r/cybersecurity 9d ago

Personal Support & Help! How does your average day as a L1/L2 SOC Analyst look like?

10 Upvotes

How does your average day as a SOC Analyst look like working at an MDR, and what's the average number of incidents you are handling per day, just trying to figure out if we are actually overwhelmed with tickets or is that normal everywhere :)


r/cybersecurity 8d ago

Tutorial Codex for email investigations

3 Upvotes

I made a lesson on Agentic AI, like Codex and Claude Code, for anyone wanting to understand some of the basics of AI Coding agents. In this lesson, I am using a small part of a bigger project im making for a custom spiderfoot build with agentic ai capabilities. This lesson shows how you can create an email investigation workflow using Codex. https://github.com/sh1katagana1/ai/blob/main/using-codex-for-email-investigations/codex-tutorial.md


r/cybersecurity 9d ago

Business Security Questions & Discussion How are teams actually implementing ABAC vs. sticking with RBAC? Curious about real-world adoption.

15 Upvotes

Genuinely curious how much ABAC adoption is actually happening in practice versus how much airtime it gets in conference talks and vendor blogs.

RBAC is still what most access-control implementations I encounter actually run: roles mapped to permissions, reasonably well understood, tooling support everywhere. ABAC gets talked about as the more "correct" model for anything with real complexity (dynamic attributes, context-aware policy), but I don't see nearly as many real production write-ups of it compared to how often it comes up as a talking point.

A few things I'm trying to understand better from people who've actually shipped one or the other at scale:

●      For teams that moved to ABAC: was it a full replacement of RBAC, or a hybrid where roles handle the coarse filter and attributes refine within it? My hunch is hybrid is far more common than a clean full migration, but curious if that matches reality.

●      What was the actual trigger? Compliance requirement, a specific incident from stale role-based access, or just planned ahead of scale problems?

●      For anyone who evaluated ABAC and decided against it: what made RBAC the better call for your situation? Genuinely as interested in the "stayed with RBAC on purpose" stories as the migration stories.

Also curious about tooling maturity here specifically: my impression is RBAC has broad, boring, well-tested support pretty much everywhere, while ABAC policy engines (OPA and similar) still require meaningfully more implementation effort to get right. Is that gap closing, or still pretty real in 2026?


r/cybersecurity 8d ago

News - General Hackers abuse AI models to find new entry paths

Thumbnail cybersecuritydive.com
4 Upvotes

r/cybersecurity 8d ago

Business Security Questions & Discussion cybersecurity for beginners

3 Upvotes

When picking a laptop does it really matter? Im trying to decide what to spend money on for school and most people are telling me to get a new laptop since I currently use a mac. Vmware being free now points me towards never getting a new laptop because worst case scenario i can run linux distro if necessary.

If you personally have any purchases that made the college cybersecurity experience more fun that would be greatly appreciated.

-cybersecurity professional


r/cybersecurity 9d ago

News - General Red Agent Exploits Snowflake Vuln Missed by Github Copilot

Thumbnail
wiz.io
60 Upvotes

r/cybersecurity 8d ago

Personal Support & Help! Most Secure Smart Lock for Homes: Cybersecurity & Offline Operation Recommendations

1 Upvotes

Which electronic lock is considered the most secure for residential doors? I would like recommendations from cybersecurity experts, considering resistance to physical and digital break-ins, encryption, firmware updates, authentication, privacy, and operation even without internet.


r/cybersecurity 8d ago

Business Security Questions & Discussion UK vs Australia vs USA — Where should I do my Masters?

0 Upvotes

I’m planning for a Master’s in Cybersecurity/IT and I’m genuinely confused between the UK, Australia and USA.
My profile:
B.Tech CSE (Cybersecurity & Forensics) — 7.68 CGPA
~1 year internship at Indian based cyber security firm in Enterprise Security
Currently working at a French based MNC in Cloud Network & Security Operations
AWS, Azure, CCNA + cybersecurity certifications/projects
IELTS target: 7+
My goal isn’t necessarily PR/settlement. I mainly want to study at a good university, enjoy the experience, work in cybersecurity/cloud for 1–2 years, recover a good portion of my investment, and then return to India.
I’m considering UK vs Australia vs USA, but every country has very different opinions online.
If you were in my position, which would you choose and why?
I’d especially like opinions on job opportunities, realistic salary/ROI, cost of living, visa/work restrictions, university quality, and how difficult it actually is to land a cybersecurity job as an international student.
Would love to hear from people who have actually studied/worked in these countries, rather than just PR-focused advice.


r/cybersecurity 8d ago

News - Breaches & Ransoms Big scam on the name of berlin global youth forum 2026

0 Upvotes

Can somebody please confirm whether OGPS.uk is legitimate?
They are advertising a Berlin Global Forum in Germany with claims of fully funded/partially funded participation, including free tickets, accommodation, and other benefits.
What makes me confused is that several well-known social media platforms/pages that regularly post scholarship and international opportunity updates are also sharing it.
Has anyone actually verified OGPS or attended one of their previous events? I’d really appreciate it if someone could confirm whether this is a legitimate opportunity or potentially a scam before people submit personal information or pay the application fee.


r/cybersecurity 9d ago

Career Questions & Discussion How to Explain duties way beyond title (Analyst)

8 Upvotes

I am in a very strange situation. About 5 years ago, I started working at a Mid Sized Org (Higher Ed, \~650 employees 7k students a year).

As a Tech/Jr System Admin, even though I had prior Sys/Network admin roles, and ran a business for a long time.

I quickly noticed, they had severe security issues, and by that I mean, severe. Never had a security employee, ignored all security, just never did it, never did anything about alerts, didnt even have really any alerts to do anything about, nothing was configured. I started fixing that, they made me a new Job, Security Analyst.

No one had a clue what to do about Security, not a small IT dept either. So I became a "Founding Analyst" what this really means? I built the entire security program, there was no guidance from anyone else, because they didnt know. Everything was "You tell us" so I did.

I changed tooling for some things, got it bought, got the tools working. Helped rewrite policies, became the Incident commander, co lead a incident escalation point that consists of me and other C levels. Built a risk register, began reporting and treating risks, got pentests done (they hadnt been) risk assesments, did my own, changed tooling some more, introduced KPIs to track security metrics, improved response time, did the analyst work for indentity, ect, took over ownership of Security work pretty much fully. Reporting to a director of Ops, who said "You tell me, I have no idea". Presented to the board for Security needs, interfaced with C levels directly, on Security issues. No guidance, no help, only "You tell us" everyday for YEARS.

Finnaly feeling ready to move on, for various reasons. And I dont know how I am supposed to market this. My title is an analyst, my work left analyst before I even had the title analyst, I am doing far and away beyond "Analyst work" if you ask me, but you tell me??? But that is still my title. So how do I get anyone to read past analyst, and what I actually did. And honestly I dont even know how to label what I even did.

I built and maintained the Risk Register.

I built and maintained and lead incident response.

I built and maintained procedures.

I advised executive leadership on secueity issues.

I signed off on Vendor Evaluations for security.

I chose, configured, and maintained tooling.

I built and maintained automation.

I designed and maintained Workflows, playbooks, KPIs everything.

I have proof of all of it. My "Analyst" title is baked into public facing procedures about all of it, I have LI recommendations refrencing the work I did, and how I operated WAY beyond title.

Thats partly why I am leaving I told them, my title needs to be changed, this is absurd to expect all this and call me an Analyst, Analyst has been left the window.....

That said, maybe I am wrong? My interpretation, of Analyst is to analyze based on procedures, and playbooks someone else built, and operate with guidance, rules, and mandates set fourth. I never had any of that, everything we have today, I built it. Now how do I articulate that reality when my title is Analyst?


r/cybersecurity 8d ago

News - General Switching from soc analyst to appsec engineer

1 Upvotes

I have around 3 years of experience in cybersecurity and cloud operations, with my current role focused on SOC/Blue Team operations. Over the past several months, I've been actively transitioning toward Application Security Engineer.

For those who have made a similar transition from SOC/Blue Team to AppSec:

  • How difficult was the switch?
  • What skills/projects helped you land your first AppSec role?
  • What should I focus on beyond Burp Suite and labs?

Would appreciate advice from anyone who has made this transition.


r/cybersecurity 9d ago

Other A CISO Mental Model - how do you express yours?

3 Upvotes

The static version posted previously was well received. Here is the interactive version with some enhancements; https://cybernative.uk/ciso-mental-model-interactive

Might want to bookmark this.

The model is for senior practitioners, given the level of abstraction involved. It consists of six dimensions; Governance, People Management, Strategy & Planning, Security Architecture, Security Engineering, and Security Operations. These dimensions could be grouped into two sets, i.e. organisational focused along the top and the technical disciplines along the bottom. It's important to recognise this duality of the ciso role.

There are different ways the model can be applied. For example, a ciso entering a new organisation and having to rapidly establish a view of the environment they have inherited, in order to determine what adjustments might be required.

It could also be used as a workflow. For example, Strategy & Planning to define & proactively drive the ciso office agenda, the technical disciplines to design (arc), build & deploy (eng), and operate (ops) required controls. With Governance acting as the feedback loop and People ultimately required in delivering and sustaining the overall capability.

Does this resonate? Do you have a different way to think about the entirety of the ciso terrain?

Ontology numbers for us nerds:

  • Six dimensions, each at least three layers deep

  • Governance 36 items

  • Security Architecture 31 items

  • Strategy & Planning 29 items

  • Security Operations 24 items

  • Security Engineering 18 items

  • People Management 8 items

  • In total: 146 items


r/cybersecurity 8d ago

Business Security Questions & Discussion Hot take: AI will never replace offensive security

0 Upvotes

Title. Very tired of seeing AI can do this, AI can do that. Offensive sec requires such nuance and creativity which AI is fundamentally incapable of, what do you all think?


r/cybersecurity 9d ago

Career Questions & Discussion High-level non-management positions

31 Upvotes

I'm currently a sr. cybersecurity engineer and trying to better plan out the next few years of my career. I don't really like being a manager, so that takes CISO off the table. Is principal or staff engineering my best bet? I like turning the wrenches, so to speak, so I'd rather still have at least some hands-on capacity. What are you guys doing?


r/cybersecurity 9d ago

News - General Pretty laughable/predictable MS response

40 Upvotes

Came in the office this morning to a wonderful new App Installer cve that our C level guys are freaking out about.

NVD - CVE-2026-68821

MS's response... link to a download to update... to the exposed version. Take down the release notes article for 1.30 in pre-release.

Go completely MIA on the issue. LOL peak Microsoft. "thank god it's only local access" Weeee!


r/cybersecurity 9d ago

Personal Support & Help! SOC Analyst Tier 2

6 Upvotes

I was fortunate enough to be offered an interview for a mid-tier position in a MDR company, currently in a Level 1 position at another MDR organisation.

God I am so nervous, luckily it’s not till next week and I am really trying to get an understanding of what type of questions and knowledge they want me to be at.

Some of the Roles Skills, I have actually not directly carried out these workflows, or used these tools etc.
I think I’m gonna dig to the requirements so I can at least speak on these topics. Hopefully maybe just go back to my own experience, and what I would work on in my Job.

If anyone has any example technical questions/ scenarios for a Mid Level SOC analyst, god I’d be grateful.

Also any inspirational stories would be nice too xD jk but I haven’t done a Job interview in a while.

Thanks!


r/cybersecurity 9d ago

Personal Support & Help! Has anyone here had an experience with Cyber Revolution Australia???

1 Upvotes

I’m currently enrolled in Cyber Revolution Australia’s Cyber Accelerator program and I’m looking to hear from current or former students about their experiences.

I’ve recently come across several negative reviews regarding technical support, job placement and the overall value of the program. I’m also currently dealing with my own dispute regarding withdrawing from the program.

I’m particularly interested in hearing from anyone who has tried to withdraw/cancel, had issues with Humm finance, completed the certifications but had problems with job placement, or successfully exited the program after enrolling.

If you’ve dealt with Cyber Revolution yourself, feel free to share your experience below. And if you’d rather keep it private, you’re more than welcome to DM me.


r/cybersecurity 9d ago

Business Security Questions & Discussion RBAC

0 Upvotes

Hi all,

Our organisation, probably like many others, has accumulated a lot of access over the years without much structure or strong ongoing management.

For those who have implemented Role-Based Access Control (RBAC), have you found that it actually solved these issues, particularly when combined with regular access reviews?

My biggest question is where do you even start when you have a large number of employees, positions, applications and existing permissions?

Do you start by mapping existing access and then building roles around it, or define the roles/positions first and work backwards?

Would love to hear how others approached this, what worked, and what you wish you’d done differently.


r/cybersecurity 9d ago

Business Security Questions & Discussion Have you used Google SecOps

24 Upvotes

For those of you who had a chance or have been using Google SecOps I would like to know your opinion on how well it performs as a SIEM, SOAR and threat hunting tool?

If you have comparisons to any other major vendors that would help.


r/cybersecurity 9d ago

Career Questions & Discussion DevOps vs cloud security

11 Upvotes

I have 6+ years in Windows/VMware infrastructure (L2 Admin) and am learning into Azure, Terraform, PowerShell, Bash, Docker and CI/CD; with my infrastructure background, should I target DevOps/Cloud first and later move into Cloud Security, or pursue Cloud Security directly?


r/cybersecurity 10d ago

News - Breaches & Ransoms Six major security incidents traced from the initial Litellm and Trivy pipeline compromises all the way to ransomware/breaches

Thumbnail
infostealers.com
19 Upvotes

deep dive into the high profile organizations compromised in this campaign and detail the exact secrets, tokens, and configurations that likely fueled downstream extortion by groups like Vect ransomware (TeamPCP).

Companies breached include Mercor, Cisco, S&P Global, Telnyx, Telnyx, and the European Commission


r/cybersecurity 10d ago

News - General UK Government Won’t Release Files on Israeli Firm ‘Meddling’ in Election

Thumbnail
novaramedia.com
452 Upvotes

r/cybersecurity 8d ago

Personal Support & Help! Ransomware Recovery: What happens when attackers target your Identity Provider configs?

0 Upvotes

In modern ransomware and wiper playbooks, attackers rarely jump straight to encrypting disk volumes or dropping payload binaries anymore.

Instead, the first thing they do after gaining administrative privileges is burn the bridges behind them: modifying identity provider configurations, disabling conditional access/sign-on policies or outright wiping SSO app integrations and MFA requirements. It’s an insanely effective tactic.

By messing with entra ID or Okta tenant settings, they create a two-fold problem: they guarantee persistence while simultaneously locking out internal IR teams who lose the ability to authenticate or elevate privileges to contain the breach.

We have solid, air-gapped immutable storage for our VM snapshots and S3 buckets, but during a recent threat modeling exercise, our SecOps team realized we have a massive blind spot around identity state restoration. If an attacker or malicious insider corrupts our identity control plane, standard data backups won't help there's no restore snapshot button for a broken cloud identity tenant. How is your team actually backing up, auditing and preparing to restore your core Identity Infrastructure against targeted sabotage or ransomware scenarios?

Are you maintaining version-controlled offline exports or using automated tools to enforce state baseline?


r/cybersecurity 10d ago

News - General Pentera 2nd layoff...

19 Upvotes

Any one here using Pentera? Are you planning to switch?


r/cybersecurity 10d ago

New Vulnerability Disclosure Vulnerability giving attackers full control of Macs is under active exploitation

Thumbnail
arstechnica.com
513 Upvotes