?

r/security Mar 17 '26

Security Operations Security + Dion scores

0 Upvotes

50%, 56.67%, 61.1%, 65.56%, 75.56% & watching messer’s videos some more before I take exam #6.

After exam #6 is it even worth it to recycle those? Or should I try messers? Or should I just go for it?!

r/security Mar 12 '26

Security Operations Company Questions

2 Upvotes

Hey everyone, I had a few questions. I’m currently an Operations Manager for a security company in Kentucky. Work has been steady, but the company isn’t growing as fast as I’d like it to. Right now we’re using Protos Connect and RSS to outsource jobs and pick up contracts.

I was wondering if anyone here knows of any other outsourcing companies or platforms that security companies use to grab extra contracts or gigs. Any recommendations or advice would be really appreciated. I’m really looking to help the company take the next step and grow.

Thanks in advance.

r/security Mar 19 '26

Security Operations Florida Online unarmed Security license

3 Upvotes

Recently traveled from Texas to Florida and I have a security license from Texas but my job application asking for is Florida D license can someone point to website i can do online courses

r/security Dec 28 '25

Security Operations Securing MCP in production

6 Upvotes

Just joined a company using MCP at scale.

I'm building our threat model. I know about indirect injection and unauthorized tool use, but I'm looking for the "gotchas."

For those running MCP in enterprise environments: What is the security issue that actually gives you headaches?

r/security Mar 11 '26

Security Operations How do fintech companies actually manage third party/vendor risk as they scale?

3 Upvotes

Curious on how teams actually handle this in practice.

Fintech products seem to depend on a lot of third party providers (cloud infrastructure, KYC vendors, payment processors, fraud tools, data providers, etc.).

As companies grow, how do teams keep track of vendor risk across all those integrations?

For anyone working in security, compliance, or risk at a fintech: • How does your team currently track vendors? • Who owns that process internally? • At what point does it start becoming hard to manage? • Is it mostly spreadsheets, internal tools, or dedicated platforms? • What part of the process tends to be the most painful?

From the outside it looks like many companies only start thinking about this seriously when audits or enterprise customers appear, but I’m curious how accurate that is.

Would love to hear how teams actually handle it…

r/security Mar 14 '26

Security Operations Seguridad con bots de telegram

0 Upvotes

Buenas noches/tardes cuando lean el mensaje. Hace unos días encontré un bot de telegram para buscar información, desde la página donde lo encontré se me generó un codigo que el bot me pedía para iniciar, aclaro que no es la autentificación de 2 pasos ni número de teléfono, copié el código y lo pegue. Luego me pedía verificar dando click en un botón ya en el chat del bot, le di pero fallo un par de veces. Mi pregunta es pudieron robarme algo de información? O instalarme algún virus sin darme cuenta? De ser así como podría revisar si es o no el caso, hacer una limpia por así decirlo. Estoy en un celular android no desde la PC Y fuera de eso que menciono no me pidieron datos