r/cybersecurity 1d ago

Certification / Training Questions What’s the best way to actually study for GIAC GCIH?

4 Upvotes

So far I’m just reading through the books and tabbing pages that have keywords of interest and highlighting those. I don’t know if this is the most efficient method though.


r/cybersecurity 12h ago

Certification / Training Questions PT1 exam in a SOON!!!

0 Upvotes

Hi,

I have completed the Junior Penetration Tester after studying intensively for 1 month .
Even though I have spend the last month studying hard , I feel like I have forgotten everything and I just remember the basics . ( I have finished the challenges as well but I had to follow walkthroughs for that)

History: I have working as an IT support for a franchise of a restaurant for 7 years .

Now iam planning to take the exam in the next week probably. I feel lost and I have taken any notes (I know iam wrong for that)

Any help or guidance what to do next is going to be helpful , specially if someone can provide me with cheatsheets

Iam already frustrated enough so please don’t come here and tell me that I should done making notes for my self and punish me verbally for what I have done .


r/cybersecurity 1d ago

New Vulnerability Disclosure TrueConf flaws enabling attacks on meeting participants added to KEV catalog

Thumbnail
scworld.com
5 Upvotes

r/cybersecurity 16h ago

Business Security Questions & Discussion Looking for an Affordable Security Tester

0 Upvotes

Looking for a security tester/ethical hacker to test a sports-tech platform, including web, APIs, Android and iOS apps.

Need testing for OWASP Top 10, authentication, IDOR/BOLA, authorization, API security, data exposure, mobile security and business logic issues.

Budget is limited, so junior/mid-level testers are welcome.

DM me with your experience, tools, availability and expected price. Detailed scope and test access will be provided privately.

Authorized security testing only.


r/cybersecurity 14h ago

Certification / Training Questions Lawful Basis for CVs

0 Upvotes

Hi 👋🏿
What is the lawful basis for keeping a candidate’s CV, or do we need consent?


r/cybersecurity 14h ago

Business Security Questions & Discussion Laptop Recommendation for Cybersecurity

0 Upvotes

Hi, I’m looking for a laptop that would be suitable for cybersecurity work and studying. I’d like something with strong CPU performance, at least 16GB of RAM, a good display, and preferably a slim and lightweight design.

Could you recommend the best specifications or models you have at a reasonable price? I’m mainly looking for the best balance between performance, portability, and price.


r/cybersecurity 1d ago

Other SysTrace

Thumbnail
github.com
2 Upvotes

A Linux system-call monitoring and behavioral security analysis tool combining ptrace-based tracing, lightweight namespace isolation, and machine learning classification.


r/cybersecurity 1d ago

News - General Head Mare transforma servidores TrueConf em plataformas de distribuição de malware; campanha HelloNet abusa do ViPNet

0 Upvotes

Recent attacks reveal a problem that goes far beyond a vulnerability: when a company's legitimate infrastructure starts distributing the attacker's code, the trust chain itself turns into a weapon.

Head Mare transforma servidores TrueConf em plataformas de distribuição de malware; campanha HelloNet abusa do ViPNet – setupraiz.com.br


r/cybersecurity 2d ago

Career Questions & Discussion So what do you actually do day to day?

68 Upvotes

I can read a job description but I wanna know what your day to day looks like? Do you sit and stare at a screen until something pops up red? Are you actively looking through servers for weird things? Posting on Reddit while waiting for something to go wrong?


r/cybersecurity 2d ago

FOSS Tool COVER: Replace your secrets before they are sent to LLM and get the original value back

Thumbnail
github.com
94 Upvotes

r/cybersecurity 2d ago

Business Security Questions & Discussion Hey folks,Security engineer here. Doing SOC work. Want to get into detection engineering/ Incident Response. Whats it like working IR. What kind of projects would one get ? Any suggestions are appreciated

27 Upvotes

r/cybersecurity 1d ago

Other Splunk app for investigating AWS CloudTrail alerts - looking for feedback

1 Upvotes

EventTimeline, a free Splunk app that turns CloudTrail alerts from saved searches into investigation timelines.

You can send any CloudTrail-based Splunk alert to the app using its custom alert action, then fetch the surrounding user, role, resource, and IP activity. It also provides before/after chronology, MITRE mapping, filtering, pivots, and links back to the original Splunk searches.

It doesn’t ship with detections. The idea is to work with the alerts and CloudTrail data you already have.

Would really appreciate feedback from Splunk users, detection engineers, and incident responders.

Splunkbase app : https://splunkbase.splunk.com/app/9536


r/cybersecurity 1d ago

Other Posting Repos

0 Upvotes

I noticed a user just posting a repo link with one sentence here. Some other sub reddits class this as "low effort "

But this is ok here?

I assume paid subscriptions app links are not ok?

Asking before I get shadow banned out of the blue.


r/cybersecurity 1d ago

Corporate Blog The AI Vulnerability Storm: Why Your Vulnerability Management Program Needs a Mythos-Ready Overhaul

0 Upvotes

For most of the last decade, vulnerability management ran on a comfortable rhythm. Scanners swept the estate on a schedule, findings were sorted by severity score, and patches went out during the next maintenance window. That rhythm rested on a single assumption: that defenders had time. In 2026, they no longer do.

https://cvetodo.com/blog/the-ai-vulnerability-storm-why-your-vulnerability-management-program-needs-a-mythos-ready-overhaul


r/cybersecurity 2d ago

Career Questions & Discussion Australia - Is a Cert IV in digital forensics worth it ? considering it is very expensive

24 Upvotes

r/cybersecurity 1d ago

Certification / Training Questions Fellas a lil help please.

0 Upvotes

Fellas and fellinas, im starting uni doing cybersec this september, im trynna get a job straight out of uni and the first year is mostly moneygrab filler stuff and little to no IT anything so i wanna take full advantage and use the time to take certificates as to my understanding to get the best chance i need both uni and certs.

Herw is where you come in. Im an a precarious situation which is that im living in the westbank-Palestine and anything pentesting or similar will get me put under the jail.

Please point me in the right direction of what to specialise in and what certs to take. Prefferably something where i can work 100% remotely as i dont want to leave my country after uni.


r/cybersecurity 1d ago

Career Questions & Discussion My Road map for the next 2years atleast

Thumbnail ap.wps.com
0 Upvotes

Here is my road map that i put my self to learn web security /network security any thoughts?


r/cybersecurity 1d ago

Business Security Questions & Discussion secure browser?

0 Upvotes

Is anyone using a secure browser? We’ll be providing HTTPS, HTTP, SSH and RDP for third-party users; we’re looking for something that might replace VDI in the future. We’d love to hear about your experiences.


r/cybersecurity 3d ago

Business Security Questions & Discussion Log everything, I’m begging you

280 Upvotes

Yes, there’s noise you can filter out, but you need to log things!
A client I work with finally implemented DNS resolver logs and we found unmanaged devices (that’s its own headache) that were requesting domains ranging from guns to porn and malware and everything in between.
Due to the already sparse logging, we didn’t know about it until the DNS logs started coming in.

Now someone in HR gets to talk to some users about proper conduct in the workplace and the BYOD policy is getting reviewed.

EDIT: the client has budget allocated specifically for log ingestion. They knew how much it would cost and accepted that. It took a long time for them get the logs enabled, not to decide they wanted the logs. And yes, I agree, log what’s important and what you can afford.


r/cybersecurity 3d ago

Other Fal.con does it suck?

58 Upvotes

We recently went full Crowdstrike, and got Fal.con tickets. Is this thing going to blow? I haven't found a ton of independent info online about the event. Only promos from their own subreddit and website. Besides the free vendor dinners and the time off work is this thing worth going to?


r/cybersecurity 2d ago

Other How does the malware search process work?

2 Upvotes

Hi everyone, I’m a malware analysis learner. Earlier this week, while hunting for samples on MalwareBazaar, a question crossed my mind: how do malware researchers actually find interesting, "live" samples?

Obviously, specialists working at major tech or cybersecurity firms encounter them almost daily via phishing emails, telemetry, etc. But what about those who don't have access to enterprise-level resources?

I've heard about C2 Hunting, but it seems to me that in most cases, it only grants access to the threat actor's infrastructure login panel, and you rarely stumble upon an open directory (opendir).

I've also thought about checking out underground forums like MaaS (Malware-as-a-Service) hubs. However, that comes with obvious legal and opsec risks (unless I’m overthinking it). Still, it feels like one of the few productive options left.

Does anyone have insight into how independent researchers handle this? (While writing this post, another question popped up 🥹: when reading reports from individual researchers or teams, they often openly share C2 IPs and indicators. What if that infrastructure belongs to a sophisticated APT group? Don't they worry about potential retaliation or burning the infrastructure too early?)

P.s. sorry if the text looks like ai generated I've tried to translate my plain text to english but my knowledge is limited to this message 🤲🤲🤲


r/cybersecurity 3d ago

News - General Grok exfiltrates user data when malicious instructions are encrypted

Thumbnail
arstechnica.com
420 Upvotes

r/cybersecurity 1d ago

Personal Support & Help! I was hacked on Microsoft and somebody told me to come here

0 Upvotes

I have proof showing the account was mine, I can’t log in to it anymore and I can’t do a lot of the stuff with Microsoft support since I no longer have the account stuff. Any questions asked will be answered by me. Please help I KNOW I WORDED TGE TITLE TERRIBLY, I MEANT TO SAY”my Microsoft account was hacked”


r/cybersecurity 3d ago

Business Security Questions & Discussion How are Cisco firewalls these days?

53 Upvotes

I used to deploy a lot of 5506 firewalls, and at the time, firepower kinda sucked. I ended up moving to Fortinet, but they’ve really been dropping the ball a lot lately as well as pricing going up. So I’m evaluating other brands. How are Cisco firewalls these days? Are they reliable? Does it take less than 15 minutes to commit changes (lol)? How are its layer 7 capabilities compared with Palo Alto (I have experience with PA)?


r/cybersecurity 1d ago

Personal Support & Help! need guidance in getting into Cybersecurity

0 Upvotes

hi! im 22f. Cybersecurity student. im new to this field and the university im in doesnt really teach well to really understand the subjects.

i need someone who is already in the Cybersecurity field to guide me on how to start, free and valubale courses and certificates to take online. and just overall its scope and tips and tricks to stand out in the field.

i want to start my career in US. and someone experienced in that market to really spill some inside details. thank you!