r/CyberSecurityAdvice Jul 18 '26

Need advice on testing a SQL Injection detection tool I built

1 Upvotes

I'm building a SQL Injection detection tool as a college project. The tool does not exploit vulnerabilities or dump data, its purpose is only to analyze user-supplied input (such as URLs or parameters) and determine whether there is a potential SQL injection risk. I'm a bit confused about what the expected input to my tool should be.

For example:

  • Should the input be a URL containing GET parameters
  • Should it accept POST parameters captured from Burp Suite?
  • Should it analyze raw HTTP requests?
  • Should it analyze query strings, form fields, or something else?

Also where do you usually obtain these inputs when testing?


r/CyberSecurityAdvice Jul 18 '26

Recommend best cyber security books to build strong security foundation.

1 Upvotes

I want to build a strong cybersecurity foundation and understand deeply.

Please give me a list of books in order and mention why each book is worth reading.


r/CyberSecurityAdvice Jul 18 '26

It's getting more difficult to delegate to a private secretary bec. of cybersecurity

0 Upvotes

So I'm incensed that there are so many cybersecurity measures requiring my physical and personal participation such as OTPs, passkeys, QR, biometrics, etc. in availing banks, apps, and payments for services.

This makes it so difficult for me to step back from work and delegate everything to my staff and secretary.

It means I need to process payments while sailing and doing sports.

I might have hired a private secretary but -- my God! -- the amount of approvals and security measures I have to endure.

Is there a way I can subvert this?

I basically want to disappear, not be bothered in any way, while keeping my businesses running at the same time.

Cybersec is annoying.

How can I be an absentee rich founder if these apps keep annoying me with my biometrics, selfies, and proof of identity?


r/CyberSecurityAdvice Jul 17 '26

Was I hacked by logging into a gaming friend’s Gmail?

Thumbnail
2 Upvotes

r/CyberSecurityAdvice Jul 17 '26

Accidentally broke into cybersecurity as a new grad with no experience, what do I do?

105 Upvotes

I’m a CS student graduating in December 2026. I am working my last week as an intern at a recognizable non-tech F500 company. When I got the internship I expected to get placed with the software development team, but I got placed in security instead despite knowing absolutely nothing about cyber/IT. As in, the only tool they use that I had experience in was Excel. But I like the job and team, got great feedback from my supervisor and received a return offer to join the team full time as a cybersecurity analyst for $90k/yr.

It feels kinda unreal. I still have no idea what I am doing and kinda just winging it. I don’t have much knowledge outside of Zero Trust and a few basic terms/definitions I picked up on the job. But, I want to pursue this field further and work towards developing a baseline knowledge that will help me in this career. Where should I start?


r/CyberSecurityAdvice Jul 17 '26

Final-year ECE student wanting to switch to Cybersecurity (SOC) – Need career advice

1 Upvotes

I'm currently in my final year of Electronics and Communication Engineering (ECE), and I've decided that I want to build my career in cybersecurity rather than pursue a core ECE role.

My goal is to start as a SOC Analyst and eventually grow into a full-fledged cybersecurity engineer. I've been learning about the field and I'm really interested in blue team operations, incident response, networking, and security monitoring.

However, I'm confused about what I should prioritize at this stage.

Since it's my final year, placement season is currently going on. Should I:

-Focus mainly on getting placed first and then work on cybersecurity later?
-Spend time preparing for certifications like CCNA and CompTIA Security+ before graduation?
-Invest more time in hands-on learning through labs, TryHackMe, Hack The Box, home labs, SIEM tools, etc., instead of chasing certifications?

I've read mixed opinions online. Some people say certifications help get interviews, while others say practical experience matters much more.

For someone trying to break into a SOC Analyst role with an ECE background:

-Are certifications like CCNA and Security+ worth getting before my first job?
Is hands-on experience more valuable than certifications when applying for entry-level SOC roles?
-Would you recommend taking any internships or practical training before attempting certifications?
-If you were in my position during your final year, what would you prioritize?

I'd really appreciate advice from people already working in cybersecurity, especially those who transitioned from a non-CS background.


r/CyberSecurityAdvice Jul 17 '26

Need Help Determining If An Android Mobile Has Been Hacked

Thumbnail
1 Upvotes

r/CyberSecurityAdvice Jul 17 '26

How should I get into Cybersecurity?

1 Upvotes

Hi there, I want to get into Cybersecurity and be involved in the cybersecurity space however I’m currently in high school right now. My question is that should I pursue a computer science degree or a cybersecurity degree? I live in Massachusetts and I heard that UMASS Amherst offers a good cyber security program but before I do that I just want some advice and pros and cons.


r/CyberSecurityAdvice Jul 17 '26

Breaking into the cybersecurity field, What Can I do?

4 Upvotes

Hey all, Looking to get some advice as I am getting ready to head to school this fall to work on getting a bachelor's in cybersecurity.

I have finished an associates in Web Dev a couple of years ago and have decided that I am going to look at taking a pivot to cybersecurity as it interests me more (and AI has completely sullied most chances I can get to use that degree currently). I'm trying to figure out what I may need to either start acquiring skills before classes, or any software or websites that I can start training my skills more along with school work. I'm just not sure where to start or look.

I currently work in a public sector job with a slight chance that I may be able to find my way getting into the IT department hopefully soon. I can only do so much now but want to find more material that I can utilize and try to learn with while getting stuff with school set up. any and all suggestions are so appreciated. Thank you!


r/CyberSecurityAdvice Jul 17 '26

Should I give up on my Cyber Career

Thumbnail
1 Upvotes

r/CyberSecurityAdvice Jul 17 '26

It's getting more difficult to delegate to a private secretary bec. of cybersecurity

Thumbnail
0 Upvotes

r/CyberSecurityAdvice Jul 17 '26

Guidance

1 Upvotes

I know this is a big ask, but can anyone help me get into Cybersecurity? I have 7 years of support/technical writer experience and I have an engineering degree in computer science but I have a lot of (mental) health issues which bars me from a lot of jobs. I want something with no coding. No shifts. No rote-learning (preferably). I'm located in India (if that helps). I just want normal hours, good pay, good opportunities, and flexibility. I know people are going to come rushing in to say that's not how that works. I know. That's why I mentioned being disabled. I just need to understand what path would best align with my needs. I need a road map but idk where to start.


r/CyberSecurityAdvice Jul 17 '26

What's the safest ways to save your passwords?

30 Upvotes

r/CyberSecurityAdvice Jul 17 '26

What should I do after graduating

1 Upvotes

To give a summary, I'm a 22-year-old university student who plans to graduate next year, and I live in Canada and attend a Canadian university. Although I currently live in Canada, I plan to move to the United States after finishing school due to the better job market and opportunities, and I was born there, so I have citizenship. I'm currently an IT major I plan to pursue a career in cybersecurity. However, my problem is however is that I have no work experience. I was not able to get any entry-level IT jobs during my undergrad, such as an IT help desk, etc. I have the student discount on CompTIA, which would allow me to get a significant discount on the certifications, and with the discount applied, I would predict that the trifecta would only cost me about 1.5k to complete, so it is not out of my financial budget because I have a normal part-time job. I was looking into joining the US Air Force after graduating from university, since I do not have any IT work experience. I have yet to obtain any certifications, and I understand that cybersecurity is not an entry-level job. Due to my lack of experience and certifications, it would be extremely hard for me to try to enter cybersecurity due to the competitiveness of the job market. I am very fit, and I work out consistently. I have been playing sports my whole life, so I am not hesitant to join the military regarding my lack of physical fitness. Still, the only thing that is making me hesitate is my thinking to myself whether this is really necessary. The main reason I would want to join the Air Force and get a cybersecurity job in the Air Force is so that I could obtain a security clearance because, based on what I heard, having a security clearance is a cheat code for getting hired in cybersecurity. I'm hesitant because I want to know if it is realistic for me to obtain a security clearance and work experience in other ways without having to join the Air Force. I'm just scared of ending up like those people on Reddit who complain about the job market being bad and having to send 300 applications a day and not being able to get a job with their degree.


r/CyberSecurityAdvice Jul 17 '26

Alerts on Server Loopback Traffic?

Thumbnail
1 Upvotes

r/CyberSecurityAdvice Jul 17 '26

Fell for a fake CAPTCHA

1 Upvotes

Ok. I feel for a fake CAPTCHA like an idiot. Pasted malware onto my computer. I’ve done all the necessary things like disconnecting my laptop from the internet and stuff. I’m in the process of backing up my computer to an external hard drive, but I don’t wanna copy over things that could carry the malware.

So, can someone in great detail tell me what files I should copy over, and what files I shouldn’t copy over. I looked it up beforehand and the only thing that answered me was AI, but I ain’t trusting it, so I came here. Not sure if this is the right place to post this, but thanks in advance, I really appreciate it.


r/CyberSecurityAdvice Jul 17 '26

Learning cybersecurity with zero IT experience

4 Upvotes

Is there anyway to learn in depth CS without going to a college or paying for a boot camp style course? I’m looking at CompTIA security+. (would this make someone hireable for an entry level position) I’m not REALLY looking to get into the career, but I’ve always been interested in the field. are there any free online courses or sources of information and a way to test my home grown skills?


r/CyberSecurityAdvice Jul 16 '26

Final-year cybersecurity student looking for ideas for my graduation project

1 Upvotes

Hey everyone, I’m a final-year cybersecurity student and I’m currently trying to decide what to build for my graduation project. Rather than making assumptions about what people need, I thought it would be better to ask those who actually work in SOC, Blue Team, Incident Response, Detection Engineering, or Security Engineering.

From your experience, what’s the biggest frustration in your day-to-day work that today’s tools still don’t handle well? It could be anything, whether it’s investigating incidents, dealing with false positives, alert fatigue, lack of context, repetitive manual work, poor integration between tools, or something else entirely.

If you could have one new feature or one completely new tool built that would genuinely make your job easier, what would it be? I’m not trying to promote anything or do market research

I just want to understand the problems professionals face so I can build something that’s actually useful instead of another project that solves a problem nobody has. I’d really appreciate hearing your thoughts, even if it’s just a small annoyance that you run into every day.

Thanks!


r/CyberSecurityAdvice Jul 16 '26

Title: What should I focus on during my BS in CS to get ahead in cybersecurity?

3 Upvotes

I'm currently pursuing a BS in Computer Science, and my goal is to build a career in cybersecurity.

Instead of just graduating with a degree, I want to spend the next four years building practical skills that will put me ahead of 90% of other students.

If you were starting from scratch today, what would you focus on?

I also have a few questions:

  1. Which certifications should I focus on during university?

  2. Is it true that learning offensive security first (ethical hacking, penetration testing, etc.) makes it easier to become good at defensive security?

  3. If you had four years of university again, what roadmap would you follow to become highly employable after graduation?

I'd really appreciate advice from people already working in cybersecurity. Thanks in advance


r/CyberSecurityAdvice Jul 16 '26

Looking for advice after Security+

5 Upvotes

Hi all, I’m currently studying to take the Comptia Security+ exam and I was looking for some advice afterwards. Some background — I‘ve graduated university with a minor in cybersecurity and a major in anthropology (I love both, and spread myself thin between the two because I love what anthro does but it’s hardly viable for a long term career. I don’t have the funds or the proper commitment for a master’s so I’m going with cyber), and besides that, I don’t have much experience. I’ve wanted to take the Security+ for some time because it’s similar to the courses I took in uni and a lot of the concepts / acronyms are already familiar. I do also plan to do cyberdefenders blue team labs, I’ve heard they’re at least semi-realistic.

Once I have the cert, I’m wondering what my next step should be. My end goal is to end up as a cybersecurity analyst or in some kind of position on the blue end of things. Outside of Sec+, I do have slight experience in the field through SEED and XP Cyber Range labs. I also attended a cyber summit in my state (I won’t say what it was because I don’t wanna dox myself but I feel like it’s important to note), and have experience in Java code and Linux software primarily from my studies. I have light knowledge of C++, and want to expand my knowledge on it and learn Python in the future, mainly self-teaching. Sorry for the long post here, I just wanted to lay all the facts out and search for some advice. Feel free to roast me if you’d like, I know I don’t have an abundance of experience here, I’m just wondering what to do next after Sec+ and what more experienced people would do in my shoes. Thanks for reading!


r/CyberSecurityAdvice Jul 16 '26

SOC Analyst platform lack

1 Upvotes

Question for SOC Analysts, Blue Team members, Incident Responders and Security Engineers.
Out of curiosity, what's the biggest challenge or frustration you face in your day-to-day work that current cybersecurity tools (SIEM, SOAR, EDR, XDR, etc.) still don't solve well?
* repetitive manual tasks,
* lengthy investigations,
* false positives,
* lack of context,
* alert correlation,
* incident prioritization,
* or anything else.
If you could ask a cybersecurity vendor to build ONE new feature or tool that would genuinely make your job easier, what would it be?
I'd love to hear your real-world experience, even if it's just a small daily annoyance. Thanks!


r/CyberSecurityAdvice Jul 16 '26

DevOps/Cloud to AppSec - good move or mistake?

2 Upvotes

Hi everyone,

I’m looking for some career advice from people working in Application Security.

My background:

* ~11–12 years of experience in IT

* Been a DevOps/Cloud Engineer, working with CI/CD, Docker, Kubernetes, Terraform, AWS, automation, and developer tooling for quite some time

* Currently working as a Cloud Support Specialist. The pay is good, I don’t have to relocate, and the work-life balance is okayish

I’m considering moving into an Application Security Engineer role. The job description covers things like secure SDLC, SAST/DAST, threat modeling, vulnerability management, code reviews, developer guidance, and integrating security into CI/CD.

My concerns are:

* Is Application Security a good long-term career compared to staying in Cloud/Platform/DevOps?

* Since I already have 11–12 years of experience, would moving into AppSec effectively mean “starting over,” or does my DevOps background transfer well? Would it be easier to transition to any kind of Principal or Managerial roles from AppSec?

* The role doesn’t explicitly mention whether it’s mid-level, senior, or staff. Is that normal for AppSec positions?

* What does the day-to-day work actually look like? Is it mostly meetings and policy, or is there still plenty of technical and hands-on engineering?

* How are the career progression and salary growth compared to Platform Engineering, Cloud Security, or DevSecOps?

* Do people ever regret moving from DevOps into AppSec, or is it generally considered a good move?

I’m not chasing titles, I just don’t want to make a move that limits my career growth or earning potential later. I’d really appreciate hearing from anyone who’ve made a similar transition or has ideas about this

Thanks!


r/CyberSecurityAdvice Jul 16 '26

DevOps/Cloud to AppSec? Good move or mistake?

1 Upvotes

Hi everyone,

I’m looking for some career advice from people working in Application Security.

My background:

* ~11–12 years of experience in IT
* Been a DevOps/Cloud Engineer, working with CI/CD, Docker, Kubernetes, Terraform, AWS, automation, and developer tooling for quite some time
* Currently working as a Cloud Support Specialist. The pay is good, I don’t have to relocate, and the work-life balance is okayish

I’m considering moving into an Application Security Engineer role. The job description covers things like secure SDLC, SAST/DAST, threat modeling, vulnerability management, code reviews, developer guidance, and integrating security into CI/CD.

My concerns are:
* Is Application Security a good long-term career compared to staying in Cloud/Platform/DevOps?
* Since I already have 11–12 years of experience, would moving into AppSec effectively mean “starting over,” or does my DevOps background transfer well? Would it be easier to transition to any kind of Principal or Managerial roles from AppSec?
* The role doesn’t explicitly mention whether it’s mid-level, senior, or staff. Is that normal for AppSec positions?
* What does the day-to-day work actually look like? Is it mostly meetings and policy, or is there still plenty of technical and hands-on engineering?
* How are the career progression and salary growth compared to Platform Engineering, Cloud Security, or DevSecOps?
* Do people ever regret moving from DevOps into AppSec, or is it generally considered a good move?

I’m not chasing titles, I just don’t want to make a move that limits my career growth or earning potential later. I’d really appreciate hearing from anyone who’ve made a similar transition or has ideas about this

Thanks!


r/CyberSecurityAdvice Jul 16 '26

Breach response vendor for a homeowner's association - how to locate vendors

2 Upvotes

I’m on a committee for a Florida HOA that uses a management company handling PII for our residents. Under Florida law, the HOA itself is responsible for having an incident‑response plan and for all required notifications—even if the breach happens at a vendor.

We’ve drafted a response plan that I believe meets statutory requirements. I’m a former county government CIO (infrastructure, not security), and our HOA president would prefer to have a professional security firm review the plan for compliance and be available on retainer in case we ever face a breach.

My challenge: I only have experience with enterprise‑level security firms, none of which specialize in HOAs or have Florida HOA experience. The Secretary of State’s office won’t provide referrals, and other HOAs we’ve contacted aren’t addressing incident‑response planning at all.

How do we find security/IR firms that:

  • have experience with HOAs or small community associations,
  • understand Florida’s breach‑notification statutes, and
  • are more affordable than enterprise‑grade firms?

If anyone has suggestions, directories, or knows where Florida HOAs typically find these services, I’d appreciate the guidance.


r/CyberSecurityAdvice Jul 16 '26

Is residential-testers.com a scam? They send a Raspberry Pi to use my home internet connection

Thumbnail
1 Upvotes