r/Information_Security

What do wealth advisors use for high value client verification?

I work with clients where a single instruction can involve serious amounts of money. One thing I keep thinking about is how we verify the actual person when they aren't sitting across from us. We have secure client portals and callback procedures. For some things we can require signed documents. But a portal still relies on someone having the right login and a callback relies on the phone number we have on file.

It gets even messier when a client has a PA or family office handling half their communication. For anyone working in wealth management or private banking what do you use to confirm the actual client before acting on a high value request? Looking for something beyond the usual callback and login checks so please keep the common tips out!

reddit.com
u/Mission_Funny4168 — 1 day ago
▲ 6 r/Information_Security+1 crossposts

Did you receive a rejection letter from the NIH for foreign risk?

The National Institutes of Health (NIH) rejects more SBIR and STTR projects because of foreign risk.

The Small Business Innovation and Economic Security Act of 2026 requires federal agencies to explain foreign risk decisions. However, many rejection letters do not give specific reasons for the decision.

We collect information to measure this problem. We want to evaluate options for action, such as:
Contact Congress.

Start legal action under the Administrative Procedure Act.

How you can help

Did you receive a rejection letter? Write a comment below or send a message if the NIH rejected your project for foreign risk this year.

Did the letter explain the reason? Tell us if the NIH gave a clear reason or a general statement.

Share this post: Send this post to other companies and researchers in your network.

Write a comment below or send a direct message.

reddit.com
u/IPTalons — 1 day ago

The fix took 10 minutes. Finding who owned the asset took 4 days and 6 escalation emails.

I need to vent about something that happened last week cause I'm still annoyed.

We had a straightforward misconfig on a server. Open port that shouldnt be open. Yeah, basic stuff. The fix itself was maybe ten minutes. Log in, update the config, restart the service, call it a fix.

The ten minute fix took four days.

Day one: I find the finding in our scanner, but no owner is listed. I check the CMDB, the owner field says IT Operations which in our org means exactly nobody. I send an email to the distro, got a big ugly nothing.

Day two: I dig through old tickets and find the server was originally set up by an engineer who left eight months ago. His replacement doesnt know anything about it. I escalate t the infra team lead.

Day three: Infra says its not theirs, it was built for an app team project. App team says they never owned it, infra stood it up for them. I escalate to both directors.

Day four: A director finally claims it, assigns an engineer, the fix happens in ten minutes just as it should have happened 4 long days ago. Ticket closed.

So this small thing tool 4 days, 6 angry emails, 2 director escalations. And this isnt even unusual. This is maybe 40 percent of our findings. The technical fix is never the bottleneck. The bottleneck is figuring out who the hell is supposed to do it.

How do you handle ownership at scale when CMDB fields are stale within a quarter?

reddit.com
u/PackPretty3479 — 2 days ago

How to run a cross-functional IR tabletop when legal and execs can't all make the same calendar slot?

I own our incident response exercise calendar. The technical team shows up every time. Legal, comms and the exec sponsor show up maybe once a year if I'm lucky, because coordinating five calendars across departments for a two-hour block is its own project.

The result: we've tested our SOC's response a dozen times and tested cross-functional coordination, the part that actually determines how bad a real incident looks to customers and the board, almost never.

It's not that leadership doesn't care. It's that a live incident doesn't wait for a calendar invite to clear, so the one part of the process that most needs practice is the part we can never get everyone into the room for at the same time.

We started running some sessions on a platform where agents fill in for the roles that can't attend (legal, comms) so the exercise still happens on the SOC's schedule instead of waiting for six calendars to align. Doesn't replace having the real humans eventually, but it's gotten us from one full cross-functional exercise a year to something closer to quarterly. Has anyone found another way around the scheduling wall?

reddit.com
u/Ok_Mulberry5100 — 1 day ago

How are teams approaching identity attack surface management across disconnected systems?

our identity footprint spans an hr system, three cloud providers, a legacy on-prem directory, and a pile of saas apps that were never centrally provisioned, and none of it talks to any of the others.

mapping the full attack surface across all of that used to be manual, which meant it was already out of date by the time we finished. what's changed is treating discovery as continuous and automatic instead of a quarterly project, so every identity system gets found and folded into one record without someone chasing it down by hand.

what's your process for keeping a current picture of exposure when the systems themselves aren't connected?

reddit.com
u/Putrd-Cohemistry-512 — 3 days ago
▲ 38 r/Information_Security+8 crossposts

The 2003 Antwerp diamond vault heist is the cleanest case study in how defense-in-depth fails. Ten independent layers, each beaten by something trivial — hairspray on the IR sensor, aluminum tape on the magnetic contact — because the attacker had 2.5 years of legitimate tenant access to study them.

The vault two floors under the Antwerp Diamond Center was the diamond trade's gold standard, in a city that handles roughly 80 percent of the world's rough diamonds. The control stack:

  • Combination lock, 100M+ possible sequences
  • Separate keyed lock
  • Multi-tonne steel door
  • Magnetic field sensor on the door
  • Seismic sensor for drilling or force
  • Light detector
  • Infrared heat-and-motion sensor
  • Doppler radar sweeping the chamber
  • Camera coverage on the approaches
  • Private guard force monitoring the whole apparatus

Ten controls, each independently credible, and the industry's assessment was that the stack was effectively absolute. Dealers stored inventory there specifically because nobody believed it could be opened.

Over the weekend of 15-16 February 2003 a crew opened it without tripping anything, forced roughly 100 of about 160 safe deposit boxes, and left with north of $100 million. No weapons, no violence, no forced entry into the building. It wasn't discovered until staff came in Monday morning and found emptied boxes and missing tapes.

What each control actually fell to

The IR heat-and-motion sensor — the layer specifically designed to catch a warm body moving in a dark room — was temporarily blinded with a film of ordinary hairspray, long enough for someone to reach it and physically disable it.

The magnetic contact on the door, which should have fired the instant the door broke its field, was defeated by holding the two halves together with aluminum and tape so the field never opened.

The light detector was covered. The combination had been captured weeks earlier by a concealed camera recording the dial being turned.

The University of Washington security group made the point that lands hardest here: taken individually, the exploit against each of the ten high-tech controls looks trivial to the point of absurdity.

Why that's the interesting part rather than the funny part

The stack was never ten independent defenses. It was ten expressions of one shared assumption — that no attacker would get close enough, for long enough, to study the set.

An IR sensor is formidable if you meet it by surprise in the dark. It's a can of hairspray if you've known its make and position for two years. A magnetic contact is unbeatable if you don't know it exists and a strip of tape if you do.

The stack's real security was a sum of surprises. Remove surprise and the layers stop multiplying difficulty and start merely adding to a to-do list. Ten controls became a sequence of known problems with known answers, and the arithmetic changed from multiplicative to additive.

That's the failure mode, and it's the one the industry eventually internalised the hard way — which is why the impenetrable perimeter got abandoned in favour of assume-breach, continuous monitoring, and blast-radius limitation.

The access model

Leonardo Notarbartolo didn't break in to study the vault. He rented in it.

For roughly two and a half years he posed as a diamond merchant with an office and a safe deposit box in the building, which gave him an unremarkable reason to come and go and to descend to the vault whenever he liked. From inside, he filmed the door and its controls with a concealed camera, took notes on guard schedules and the brand names of the locks and safes, and at some point obtained building blueprints. He carried all of it back to Turin and built a complete model of the target.

He defeated the vault by being welcomed through it, repeatedly, until he understood its controls better than the firm that installed them. The taxonomy for that is a decade old now — legitimate access, long dwell, extensive reconnaissance, single objective, exfiltration in one event — but Antwerp is the physical-world version, and it predates the vocabulary by years.

The control that was actually missing

Everything in the stack was a prevention control. The vault could be opened, and there was no meaningful capability to notice that it had been.

It was opened, occupied for around two hours, comprehensively looted, and closed again — over a weekend, with nobody watching, and the only record of any of it walked out the door in a bag. Detection lag was roughly 40 hours, and detection when it came was a human noticing empty boxes.

Ten prevention controls, zero response capability, and log integrity that depended on the logs being physically present in the building the attacker was inside.

The cleanup

They engineered every step of the intrusion and none of the exit.

The evidence bag was supposed to be burned. One crew member, left alone with it, convinced himself he heard someone coming, scattered the contents across a patch of ground off the E19 and fled. The land belonged to a retiree with a documented hatred of litterers and a habit of reporting illegal dumping.

Within about 48 hours he found the pile and called the police. Recovered from it: a Diamond Center videotape, envelopes from the building, payment stubs, a business card belonging to the crew's electronics specialist, a discarded SIM card, a supermarket receipt whose timestamp let investigators pull store camera footage of one of the crew, an invoice for a low-light surveillance system naming Notarbartolo as the purchaser, and a half-eaten salami sandwich carrying his DNA.

Notarbartolo drew ten years. Others got five apiece. Several participants were never identified. Almost none of the diamonds were recovered, because loose stones are fungible, anonymous, and effectively untraceable once they re-enter the flow through Antwerp and Mumbai and Tel Aviv.

The attack was the engineered part. The cleanup was the part that generated attributable artifacts, which is more or less exactly how sophisticated intrusions get attributed now — not by failing to get in, but by reusing infrastructure, leaving metadata, or otherwise producing the digital equivalent of a sandwich with your DNA on it.

Full write-up on the vault, the reconnaissance, the crew, and the Wired interview where the ringleader claimed the whole thing was an insurance fraud:

https://unteachablecourses.com/antwerp-diamond-center-heist/

The question I'd put to this sub: the Antwerp stack failed because ten controls shared one assumption and nobody stress-tested the assumption rather than the controls. In practice, how often does a layered architecture get audited for correlated dependency — where the layers look independent on the diagram but all rest on the same premise about attacker dwell time, or the same identity provider, or the same assumption that a tenant with valid credentials isn't the threat? I've seen plenty of control-by-control audit. I've seen much less "what single assumption, if false, degrades all of these at once."

reddit.com
u/unteachablecourses — 3 days ago

is agentic identity turning into a bigger security blind spot than employee accounts?

so ibeen digging into our identity inventory and i found that the fastest growing category by far isn't employees or even traditional service accounts... wow it's ai agents. we've got agents pulling data from internal apis, kicking off workflows, and writing to systems, and each one needs its own credentials to do that. some of them got provisioned quickly to hit a deadline and ended up with broader access than anyone intended.

also meanwhile every identity conversation still starts and ends with locking down employee logins. then the agentic identity barely comes up in the same breath even though these agents can take actions at machine speed with permissions nobody ever reviewed.

just wanna know cuz im not sure that...is this the bigger exposure right now, or am i overindexing because it's the thing i'm staring at

how other security teams are prioritizing agentic identity relative to the usual employee-focused identity work.

reddit.com
u/WolfShoddy7443 — 2 days ago
▲ 27 r/Information_Security+2 crossposts

OathNet is probably the most underrated IntelX / DeHashed alternative right now

I've known about OathNet since pretty much the start, and I still think a lot of people are sleeping on it.

IntelX has massive numbers, but a lot of the results I've seen are duplicate combo lists and repeated credentials. I don't need the same email showing up 20 times.

OathNet feels much more investigation-focused.

The infostealer side gives you the victim context, machine info, domains, services, identities, metadata and even the original file tree.

You can also pivot through fields like:

>email / username / phone / IP
domain / subdomain
Discord ID / Steam ID / Instagram ID / Twitter ID
HWID
service / OS
social + gaming identifiers

I mainly use it to monitor my own emails and accounts I manage through my agency, so I can catch exposed credentials early and rotate them before they become a security issue.

I'm on Pro and honestly it's more than enough for my use case. Paying around $30/mo instead of €2.5K/year for IntelX Researcher is a huge relief.

Their cheapest plan costs only $9.99/mo.

They're also running an anniversary promo right now with 30% off, so the plans are even cheaper at the moment, which is kind of insane for what you get. psst the coupon name is : ANIV30

I'll attach a few screenshots of the stealer view + file tree because that's the part that sold me.

I forgot to mention that it shows the amount of exposed cookies and the infection path, from where the infostealer was ran from.

This is the filetree view which is absolutely insane

https://preview.redd.it/nd20ayu3stjh1.jpg?width=2515&format=pjpg&auto=webp&s=b10517c3d5bbcd5b8537fac541ded46b569e7099

screenshots from : oathnet.org

reddit.com
u/SubstantialArtist948 — 3 days ago

Zscaler vs Cato: best SASE platform for enterprise GenAI security in production

We are a ZIA/ZPA shop, roughly 4,000 seats, renewal in about seven months. Not shopping for the sake of it, but the AI requirements landed after our last contract and I want to know whether we are better off expanding here or looking at Cato.

Where we are with Zscaler on the AI side: SSL inspection is solid, the AI app category exists, DLP works about as well as our policies deserve. What I am less clear on is inline prompt-level control versus app-level allow/block, and how much of the newer AI functionality is included versus a separate SKU.

The Cato pitch we got leaned heavily on single-pass processing and one policy engine covering network, security, and AI, plus their inline inspection story. Sounded clean in the demo. Skeptical of demos.

Asking here specifically because I want the incumbent perspective: if you have added AI controls on top of an existing ZIA deployment, was it configuration or a new purchase; how has inspection performance held up on streaming LLM responses; has anyone actually evaluated Cato head to head and stayed, and what kept you; and for anyone who left, what was the deciding factor?

reddit.com
u/Acrobatic-Layer9109 — 4 days ago

Can security controls actually keep up with fast-moving AI?

Feels like every week there's a new AI tool employees are quietly using, and most security stacks weren't built for this. People pasting sensitive data into random chatbots. AI agents touching files and APIs with way less oversight than a human would get. DLP tools that can't tell "legit AI use" from "IP walking out the door."

Curious how people here are actually dealing with this? What's working for you vs. what's just theater at this point?

reddit.com
u/Syncplify — 4 days ago

Studying cybersecurity, want to end up in Cloud Security — what's the best path to get there?

I'm a cybersecurity student and I want to specialize in Cloud Security long-term. I already know it's not an entry-level field, so I'm not asking how to skip the line.

My question is: what's the best route to get there? Which first job actually builds toward it — help desk, SOC, sysadmin, DevOps, backend dev?

If you work in cloud security: what path did YOU take, and what would you do differently if you started today?

reddit.com
u/One-Imagination658 — 3 days ago
▲ 38 r/Information_Security+2 crossposts

How to present Threat Intelligence properly to execs????

So, to give some background. I lead the threat intelligence program of a major bank. Now we receive tons of IOCs/CVEs and brand abuse/impersonation cases and we do take action on them accordingly.

But whenever we create a presentation, it's always numbers

- no. Of IOCs we received, sources (regulator/commercials)

- social media/brand abuse/impersonation/rogue apps count & takedown status.

But execs don't understand these numbers. How can I present the data such that they are assured that we are safe from any kind of threat & prepared for what's coming in the future.

Been researching lots of things but didn't quite get anything. Would really appreciate your views and guidance here.

reddit.com
u/Longjumping-Ebb-578 — 6 days ago
▲ 1 r/Information_Security+1 crossposts

What other organisations then Securex work with the government?

What other organisations then Securex work together with the government? And can you explain me why? I understand that governments make risk-analyses but what if they see risks in everything when there simply are no risks at all?

reddit.com
u/BackToTheFuture1181 — 4 days ago
▲ 1 r/Information_Security+2 crossposts

White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination

White House launches cybersecurity clearinghouse to patch software flaws discovered by AI

The 'Gold Eagle' initiative seeks to help federal agencies, critical infrastructure operators and artificial intelligence developers patch crucial security flaws uncovered by advanced AI models.

whitehouse.gov
u/chota-kaka — 6 days ago

Is WhatsApp actually a good place for confidential work?

WhatsApp is encrypted and convenient so I get why people use it when something sensitive comes up. But I’m not sure encryption alone solves the problem anymore. If someone gets access to a device or manages to impersonate a person you trust then the conversation being encrypted doesn’t help much.

I’ve seen people use Signal and newer stuff like Kibu that puts more focus on verifying identity. Curious what people here actually trust for sensitive conversations. Is WhatsApp enough or do you use something else?

reddit.com
u/ReserveFlaky8298 — 6 days ago

Why does enterprise sec trust phone numbers so much?

I keep seeing phone numbers treated as proof of identity. Call the number on file and send a code. Confirm the request over the phone and that made sense when controlling a phone number was a decent sign that you were talking to the right person. I don't think its that way anymore and feel free to disagree, Numbers can be spoofed, SIM swaps, Calls can be forwarded. And now a familiar voice isn't much proof due to AI.

Yet for things like wire transfers and sensitive account changes the fallback is still often “call the known number.” Feels like we’ve built strong security around data while leaving identity tied to something that was never designed to prove who a person is. Why are phone numbers still trusted this much?

reddit.com
u/SignificantSearch945 — 9 days ago
▲ 51 r/Information_Security+7 crossposts

xFW - Open-Source eBPF Volumetric DDoS Protection

Hi Reddit,

DDoS attacks are becomeing larger and cheaper to launch, so we work on a scalable open source solution to mitigate them.

Tempesta xFW's core is XDP and TC eBPF programs implementing volumetric DDoS filtering. A user-space daemon handles gRPC requests from CLI tool or WebAPI (via C library).

It supports two packet-path architectures:

  • host-based protection, such as CDN edge or on-premises application delivery controller (ADC) cases, where the host is a TCP connection endpoint. This is good for protecting a local web or DNS server.

  • router-based protection, such as ISP, hosting, or IaaS provider cases, where the host routes IP packets to protected servers or networks.

Router-based deployment can be always-on/pass-through or on-demand/redirection protection. In the later case, a node may not "see" normal clean traffic and may receive only traffic containing a DDoS attack. Also, the node may receive only client-to-server traffic, as in direct server return (DSR) or some traffic scrubbing scenarios. In this mode a DDoS sensor and mitigation controllers are typically needed.

Traffic performance metrics are exported in Prometheus format.

DDoS incidents are aggregated per source IP and logged to Clickhouse for analysis.

A dry-run (evaluation) - mode allows you to observe all reported incidents and metrics without blocking traffic..

Single Xeon Gold 6348 with ConnectX-6 dual 100Gbps reach 196Mpps and 176Gbps of filtering capacity.

u/krizhanovsky — 8 days ago

153GB of stolen credentials surface after LiteLLM supply chain attack

153GB credential archive surfaced after a supply-chain compromise in a widely deployed AI proxy library. The archive contained 433,909 files spanning thousands of corporate domains: AWS access keys, internal API tokens, database passwords. These are non-human identities — the machine credentials that keep production infrastructure running.

The uncomfortable part is that most organizations have no accurate count of how many non-human credentials exist in their environment, let alone which ones are actively in use, over-scoped, or already exposed. Human identities get offboarding checklists and MFA. Machine identities often get neither.

When a breach like this surfaces, the damage window is not the moment of compromise — it is every day between compromise and discovery that those credentials remained valid and undetected.

For those of you working in platform security, cloud infra, or AI/ML ops: how are you actually tracking non-human credential sprawl in your environment? Are you doing anything differently for credentials introduced specifically by AI tooling and third-party model proxies?

reddit.com
u/No-Conclusion3720 — 7 days ago
▲ 2 r/Information_Security+2 crossposts

[IT/Cybersecurity] [4 YoE] [India] [Seeking SOC Analyst]

Background: 4 years in IT Support/Desktop Support roles, including a banking environment (BFSI). Recently completed a cybersecurity certification to transition into the field

Applying mainly for entry level SOC Analyst and GRC roles. Getting rejected consistently I'm not sure if it's the resume, market conditions, or how I'm positioning my experience

Would appreciate honest feedback on formatting, content and whether my IT support experience is being framed effectively for cybersecurity roles.

u/huntwithak47 — 10 days ago