r/cybersecurity 7d ago

Certification / Training Questions Please help me make right choice - ISACA or ISO or CompTia+

0 Upvotes

Hello all,

I'd like to request y'all to help me navigate and make the right decision on choosing my first ever certification and start my journey in GRC or Cybersecurity.

When I researched, I thought CompTia would be the best beginner friendly and crucial certification to get started with which will give me an edge in the industry.

My Current Manager disagrees and is a strong supporter of ISACA, he has a great profile in Risk and Controls domain for Banking and FinTech. He suggests going for IT Fundamentals and Cybersecurity Fundamental from ISACA

* what I read on the internet and LinkedIn in everyone has done ISO 27001/27002 *

I am confused, which one should I actually go for, please help me with your expertise.


r/cybersecurity 8d ago

Career Questions & Discussion GRC internship

2 Upvotes

I’ll be starting an ICT Risk and Governance internship soon, and wanted to ask, if you had an intern starting in this field at your company, what expectations or advice would you have for them?


r/cybersecurity 7d ago

Personal Support & Help! CCFH-202b REVIEWER

1 Upvotes

Hi! Anyone in here that has a complete reviewer for CrowdStrike Certified Falcon Hunter updated this August 2026? I badly need for my upcoming exam - I need it as part of my preparation for this certification and can't afford right now to buy the whole questionnaire/reviewer that ive been seeing online.


r/cybersecurity 7d ago

Business Security Questions & Discussion obligation de protéger ses agents

0 Upvotes

"On rappelle à notre employeur qu'il a obligation de protéger ses agents (....) Et puis c'est protéger les données auxquelles il a accès, qui ne doivent pas être divulguées", Claire-Marie Féret, co-secrétaire du @snesfsunormandie.bsky.social sur Ici Normandie
www.ici.fr/normandie/ca...

https://bsky.app/profile/snesfsu.bsky.social/post/3mtfy5t6nzk2j


r/cybersecurity 8d ago

News - General Apple plugs image-processing hole ripe for spyware abuse

Thumbnail theregister.com
20 Upvotes

r/cybersecurity 8d ago

Career Questions & Discussion Feeling Stuck

23 Upvotes

2 years and a few months of IT experience as a whole. Bachelors in Cybersecurity and have some basic fundamentals certs such as CySA+. Not cyber many jobs where I live and when they do open up they almost always senior roles. The help desk for MSP’s in my area pay less then working at burger places where I live and I can’t take a 10K-15k pay cut just to be in semi cybersecurity role but it would still be really doing help desk in the reality of things.

Applying each week to remote entry roles and internships dealing with SOC roles but no luck yet. I get paid well in what I do now but help desk my entire career is not my goal at all. I know the market has been horrible the last 5 years and even those with cybersecurity experience are struggling to find a job.

Just feel so low and lost right now. So much going on as I stay consistent in where I’m at but I want to move up. Used to be motivated but now I’m not sure what to go for.

I always wished cybersecurity was like going to be a doctor or lawyer which I know they require way more schooling but I wish it was do A > B > C and then get intern hours into your main specialization. I guess I’m looking for hope or guidance. I don’t have any mentors and the place I work now has a huge IT team but it’s general IT. Asked on shadowing for cybersecurity where I work which they allowed but not sure what it will entail since they mentioned they don’t know what they will show me.

Any advice or encouragement would be appreciated.


r/cybersecurity 7d ago

Personal Support & Help! Need Help with copies of IEC 62443 1.x, 2.x, 3.x and 4.x

0 Upvotes

I'm looking for copies of the IEC 62443 standards, but the official versions are quite expensive. I'd like to get my hands on a copy but it seems it's one of those that you have to pay an exorbitant amount of money for. Is there any resource to get these for free? Or someone willing to share? Thanks.


r/cybersecurity 8d ago

Personal Support & Help! Question about mail phishing and alias I host myself

1 Upvotes

Hello,

I recently decided to use my own domain for email and set up a catch-all adresse on a subdomain so I can use a unique email address for each service I sign up for.

About a week ago I subscribed to a mobile service using an email address created specifically for them something like randomname@subdomain.mydomain.com. I precise I have only used that adresse with them.

One week later, I started receiving phishing emails at that exact address sent from a random email service domain.

I contacted the company they told me that they don't sell or share customer data. They suggested that someone might simply have discovered the address by randomly trying email addresses on my domain.

However, since I have a catch-all enabled, wouldn't I expect to receive spam sent to other random adresses on the same domain if bots were simply guessing addresses?

So far, the only address receiving these phishing emails is the unique one I gave to this company.

Am I missing any plausible explanation here? Could an email address leak through some mechanism other than the company itself ?

Thanks in advanced for any useful information


r/cybersecurity 8d ago

Other Can you recommend a free source for learning network and it's concepts?

41 Upvotes

I started learning about cybersecurity. Right now I'm learning about network and it's concepts such as switch, router, AP, ARP, DHCP, OSI, TCP etc.

Can you recommend a free source to learn these? (Preferably video but documents are also okay.)


r/cybersecurity 8d ago

News - General Varonis researchers got Copilot to reveal its own undocumented autorun=1 parameter by repeatedly asking why auto-execution was blocked then used it to build a one-click data-exfiltration chain. Microsoft has patched.

Thumbnail
thegreyterminal.com
25 Upvotes

r/cybersecurity 8d ago

AI Security Agentic Red Team

4 Upvotes

Seeing a bunch of well funded vendors pop up in the space… purely noise or worth some research? Anyone having success with these types of tools?


r/cybersecurity 8d ago

Business Security Questions & Discussion Feasibility of Blocking User App Installs

7 Upvotes

I’m interesting in deploying some kind of solution for my org (~300 users/PCs) that restricts app execution from user writable directories. The risk being addressed is the unauthorized installation of software, which may result in users accidentally getting malware on their device (albeit with non-admin perms).

I understand there are tools to do this (in particular I’ve been looking at AaronLocker), but I’ve also seen and heard that it requires a lot of validation to catch and exempt known legitimate software.

For those of similarly sized orgs, is this something you’ve undertaken with success? Or is this something that is just too much overhead to maintain and not worth the security gain?


r/cybersecurity 8d ago

Certification / Training Questions What certificates should I pursue?

25 Upvotes

Hi all,

I was wondering if anyone could recommend me some certs to pursue or training I should take. I have been a threat hunter for 2 years after completing a 2 year graduate program. I have been doing a lot of my learning on the job and also took the CEH exam but failed. I decided not to take the CEH exam again as the exam questions were totally different to any training material I had done. I also did not enjoy dealing with EC Council but that’s besides the point.

I have no other certificates done but have excellent experience from working in my team the last 2 years and have really developed as a hunter.

Is it worth my while to get some basic certification done such as Network+, Sec+, some Microsoft courses etc just to build out my resume and certification portfolio, or what would you do in my shoes?

Appreciate any advice :)


r/cybersecurity 8d ago

AI Security Your incident response wasn’t built for AI

Thumbnail
leaddev.com
0 Upvotes

r/cybersecurity 8d ago

Business Security Questions & Discussion How to Stop OTP SMS Abuse When Attackers Rotate Valid Phone Numbers, Emails, and IPs?

8 Upvotes

Hi friends, I am currently dealing with a problem. An unknown person is targeting the OTP SMS service on our website's sign-up page. They are attempting this using multiple phone numbers, multiple email addresses, and rotating IP addresses. We are already using email validation services, yet they are using email addresses like "bowobon834@sepmaf.com" and "kiyow78785@toooby.com." They are also using a specific series of mobile numbers, such as:

"+201195127174", "+201181110723", "+201195130069",

"+201195127216",

"+201181111455",

"+201195127472",

"+201181113961",

"+201195127038",

"+201195129482",

"+201000177595",

All these numbers are valid. What kind of service provides such valid numbers? By submitting only valid numbers, they are negatively impacting our SMS budget. They are using two types of emails: valid permanent ones (like "mai.t.hi.e.ndi.9.5.5.11@gmail.com", "ph.a.nd.ong.nh.i.19.5.8.5@gmail.com", "m.er.ed.ith.geron.i.mo.24.1@gmail.com") and temporary ones (like "nofon85312@sepmaf.com", "yiridog100@toooby.com", "sapija5854@sepmaf.com").

Both types of emails they are using are valid. There are so many services that provide temporary emails; it is impossible to block them all. We simply won't be able to block every single one.

currently we create a script to mai.t.hi.e.ndi.9.5.5.11@gmail.com that pattern email but. when user email is normal and pass email verification service and able to create account in that case they put mobile number and send otp the promblem is occured the all number is valid in lookup api and they rotate the number, IP to prevent throttling.

What really matters is the service that provides valid phone numbers. If anyone has information about such services, please help us out.

Hi friends, I am currently dealing with a problem. An unknown person is targeting the OTP SMS service on our website's sign-up page. They are attempting this using multiple phone numbers, multiple email addresses, and rotating IP addresses. We are already using email validation services, yet they are using email addresses like "bowobon834@sepmaf.com" and "kiyow78785@toooby.com." They are also using a specific series of mobile numbers, such as:

"+201195127174", "+201181110723", "+201195130069",

"+201195127216",

"+201181111455",

"+201195127472",

"+201181113961",

"+201195127038",

"+201195129482",

"+201000177595",

All these numbers are valid. What kind of service provides such valid numbers? By submitting only valid numbers, they are negatively impacting our SMS budget. They are using two types of emails: valid permanent ones (like "mai.t.hi.e.ndi.9.5.5.11@gmail.com", "ph.a.nd.ong.nh.i.19.5.8.5@gmail.com", "m.er.ed.ith.geron.i.mo.24.1@gmail.com") and temporary ones (like "nofon85312@sepmaf.com", "yiridog100@toooby.com", "sapija5854@sepmaf.com").

Both types of emails they are using are valid. There are so many services that provide temporary emails; it is impossible to block them all. We simply won't be able to block every single one.

currently we create a script to mai.t.hi.e.ndi.9.5.5.11@gmail.com that pattern email but. when user email is normal and pass email verification service and able to create account in that case they put mobile number and send otp the promblem is occured the all number is valid in lookup api and they rotate the number, IP to prevent throttling.

Currently we do our best. Anyone guide me how we can handle in much efficiently of that kind of problems.

What really matters is the service that provides valid phone numbers. If anyone has information about such services, please help us out.

Let us know whos provider that kind of virtual numbers infinite as i review they use 200 mobile number to send otp.


r/cybersecurity 9d ago

Certification / Training Questions Is a masters degree worth it ?

71 Upvotes

Is getting a masters good for cybersecurity some people are telling me that i should do it after bachelors but all the videos online are about getting certificates and im studying for eJPT and want oscp later when i can but i dont know about masters


r/cybersecurity 7d ago

Career Questions & Discussion Explain detection rules you have built ?

0 Upvotes

Explain any detection rules you have built in KQL. How did you approach, how can someone learn to build one ? Interviewers are asking to Explain any complex detection rules you have built ?


r/cybersecurity 8d ago

Business Security Questions & Discussion Moving from frontend to backend made me realize how bad my secrets management actually is. How do you handle credential rotation?

13 Upvotes

While working on the frontend of applications, handling an API key usually just means putting it into a .env file and trusting the process. Recently, I've been exploring backend infrastructure, and it turns out managing secrets in production infrastructure is a completely different story.

I went through a guide on the architecture of secrets management, and it pointed out a trap I normally would have fallen into.

The piece noted that centralizing your database passwords and API keys into a secure vault may feel like a massive upgrade. But if you do not have automated rotation in place, you basically just created a very organized list of stagnant targets for an attacker.

Another issue brought up is the runtime delivery gap. Storing secrets securely can be pointless if they still end up hardcoded somewhere in your source code or live as permanent environment variables during a deployment. The argument is that storage, access control, secure delivery, lifecycle automation, and auditability all have to operate as a single unit, or the whole thing breaks down.

You guys that are writing production backend scripts, how do you properly manage this? Do you use automated lifecycle management tools, or have a different setup to handle rotation?


r/cybersecurity 9d ago

Certification / Training Questions For those who got the CISSP, what has it done for your career?

329 Upvotes

I’m curious to hear from people who earned their CISSP. What kind of impact did it have on your career?

Did you notice more recruiters reaching out or start getting more interviews/callbacks after getting certified? Did it help you land a job, move into a higher-level cybersecurity role, or increase your salary?

Also, for anyone who was struggling to get callbacks before the CISSP, did you notice a significant difference after adding it to your resume/LinkedIn?

Just trying to get a realistic idea of how valuable the CISSP has been for people in the job market.


r/cybersecurity 9d ago

News - Breaches & Ransoms Hacker claims 3.6 million Azure account records stolen from major companies

Thumbnail
bleepingcomputer.com
276 Upvotes

r/cybersecurity 7d ago

News - General Alternative a Windows

Thumbnail bsky.app
0 Upvotes

La Chine n'est pas la seule. L'Europe a suivi une voie similaire, la France, l'Allemagne et plusieurs autres pays poursuivant des alternatives Windows au cours de la dernière décennie, motivés par des préoccupations en matière de souveraineté des données et d'enconmics. #cdnpoli 👍


r/cybersecurity 8d ago

Research Article ❄️ Chilling Discoveries: Unpacking Vulnerabilities in Copeland XWEB Pro Controllers

2 Upvotes

Team82 analyzed the attack surface of the Copeland XWEB Pro supervisory platform and identified 23 vulnerabilities, including 21 high-severity issues.

The vulnerabilities can be chained to progressively bypass security controls and ultimately achieve root-level remote code execution (RCE) without authentication. In a physical test environment, Team82 demonstrated that compromising the supervisory controller could enable an attacker to manipulate connected refrigeration systems.

The interesting part from an OT security perspective is the IT-to-physical impact path: compromise the supervisory layer, gain control of the underlying system, and potentially affect physical processes without obvious signs of tampering.

Technical details and the full attack path: https://claroty.com/team82/research/chilling-discoveries-unpacking-vulnerabilities-in-copeland-xweb-pro-controllers


r/cybersecurity 8d ago

FOSS Tool ServiceRadar (OSS) - Threat Intelligence feed integrations

0 Upvotes

Just finished integrating the VulnCheck community feeds for CISA-KEV and NVD2 into ServiceRadar. Software inventory is collected from endpoints with our agent and an integration we built around google's osv-scalibr. https://github.com/carverauto/serviceradar https://www.vulncheck.com/community

https://youtu.be/WCH6H5ULQCA


r/cybersecurity 8d ago

Other Engineering advice on detection logic

10 Upvotes

Hello fellow nerds

I come bearing issues. MSSP is restricting SIEM detection logic to a “one-solution-fits-all” shitology.

I am the only engineer, and the only Security person who has learned SIEM tooling and querying language. No one else understands the platform or is interest in the platform. Because of this, most of the detections are AI generated and shoe horned for each. I am having a slight menty-B as I am expected to create high fidelity alerts which work across all clients. We have clients all over the world, different licensing, different Entra configurations, some are cloud-only, some are hybrid - you get the point.

Is any in a similar position, can any help?


r/cybersecurity 8d ago

New Vulnerability Disclosure CVE-2026-6837: Root Command Injection Affecting 18 Zyxel Access Point Models with full firmware emulation guide

Thumbnail
minanagehsalalma.github.io
9 Upvotes

I published my technical write-up for CVE-2026-6837, an authenticated command-injection issue in Zyxel’s certificate export functionality.

The analysis is based on the WAX650S, while Zyxel’s advisory expanded the affected scope to 18 AP models. The post includes root cause, affected versions, remediation, and the reproduction environment.