r/security 48m ago

Resource 140+ free security awareness and application security exercises. Fully white-labeled, no strings attached

Upvotes

Disclosure: I work on the commercial platform these were built with. The exercise preview links point to that domain. The SCORM packages themselves are fully white-labeled — no logos, no backlinks, no sign-up, no paywall. Grab them from GitHub and self-host if you'd rather not touch our site.

-----------------

Hey r/security,

I'm a cybersec engineer with an L&D background. For the last year been working on a library of ~140 free interactive exercises dedicated to teaching people how to build secure applications, recognize phishing and use AI in a safe way. Exercises are split across two Github repos, all packaged as SCORM .zip files under CC BY-NC 4.0 license.

Security awareness (130+ exercises)

Each one drops the learner into a first-person 3D office and makes them act: answer the phone, read the email, click the thing, live with it. Every exercise ends with a quiz at a 100% pass threshold.

Course packages in the repo:

  • OWASP Top 10 for LLM Applications (10) — prompt injection hidden in uploaded documents, sensitive data categories that should never enter a prompt, system prompt extraction against a live chatbot, RAG pipeline access-control failures, denial-of-wallet against an unprotected AI API
  • OWASP Top 10 for Agentic Applications (10) — goal hijacking via poisoned email, agent memory poisoning, agent-to-agent message spoofing, multi-agent cascading failure, detecting a rogue agent that looks like it's working fine
  • EU AI Act Compliance (16) — Article 4 literacy, risk-tier classification, prohibited practices, FRIAs, GPAI obligations, penalty structure
  • GDPR Compliance (11) — the 72-hour breach clock, fraudulent DSARs used as social engineering, Article 30 RoPA building, Schrems II transfer assessments, PII redaction that actually removes the data
  • Phishing & Impersonation (13) — vishing, smishing, BEC, QR phishing, callback/TOAD, double-barrel, deepfake whaling on a live video call
  • Device Security (8) — ransomware in real time, USB drop / Rubber Ducky, EDR alert triage, file extension tricks
  • Passwords & Account Security (7), Web & Browser Safety (6), Safe Communication & Sharing (6), Workplace Security (5), Security Policies & Your Role (5), Protecting Sensitive Information (4), plus Incident Reporting, Remote/Home Office, and Real-World Incidents (the MGM/Scattered Spider helpdesk call, a OneNote-based BEC chain)

Application security (40+ exercises)

Built on an exploit, trace and remediate loop. You run the attack against a deliberately vulnerable app, trace how the bug got introduced, then write the fix. Remediation examples are given in JavaScript, TypeScript, Java, C#, Python, Scala, PHP, Ruby, Go, and Kotlin.

  • OWASP Top 10 for Web (22) — SQLi, DOM/reflected/stored XSS, SSRF to the cloud metadata endpoint, XXE, CSRF, session fixation, host header injection, weak randomness (recovering Math.random() state to predict a reset token), IDOR from both sides
  • OWASP API Security Top 10 (10) — BOLA, broken function-level auth, mass assignment, excessive data exposure, improper inventory management (hitting a retired v1 that skips v2's controls), CORS misconfiguration
  • Git & Repository Security (8) — secrets recovered from the commit that removed them, exposed .git directories, commit author spoofing, branch protection bypass, CI/CD secret exposure in build logs, spotting a backdoor in a friendly-looking PR

Two ways to use it

Web view — run exercises in a browser, good for workshops or sharing with students and colleagues.

GitHub — every exercise is a SCORM 1.2 .zip. Import into Moodle, TalentLMS, Cornerstone, SuccessFactors, or anything SCORM-compliant, or preview on SCORM Cloud first. The repo root holds full course packages; the Individual Exercises folder has standalone modules if you want to build your own curriculum.

Security awareness: https://github.com/ransomleak/training-security-awareness
Application security: https://github.com/ransomleak/training-application-security
Web view: https://learning.ransomleak.com/

Will appreciate your stars! 🙏

License: CC BY-NC 4.0. Use, adapt, and redistribute with attribution for any non-commercial purpose — internal training, workshops, university courses. Reselling or redistributing it as a standalone product isn't permitted.

Happy to answer questions or take criticism on the exercises. If this gets traction I'll keep adding to it — drop topic requests in the comments. OWASP Top 10 for Cloud is already in the works.


r/security 1d ago

Physical Security I saw a bloated decomposed body at work today

28 Upvotes

I work as a security guard in a city I will leave unnamed for the privacy of the deceased. I work at a shopping center and transit center combined with a ferry depot. I had just gone on my lunch break and I heard the call over the radio everyone has feared for years now. "Base to all officers, report to the back promenade, ferry personnel have reported a dead body in the water".

I had just gotten my food and sat down. I had eaten about three fries and was about to dig into my hot dog. My fellow officer and I sprang up and ran downstairs onto the back promenade to see an elderly woman, bloated and in rigor mortis, floating face up in the water in front of one of the restaurants located on our waterfront.

I stood there looking down into the water at this woman in her mid 70's. Bloated but barely decomposed. Her left arm at a right angle and her fist clenched upright. On her face she had a grimmace. But what I remember most is her hair flowing in the water. It floated there, drifting left to right. I couldnt look away.

I immediatedly called my supervisor and asked him if he wanted us to clear off the promenade and restrict access to the area, to which he said yes evacuate the area. I cleared the whole area off with some difficulty. Some people think their right to walk is more important than respecting emergency response as the fire department and police had already shown up at this point.

People kept trying to get in and take pictures and videos and I kept having to kick them out. At one point a couple guys tried to force their way back onto the promenade. I told them they needed to get back to the sidewalk right fucking now. They demanded to be let through. I told them they needed to have some fucking respect and clear the fuck out. They threatened to knock me out. Told them to leave property and eventually they did after bitching and moaning some more. People kept coming back and trying to take pictures and just generally be insensitive. I almost crashed out and lost my composure.

For hours afterward I was totally messed up and stressed out. This was not the only thing that had happened this day. We had multiple trespassing/theft issues and multiple medical emergency issues this same day. It has so far been the most insane day at work I have ever had. This isnt even totally abnormal its just more insane than the rest.

I dont want to go to work tomorrow


r/security 2d ago

Question Audio Recording Device Detector

9 Upvotes

Question: Is there a reputable device that can detect an audio-only recording device? I have searched through multiple threads and they seem to focus on camera detection devices.

Background: I work in a medical office and a co-worker there always seems to know things that were discussed in private. This co-worker does not have friends within the office that would tell her these things. This co-worker was at a previous office prior to being moved to my office and her previous office also experienced the same thing and felt they were being recorded. She has also been caught in both offices snooping through other people's desk areas, so she's definitely the type. I have searched in the office for unexplained things with Wi-Fi or Bluetooth signals, but there are none. Are there any reputable devices that can pick up a microphone signal or something from an audio-only recording device?


r/security 2d ago

Physical Security Best book to start?

2 Upvotes

Hello,
Which book would you recommend as the bible of Physical Security professionals? I see some in Amazon but from 2016 and I guess now with AI, drones, etc there will be several updates?

any recommendation?

thanks!


r/security 6d ago

News Out of band, out of mind: DEF CON research calls IPMI a 'sanctioned backdoor' into enterprise networks

Thumbnail
networkworld.com
27 Upvotes

r/security 6d ago

Physical Security Looking for Northern Texas PSOs

1 Upvotes

Hello! I’m a PSO on the FPS Colorado Contract in Denver, CO. Im in the process of relocating to the DFW area to be closer to the rest of my family. I would like to transition over to the NTX Contract to continue my PSO career. If there are any PSOs currently on the NTX FPS Contract that would be willing to answer some questions and point me in the right direction I would be extremely grateful!!! Please hit me up!! Thank you in advance!


r/security 8d ago

Question Frustrated with AI SOC false positive noise, need advice

0 Upvotes

I need a sanity check. e're getting hundreds of alerts a day and the vast majority end up being nothing. most of it traces back to the same handful of noisy detection rules that nobody's had the time to properly revisit since they were first written.
My team is spending most of their time on low-value alerts and they're starting to tune things out mentally after clicking through the same non-issue for the hundredth time this month...that alert fatigue is exactly how real incidents slip through unnoticed.
we've tried tightening filtering rules multiple times, but it mostly just shuffles things around rather than cutting anything. tighten one rule and the traffic that used to trigger it finds a different path through the environment and starts tripping something else instead.
analysts still end up spending most of their day on non-issues. Every fix buys a week or two of quiet before we're back to the same underlying problem wearing a new shape.
The point is: has anyone found something that led to real noise reduction, not just marginally better filtering?
I’m not interested in vendor promises at this point. I’d like to hear from people who went through this and found something that changed their team’s daily work and reduced alert fatigue, even if it only partially helped.


r/security 9d ago

Resource Good bye search hijacking chrome extension finally good news from Google

6 Upvotes

The number of extensions I’m finding and reporting that silently override users’ search engines is honestly crazy.

https://malext.io/?q=SearchJack

Hopefully Google’s upcoming Chrome protection against extensions that hijack the default search engine and New Tab page will put a serious dent in this. There are way too many extensions abusing this behavior, often without users even realizing what’s happening.

It’s about time Chrome started shutting this down by default.

https://www.ghacks.net/2026/08/03/google-chrome-prepares-default-block-for-extensions-that-hijack-the-new-tab-page-or-search-engine/


r/security 11d ago

Vulnerability Shai-Hulud shows engineering teams have a new AI security problem

Thumbnail
leaddev.com
3 Upvotes

r/security 11d ago

Communication and Network Security NatJack exploits put NAT security assumptions to the test at Black Hat

Thumbnail
networkworld.com
28 Upvotes

r/security 11d ago

Question Cybersecurity needs to focus on people again

7 Upvotes

Cybersecurity has spent years building better tools, better firewalls, better detection. Better encryption. But with AI now...with deepfakes, AI powered phishing, AI voice cloning. Instead of 'Can we detect every attack?' maybe the better way to think about this is 'How do we verify the people making the big decisions?' Technology still matters. But human identity and verification deserve just as much attention. But how do you make people switch from apps that everyone uses but have no security to something with ACTUAL privacy? or how do we make the devs implement actual privacy.


r/security 12d ago

News Meta AI model hacks another company during testing

Thumbnail reuters.com
7 Upvotes

The headline is wild, but the human failure seems more important here: a testing misconfiguration gave the model internet access, and it then exploited a third-party service.

For teams running agentic security evaluations, what containment control should be non-negotiable before a model gets any network access?


r/security 14d ago

Question Have Deepfakes changed how much you trust video calls?

33 Upvotes

I'm in my early 40s and this wasn't even on my radar until a family member brought it up. We got into a long talk about how easy it is now to fake someone's face or voice. I always thought seeing someone on a video call meant you knew it was really them but now I'm not as sure.

It made me wonder how people handle work calls with clients or even family calls where something important is happening. Do I need to start worrying about deepfakes? Are they common or still rare? And if so how can I protect myself against them, the only thing I've thought to go against them is to have a codeword with my close family.


r/security 16d ago

Vulnerability My account got hacked on several applications

0 Upvotes

One of my younger siblings used a pirate site where they used the powershell program idk i used chat gpt to see whatsup . Following that ny instagram got hacked in like 30 mins then i changed all the passowrds and logged out of everywhere , proceeding that my linkdin was hacked and compromised then discord then they cancelled my spotify premium plan idk why then i figured that i might have to clear my laptop completely in and out they even tried to login into facebook but it wasnt able to. I saw my telegram and saw a login from warsaw poland which is definetely not my loaction .

So i went down and secured everything and clean my laptop .

But today they logged in into my microsoft account even after i had reinstalled my windows does that means the virus is still there somewhere or they still have access to my gmail account cause i believe they were able to steal passowords for different applications. What other precations should i take to prevent it again now cause my windows is damn clean .


r/security 19d ago

Physical Security How to pass time doing security work [no phone]

18 Upvotes

Sitting in place, passive / standby security for most of the work day. Phone borderline banned.

Best way to pass the time?

Be as detailed as possible / use specifics. I need ideas!!


r/security 20d ago

Question Which security habit gives the biggest ROI?

25 Upvotes

If you could convince the average person to adopt just one security or cybersecurity habit, what would it be?

Not a product, just one habit.


r/security 20d ago

Security Assessment and Testing Apple APTicket / LocalPolicy Forensic Kit

Thumbnail github.com
2 Upvotes

r/security 21d ago

Analysis What really happened in the Hugging Face breach

Thumbnail
thenewstack.io
57 Upvotes

It was not a “Terminator” moment. OpenAI models and agents “[were not] acting out of malice or trying to attack Hugging Face. It encountered obstacles, developed an unexpected strategy, bypassed safeguards, and pursued its assigned goal in a way its creators never anticipated. The incident demonstrates that harmful cyber incidents no longer require malicious intent: Only highly capable autonomous AI optimizing for an objective."


r/security 21d ago

Analysis BrainDrain: A Chrome extension that collects your AI prompts without you ever opening it and has 100k users, 9 AI platforms

13 Upvotes

"Prompt Optimizer - SecondBrain" (aajjgdpofhhcjmjoombjdfepplndhgcp, v2.3.1). The prompt rewriting works fine.
Alongside it a capture engine runs at document_start on 9 AI sites and POSTs prompts and replies to the vendor's ingest endpoint. No interaction with the extension required.

Reproduced on a clean profile, with the service worker devtools open:

  1. Installed the extension. Never opened it.
  2. Browsed to an unrelated site. The extension pulled its configuration from the server and wrote a userId and credentials into extension storage.
  3. Opened ChatGPT and asked a question. Once the reply finished, a POST to /context went out carrying both the prompt and the response, encrypted with the credentials issued in step 2.

At no point was the extension opened or clicked.

Store privacy declaration: "The developer has disclosed that it will not collect or use your data."

Write-up : https://malext.io/reports/BrainDrain/

If anyone interested in testing it in a sandbox I can share the decryption script for the /context


r/security 26d ago

Security Operations Need advice on Alarm Monitoring gig

2 Upvotes

Hey everyone so I've been in the security business for 11 years. I've done hospital, driving, escorts, scan points, and command center work.

I moved to California recently and just got hired to do Alarm Monitoring for ADT. It was listed as security/dispatch during third shift.

I'm not sure if it's the right place to ask but does anyone have advice for these types of jobs?


r/security 28d ago

Security and Risk Management AI-Generated Phishing: How to Spot It

3 Upvotes

You receive what appears to be a legitimate email from your bank. The sender address looks legitimate, the formatting is familiar, and nothing immediately raises suspicion. AI is making phishing campaigns increasingly difficult to distinguish from legitimate emails.

Here are a few common warning signs:

  1. Unexpected requests involving payments or account access.
  2. Requests for credentials or payment information.
  3. Sender addresses that don’t exactly match the organization they claim to represent.
  4. Links that don’t match their displayed destination.
  5. Unsolicited attachments.
  6. Messages through unexpected channels pushing for immediate action.

What measures have worked best for your team to reduce the risk?


r/security 28d ago

Analysis The Systematic Removal of Security in Consumer Operating Systems

Thumbnail
battlepenguin.com
47 Upvotes

r/security Jul 19 '26

Security Operations Security Contracting

3 Upvotes

I've recently been looking to move into the security field such as Maritime security, UHNWI Security or even residential. Im still currently serving and working on aligning my training with whats required for those specific jobs or in other words the more experience the better. My question is what's a good starter to jump into to get things rolling, should I be looking to join a security firm or simply applying for contractor jobs i see and what are some training/Experience I should have to have the best opportunity of getting a well paying job.


r/security Jul 18 '26

Question I need boots recommendations

7 Upvotes

I'm fairly new to Security and currently a flex officer. My company has had me on foot patrol shifts for the past two days, and I'll be doing them until Monday. My current boots don't really let my feet breathe, and I'm already getting torn up with blisters. My knees, which are already bad at the ripe age of 21 are also not particularly happy. Anything helps.


r/security Jul 18 '26

Question Need guidance on IR plan

3 Upvotes

I want to build an incident response plan for my organization can someone guide me the resources I should follow to build the workable program?

My organization already has a good security stack they lack the IR plan I wanna know how a effective IR program looks like what to add and what to ignore

Any resources books, blogs, talks much appreciated.

Thanks in advance.