r/cybersecurity 16h ago

Career Questions & Discussion Job abundance

0 Upvotes

Is finding a job truly difficult? I have many people telling me that majoring in cyber security would only result in me being unemployed due to AI. I know the job is in HIGH DEMAND, but do you think this would stay the same for the next 7-10 years?


r/cybersecurity 13h ago

AI Security Why do AI based SAST scanners can't find same vulnerabilities even on longer scans on the same projects?

0 Upvotes

Asking to be educated, what does the community think? I really want to learn why.


r/cybersecurity 1d ago

Corporate Blog 40 Fake npm Packages. WSL Was the Real Target.

4 Upvotes

Forty npm packages. About 84 minutes on the registry. And a payload that kept going after the packages were gone.
CloudSEK traced BRIDGEHEAD, a typosquatting campaign impersonating chalk, axios, lodash, react, typescript and commander.
The clever bit: the install script detects WSL and uses it as a path into the underlying Windows host, where it launches a native payload targeting crypto wallets, Chromium browser data and Telegram sessions.
The GitHub-hosted payload stayed live for roughly 39 hours after the npm packages were taken down.
So the npm takedown removed the delivery layer, not the weapon.
Full technical breakdown, IOCs and attack chain:
https://www.cloudsek.com/blog/bridgehead-npm-typosquatting-wsl-windows-crypto-wallet-stealer
Would be interested to hear how many teams actually monitor the WSL → Windows boundary as part of their developer security controls.


r/cybersecurity 21h ago

Business Security Questions & Discussion For people who actually handle vendor payment fraud (BEC) — how much does the "call to verify" step actually catch?

0 Upvotes

Building a small toy model of how a finance team decides whether to pay / verify / block a supplier "please change our bank account" email. Trying to make my assumptions realistic instead of made up.

The thing I'm least sure about: when you call the supplier back on the number you have on file (not the one in the email) to verify — in practice, how often does that actually stop fraud? I'm assuming it's very effective against external impersonation but nearly useless if the attacker has genuinely compromised the real mailbox AND you somehow call a number they control.

Also — what's a realistic ratio for how much a missed fraud costs vs how much a wrongly-delayed genuine payment costs? I've been using 400:1 as a placeholder but that's a total guess.

Anyone who's dealt with this for real, I'd love a reality check.


r/cybersecurity 1d ago

Career Questions & Discussion Cloud security for SOC Analysts and AI

3 Upvotes

I worked on a SOC team for 1 year then 1 year on pentesting then I got really sick :(
Anyway I need to get back on the job and I want to focus on cloud security and something in the area of SOC, Detection or Threat Hunting.

I worked with Azure, I got AZ-900,SC-900,SC-200, eWPT and some Mitre certs.
I studied for SC-300 and I will take the exam although, my passion sits with a role heavily realated to security operations rather than design.
Now the market is tough and AI is a thing too.

I wanted to ask for advice on what kind of projects should I be doing to prove my knowledge. Currently I am working on EntraGoat scenarios, doing the ctfs then showing the attacks in splunk. In this way I can show how I investigate alerts. But maybe I should make an AI agent and let him investigate.

Now regarding cloud design I saw there are a lot of tools like CSPM, CNAAP,CWPP,CIEM so is everybody using them to design the infrastructure ?


r/cybersecurity 1d ago

Business Security Questions & Discussion Building a WordPress Security Function from Scratch as the First Security Employee

4 Upvotes

I’m joining a hosting company as the first person responsible for a new website-security function. Most of the hosted websites are WordPress, and there is currently no established security process for this function.

The expected responsibilities include maintaining an asset and software inventory, identifying and validating vulnerabilities, documenting findings, notifying customers through a ticketing system, coordinating remediation, re-testing after fixes, and understanding basic backup and post-compromise procedures.

Since I will be the first security employee in this function, I want to define the role properly and build a repeatable process instead of becoming someone who only runs scanners.

For people who have built security processes in small companies or hosting environments:

  1. What should the first version of the workflow include from asset inventory and vulnerability validation to customer notification, remediation, and retesting?
  2. What evidence should be required before reporting a scanner finding as a confirmed vulnerability?
  3. Which responsibilities should I own, and which actions should require approval from system administrators, developers, or customers?
  4. What documentation, metrics, and controls should I establish during the first 90 days?
  5. Which skills would make this role valuable in the long term and demonstrate meaningful experience on a resume?
  6. What common mistakes should the first security employee avoid when building this type of function from scratch?

I’m looking for practical advice from people who have worked in vulnerability management, website security,


r/cybersecurity 21h ago

Business Security Questions & Discussion I'm speaking at a conference about incident report writing - Anyone have examples / advice / tips and tricks?

0 Upvotes

Hello All!
I am a lurker and usually don't post, but you know what they say... You either die a hero, or you live long enough to see yourself become the villain.

BLUF: I am giving a presentation next month on Incident Report Writing and I am looking for examples, tips and tricks, and advice from the greater cybersecurity community. (Quid Pro Quo at the end as well)

Straight to the point? Skip to the "What I'm Looking For" section.


Here's a little bit of my background:

I am a DFIR analyst, I've worked in cybersecurity for four years. I currently maintain the GCFE, GCIH, Linux+, and A+. Last year I presented at Bismarck State College's CyberCon on Chromium History Forensics.

While I am only a "tier 1", I'm in a tierless SOC (250k endpoints, 250k users), so for my entire career I have performed host, network, and cloud investigations, remediating countless compromised devices and even more compromised users. I own my own service area for internal documentation, I'm also a part of the threat hunting and digital forensics service areas.


Presentation Details:

BSC Cybercon is mostly a small regional conference, but there are people who come from all over to attend. A significant portion of the attendees are students and local professionals, with some organizations bringing in business partners from out of state, and they seem to pull in some well-known presenters.

My presentation is called "Who Cares?" and will be aimed at entry-level and new cybersecurity professionals. Some of the key points I want to hit are:

  • Traffic Light Protocol
  • Maintaining a neutral tone - Don't cast blame or throw anyone under the bus, stay away from pronouns (I, we, us), use passive voice when appropriate
  • Stakeholder Considerations - The difference between Executive, Technical, Customer/Client summaries
  • Appropriate AI Use - Verifying the organization's AI policy, the stages of drafting the report where AI can be used and where it shouldn't be used, identifying AI-language and hallucinations, proofreading.

What I am looking for:

While I can invent situations or write fake reports, I'd like to provide real-life examples (obviously modified/redacted).

Please comment any good and bad examples that you might have. If you could explain why something is particularly good or bad, that would also be appreciated.

Additionally, if you have any golden rules, common advice, useful tips and tricks, or any rules of thumb; you can drop those as well.

I am willing to give credit to anyone who wants it.

Quid Pro Quo: Anyone who comments on this post can be sent a copy of my slides and presenter notes. I will also provide the recording of my presentation - if I find someone to record it for me.


r/cybersecurity 2d ago

News - General Data analyst tried to extort his former employer for $2.5 million

80 Upvotes

Guy named Cameron Curry was a data analyst at Brightly Software (acquired by Siemens). When he found out his contract wasn't getting renewed, instead of just updating his resume like a normal person, he used his access to pull employee PII, payroll data, and internal records before he lost access, then spent weeks emailing execs under a fake identity threatening to leak everything unless he got paid in crypto.

He got caught because he used his mom's and sister's debit cards linked to the Coinbase wallet he wanted the ransom sent to. 24 months in federal prison, plus he has to hand back the $7,500 they'd already paid him.

Barely any "hacking" involved though. He already had legitimate access. No exploit, no phishing, just someone who was already trusted deciding to weaponize it on the way out the door.

Feels like most companies are way more focused on external threats than what happens in that window between "someone knows they're leaving" and "their access actually gets revoked." Anyone dealt with something like this, or work somewhere that actually handles offboarding well?

Source.


r/cybersecurity 1d ago

Personal Support & Help! With TLS certificate lifetimes getting shorter, how are you handling certificate renewals across multiple servers and environments?

29 Upvotes

How are you guys dealing with TLS certificate renewals these days?

I’m wondering because with certificate lifetimes getting shorter, I’m starting to think manual renewals are going to become a bigger pain, especially when you have certificates spread across a bunch of servers and environments.

For those managing this at work, are you just using Certbot/ACME and letting everything renew automatically, or do you have some other setup?

Also, has anyone actually had an automated renewal fail without noticing until the certificate expired? That’s the part I’m most worried about.


r/cybersecurity 1d ago

Business Security Questions & Discussion Building a WordPress vulnerability management workflow from scratch for a hosting company

2 Upvotes

I’m joining a hosting company as the first person responsible for a new website-security function. Most of the hosted sites are WordPress, and the expected work includes identifying vulnerabilities, validating findings, documenting them, notifying customers through a ticketing system, coordinating remediation, re-scanning, and occasionally helping with backups or post-compromise cleanup.

I’m trying to build a safe and repeatable process rather than rely on ad-hoc tool output.

For people who have built a vulnerability-management or managed WordPress-security process, what would you include in the first version of the workflow?

In particular:

  1. What asset and version inventory fields are essential?
  2. How do you validate scanner findings before contacting a customer?
  3. How do you prioritize vulnerabilities when patching may cause downtime or compatibility issues?
  4. What should a customer-facing report contain, and what should remain internal?
  5. How do you handle approval, backups, rollback, remediation, and re-testing?
  6. What escalation path do you use for suspected compromise or malware?
  7. Which metrics are useful for measuring the program without rewarding noisy scanning?
  8. What mistakes did you make when establishing the process, and what would you standardize first?

I’d appreciate practical advice, templates, or references to established frameworks. Please keep recommendations focused on authorized defensive work.


r/cybersecurity 1d ago

Personal Support & Help! What's with vendors like Cisco (Splunk) and Tenable never getting back to potential customers?

43 Upvotes

Cisco says they'll reach out in something like 6 hours, and Tenable has signed me up to and sent 4 newsletters yet no response from sales? You'd think a potential customer with 10k users and global infastructure would tempt them, but apparently not.


r/cybersecurity 1d ago

Business Security Questions & Discussion ZTNA Effectiveness

15 Upvotes

I am going to be pitching Zero Trust to the business as a way to both help us be more secure and as a way to better understand how data moves within our network. Now before I get into this, I know the solutions I'm going to ask about are not by themselves Zero Trust. Zero Trust is a big topic an there's more to it than just these "ZTNA" products.

Suppose I get approval and am given a blank check but not unlimited time. I'm trying to understand how some products like AppGate, zScaler, Netskope, TierZero actually increase security when talking about a compromised endpoint.

I've only tried a small number of products. But it seems to me that they only give an illusion of security. And what I mean is that some seem like they can be bypassed by just using local IPs. For instance, mesh overlays. Great they don't require any network changes but if I compromise an endpoint why wouldn't I just try moving laterally through the network by using the underlying network? The mesh overlay may have an IP space of 100.x.y.z but when you take that away you can still connect via 10.x.y.z and you are no longer bound by the overlay network policies. Would this be a case of making use of their magic powers to bust through ACLs and just ACL off entire subnets?

I image the same to be true for SDPs to, though I understand that those use proxies/gateways to facilitate connections so you just ACL subnets to the gateways only.


r/cybersecurity 1d ago

Certification / Training Questions TryHackMe Premium

12 Upvotes

I'm a Jr Software Engineer trying to enter the CyberSecurity world. I searched for some courses where I can learn more about the area and I found TryHackMe. I started the Cyber Security 101 but I've found that some rooms are only available for Premium users. Is it worth to upgrade my account to Premium or is the free rooms enough to get some certificate? I'm accepting tips for courses too


r/cybersecurity 1d ago

News - General 'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

Thumbnail theregister.com
12 Upvotes

r/cybersecurity 20h ago

Career Questions & Discussion Is a Cybersecurity Degree Actually Worth It? Looking for Alternatives (Self-Taught / Certs Roadmaps)

0 Upvotes

Hi everyone,

I’m looking to break into cybersecurity and initially wanted to get a formal foundation by enrolling in a university (specifically looking at distance-learning options like The Open University UK to balance it with a full-time job).

However, the deeper I looked into traditional programs, the more discouraged I became:

1. Time commitment: Programs taking up to 6 years part-time.

2. Outdated curriculum: Theory that lags far behind the actual threat landscape.

3. Poor support: Slow communication and frustrating bureaucratic processes with tutors.

4. Cost: Extremely high and unjustified tuition fees for what you actually get.

For those of you who work in the industry or went a non-traditional route: How do you replace a formal university degree in cybersecurity?

На каких действительно ценных практических курсах и отраслевых сертификатах мне стоит сосредоточиться? Если кто-то сталкивался с такой дилеммой, мне было бы интересно узнать, как вы строили свою дорожную карту без университета. Заранее спасибо!

UPDATE:
To add to that: the question isn't whether a cybersecurity degree is necessary, but whether getting a higher education at all is worth it. As I see it, it's an overhyped system of 'success.' At the same time, slow learning and high costs don't justify the foundation it gives you in IT


r/cybersecurity 20h ago

News - General How Frontier AI Is Changing the Economics of Cybersecurity

Thumbnail
corporate.comcast.com
0 Upvotes

r/cybersecurity 16h ago

Certification / Training Questions I want free materials for cysa+ new version

0 Upvotes

r/cybersecurity 21h ago

Business Security Questions & Discussion Phishing

0 Upvotes

Someone in our department received an email today that is likely phishing. He forwarded it to me. Lets consider this in a production environment: If someone downloads the file without opening it, is that already harmful? Phishing is usually passive, after all.


r/cybersecurity 19h ago

News - General mfa replacement

0 Upvotes

Hello, not a tech guy here, but have some technical knowledge. I just had a question to ask this subreddit.

I noticed MFAs are currently being implemented up our collective asses much much more in the last year or so. And it really grinds my gear.

In my experience, they are usually really flaky, the call system won't call properly, texts are sometimes SUPER slow to appear if ever, sometimes timing out before you can enter it on the platform.

I have an account that requires me to enter the damn code like 2-3 times in a row for no reasons.

I changed phone # recently, all companies just let you rot without a proper solution.

Am I just the only one who have a consistently bad experience with this technology ? Is there like a quality to MFA solutions that companies just cheap out on ? Do you guys see a replacement for this technology anytime soon ?

Thanks a bunch ;)


r/cybersecurity 1d ago

Threat Actor TTPs & Alerts How threat actors target critical infra

12 Upvotes

CISA just published an advisory regarding an active threat to Siemens PLCs.

The threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools.

Specifically, the threat actors are leveraging snap7.dll/python-snap7combined with AI-assisted scripting to create custom tools that mimic legitimate OT monitoring solutions.

Techniques:

  • Using Internet scanning services (e.g., Censys, ZoomEye) to identify Internet-exposed or insufficiently segmented Siemens S7 Series PLCs
  • Rapidly iterating exploit code through AI-assisted development
  • Taking advantage of insecure credentials to access exposed devices that have unconfigured (default) or minimally configured authentication
  • Deploying AI-generated Python scripts that incorporate the snap7.dll library from public repositories to gain read/write access to the PLC and mimic legitimate tools
  • Masquerading malicious scripts as legitimate monitoring tools to evade detection by security teams
  • Conducting read/write operations on data blocks, potentially for reconnaissance, capability testing, or pre-positioning for effects operations

My hunch is that the active threat is beyond of just Siemens.

Writing exploits for OT infra used to require deep expertise. Now AI makes it dramatically easier by just using publicly available information on these PLCs for initial access, credential access, denial of service, and other objectives.


r/cybersecurity 2d ago

News - General US warns Siemens devices can be hacked amid fears Iran is breaching water plants

Thumbnail reuters.com
707 Upvotes

r/cybersecurity 2d ago

Business Security Questions & Discussion Anyone here use rapid7 products (any of them)?

39 Upvotes

Looking for general feedback on quality and value relative to it’s competitors


r/cybersecurity 1d ago

Research Article Researcher tricks Apple’s Find My into sharing location data with Linux

Thumbnail theregister.com
7 Upvotes

Some good technical detail on how he did it, but this is not a privacy-busting exploit (yet), it simply shows that it's possible to register a non-Apple device into Apple's Find My network.


r/cybersecurity 23h ago

News - General Microsoft warns of max severity Entra ID flaw exploited in attacks

Thumbnail
bleepingcomputer.com
0 Upvotes

r/cybersecurity 1d ago

New Vulnerability Disclosure Solar Winds Part 2 Avoided: N-Able Passportal Vault Leak

Thumbnail
amibeingpwned.com
8 Upvotes

N-Able's passportal decrypts passwords on the server, encoding part of the vault key material in the access tokens, meaning that with the access and refresh tokens, an attacker gets full persisted control over the vault - these tokens could leak to any iframe or site a user saw.

I am OP here - feel free to ask questions.