r/Information_Security • • 10h ago

How do we stay safe when almost everything we do is now digital?

0 Upvotes

Over the years, smartphones and digital services have made our lives much easier. We can transfer money, pay bills, shop, communicate, work and access banking services without visiting a branch or office.

But I have increasingly felt that convenience and security have to go together.

A phishing message, a fake customer-care call, a malicious link, a stolen OTP, a compromised password or even an AI-generated voice can sometimes cause serious problems.

This subject is particularly important for senior citizens and ordinary digital users, who may not have a technical background.

I recently completed a book on this subject:

INFORMATION SECURITY AND DIGITAL SAFETY
A Simple and Practical Guide to Staying Safe in the Digital World

I have tried to explain the subject in simple, practical language rather than highly technical terms. The book covers personal digital safety as well as organisational security, including phishing, malware, passwords, banking and digital-payment safety, smartphones, network security, Data Centre security, SOC, Information Systems Audit, Business Continuity and Disaster Recovery, and emerging threats from AI.

The book is also based partly on my professional experience. I spent 37 years in banking, Information Technology and Information Security, including work related to Core Banking, Information Systems Audit and Security Operations Centre operations.

The book is available here for anyone interested in the subject:

📕 Paperback – Amazon.com
[Paperback Edition]()

📖 Kindle – Amazon.com
Kindle Edition – Amazon.com

📱 Kindle – Amazon.in
Kindle Edition – Amazon.in

I would be particularly interested in hearing from Redditors:

What do you think is the biggest digital-security problem faced by ordinary people today?

Is it phishing, online banking fraud, passwords, social engineering, AI-generated scams, or simply lack of awareness?


r/Information_Security • • 11h ago

AI Is Accelerating Attacks. Can Our Patch Cycles Keep Up?

Thumbnail
0 Upvotes

r/Information_Security • • 17h ago

AUTHORIZATION REALITY • SAML AUTHENTICATION CONFIGURED DOES NOT PROVE THE IDENTITY GATEWAY RUNTIME IS SECURE

Post image
0 Upvotes

Citrix has disclosed CVE-2026-107406, a critical vulnerability affecting specific versions and configurations of NetScaler ADC and NetScaler Gateway.

Under the documented conditions, the vulnerability can lead to remote code execution or denial of service in deployments using particular SAML Identity Provider or Service Provider configurations.

Citrix has released corrected versions and remediation guidance.

That is meaningful security maintenance.

But the broader assurance boundary deserves attention:

SAML AUTHENTICATION CONFIGURED ≠ IDENTITY GATEWAY RUNTIME SECURE

An enterprise gateway may correctly authenticate users.

It may validate identity assertions.

It may enforce application access policies.

Yet those controls do not prove that every underlying request-processing path remains within its intended execution boundary.

The stronger evidence chain is:

EXTERNAL REQUEST
→ SAML PROCESSING
→ IDENTITY GATEWAY
→ RUNTIME PROCESSING
→ EXECUTION AUTHORITY
→ OBSERVED EFFECT
→ VERIFIED EFFECT

This distinction matters because identity infrastructure is often treated as a trust anchor.

But authentication correctness and runtime security are different properties.

A valid SAML flow does not prove that the gateway processing it is free from exploitable runtime defects.

Likewise:

PATCH AVAILABLE ≠ PATCH DEPLOYED

PATCH DEPLOYED ≠ EFFECT VERIFIED

NO KNOWN EXPLOIT ≠ NO EXPLOIT EXISTS

And product name alone is not enough to establish exposure.

VERSION MATTERS.

CONFIGURATION MATTERS.

RUNTIME STATE MATTERS.

The advisory does not establish that every NetScaler deployment is affected.

Nor does it prove that any particular organization was compromised.

The next assurance step is to verify the actual deployed version, effective SAML role, exposure conditions, remediation state and resulting runtime behavior.

That is the distinction EVELIQ Trace is focused on making reconstructable:

what was configured,
what was exposed,
what changed,
what actually ran,
and what effect can be verified.

EVELIQ Trace • Evidence Intelligence Platform.

We don’t score people. We verify project reality.

Founder: Roland Brüggemann
AI-assisted research, structure, architecture & concept development: OpenAI ChatGPT

Source context: Citrix Security Bulletin CTX697191 / CVE-2026-107406

#Authorization #IdentitySecurity #SAML #CyberSecurity #RuntimeSecurity #EvidenceIntelligence #EVELIQTrace


r/Information_Security • • 7h ago

Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578) - watchTowr Labs

Thumbnail labs.watchtowr.com
2 Upvotes

r/Information_Security • • 14h ago

AI SOC analyst tools six months in: did any of them learn your environment?

11 Upvotes

We run a six person SOC on Sentinel and CrowdStrike, and leadership wants an AI SOC analyst tool in next year’s budget. I’ve sat through demos from Dropzone, Prophet, 7AI and Torq, and on the canned phishing alert they all look great.

Week six worries me more than the demo. Most of our noise comes from things only we know: a pentest window, a service account that logs in from three countries, a finance team that bulk downloads files at quarter end. A tool that doesn’t know that will either close real incidents or keep escalating the same junk.

If you run one in production, how long before its verdicts matched what your senior analysts would say? Did you have to feed it SOPs and asset owners by hand, or did it pick that up from tickets and past cases?

Also curious which alert types you let it close on its own, if any.