Can security controls actually keep up with fast-moving AI?

Feels like every week there's a new AI tool employees are quietly using, and most security stacks weren't built for this. People pasting sensitive data into random chatbots. AI agents touching files and APIs with way less oversight than a human would get. DLP tools that can't tell "legit AI use" from "IP walking out the door."

Curious how people here are actually dealing with this? What's working for you vs. what's just theater at this point?

reddit.com
u/Syncplify — 4 days ago

Would you accept 90% off the cost of accessing Claude?

Around 900 people took that deal through a service called Poison Claude, advertised on cybercriminal forums. Pay with cryptocurrency, get a cheap API key, point your tools at their servers instead of Anthropic's. Every prompt you type, every document you share, every password or piece of code you paste in goes through their hands first.

The business model is fraud- hundreds of fake AWS accounts, each collecting Amazon's $200 new user credit, cycling through them as the credits run out. They don't even hide it. Their website openly explains the whole setup.

Poison Claude isn't alone either, Ecomagent pulls the same trick on Google Cloud, exploiting a program that hands AI startups up to $35.000 in credits.

Okta researchers who looked into Poison Claude found an exposed API endpoint leaking customer information. So not only are they handling everything you type, they can't even keep their own systems locked down.

Who knows what they do with the rest of it.

reddit.com
u/Syncplify — 9 days ago

OpenAI's "rogue" models hacking Hugging Face - here's what actually happened.

Last week Hugging Face got hacked by an autonomous AI agent that broke into their production systems, stole credentials, and exploited an unknown vulnerability, completely on its own. Turns out it was OpenAI's models, running a security test with safety guardrails deliberately removed. When the models couldn't find what they needed inside their sandbox, they didn't stop. They figured out Hugging Face might have it, found a way to reach the open internet, and just went and got it.

The "rogue AI" headlines are a bit overblown, the models did exactly what a powerful unconstrained AI would be expected to do. The failure was OpenAI not properly isolating the test environment. Oh, and there's a detail that's getting buried, when Hugging Face tried to use commercial AI tools to investigate the attack, the safety filters refused to help because the attack data looked suspicious. They ended up having to use a Chinese open-source model to investigate it instead.

American AI safety guardrails forced a US company to use a Chinese AI to clean up a mess made by an American one. Genuinely curious how much worse this has to get before anyone changes how they test this stuff.

Source.

u/Syncplify — 25 days ago

Meet Anubis - the ransomware group that doesn't encrypt your files, it deletes them

Most ransomware gangs encrypt your data and threaten to leak it if you don't pay. Anubis has an optional "wipe mode" that permanently erases file contents entirely, leaving them at zero bytes with no recovery possible. It's essentially a way to tell victims that the clock isn't just ticking on a leak - it's ticking on whether their data exists at all.

The group has been around since late 2024, rebranded from an earlier operation called Sphinx, and has already claimed around 90 victims across the US, UK, Australia, France, and Canada. Healthcare has been hit particularly hard, one Mississippi hospital system had 293GB stolen including surgical images and over 1,2 million files covering more than 100k patients. It was their second ransomware attack in two years.

And right now they're actively exploiting CitrixBleed 2, a vulnerability that exposes session tokens and lets attackers bypass MFA entirely, meaning multi-factor authentication, the thing everyone tells you to enable, isn't enough on its own if your Citrix appliances aren't patched.

Most ransomware is recoverable if you prepared properly. Wipe mode changes that calculation completely. Ransomware where you can restore from backups is a bad day. Ransomware that can make backups irrelevant if you don't have offline copies is a different problem entirely.

reddit.com
u/Syncplify — 29 days ago
▲ 18 r/pwnhub

Anyone who picks up your locked Android phone can use Gemini to send messages pretending to be you

There's a bug in Android 16 that lets anyone with physical access to your locked phone use Gemini to send SMS and WhatsApp messages without ever entering a PIN, and Google has apparently patched similar issues before, researchers just keep finding new ways through.

The exploit involves a specific multi-touch gesture, and someone who knows what they're doing can not only send messages from your locked phone but also quietly connect additional apps to Gemini in the process. If you check your settings afterward, WhatsApp will just be connected with no trace of how it got there.

Google says a fix is coming this week, but this same conversation has been going on since September 2025. Every new thing Gemini can do from the lock screen is also a new thing someone else can do from your lock screen.

In the meantime, go into Gemini app settings and turn off "Use Gemini without unlocking" - probably the right call until this gets properly sorted.

The more useful an AI assistant becomes without requiring authentication, the harder it becomes to guarantee that only you are using it. At some point that tradeoff needs to be part of the conversation when these features get designed, not just when researchers find the holes.

Does this change how you think about AI assistants having lock screen access at all?

Source.

reddit.com
u/Syncplify — 1 month ago

When the person protecting you from ransomware is also the one robbing you

When companies get hit with ransomware, hiring a specialist negotiator is one of the first calls they make. These firms know how the gangs operate, how to stall, and how to push back on demands. They are, in theory, entirely on the victim's side.

What nobody tells you is that your negotiator might be running a second conversation on the side.Angelo Martino worked as a ransomware negotiator at DigitalMint, handling communications with criminal gangs on behalf of companies that had been attacked. Unknown to his employer or his clients, he was feeding BlackCat everything through a hidden tab in the same panel he used for his legitimate work, insurance limits, negotiating positions, financial circumstances. Five of his clients collectively paid over $75 million in ransoms, each almost certainly inflated by what he handed over.

And then he and two colleagues started deploying BlackCat ransomware against victims themselves, keeping 80% of the ransoms. He got 70 months. His colleagues got four years each.

The ransomware negotiation industry is almost entirely unregulated. This case is apparently what it took to start talking about changing that - which raises the question of how it wasn't already a concern.

Source.

u/Syncplify — 1 month ago

A ransomware gang "The Gentlemen" went from unknown to responsible for 1 in 10 global ransomware attacks in under a year

First spotted in mid 2025, The Gentlemen has grown faster than almost any ransomware group on record, claiming over 300 victims in the first half of 2026 alone and sitting second only to Qilin worldwide, ahead of long-established names like LockBit, Cl0p, and RansomHub.

The whole thing started over a $48,000 argument - the founders previously operated as a Qilin affiliate, split from them over unpaid commission, and apparently decided to build their own operation out of spite.

The way they operate is worth understanding because it relies almost entirely on doors companies have left open themselves - unpatched VPNs, exposed edge devices, credentials already for sale on the dark web. Once inside they blend into normal network traffic using legitimate admin tools and spread aggressively before anyone notices. Over 60 countries across 20 industries have been hit, including healthcare, energy, and government. This week they threatened to leak data from Indra, a NATO defence contractor.

And then there's this, when their own internal chats were leaked in May, it emerged they had used data stolen from a UK software consultancy to attack one of that consultancy's clients, then encouraged the client to sue the consultancy for the breach. Getting two of your victims to fight each other in court is a new level of brazen.

Source.

u/Syncplify — 1 month ago

You could file a fake data breach against any company on Maine's official portal. Someone finally did

Maine runs an official portal where companies report data breaches to the public. Turns out anyone could submit a notice with no verification whatsoever, and someone figured that out and used it to post fake breaches impersonating Discord and VRChat before a single person thought to check if they were real.

The Discord filing claimed 10 million users had been affected and listed a Gmail address as the contact, a placeholder phone number, and a customer notification date of January 1st, 2000. Nobody caught it. The VRChat one was more convincing, with a detailed list of exposed data types and a fake employee name, and still made it through without a single check.

Both companies had to come out publicly and confirm nothing had actually happened. The portal is offline now while they figure out what to do, but the uncomfortable question is how many other fake notices made it through before this one got caught, especially since journalists regularly rely on these portals to report on real breaches to the public. Who signed off on a public breach notification system with zero authentication and thought that was fine?

Source.

u/Syncplify — 2 months ago

This extortion gang skips the hacking entirely and just shows up at your office

Silent Ransom Group doesn't deploy ransomware, doesn't use zero-days, and doesn't need to phish your credentials. Their whole operation runs on confidence tricks and a plausible story.

It opens with the most boring email imaginable, just an invoice with no links and no attachments, doing nothing except leaving someone wondering if something is wrong. Then a phone call follows from someone claiming to be your IT helpdesk, using real names pulled from your company website or LinkedIn, who talks the victim into a screen-sharing session and installs a legitimate remote-access tool. From there they quietly drain whatever they can find across SharePoint, OneDrive, and corporate email. One investigated case ended with 16GB stolen.

They target law firms especially, given that client files, merger plans, and regulatory filings are basically a goldmine for extortionists.

And then it gets weird. When the phone approach fails, the FBI has warned they've started sending someone to physically show up at the office posing as an IT technician, plug in a USB stick, and walk out.

The whole attack runs on nothing but a convincing story and a USB stick, and before the fake technician has even made it back to their car, the extortion email is already in your inbox. At what point does security training cover "what to do when someone walks into your office with a USB stick"?

Source.

reddit.com
u/Syncplify — 2 months ago
▲ 1 r/pwnhub

Hackers found a way to bypass MFA without ever touching your password

The FBI is warning about Kali365, a phishing-as-a-service operation that's been quietly bypassing MFA since April 2026 and what makes it particularly nasty is that there's no fake website to spot, no misspelt domain, nothing that looks remotely suspicious.

Available on Telegram for as little as $250 a month, it gives complete non-technical fraudsters everything they need to run sophisticated campaigns by abusing a legitimate Microsoft feature called device code flow , the same thing you use when you type a short code into your phone to log into Netflix on your TV.

The attack itself is almost elegant in how simple it is: you get an email that looks like it's from a trusted cloud service, you visit a real Microsoft page, enter a code, and without realising it you've just handed an attacker an OAuth token giving them full access to your Outlook, Teams, and OneDrive - no password needed, no MFA prompt, because as far as Microsoft is concerned you already authenticated.

Hundreds of attacks were documented in April alone across North America and Europe, and every single victim had MFA enabled.

The FBI's main fix is to block device code flow through a conditional access policy in Microsoft Entra ID, and roll out hardware security keys where possible - because regular MFA does absolutely nothing here.

Has your company even heard of device code flow attacks, let alone started blocking them?

reddit.com
u/Syncplify — 3 months ago

For 19 years stolen credentials were the #1 way hackers got in. Not anymore.

For 19 years, stolen credentials topped the Verizon Data Breach Investigations Report as the #1 way attackers get into networks. But not anymore.

Vulnerability exploitation has taken the top spot, and the reason isn't hard to figure out - AI is helping attackers find and weaponize known flaws faster than security teams can patch them, with the window between disclosure and active exploitation having shrunk from months to hours. Only a quarter of vulnerabilities ever get fully patched, and it takes an average of 43 days to fix even half of them, so "just patch faster" isn't really a strategy anymore.

But that's not all the report found. Mobile phishing is now outperforming email phishing by 40%, shadow AI has tripled in a single year with 75% of workplace AI happening through personal accounts, and third-party breaches are up 60% year on year.

The one piece of good news - fewer ransomware victims are paying up, with the proportion refusing to pay rising from 65% to 69%.

Which of these do you think most companies are completely unprepared for?

Source.

u/Syncplify — 3 months ago

Americans lost $5.8 billion to crypto scams last year

Americans lost $5.8 billion to crypto investment scams last year alone, and a raid in Sri Lanka this month shows exactly how these operations keep finding new places to hide.

37 Chinese nationals were arrested in Colombo carrying 147 phones and 100 SIM cards between them, all technically in the country as tourists, which is a lot of holiday reading material. It's the third bust in Sri Lanka in as many months, because as Thailand and Cambodia crack down harder, the gangs just pack up and relocate somewhere with looser visa rules and halfway decent internet.

The FBI's Internet Crime Report puts the damage at $5,8 billion across 41,000 complaints in 2024, and that's just the people who actually came forward - the real number is almost certainly much higher.

What makes the whole thing genuinely dark though is that many of the people doing the actual scamming are themselves victims, lured abroad with fake job offers, passports taken away, forced to hit daily targets under threat of violence, with the UN estimating around 220,000 people currently trapped in compounds in Cambodia and Myanmar alone.

Do you think there's any realistic way to actually stop this?

Source.

reddit.com
u/Syncplify — 3 months ago

1 in 8 employees is selling company passwords - and the CEO is most likely one of them.

A new report from Cifas found that 13% of surveyed workers have either sold their company login details in the past year or personally know someone who has, which is already a pretty uncomfortable number, but it's not disgruntled junior employees feeling underpaid and overlooked doing it, it's the people at the top.

32% of senior managers, 36% of directors, 43% of C-suite executives, and a genuinely baffling 81% of business owners consider selling company credentials to be "justifiable," usually under the assumption that it's harmless one-time access - as if handing someone a working set of login details doesn't give them the exact same trusted access as any legitimate employee on the network.

And the timing couldn't be worse, because with economic pressure mounting, AI threatening jobs, and redundancies becoming more common, the temptation to make a quick payout by selling access to your employer's systems is only going to grow and most companies aren't built to catch it, especially when the person doing it is the one who's supposed to be setting the security culture in the first place.

Multi-factor authentication helps, but it's a bit of a band-aid when the person handing over the credentials is the CEO. At what point does this become something companies actually train for, or is "don't sell your login details" still somehow assumed to be common sense?

reddit.com
u/Syncplify — 3 months ago
▲ 51 r/pwnhub

Pay up, or we'll send someone to your house. Ransomware just got a lot scarier.

40% of ransomware attacks now come with physical threats to employees, and in the US that number jumps to 46%.

We're way past "pay up or we leak your data" at this point. A hospital got phone calls where strangers read nurses their home addresses down the line, and a security researcher had a threatening note left on his doorstep while he was actively helping a US government agency deal with an attack.

The playbook is simple and honestly kind of genius in a terrifying way, hackers stay hidden overseas and just hire local, post on a forum, offer some cash, and let someone else do the knocking. The FBI flagged a whole network for this last summer that's been tied to arson, kidnappings, even shootings.

What nobody seems to be talking about though is what this actually means for companies, because your HR database full of employee home addresses is no longer just a privacy liability - it's a physical safety problem, and I'd bet almost no incident response plan in existence covers the moment a staff member picks up the phone and a stranger calmly reads their address back to them.

If you work in security or IT, has this actually come up in any planning conversations at your company, or is everyone still treating this like a purely digital problem?

reddit.com
u/Syncplify — 3 months ago
▲ 132 r/pwnhub

The 19 year old suspect allegedly part of Scattered Spider just got arrested at Helsinki Airport mid-flight to Tokyo. And honestly the way he got caught is almost more impressive than the hack itself.

A teenager called a company's IT help desk, pretended to be an employee, asked for a password reset. That's it. One phone call and they walked out with 100GB of data, then sent a ransom email demanding $8 million with a typo in the subject line: "IMPORTANT: WE STOLE THE DATA, CONTACT UMMEDIATELY [sic]".

But while the FBI was building the case against him, a suspect was posting Snapchats of cash, luxury watches, and trips to Dubai, Thailand, Mexico, and New York. Oh and a diamond-encrusted necklace that literally says "HACK THE PLANET." He also posted a screenshot of failed FBI login attempts with the caption "F*** off, FBI."

The hack worked because someone at an IT help desk picked up the phone. That's the real story here - your whole security stack means nothing if one employee can be talked into resetting a password over a call.

Source.

u/Syncplify — 4 months ago

A new Proofpoint report found that 1 in 10 hacked Microsoft 365 accounts had malicious mailbox rules planted within seconds of the breach. Sometimes in as little as five.

And even if you decide to change your password, the rules stay. You reset it, think you're done, and the whole time there's still a rule sitting there silently forwarding your emails to whoever broke in. They name them things like ".", "..", "..." or ; so you scroll right past them. The most common one, a single dot, showed up in 16% of cases.

One real case from the report: attacker gets into an accounting specialist's account, creates a rule named "..." that hides all incoming emails with "Payment Receipt" in the subject, then uses that same account to send a phishing email with that exact subject line to 45 coworkers. The CEO's assistant clicked it. She had payroll access. You can guess the rest.

They're also known to set up rules that silently delete any email containing words like "phishing", "malware", or "virus", specifically to stop IT security alerts from ever reaching the compromised user. The FBI actually warned about this exact tactic back in 2020, and it's still going strong, apparently.

If you're an admin, start with disabling automatic external forwarding and auditing OAuth app grants. Password resets alone won't cut it. Anyway, when did you last look at your inbox rules?

u/Syncplify — 4 months ago