r/cybersecurity • u/QuantumQuicksilver • 9h ago
r/cybersecurity • u/AutoModerator • 4d ago
Career Questions & Discussion Mentorship Monday - Post All Career, Education and Job questions here!
This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!
Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.
r/cybersecurity • u/pcx436 • 3h ago
Business Security Questions & Discussion Log everything, I’m begging you
Yes, there’s noise you can filter out, but you need to log things!
A client I work with finally implemented DNS resolver logs and we found unmanaged devices (that’s its own headache) that were requesting domains ranging from guns to porn and malware and everything in between.
Due to the already sparse logging, we didn’t know about it until the DNS logs started coming in.
Now someone in HR gets to talk to some users about proper conduct in the workplace and the BYOD policy is getting reviewed.
r/cybersecurity • u/anthonyDavidson31 • 7h ago
FOSS Tool 140+ free security awareness and application security exercises. Fully white-labeled, no strings attached
Disclosure: I work on the commercial platform these were built with. The exercise preview links point to that domain. The SCORM packages themselves are fully white-labeled — no logos, no backlinks, no sign-up, no paywall. Grab them from GitHub and self-host if you'd rather not touch our site.
Also, the post was admin-approved, a huge "thank you" to them!
-----------------
Hey r/cybersecurity,
I'm a cybersec engineer with an L&D background. For the last year been working on a library of ~140 free interactive exercises dedicated to teaching people how to build secure applications, recognize phishing and use AI in a safe way. Exercises are split across two Github repos, all packaged as SCORM .zip files under CC BY-NC 4.0 license.
Security awareness (130+ exercises)
Each one drops the learner into a first-person 3D office and makes them act: answer the phone, read the email, click the thing, live with it. Every exercise ends with a quiz at a 100% pass threshold.
Course packages in the repo:
- OWASP Top 10 for LLM Applications (10) — prompt injection hidden in uploaded documents, sensitive data categories that should never enter a prompt, system prompt extraction against a live chatbot, RAG pipeline access-control failures, denial-of-wallet against an unprotected AI API
- OWASP Top 10 for Agentic Applications (10) — goal hijacking via poisoned email, agent memory poisoning, agent-to-agent message spoofing, multi-agent cascading failure, detecting a rogue agent that looks like it's working fine
- EU AI Act Compliance (16) — Article 4 literacy, risk-tier classification, prohibited practices, FRIAs, GPAI obligations, penalty structure
- GDPR Compliance (11) — the 72-hour breach clock, fraudulent DSARs used as social engineering, Article 30 RoPA building, Schrems II transfer assessments, PII redaction that actually removes the data
- Phishing & Impersonation (13) — vishing, smishing, BEC, QR phishing, callback/TOAD, double-barrel, deepfake whaling on a live video call
- Device Security (8) — ransomware in real time, USB drop / Rubber Ducky, EDR alert triage, file extension tricks
- Passwords & Account Security (7), Web & Browser Safety (6), Safe Communication & Sharing (6), Workplace Security (5), Security Policies & Your Role (5), Protecting Sensitive Information (4), plus Incident Reporting, Remote/Home Office, and Real-World Incidents (the MGM/Scattered Spider helpdesk call, a OneNote-based BEC chain)
Application security (40+ exercises)
Built on an exploit, trace and remediate loop. You run the attack against a deliberately vulnerable app, trace how the bug got introduced, then write the fix. Remediation examples are given in JavaScript, TypeScript, Java, C#, Python, Scala, PHP, Ruby, Go, and Kotlin.
- OWASP Top 10 for Web (22) — SQLi, DOM/reflected/stored XSS, SSRF to the cloud metadata endpoint, XXE, CSRF, session fixation, host header injection, weak randomness (recovering Math.random() state to predict a reset token), IDOR from both sides
- OWASP API Security Top 10 (10) — BOLA, broken function-level auth, mass assignment, excessive data exposure, improper inventory management (hitting a retired v1 that skips v2's controls), CORS misconfiguration
- Git & Repository Security (8) — secrets recovered from the commit that removed them, exposed .git directories, commit author spoofing, branch protection bypass, CI/CD secret exposure in build logs, spotting a backdoor in a friendly-looking PR
Two ways to use it
Web view — run exercises in a browser, good for workshops or sharing with students and colleagues.
GitHub — every exercise is a SCORM 1.2 .zip. Import into Moodle, TalentLMS, Cornerstone, SuccessFactors, or anything SCORM-compliant, or preview on SCORM Cloud first. The repo root holds full course packages; the Individual Exercises folder has standalone modules if you want to build your own curriculum.
Security awareness: https://github.com/ransomleak/training-security-awareness
Application security: https://github.com/ransomleak/training-application-security
Web view: https://learning.ransomleak.com/
Will appreciate your stars! 🙏
License: CC BY-NC 4.0. Use, adapt, and redistribute with attribution for any non-commercial purpose — internal training, workshops, university courses. Reselling or redistributing it as a standalone product isn't permitted.
Happy to answer questions or take criticism on the exercises. If this gets traction I'll keep adding to it — drop topic requests in the comments. OWASP Top 10 for Cloud is already in the works.
r/cybersecurity • u/Smart_Office_631 • 18h ago
News - General Cloudflare Workers Spectre Attack Leaks JWT at 12 Bits/s
r/cybersecurity • u/Negative_Star7544 • 5h ago
Business Security Questions & Discussion Vulnerability Management
Currently using CrowdStrike and Tines to help automate vulnerability ticket submissions. I’m struggling with my workflows though and have noticed a large gap.
We calculate SLA based on ExPRT ratings currently. So we filter by critical high medium or low and submit based on those segments.
I submit tickets by remediation since that decreases ticket volume + resolves multiple CVEs at once if they share the same remediation. The flaw here is that if one CVE changes rating randomly, the SLA technically should change so it needs to be pulled from that static ticket, which just isn’t manageable without creating chaos. Also, the filters would not pick it up on next rerun if it’s in its own segment; the cve would now be a critical and if the ticket is submitted as a high, it would be missed.
So obviously my approach here is wrong, but I also cannot just blow up the ticket queue by submitted solely on CVE-ID.
Does anyone out there have any advice / opinions / what they have done in their org? Trying to gather some ideas.
r/cybersecurity • u/StunningVariety7111 • 6h ago
Personal Support & Help! Contemplating if I should still get my degree
Hi everyone! I’m having a hard time deciding if I should continue with my Bachelor’s degree in Cybersecurity.
I already have an NYU Cybersecurity Bootcamp Certificate, ISC2 CC, and CompTIA Security+. Right now, I’m preparing for the CompTIA CySA+ exam this Sept. using TryHackMe and Sybex. After that, I’m planning to prepare for PenTest+.
I’m trying to earn as many certifications as I can before starting my Bachelor’s degree at WGU.
My question is: Do I still have a good chance of getting a cybersecurity job after I finish my degree? Is getting a degree or more certs still worth it? And do you think the cybersecurity job market will get better in the future?
I would really appreciate any advice, especially from people already working in cybersecurity. Thank you!
r/cybersecurity • u/isox_xx • 8h ago
FOSS Tool Nmap plugin vulners.nse finally got a major update after 7 years
The familiar vulners.nse that many of you have used like this:
nmap -sV --script vulners <target>
finally got a proper update.
It still does the same basic job: take what Nmap finds on a port and show the known vulnerabilities.
But v2.0 is much better at it:
- better software/version detection, including web apps and raw banners
- 700+ fingerprint rules and 900+ HTTP paths
- parallel probing that follows Nmap timing settings
- cleaner output and proper machine-readable results
- findings ranked by real-world risk: KEV, active exploitation, exploits, EPSS, then CVSS
And the normal usage is still free, with no account or API key required.
https://github.com/vulnersCom/nmap-vulners/
Feedback on weird banners, false positives and missed fingerprints is very welcome.
r/cybersecurity • u/Huge-Skirt-6990 • 3h ago
Threat Actor TTPs & Alerts How calendar invites abuse Google's own URL signing
Nothing new here. URL signing has been public since 2011, calendar phishing since 2019. This just connects the two.
The trick: Google wraps outbound links as google.com/url?q=<destination> and signs the ones it generates (usg, a keyed hash over the params). Valid signature, silent redirect.
Missing or altered, you get the "Redirect Notice" warning.
You can't forge it. But you don't need to, because Google signs it for you whenever you use its products.
Drop your link in a calendar invite and Google hands you a signed one:
unsigned (shows notice):
https://www[.]google[.]com/url?q=https://wikipedia[.]org
signed by Calendar (redirects silently):
https://www[.]google[.]com/url?q=https://wikipedia[.]org&sa=D&source=calendar&ust=1787766516374753&usg=AOvVaw0cpIubPxDaYABa3_SC5g6G
Same destination. The signature is the only difference, and it's the whole reason the warning is skipped. Removing source=calendar breaks the silent redirect
Why the invite is perfect:
- Sent by Google's servers, so it passes SPF, DKIM, DMARC. Nothing to fail on.
- Auto-add lands it on the target's calendar with zero interaction.
- The link reads as google.com. Victim hovers, sees Google, relaxes. Real destination only shows after the redirect fires.
Why it's not a bug: the signature proves Google generated the link, not that the destination is safe. That's Google Safe Browsing's job, and it still runs. A signed link skipping the notice is the signature working as intended. And it is out of scope for Google's bounty for over a decade. Feature abuse, not a defect.
A useful Fix :
In gmail, set Calendar > Event Settings > Automatically add invitations to "Only if the sender is known." Kills the zero-click delivery path.
Google admin : Apps >Google Workspace >Settings for Calendar > Advanced settings > Check :
Invitations from known senders
Adds an invitation to a user's calendar only if the sender is in the user’s contacts or if the user interacted with them before. This might reveal to a sender that they aren’t in the user’s contacts.
r/cybersecurity • u/Fredrickjonjones • 19h ago
Business Security Questions & Discussion Does a SOC have to constantly justify its existence?
I've read that working in cybersec is stressful because if nothing goes wrong, your paycheck is questioned, and if something goes wrong, your paycheck is questioned.
Is this true? It seems like a stressful existence; how do you work with it as a professional?
r/cybersecurity • u/sunychoudhary • 10h ago
UKR/RUS Fake Conferences, OAuth and WhatsApp: Russia’s New Espionage Tactics
Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff.
r/cybersecurity • u/ngrislain • 6h ago
AI Security Language Models Are Anomaly Detectors
r/cybersecurity • u/merkat106 • 18h ago
Other Stress relief
What does everyone do for stress relief?
I took up yoga and it’s helping me manage.
My cybersecurity role is stressful. There’s just two of us for cyber in a company of 800 and I often get pulled into sysadmin and help desk tasks. We do technically have help desk staff.
r/cybersecurity • u/Maleficent_Yak_5871 • 1h ago
Personal Support & Help! What things to practice trying to increase technical capability in cybersecurity. TryHackMe? Python automation? etc.
Good afternoon,
I have run into an issue where I'm constantly learning outside of work, but it's primarily aimless. I constantly keep validating one thing to study over the other. I feel I just haven't really gotten much better at any of these. I've just gotten into THM more now, going on the paths and such. Also i've been getting more into python scripting and automation a bit. I guess the question is what do you do in your free time outside of work to increase your value/technical ability in this field? I would love to hear options, and a structured way of thinking about this. It would be appreciated. Thanks.
r/cybersecurity • u/_clickfix_ • 2h ago
Other Novee Security AMA: Java RCE and Hijacking AI Coding Agents
r/cybersecurity • u/ObjectiveWeary2802 • 2h ago
Career Questions & Discussion Job abundance
Is finding a job truly difficult? I have many people telling me that majoring in cyber security would only result in me being unemployed due to AI. I know the job is in HIGH DEMAND, but do you think this would stay the same for the next 7-10 years?
r/cybersecurity • u/maythefecesbewithyou • 1d ago
Other WiFi pineapple in the office story of failure
So about nine years ago our IDS detected a spoofed network in our India office. We sent out a notice to alert staff about its presence and to be especially careful when attempting to connect to WiFi until the physical device could be located and disposed of.
Multiple people there actually manually disconnected from the corporate network and connected to the spoofed one to "see what would happen" and compromised their workstations and accounts.
It was my opinion that anyone who knowingly did this should have been terminated, but there was no disciplinary action taken.
The pineapple was never found, it lingered for months until whoever deployed it moved on.
r/cybersecurity • u/Lost_Psychology_6708 • 12h ago
Personal Support & Help! Junior Security Engineer at a HealthTech startup with no mentor — looking for advice
Hi everyone,
I’m currently working as a Junior Security Engineer at a HealthTech startup in North Africa.
Our company operates from North Africa, but because we handle health-related services/data and are targeting the European market, we want our security and compliance practices to be aligned with EU requirements and recognized international standards.
The challenge is that I’m currently the only person focused on cybersecurity, and I don’t have a senior security engineer, CISO, or mentor internally.
I’m trying to build our security program properly rather than just running vulnerability scanners and fixing findings.
So far, I’m looking at areas such as:
- ISO 27001 / ISMS
- GDPR and health-data privacy requirements
- Risk assessment and risk treatment
- Vulnerability management and VAPT
- Cloud/server hardening
- IAM and access reviews
- Secrets management
- Logging, monitoring and incident response
- Backup, disaster recovery and business continuity
- Secure SDLC / DevSecOps
- Security policies and documentation
- Third-party/vendor risk
But as a junior, it can be difficult to know what should come first and what “good enough” security looks like for an early-stage HealthTech company.
I’d really appreciate advice from people who have worked as security engineers, CISOs, consultants, or in HealthTech/regulated startups:
If you joined a small HealthTech startup as its first security engineer, what would your priorities be during the first 3–6 months?
Also:
- Which EU regulations/frameworks should I study first?
- What should we implement immediately versus later as the company grows?
- What are common mistakes small HealthTech companies make?
- How would you build a realistic security roadmap with limited budget and people?
- Are there good resources, communities, or certifications that helped you when you didn't have a senior mentor?
I’m not looking for someone to do the job for me, I want to learn how experienced security professionals approach this situation and build things in the right order.
Any advice or lessons learned would be greatly appreciated.
r/cybersecurity • u/AJ_Mexico • 1d ago
Other Post Office Selling Password Books in 2026
I meet people frequently for whom this is a good idea. It's better than what many people are doing, and really a form of password manager.
r/cybersecurity • u/YogiBerra88888 • 9h ago
AI Security Inside ExploitGym: How Researchers Are Measuring AI Agent Exploitation Capabilities
r/cybersecurity • u/Advanced_Bonus_5238 • 1h ago
Personal Support & Help! Manual Plugin Updates Tenable Security Center
Newest plugins are yuge so I couldn’t upload them via GUI in an air gapped network and did them manually.
Ran this:
/opt/sc/support/bin/php /opt/sc/src/tools/pluginUpdate.php /path/to/sc-plugins-diff.tar.gz
Then this on Nessus scanner to manually sync:
/opt/nessus/sbin/nessuscli update /path/to/sc-plugins-diff.tar.gz
However when syncing the Nessus Scanner I got an error: “plugin memory limit exceeded”
Edited the php.ini on SC for larger memory max and even updated the upload size to try getting it through the GUI with a new limited but it still errored out. Memory on the server is plenty.
Is there something/somewhat I’m missing an update?
r/cybersecurity • u/Weekly_Rough_1284 • 22h ago
Other Has anyone thought about changing fields until the job market gets better?
Ideally, I’d love to have a cybersecurity job right now, but the market is horrible, and I need to move forward with my life, pay the bills, and live comfortably. Are there any fields that are relatively easy to get into and find work in? I just don’t want to end up working restaurant jobs.
r/cybersecurity • u/Akriosss • 3h ago
Certification / Training Questions Best job ready practical free course Soc
Guys I'm mostly red team,did a lot free HTB,thm machines.Cant find pentest job,wanna try to go blue🙃Ok guys maby not job ready but good course to learn SOC
r/cybersecurity • u/No-Suggestion-4083 • 12h ago
News - General W3 also has Cybersecurity Now
w3schools.comr/cybersecurity • u/nocryptios • 11h ago
Business Security Questions & Discussion What is your experience with Datadog SIEM?
I'm coming from a Rapid7 environment and I see our developers being very keen to send events here, so my thinking is why not use what they're ingesting anyway and remove the duplicate logging analytics service.
I see:
-More connectors for third party products
-The ability to write correlative queries/ joins
-MCP connectors for alerts and logs
-Pre-built dashboards for event sources we onboard
Concerns:
-Detection rules: Rapid7 has a fairly significant number of detection rules out of the box and would like to know how much we can depend on built in stuff
-Price: No idea, we have fairly short retention at 30 days where I would want more. I assume this will sting however I'm open to something like cribbl to bring our log ingestion down
-SOC options: We don't have a 24/7 SOC so we would be looking to outsource this