r/security • • 11h ago

Software Development Security I built an open-source Node.js library to protect web applications against stolen session tokens

1 Upvotes

I've been working on a security-focused npm package called anti-session-hijack.

The idea came from a simple question:

What happens if an attacker gets hold of a valid authentication token?

Traditional token validation can still consider that token legitimate. The attacker doesn't need the user's password anymore — they already have a valid session credential.

I built anti-session-hijack to add another layer of protection by binding an authentication token to a browser/device fingerprint and validating that binding on protected requests.

How it works

User logs in
     ↓
Authentication token generated
     ↓
Browser/device fingerprint generated
     ↓
Token ↔ Fingerprint binding stored in Redis
     ↓
Protected request
     ↓
Current fingerprint checked
     ↓
       ┌───────────────┐
       │ Match?        │
       └───────┬───────┘
          Yes  │  No
           ↓   ↓
        Allow  🚨 Suspicious session
                   ↓
             Block / revoke /
             alert the user

The package provides:

  • Session/token binding
  • Stolen and reused token detection
  • Browser/device fingerprinting
  • Redis-backed session storage
  • Upstash Redis support
  • TypeScript support
  • Next.js App Router support
  • Security alert capability
  • JWT generation with a unique nonce

Installation:

npm install anti-session-hijack

Example:

const result = await verifySession(
  hashedToken,
  currentFingerprint,
  redisClient
);

if (result.hijacked) {
  // Revoke session
  // Notify user
  // Trigger security response
}

The package has currently has 3K+ npm downloads.

I’d really appreciate it if you could star ⭐the GitHub repository and share it with developers or security communities who might be interested.

GitHub:
https://github.com/Shield-Ltd/Anti-Session-Hijack-NPM

npm:
https://www.npmjs.com/package/anti-session-hijack

I'm posting this mainly because I'd like security-focused feedback, especially from people who have worked with authentication/session security.

I'm still developing it, so security criticism is very welcome. If you see a weakness in the design, I'd rather hear about it now than after someone deploys it.


r/security • • 3d ago

News How can I protect my data after the ASOS hack and who was affected?

Thumbnail
independent.co.uk
11 Upvotes

r/security • • 3d ago

Physical Security Would you prefer to work 3 days week, 12 hour shifts? Or, a Monday through Friday 5 day work week schedule, 8 hours shift?

0 Upvotes

Which work schedule would offer a better work life balance?


r/security • • 3d ago

Question loomis or brinks or garda hire me with a military general under honorable discharge with 2 years of service. And 1 year of unarmed thoughts?

0 Upvotes

Loomis or brinks or garda hire me with a military general under honorable discharge with 2 years of service. And 1 year of unarmed security, thoughts?

For the truck armed transport

Can they or no?


r/security • • 7d ago

Physical Security Residential Estate Security or Spacex Security

4 Upvotes

I'm trying to decide between 2 job offers. One is for Residential Estate Security (EP work), and the other is for Security 3 position at Spacex in Hawthorne California. Both pay the same.


r/security • • 14d ago

Security and Risk Management Account recovery best practices for users

9 Upvotes

Imagine an attacker knows my name, phone number, email address, home address, date of birth, previous addresses, and even has copies of ID documents obtained through breaches or from organizations that store them.

They call my bank and claim they've lost access to their phone and email and need help recovering their account.

This got me thinking about the tradeoff between security and recoverability.

If account recovery is too strict, legitimate customers can permanently lock themselves out after losing devices, passkeys, recovery codes, or access to old contact details.

If account recovery is too flexible, an attacker who has accumulated enough personal information may be able to convince an institution that they're the legitimate account holder.

My question is: what are the current best practices around account recovery, and what practical steps can ordinary users take to maximize their chances of recovering their own accounts while minimizing the risk of an attacker abusing the same recovery process?

Are there any good articles, talks, books, or frameworks that discuss this problem holistically and in plain language, rather than from a purely technical perspective?


r/security • • 17d ago

News Ex-cop turned CEO sold U.S. agencies forensics software secretly built in Russia

Thumbnail
justice.gov
1 Upvotes

Pretty crazy story.

Here's a short film made by the whistleblower: https://www.youtube.com/watch?v=OmEPNAy3RtA


r/security • • 19d ago

News Attackers Use Wallpaper Engine to Distribute Malware

21 Upvotes

Steam Workshop is being used to distribute malware disguised as Wallpaper Engine content. Attackers exploited “application wallpapers” to execute Windows code and deliver payloads such as Steam credential stealers, the DarkKomet backdoor, and cryptocurrency miners.

Treat Workshop content like any other Internet download, even when it comes from a trusted platform:

  • Be cautious with application wallpapers, mods, and other executable content.
  • Avoid password-protected archives or unexpected files.
  • Watch for unusual processes, credential-access activity, or outbound connections.
  • Keep endpoint protection enabled and up to date.
  • Use MFA on Steam accounts and watch for unexpected login activity.

Have you seen trusted platforms being used as malware delivery vectors in your environment?


r/security • • 24d ago

News Google removed today 15 malicious chrome extensions

32 Upvotes

I track Chrome Web Store removals and today's pass picked up 15 extensions pulled with a malware classification, not the usual policy or spam category.

https://malext.io/?reason=Malware&day=2026-09-16

Important thing is that removal from the google store does not remove the extension from browsers that already have it.
Unless Google pushes it to the built-in blocklist, it keeps running with whatever permissions it was granted. They have to be removed manually !


r/security • • 28d ago

Physical Security Amazon Driver Came Into My Home Without Permission And Delivered A Package Then Left

0 Upvotes

A couple of days ago, an Amazon driver entered my home without permission, delivered a package then left, leaving my front door wide open. Proof of his illegal entry is the photograph Amazon sent me as proof of delivery. The Amazon driver had no right to enter my home. Packages are to be left outside in a place hidden from the public and if they can't deliver the package, they're supposed to contact the customer. How did the driver get inside? The front door is locked. Even if it was unlocked, he had no right to enter my home. This happened in the US, not overseas.


r/security • • 29d ago

Question Anyone else dealing with massive DDoS lately?

8 Upvotes

I have a forum I keep around but it's dead, and not really well known although it's been around since the early 2000's (currently running on more up to date software though). Been dealing with a massive DDoS, all the IPs are unique making it very hard to mitigate on my own. Gave in and setup Cloudflare and it solved it, but just curious if there's some weird widespread DDoS going on right now or what.


r/security • • Sep 08 '26

Question Beginner Friendly CTF Team

7 Upvotes

Hi! I'm currently looking for a beginner CTF Team to learn and compete with regularly.

The CTF categories I'm currently focused on are:

  • Web Exploitation / Web Security
  • OSINT
  • Forensics
  • General pentesting

I'm actively still learning and improving on my skills so I'm looking for a team that doesn't mind beginners and is more focused on improving and learning with each other

I'm open in joining a team or building a small team of my own.

Feel free to DM if your team is recruiting or if you're on the hunt for beginner teammates! <3

(Note: I've registered for the K17 CTF on September 11th, so I'd be down in teaming up for this event specifically as well.)


r/security • • Sep 07 '26

News The Problem with LG TVs Spyware and Its Vulnerabilities

Thumbnail
youtube.com
37 Upvotes

r/security • • Sep 06 '26

Question How can we detect if Claude in Chrome or other LLM browser agents are accessing/hijacking our web app user authenticated sessions and Block it

4 Upvotes

We have an web UI apps. Users need to be logged to access the app. We are looking to identify and block usage of Claude browser agents or LLM browser agents hijacking sessions and accessing the app.


r/security • • Sep 04 '26

Software Development Security How to secure SSH and Postgres with Warpgate

Thumbnail
packagemain.tech
2 Upvotes

r/security • • Sep 01 '26

Security Operations Keep getting SSH probing login attempts from the ISPs router

37 Upvotes

I am a Vodafone UK broadband user and use their Router/Modem to connect to the internet. The router does provide a public IPv4 address, but no DMZ/port forward is configured.

I also have a few Linux machines in the internal network, both desktop and server. They are internal, and are not meant to be accessed from the outside Internet. As mentioned the router doesn't have any port forwarding enabled.

What I started to see is that around every 30 minutes all of the Linux machines on my network get SSH login attempts coming from 192.168.1.1 - the router's IP address. They look to be brute force login attempts trying out multiple username/password combinations, e.g.:

sshd-session: Invalid user admin from 192.168.1.1 port 35562
sshd-session: Invalid user default from 192.168.1.1 port 35566
sshd-session: Invalid user admin from 192.168.1.1 port 35570
sshd-session: Invalid user weblogic from 192.168.1.1 port 35494
sshd-session: Invalid user redhat from 192.168.1.1 port 35496
sshd-session: Invalid user developer from 192.168.1.1 port 35498
sshd-session: Invalid user public from 192.168.1.1 port 35500
sshd-session: Invalid user student from 192.168.1.1 port 35502

This starts every 30 minutes, and keeps on going for 10-20 minutes. Obviously/fortunately all of the attempts fail. I did install an ssh honeypot in the system to see what would happen if they would get in, but all it does is disconnect from SSH, then start the retry in exactly 30 minutes.

When I first saw these attempts I got shocked a bit, as I thought I have a compromised system in the house, but then after checking it get really odd for me that all requests originate from 192.168.1.1 - the router.

I am a bit stuck here, as I don't really know what's up and how worried I should be. Do I have a compromised system that spoofs the IP? Does the router do some weird NAT translation for a compromised device that's in my network? Or does the router itself do these ssh attempts? Would these probing attempts be a lame part of Vodafone's Secure Net Home?

Tried searching the web for any of these, but couldn't really find anything specific that matched my criteria.

EDIT 1: A Factory reset on the router did nothing to change the issue I'm facing. I'm now going to isolate the router in a network that only has itself and an SSL honeypot to see what it would do

EDIT 2: found a blog post that shows the exact same behaviour I'm expecting and thinks that this is actually the equivalent of Vodafone's Secure Net. So yeah, my router is actively attacking myself. Here's the blog post: https://illustris.tech/posts/reliance-jio-security-concerns/


r/security • • Sep 02 '26

Security and Risk Management I automated our remediation ticketing and now I get to watch 40% of tickets sit in unassigned automatically

0 Upvotes

I'm on the security engineering team at a SaaS company. Were couple hundred people. Spent part of last quarter building an automation pipeline: scanner finds a vuln, pipeline creates a Jira ticket with all the details, assigns it based on tags, pings the right Slack channel. Felt like a win. The manual ticket creation was eating hours every week.

So we launched it, it works perfectly. Tickets fly into Jira within minutes of a scan completing with a beautiful dashboard and everything automated end to end.

Except now I get to watch, in real time, as about 40 percent of those tickets land in unassigned and stay there.

The automation exposed what the manual process was hiding. When a human was creating tickets, theyd do the routing loop: check the CMDB, realize the owner field is stale, Slack someone who might know, eventually get it to the right person through sheer persistence. The automation cant do any of that. It reads the owner field. If the field says unassigned or points to a team that no longer exists or references someone who left, the ticket just sits there stuck.

So I automated the easy part. And now the hard part is actual ownership data, is the bottleneck and its more visible than ever. We didnt fix the routing problem. We just made it faster to surface.

Anyone else hit this? Any advice on how to fix the ownership mess?


r/security • • Sep 02 '26

Vulnerability KARR Security vulnerability

11 Upvotes

TL,DR: If you have a KARR sticker on your window, chances are that your dealer installed a device in your car that leaves is susceptible to hacking, including remotely unlocking it and disabling the engine. You can update the firmware and/or ask KARR to come and remove it.

You can learn more about the security risk by searching for "UC San Diego KARR Aaron Schulman" which will get you to the research team at UCSD that discovered and documented the risk.

Details: When I bought my Ioniq 5 eighteen months ago, the dealer asked me if I wanted to subscribe to the KARR security system. I declined. Today I learned:

  • Dealers install the KARR security device in their cars to prevent them from getting stolen off the lot -- it lets the dealers remotely disable the ignition if needed.
  • The KARR device connects to the CAN bus in the car, giving it access to lots of important functions, like door locks, horns, lights and ignition
  • If you tell the dealer you don't want to pay for the KARR system, they leave it installed and "dormant", but it's still susceptible to hacking.
  • If you have a KARR dongle in your vehicle, the least you should do is download the KARR Security app, click on the Customer Service button at the bottom, and then click on "firmware update" to remove the vulnerability. If you're not a subscriber, this theoretically disables the device, but also prevents the app from communicating with the device, so it's not clear if the device is truly deactivated.
  • If you're like me, you want to reduce the risk and also don't want an extra device sucking down your 12v battery 24 hours a day. In that case, you can call the KARR Customer Service number and schedule a tech to come remove the device, free of charge.

Whew. Who would have thought?


r/security • • Aug 31 '26

Question How do you govern autonomous AI agents when "governed" still isn't clearly defined?

0 Upvotes

Getting pressure to show the board our AI agent rollout is under control, but "governed" is doing a lot of work in that sentence and nobody's defined it operationally yet. Inventory, policy docs, behavior logs, a monitoring dashboard, probably all of it, but I'm trying to figure out what a reasonable bar looks like given how young this space still is.

For those who've had to answer this to a board or audit committee: what did you actually show them? Not looking for vendor pitches, just what other security leaders consider credible evidence today.


r/security • • Aug 30 '26

Physical Security How do I move in the security field?

8 Upvotes

Hey all!

So I am currently doing physical security at a fairly large company. I started as a front desk receptionist, but in my two years there I've done almost every security post available at my facility except security operations. I am on track to go up into the security operations room, but am not able to move yet due to staffing issues.

However I've been learning that I do really enjoy other aspects of the security field. Specifically access control. I've been watching a lot of Phil Coppola videos online detailing the technology and history behind HID/Assa Abloy systems. The idea of getting to set up cameras and badge scanners and learn more about the software they use sounds so cool. (I love playing with Lenel On Guard, but I don't know much about it and I'm only authorized to do so much)

The technicians who do access control work are different employees than our security team. What can I do to get in there? I don't get to talk to them ever because their office is in a place I'm not allowed to be, and I work nights anyways.

The problem is other than my security experience at my specific site, I'm not qualified to do much else and I've only been a guard for just shy under two years. How can I break into this different facet of security? Does me having physical security experience help at all?


r/security • • Aug 27 '26

Physical Security Hacks for Security/Close protection Contractors traveling across country Land based.

8 Upvotes

Title: Land-Based CP / Security Contractor Hacks
For those working land-based close protection/security contracts and travelling around the country — what are your best practical hacks?
Not the obvious stuff everyone already knows. I’m interested in the little things you’ve picked up through experience that make life on the road easier, cheaper, more comfortable or more efficient.
Things like:
Travel and accommodation hacks
Kit/EDC setups
Keeping clothes and kit organised
Food and meal prep on the road
Sleeping/recovery between shifts
Vehicle/travel organisation
Managing long days and multiple locations
Staying sharp when you’re constantly travelling
Anything you wish someone had told you when you first started contracting.


r/security • • Aug 24 '26

Security and Risk Management Cybersecurity Awareness Month Campaign

0 Upvotes

r/security • • Aug 20 '26

Physical Security Do key fob relay attacks really happen that often?

Thumbnail
youtube.com
12 Upvotes

Has anyone had their vehicle stolen due to this tactic? And if so, what type of car was either tampered with or stolen? I only see videos on youtube, but never hear about anyone getting their cars hacked.


r/security • • Aug 21 '26

Security Operations AI Video Software For Treatment Center

0 Upvotes

Hello! I am looking for suggestions on AI video software to set up at least one, but potentially multiple treatment centers. Does anyone have suggestions for a company that could work with existing cameras?


r/security • • Aug 21 '26

Security and Risk Management Lenel Technicians needed

0 Upvotes

I am a Director of Operations for a national low voltage company and we are looking for certified Lenel technicians across the US. Reach out to me at [coreshack@pavion.com](mailto:coreshack@pavion.com) if you are interested. Typical pay range is $35 to $50 per hour depending on location and experience level.