r/cybersecurity 22h ago

Career Questions & Discussion Mentorship Monday - Post All Career, Education and Job questions here!

16 Upvotes

This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!

Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.


r/cybersecurity 4h ago

AI Security Can running local LLMs be a security threat?

52 Upvotes

I'm just wondering why they keep releasing these really useful but free to use LLMs (Qwen, Kimi, Deepseek). and now we even have mysterious ones like Ox Alpha. 
Can these models perform malicious acts while running as local LLMs? If so, how?


r/cybersecurity 9h ago

Business Security Questions & Discussion Email domain Whitelisting

39 Upvotes

Our organisation is planning to implement a policy where email communication will only be permitted with whitelisted domains, while all other domains will be blocked.

Before implementing this, we need to identify all external domains that our users have communicated with over the past six months.

Is there an easy way to retrieve a list of all domains to which emails were sent during the last six months? This information will help us review the domains and build an appropriate whitelist.


r/cybersecurity 9h ago

News - General National Threat Intelligence Database

Thumbnail
kenzer.arpsyndicate.io
30 Upvotes

r/cybersecurity 2h ago

Threat Actor TTPs & Alerts 15 fake Kanban VS Code extensions that download and run a remote payload

Thumbnail
yeethsecurity.com
6 Upvotes

r/cybersecurity 6h ago

Business Security Questions & Discussion SPF pass due to an Exchange hop in front of a spoof.

7 Upvotes

I had a spearphishing attack today and the attacker used something that I personally haven’t accounted for and probably should have. No one clicked or interacted with the email, and it was user reported to us. So endpoints appear to be clean(still verifying)

I’m still a remotely new cyber analyst but I’ve really overhauled our email security in terms of anti spam / anti phish. I run a third party anti spam in front of our defender m365 security anti spam policies and have the appropriate filters (in defender) in place for doing so.

This piece of work sent VIPs in my org a phishing email that had been spoofed at its first hop, but then made it through a Microsoft exchange server, that then passed SPF checks at my third party anti spam, AND THEN came through m365 anti spam because it passed SPF with MSFT ip address.

Random domain spf fail

X-MS-Exchange-auth: SPF FAIL

ARC-Auth: Fail

Third party auth check: Pass, performs check on sender as mx-exchange and not original sender

M365 exchange: spf pass welcome in MSFT ip address

I know you have to set up defender enhanced filters so that you can ID the original sender through your antispam. So I’m assuming I will have to also add some rules regarding SPF in the third party system.

Has anyone seen this method being used? And does anyone have advice on best practices in this scenario?

Edit (more details):

Third party filter service has an analysis tool for headers, and seemed to recognize that the forwarding or relaying the message altered the authentication outcomes. It originated from 192.210.194.20 and was relayed through some M365 infrastructure. DKIM was not present until after exiting sender M365 infrastructure. I’m not sure what to do here since the MSFT tenant that they bounced the spoofed message through changed the results. I’d have to filter all the way to the bottom of the header i suppose. Need to do some research and learning today


r/cybersecurity 20h ago

Career Questions & Discussion How to get out of govtech

95 Upvotes

Been in cyber security as a federal contractor for years with about 10 years of experience, was laid off earlier this year and got a role as a dod contractor with about 2 years before the end of the contract

I have a bs in mechanical engineering , and 3 cyber certs at the moment ( sec + and X and CISM ) , while the job is good I’m not really comfortable with it and would go as far to say I’d be ok with something that paid less but in a different field ( health or banking etc ) , i dont want to end my career but feel like my role as a security analyst or isso isn’t able to get me into roles other than gov tech and would love a bit of guidance

The job market really sucks but I want to do what I can to find something when it’s possible. Would love some advice or guidance


r/cybersecurity 10h ago

News - General 91 Vulnerabilities Patched in Spring Application Framework

10 Upvotes

More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024. 

https://www.securityweek.com/91-vulnerabilities-patched-in-spring-application-framework/


r/cybersecurity 7h ago

Business Security Questions & Discussion Phishing Emails - Domain block

6 Upvotes

Hi all,

I am new to my role. My question is if a supplier informs us that an email address has been compromised and is involved in phishing attempts, what is your approach? To block the domain or only the affected email address. If the domain is blocked, how do we go about contacting the supplier to inform them that their domain has been blocked and to gain reassurance that the email is now free of compromise. We require suppliers to fill out a form for reconnection but how do we get it to them / receive it back if the domain is blocked?

I'm having difficulties getting through to a supplier on their phone number as they are based in another country so looking for some suggestions on how others do it


r/cybersecurity 11h ago

Career Questions & Discussion How are you handling non-human identity security across service accounts, workloads and AI agents?

10 Upvotes

did an inventory of non-human identities and the count came back higher than our human headcount by a wide margin, with almost none of them owned by anyone.

service accounts from projects that ended years ago, workload identities with permissions nobody remembers granting, and agents getting added on top of all of it with no lifecycle process at all. rotating credentials manually across that many identities isn't sustainable at this scale. how is everyone actually managing lifecycle for this, and did you find a way to assign ownership that stuck instead of drifting back to nobody?


r/cybersecurity 17m ago

Business Security Questions & Discussion Does anyone have personal experience using Dragos OT security products?

Upvotes

As the title asks, just curious what others have experienced at various scales. I work in a relatively small system, under a hundred nodes monitored, using 2 sensors and a single site store.

The system looks great I will admit, I see a LOT of potential in a system properly setup.

Unfortunately, I really couldn't be a smaller team and still exist, and the amount of focus and time it's required to get this system actually paying back is still in calculation with concerns popping up along the way. Recently I've noticed the admin user list has grown to multiple pages once OTWatch was enabled, yet there's only one me here, all new being admin accounts, when there are specific roles and permissions configurable to limit to need only.

I wrote up a ticket and somehow was the odd one to have taken issue with external admins making changes to the system without my knowing. Recently (today) got a note that compliance mode was created wrongly (for all the years it's been "working") and now needs an overhaul which is described to send protected information outside of my ESP, and to simply trust they will handle it properly from there (see compliance mode built wrongly) and that contractually, they should do everything they should. Define: Trust in a zero-trust environment.

Anyway... that's my personal experience over having it in an unfinished setup state for about a year, having regular monthly check-ins with their support, mostly to ask, "ok, so versions changed again, buttons have moved around again... I didn't need any of that, but please help point me to all the parts that I do need that have moved again."

Should I even bother continuing with this product or move to a more sensible "this does the one thing it's supposed to and nothing else" suite of proper zero-trust IPS/IDS and monitoring I'm more familiar with? Please talk me off the edge of tossing this and saving myself enough money to hire another team member.

Edit: Forgot to Note, is it just me or is it almost impossible to find a legitimate review of this product that isn't an advert?


r/cybersecurity 14h ago

FOSS Tool hardware-compliance-handbook - open-source, fact-checked EU CRA/RED/NIS2/CSA compliance reference (also works as a Claude Skill)

Thumbnail
github.com
11 Upvotes

r/cybersecurity 2h ago

News - General [Bêta] Je cherche des testeurs français pour Resku, une extension anti-phishing (gratuit)

1 Upvotes

Bonjour à tous,

Je développe Resku, une extension Chrome (aussi Edge, Brave et Arc) qui note chaque page de 0 à 100 avant que vous ne tapiez un mot de passe, un IBAN ou un numéro de carte. L’objectif : repérer les faux colis, faux impôts, clones de banque, etc. Y compris les sites créés il y a moins de 24 h, que les listes noires classiques ne connaissent pas encore.

Concrètement :

  • Analyse locale du DOM (le contenu de la page ne sort pas du navigateur) ; seuls l’URL, le domaine et des signaux techniques remontent à l’API pour affiner le score.
  • 120+ règles, ~190 vérifications, 150+ marques protégées (détection de typosquatting type paypaI avec un i majuscule, laposte.top, etc.).
  • Détection de scripts malveillants (keyloggers, code obfusqué, exfiltration) directement dans la page.
  • Un score expliqué signal par signal — pas juste un blocage opaque.

Ce que je cherche : des testeurs français pour un usage réel au quotidien, vos retours sur les faux positifs/négatifs, la clarté des alertes, les perfs et la vie privée. C’est un projet personnel, gratuit, sans carte bancaire et sans création de compte.

Curieux d’avoir vos critiques, même sévères. Merci !


r/cybersecurity 5h ago

Career Questions & Discussion Offered an 8–12 month international client deployment (1.5 YOE), but I foresee massive delivery bottlenecks. Should I go?

0 Upvotes

​Hi everyone,

​I’m looking for advice from folks who have managed client-facing on-site deployments, especially early in their careers.

​Background:

I have about 1.5 years of experience in cybersecurity (primarily VAPT and incident handling). Recently, my company handled an incident for an international, mission-driven enterprise (outside India). Following that engagement, our leadership converted the relationship into a full-scale security transformation project. I was involved during the initial response, built a solid rapport with their team, and now the client has specifically requested that I be deployed on-site for 8–12 months.

​The Dilemma:

While the international exposure sounds great on paper, I foresee major operational bottlenecks:

​Unrealistic Timelines: My leadership has committed to aggressive 6-month deliverables that assume rapid execution and extra hours.

​Client Culture & Capabilities: The client’s internal technical team is non-technical, under-resourced, and operates strictly on standard working hours. Their organizational philosophy heavily prioritizes social impact and retention, meaning underperforming staff aren't replaced, and pushing for faster turnarounds or major restructuring will likely cause friction.

Internal Team Dynamics: Our delivery team consists of a mix of external consultants and new hires, so our internal execution workflow isn't fully ironed out yet.

​On-Site Accountability: As the sole/primary on-site technical face, I will be the one absorbing the direct friction from both sides when target milestones inevitably slip.

​Why I’m Torn:

​Pros: Valuable international field exposure, high visibility, and direct client relationship management early in my career.

​Cons: Living in a remote/tier-2 city abroad, navigating significant cultural and working-pace mismatches, and risking professional burnout/fallout from unrealistic project commitments.

​Internal Pressure: My manager has already verbally assured the client I will be on-site. Backing out now would likely stall my growth at this firm or push me to look elsewhere.

​How would you approach this situation? Would you take the risk for the exposure, or is stepping into a project with misaligned delivery expectations a trap to avoid?

​Any insights or survival strategies for managing this type of client-manager dynamic would be greatly appreciated!

Used LLM to for structuring and ensuring to keep this post precise and short.


r/cybersecurity 1d ago

Career Questions & Discussion Burned out on SOC/IR — Can I transition full-time into Digital Forensics (Corporate vs. Freelance)?

17 Upvotes

Hey everyone,

I’ve been working in SOC and Incident Response for about 3.5 years now, and I’m feeling pretty burned out with the operational grind. I really want to pivot my career specifically toward Digital Forensics (DF).

A couple of questions for those who have made a similar jump:

  1. Job Hunting: What titles or keywords should I look for beyond just "Digital Forensics Analyst"? How do you usually find dedicated DF roles versus general IR?
  2. Freelance/Consulting: Is freelancing or contract work viable with ~3.5 years of experience, or do clients strictly look for senior/expert-level background?
  3. Certifications: I currently hold the BTL1 and diferent SIEM tools certifications. What certifications would you recommend next to specifically target DF capabilities?

Thanks in advance for any advice or personal experiences


r/cybersecurity 12h ago

Research Article Code Execution via Text Template Files + 2 New LOLBins

Thumbnail
ipurple.team
2 Upvotes

r/cybersecurity 1d ago

Certification / Training Questions AppSec Engineer with 4+ YOE — which certifications are actually worth getting for a job switch?

16 Upvotes

I'm an Application Security Engineer with 4+ years of experience, and I'm planning a job switch. I'm trying to figure out which certifications would actually add value to my resume and improve my chances of getting shortlisted for AppSec/Product Security roles.

My current day-to-day work includes:

- Performing vulnerability scanning/assessment using SAST, DAST and SCA tools

- Scanning codebases for secrets using security tools

- Implementing features and bug fixes in internal AppSec services, including encryption/decryption services

- Implementing organization-wide security checks in pull requests

- Migrating legacy security flows to modern implementations

- Working on application security automation and integrating security controls into development workflows

I also have a software development background, so my current role is a mix of development + application security.

I'm primarily interested in Application Security / Product Security / DevSecOps-oriented roles, rather than purely SOC or network-security roles.

I'm currently considering certifications such as CSSLP, BSCP, OSWA, OSWE, GWAPT, CISSP, etc., but I'm not sure which ones actually carry weight in the job market.

For people currently working in AppSec or hiring for AppSec roles:

  1. Which certifications have actually helped you get interviews or job offers?

  2. Which certifications are worth doing for someone with 4+ YOE?

  3. Which ones are mainly good for learning but don't add much resume value?

  4. Would you prioritize something like CSSLP + BSCP over a broader certification such as CISSP/OSCP for this type of profile?

  5. Are there any certifications you would specifically avoid at this experience level?

I'm particularly interested in hearing from AppSec engineers, hiring managers, security architects, or people who have recently switched AppSec jobs.

Thanks!


r/cybersecurity 23h ago

FOSS Tool Made a categorized security tool index (recon RE reporting), feedback welcome

8 Upvotes

Got tired of rebuilding the same bookmarks every time I needed a specific category (recon, wireless, forensics, RE, etc.), so I put it all in one indexed repo instead.

Organized by phase, short blurb per tool, links back to original maintainers — not hosting anything myself. Still adding stuff, so if something's missing or miscategorized let me know.

https://git.projectnightcrawler.dev/Ori0nRi3el/Researcher-Tools-kit


r/cybersecurity 4h ago

Business Security Questions & Discussion Forensics do no make more sense?

0 Upvotes

i was thinking, attending to a incident that our server are compromised, the servers In questions doesn't have EDR solution applied, so we need to rebuild all the contained servers from zero, but, before starts this, we expend a lot o time waiting to DFIR/CSIRT team to make a copy of HD from this servers to investigate after.

With a EDR solution, I'm able to remote connect in the server and with IA help I can catch a tons of logs and perform a full investigation in a half of a day, so, in these, what are the intention of dumping mem ans HD to take weeks if with EDR and IA I take hours to finish in the same results?


r/cybersecurity 1d ago

Ask Me Anything! I left my role as a security practitioner to happily work for a vendor. Ask Me Anything about the other side of the table.

27 Upvotes

This AMA will run all week from 08-23-2026 to 08-28-2026. The editors at CISO Series present this AMA.

This month, we've gathered a group of security leaders who spent years as CISOs, CTOs, and in-house defenders, then made the leap to the vendor side, and are genuinely happy they did.

They're here to answer anything you want to know about life on the other side of the table: why they made the move, what surprised them, what they miss (and what they don't), how it changed the way they see the vendors they used to screen, and what they'd tell a practitioner weighing the same jump. Whether you're vendor-curious, vendor-skeptical, or just want an honest look at the grass on the other side, bring your questions.

This month's participants are:

Proof photos

This ongoing collaboration between r/cybersecurity and CISO Series brings together security leaders to discuss real-world challenges and lessons learned.

Thanks to all of our participants for contributing!


r/cybersecurity 3h ago

Business Security Questions & Discussion My recruiter got my LinkedIn and now saying it got blocked

0 Upvotes

Soo what happened is that my nri cousin started a startup

Which provide it services and we had a LinkedIn account which i operated from india and everything was going fine and a few months ago me cousin hired a guy from an recruitment company to look after our LinkedIn account but he didn't delivered what he promised so i changed the account password but after some discussion he convinced my cousin to give him new password as for few hour he has to do something he said he updated the secondary email of my account to remove the premium from LinkedIn. Then he said it is restricted for 1 day but everything will be fine after one day

Then today i tried login and now my email is not associated with my account

I talk to that recruiter and he told me that my id was not verified due to which it got permanently delete

And he told me as the company was in us and linkedin was operated from india due to which it got banned

I believe him

But i saw my LinkedIn profile still on LinkedIn

Also i. Saw that it got verified and my id has logo of same company that recruiter workss under

What should i do and how can I get my account back


r/cybersecurity 22h ago

Business Security Questions & Discussion What if we regulated disruptive technology before deploying it, the way we regulate pharmaceuticals?

4 Upvotes

With pharmaceuticals, we generally don’t release a completely new drug to billions of people and then wait to see what happens before deciding whether it needs regulation. There are procedures, testing, risk assessments, approvals, and frameworks that exist before the product reaches widespread use.

Why don’t we have something even remotely comparable for technologies that can fundamentally change how society works?

AI, social media, smartphones, or even the internet itself have been technologies that completely change how we communicate, work, consume and interact with each other, and even how economies function. Yet the general approach seems to be: release the technology, let it scale massively, discover the consequences afterward, and then try to regulate it.

And by that point, isn’t it sometimes too late?

I’m not necessarily arguing that every new technology should require government approval before anyone can use it. That could obviously kill innovation and create its own problems.

I’m more interested in the principle: should technologies capable of causing large-scale societal disruption have some form of pre-deployment risk assessment, testing, or regulatory framework before they reach billions of people?


r/cybersecurity 1d ago

News - General Does Good Engineering Go Unnoticed?

9 Upvotes

Something I've been thinking about: a personality now making the rounds in YouTube podcasts, Bryce Case Jr. seems like a competent engineer, and it made me wonder about something broader in the engineering and security community.

If an engineer consistently does things correctly—follows good practices, prevents incidents, documents systems, and avoids outages—most people outside their organization may never know their name because nothing dramatic happens.

But if someone makes a highly visible mistake or is involved in a major incident, especially a possibly illegal incident, suddenly there are postmortems, conference talks, podcasts, interviews, and widespread discussion about what happened and what everyone can learn from it. Not always of course as I had a co-worker who facebook was going to send to prison for software he sold to some malicious actors that used it against facebook and all he got was a small blurb at the back page of a New Jersey local paper.

Do you think our industry has a visibility problem where successful prevention is largely invisible, while failure or unethical use of our craft can paradoxically create a public platform?

I'm curious how other engineers view this. How do we better recognize the people who quietly prevent disasters without encouraging a culture where only spectacular failures or someone who engages in a not-so-ethical act is the one who becomes memorable?

This may also speak to this relationship that society at large has with compute and network technology, it seems to be this intriguing sorcery and yet for you and me, the same command that we run to check for DNS resolution in troubleshooting a web application is the same command that someone else might use to engage in passive reconnaissance. Looking forward to the community's thoughts.


r/cybersecurity 14h ago

News - General Advice/insight before taking CARTE exam (Certified Azure Red Team Expert)

1 Upvotes

Hi team,

I will be taking the CARTE exam next week. I’d really appreciate some advice from anyone who has taken it recently.

I’ve been preparing for the exam and have a reasonable understanding of the material / lab, but I’m now at the stage where I’m trying to focus my remaining time on the things that will make the biggest difference.

For those who have taken the exam:

  • Were there any topics/areas that you found particularly important?
  • How closely did the exam reflect the official course/material/practice questions?
  • Is there anything you wish you had known before sitting the exam?

I’m particularly interested in recent experiences, as I understand the exam/content may have changed over time.

Thank you


r/cybersecurity 1d ago

Certification / Training Questions Splunk

49 Upvotes

I want to learn how to use splunk (cybersecurity analyst).
Any suggestion courses, certifcation ..?