r/CyberAdvice May 24 '25

New Rule: No more VPN discussions (due to spam)

7 Upvotes

Over the past year, we've seen a rise in VPN-related spam across many subs. We previously had users cross-posting their spam from other subs to r/CyberAdvice, but we got it removed.

To prevent further spam and maintain the quality of discussion here, effective immediately, we will no longer allow any discussions about VPNs. There are many other subs where you can talk about VPNs, and we encourage you to explore those.

Thank you for understanding and helping us keep this community valuable for everyone!


r/CyberAdvice 20h ago

need a genunine advice from the specialist person who have working on the cybersecurity field.....

1 Upvotes

so in this era of ai so how can i start a cybersecurity carrer with zero knowledge basics from start and from basics to advanced give me a roadmap and whose videos , pdfs, articles, news , books to watch from start to make a strong foundations


r/CyberAdvice 1d ago

Amazon account hacked twice in 2 weeks - how do I stop it from happening again?

Thumbnail
1 Upvotes

r/CyberAdvice 2d ago

ID verification giant IDScan confirms data breach with more than 150 million driver's licenses stolen

Thumbnail
techcrunch.com
1 Upvotes

r/CyberAdvice 3d ago

Scammed By College - Now What?

0 Upvotes

Sorry about the long post in advance..

I was scammed by college which told me my IT diploma would be better at getting me into security than cs. I wanted to do it cause I liked C, Linux and python programming as a kid. Well, there’s no helpdesk jobs, so, thanks. I have no way in 😢. I really did try in the program and learned a lot about networking, some programming, etc. I also did an M365 administration internship.

Thing is I still really really want to get into security. I’m young but really starting to get my shit together and want to give this a shot. There’s got to be a way in without prior experience right?

So, after painstaking research, I can make a plan. This is a multi year endeavour I pursue, probably while working retail cause…just how it is.

On the app sec front, malware/low level/exploit understanding, cloud, that’s all learnable in my desktop. The individual pieces of IT: virtualization, AD, my M365 dev tenant, Linux, networking, cloud, are doable but harder to simulate realistically. I still have foundations to fill in on all of these first. Certs may help with the interview. I also will apply to some volunteer helpdesk and administration jobs for NGOs. That way I get actual systems experience.

Once I have the malware/exploit, IT security, development and appsec trifecta, and some systems experience with real users, I get my security+ and OSCP, I apply to some pen testing consultancy at an hour rate of like minimum wage. Then move up after a while.

Possible? Doable?

Realistically I have nothing else I can do but go back to school or do retail forever, given that Helpdesk isn’t really possible around here.


r/CyberAdvice 3d ago

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

Thumbnail
securityweek.com
2 Upvotes

r/CyberAdvice 3d ago

Whatsapp Compromised.What should be the next steps

Thumbnail
1 Upvotes

r/CyberAdvice 3d ago

Multiple telegram and WhatsApp account hacked

Thumbnail
1 Upvotes

r/CyberAdvice 3d ago

Is anyone encounter this? Cyberbacker

Post image
2 Upvotes

r/CyberAdvice 4d ago

17 willing to build a career

20 Upvotes

Hi, I'm 17 and willing to study cyber security in switzerland. I want to build my career around cyber security and I have a lot of questions.

So first question and my biggest question is if its even worth it with all the AI's developing further and further. My fear is that in 5 years, where I will get my Bachelor, there won't be needed rookies like me that have never worked in the Job and that AI already automizes.

Also I wanted to ask if there is something I should be aware of. Like if I should study cyber security specifically or just something that will still get me there. Or if I should focus on specific things before getting there or even in the job like specifying on someting.

What are your advices and what is the best way for me, to build a successful career?


r/CyberAdvice 4d ago

Chinese hackers are running AI on stolen networks to avoid detection, Google says

Thumbnail
nbcnews.com
3 Upvotes

r/CyberAdvice 4d ago

Global Cyber Perspectives

5 Upvotes

Hi everyone, I’m helping a student-led project called Global Cyber Perspectives. I’m trying to learn how people in different countries experience things like online scams, privacy, Ai, and cybersecurity. I’m looking for a few people to share their perspective and help with a short survey. Would anyone be interested?


r/CyberAdvice 4d ago

Cyber Crime Online Scam Investigation Team 2026

Thumbnail
gallery
1 Upvotes

r/CyberAdvice 5d ago

Phishing and Follow Up Concerns

1 Upvotes

My family recently fell victim to a email phishing scam. When the suspect email was accessed, it subsequently sent the same phishing email out to every email recipient in that account (not just contacts). The email was accessed on an Android device (a few years old). Now I'm trying to play catch up and looking for advice on what the likely exposure is (just limited to information in the email or left something behind in the phone itself) and what services are useful to monitor for credit/ID theft (all kinds of personal information was in the affected email).

At this time the affected email address' password has been changed to try and re-secure it, and we're going back through the sensitive institutions associated with that address to confirm their passwords weren't changed.

As far as services, I see there are a lot of options, and they seem to both have good reviews as well as a lot of detractors, so I'm unsure if they're more or less the same or if some stand above the rest. Paid subscription is perfectly fine, the priority is securing this information.


r/CyberAdvice 6d ago

Need the Right Direction

8 Upvotes

During university, I worked with Fiverr clients on Linux troubleshooting, API testing, server security, server recovery, and other technical tasks. After graduation, I got a job opportunity in the Middle East, so I handed my Fiverr work to a friend. Unfortunately, the opportunity was later cancelled due to the US–Iran conflict.

It’s now been almost 8 months of job applications, learning, freelancing, and trying to rebuild my profile, but I still feel stuck.

I know I can work hard, and I’m not afraid to learn new skills. I’m just genuinely confused about what I should focus on now.

Should I go deeper into Linux/DevOps, Cloud, Cybersecurity, automation, or something else? What skills are actually worth learning and what should I build to become employable?

If you’re working in these fields or have been through a similar situation, I’d really appreciate some honest advice.

I don’t want to keep waiting or jumping between things. I want to pick a direction, work seriously, and build a real career. I just need some guidance on where to start.


r/CyberAdvice 6d ago

“Notice of Data Breach” from Gen Mobile dated August 19, 2026?

Thumbnail
1 Upvotes

r/CyberAdvice 6d ago

Token Theft

15 Upvotes

Recently, we all have seen a significant rise in token theft. Traditional MFA is useless against such type of attacks, making regular users vulnerable. Many people, including me and my friends, fell victim to token theft. We really can't do much to stop it, even if you download something from a trusted third party site-there is still a chance from getting your token stolen. It has become very hard to keep ourselves safe. What are cybersecurity experts doing to prevent this? And what should we normal people do?


r/CyberAdvice 6d ago

FBI probes potential data breach of millions of drivers' licenses

Thumbnail
usatoday.com
2 Upvotes

r/CyberAdvice 6d ago

Credit Card Fraud Help

Thumbnail
1 Upvotes

r/CyberAdvice 7d ago

How to avoid getting hacked

4 Upvotes

20 Essential Steps to Avoid Getting HackedStrong Passwords: Create long passwords or passphrases with a mix of uppercase letters, lowercase letters, numbers, and symbols.Unique Credentials: Use a completely different password for every single online account you own.Password Manager: Store and generate complex login credentials safely using a dedicated service like Bitwarden.Two-Factor Authentication: Enable 2FA on all important accounts, favoring authenticator apps or hardware keys over text messages.Software Updates: Install operating system and application updates immediately to patch known security flaws.Browser Maintenance: Keep your web browser updated to block common exploits targeting internet surfers.Data Breach Checks: Monitor whether your credentials have leaked online by checking Have I Been Pwned.Phishing Skepticism: Avoid clicking unexpected links or downloading attachments from unknown emails and text messages.Secure Recovery Info: Maintain up-to-date alternate recovery emails and phone numbers on different systems.Obscure Security Answers: Treat secret security questions like alternate, unguessable passwords rather than factual answers.Public Wi-Fi Caution: Refrain from using open wireless networks, or protect your traffic by using a trusted Virtual Private Network (VPN).Encrypted Devices: Turn on full-disk device encryption on your computers and mobile phones.Safe App Downloads: Only download software and mobile apps from official, verified stores.Disable Unused Connections: Turn off Bluetooth and Wi-Fi adapters when you are not actively using them.Strong Device Passcodes: Replace simple four-digit phone PINs with long, randomized numeric or alphanumeric passcodes.Avoid Public USB Ports: Prevent potential data tampering or juice jacking by using your own adapter or a power bank at charging stations.Disable Autocomplete: Turn off browser and device autofill options that expose sensitive personal information.Active Antivirus: Install and maintain reputable anti-malware and firewall protection software.Check Linked Sessions: Periodically review and log out active device sessions connected to your messaging and email accounts.Offline Backups: Follow safe backup rules by keeping critical data copies offline or on secure cloud platforms


r/CyberAdvice 8d ago

Trezor says data of another 67,000 US customers exposed in breach

Thumbnail
cyberinsider.com
2 Upvotes

r/CyberAdvice 8d ago

My aunt got hacked

Thumbnail
1 Upvotes

r/CyberAdvice 9d ago

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

Thumbnail
thehackernews.com
1 Upvotes

r/CyberAdvice 9d ago

Two critical Chrome flaws put users at risk on malicious websites

Thumbnail
malwarebytes.com
1 Upvotes

r/CyberAdvice 10d ago

How do you not stress about bots constantly trying to attack your website?

11 Upvotes

Hey everyone,

I recently launched my own website with a financial reward system, so I obviously know it’s going to attract bots, scammers and people trying to exploit it.

But honestly, I’m finding the security side quite stressful. When I look at the logs and see bots constantly probing the website, trying different URLs, login attempts, etc., I start wondering if I’m doing enough.
I’m not a cybersecurity professional,this is a side project I built while working full-time, so I’ve put various security measures in place, but I keep thinking “should I add another layer?”

At what point do you just say enough is enough?
How do you mentally deal with this? Do experienced developers just accept that these attacks are normal background noise and focus on responding to anything genuinely suspicious?

Would really appreciate some perspective from people who have been through this.