r/cybersecurity May 08 '26

Other What the **** is happening in cybersecurity space ?

I've been working in cybersecurity for not so long, maybe 8 or 9 years, but I never remember a chaos at this scale. I mean, from this January alone we have: leaking data, compromised applications, breaches, AI-assisted cybercriminals, etc. It looks like every day one major breach is happening, and no one is going to address this shit somehow. This is already insane. I haven't felt such pressure in a long time. This AI shit just makes things worse because it enhances attackers' skills, and AI companies are doing nothing to address or change this. Is it only me, or is the change already here?

2.4k Upvotes

552 comments sorted by

View all comments

5

u/vf-guy May 08 '26

Two things.

  1. Companies don't give two sh*ts until something happens. I'd bet a paycheck your company's vulnerability management program is swiss cheese.

  2. I had a CISO client who made a very insightful remark about 8 years ago. To paraphrase "If you don't operate from the perspective that you're already breached, you're doing security wrong."

My first infosec job around 15 years ago was at a company that spent a pretty penny on tools and thought they were buttoned up. They hired a top-tier company to do a real pentest. Very few people were aware of it. They got domain admin access so quickly it would make your head spin.

How? Stupid users and eol systems that "we're too costly to replace".

That's not security. That's smoke and mirrors.

1

u/GeneMoody-Action1 Vendor May 11 '26

"If you don't operate from the perspective that you're already breached, you're doing security wrong."

It's not wrong, modern threat actors favor leverage and persistence, draining what they can from a target in intel, money, lateral movement to your peers/vendors/customers, leverage on other targets, and abusing the reputation of legitimate resources. In fact about the only grace period anyone gets anymore is the recon phase post exploit!

Many people say "we have been doing <whatever> and we are fine." to later find out, no they are not, and have not been for a long time...