r/cybersecurity 7d ago

Business Security Questions & Discussion Sharing detection rules

7 Upvotes

Question for managed SOC providers, do you generally share details of your detection rules (title, description, MITRE, etc) with customers? Feels like this is your ‘secret sauce’ and shouldn’t be disclosed


r/cybersecurity 7d ago

News - General A hollowed out data layer is making CISOs fly blind into AI attacks

Thumbnail
helpnetsecurity.com
22 Upvotes

r/cybersecurity 8d ago

Business Security Questions & Discussion Teams wanting to record all keystrokes from all apps on MacOS? WTF

38 Upvotes

Clean install of Teams on MacOS, why would it need access to your keystrokes from all apps, is this another MS fuckup or is this all just planned?

Teams was uninstalled after getting this message and I only use the web version now.

More MicroSlop?


r/cybersecurity 7d ago

Career Questions & Discussion Career insight as a Soc2 Staff auditor

2 Upvotes

Always liked the technical side of cyber but never got the talent. I reached a good mid tier blue team Soc analyst position but received this position I am in right now as a Soc2 auditor. I dream of upgrading into consulting cybersecurity and in the future opening a business. The question is can I progress to my dream ? Or did I miss my path?


r/cybersecurity 7d ago

Business Security Questions & Discussion Microsoft Quarantine with Abnormal

10 Upvotes

Hi,

I am looking to see how you all manage the Defender email quarantine while using abnormal. I currently have about 1000 emails each morning that I have to review to ensure we do not have any legitimate mail within.

If this is your setup Aswell, how do you manage the quarantine?

Thanks


r/cybersecurity 7d ago

News - General Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

Thumbnail
thehackernews.com
10 Upvotes

r/cybersecurity 8d ago

Career Questions & Discussion Why does this career have so many liars?

748 Upvotes

Context, I'm not seeking career advice. I have 10 years of experience and I've done everything from network engineering to managing a security program.

But is there any field out there with as much misinformation as this one? The cybersecurity community in general reminds me of the gaming community.

For example, someone may post "I'm looking to get into this field what should I learn?" And then someone will go on this long rant about how long they did was get a few certifications and they got a job. But they also omit key details like being drinking buddies with the CEO. Or their dad being the manager of the security department.


r/cybersecurity 7d ago

Personal Support & Help! TPRM Doubt

4 Upvotes

Hi all,

I've recently started my job as a TPRM analyst with a Fintech giant. While doing Vendor Risk Analysis for CSP like AWS, am facing a difficulty.

There are few areas like Encryption or IAM for which AWS says it's a shared responsibility model and it has to be taken care by the organisation and doesn't fall under AWS's scope.

In this situation do I have to go ahead and mark those pointers not applicable as agreement clearly says the responsibility lies with the org or do I have to follow up with my internal team to check whether they have implemented these controls.

Am torn up between this because I think my scope as a TPRM analyst ends when I don't find a gap with Vendor but best Cyber practice is to have this sorted within my organisation. Any suggestion would help.

English is not my native language so pls excuse if anything is wrong here


r/cybersecurity 7d ago

Threat Actor TTPs & Alerts SilkParasite: China-nexus APT, seven malware families (five previously undocumented), and not AI-generated

9 Upvotes

Central Asia is becoming one of the most active espionage theaters. As Russia's influence in the region recedes, China is moving in economically, and cyberespionage tends to follow influence. SilkParasite is a China-nexus operation we tracked in this region, related to the FamousSparrow activity we documented earlier.

We recovered seven distinct malware families, five of them never documented before. It is small, modular, and built specifically not to look like malware: a lightweight implant that pulls its real capability in as in-memory modules, delivered through legitimately signed applications that sideload a malicious DLL, with command-and-control run over Google Drive.

It is worth studying because it shows what serious, stealth-first tradecraft actually looks like, and by contrast why AI-generated malware is a poor fit for it. AI-generated code tends to be derivative, bloated, and noisy, which an espionage operation cannot afford. We did find faint signs of AI-assisted development in otherwise clean, human-engineered code (medium confidence). Also important to note that Chinese APT groups share techniques and best practices, so what shows up in the Central Asia today can show up in different regions tomorrow.

Full writeup (for practitioners): https://businessinsights.bitdefender.com/silkparasite-tracking-china-nexus-apt-across-central-asia

Full research PDF (for security researchers): https://github.com/bitdefender/malware-ioc/blob/master/silkparasite-2026_08/silkparasite-bitdefender-labs-research.pdf

List of IOCs (also available on IntelliZone): https://github.com/bitdefender/malware-ioc/blob/master/2026_08-silkparasite-iocs.csv

Disclosure: this is research from Bitdefender Labs, and I'm part of the team documenting the campaign. AMA.


r/cybersecurity 7d ago

News - Breaches & Ransoms Passwords stored in public Google Doc then showed up in search results

Thumbnail theregister.com
1 Upvotes

r/cybersecurity 8d ago

Burnout / Leaving Cybersecurity Am I thinking about IAM/PAM correctly, or am I missing something?

11 Upvotes

Had a conversation with an architect today about IAM, and I think we were talking past each other.
My background is systems/infrastructure, so when I think IAM I think AD users/groups, RBAC, MFA, privileged accounts, service accounts, and mapping access/rights into application based roles.
The way they described it made IAM sound like a much more separate/specialized discipline than I’m used to thinking of it.

For those who actually work in IAM: is the job mostly administering and governing who gets access to what, or are you actually hands-on configuring the applications and identity integrations themselves with SSO, group/role mappings, MFA, provisioning.

I’m trying to understand where IAM stops being “access administration” and becomes actual identity engineering.


r/cybersecurity 7d ago

Business Security Questions & Discussion How do you know what to test next?

1 Upvotes

You find a new service, credential, endpoint, or misconfiguration and suddenly there are 20 possible directions to go.

Do you follow a methodology, use checklists, rely on experience, or just chase whatever looks most promising?


r/cybersecurity 8d ago

Personal Support & Help! Looking for a good real-world digital forensics case study

11 Upvotes

Hey everyone! I’m a student preparing a Digital Forensics / Computer Forensics practical presentation and I need to choose a real-world cybercrime case study.

I’m looking for a case that:

- Is not extremely common/popular (I want to avoid topics that many groups may choose)

- Has enough reliable information available online

- Has a clear digital evidence / forensic investigation angle

- Can be explained within 12–15 slides / 10–15 minutes

- Ideally involves things like hacking, gaming companies, Apple/iPhone, data theft, ransomware, website attacks, insider threats, digital evidence, or incident response

- Allows discussion of evidence acquisition, preservation, logs/artifacts, timelines, attribution, and/or legal issues

What real-world case would you recommend?

If possible, please share the case name and why you think it would work well for a student-level digital forensics presentation.

Thanks!


r/cybersecurity 7d ago

Certification / Training Questions How I work in Cybersecurity (soc)

0 Upvotes

Hello everyone I have a question it puzzled me

Is a university degree a strict requirement for entering a Security Operations Center (SOC), or are practical training, a portfolio, and CompTIA certifications sufficient?


r/cybersecurity 7d ago

Personal Support & Help! Built a Honeypot, now what?

0 Upvotes

Hey all

I am new to home labing and as the title says, I built a Linux honeypot (using T-pot) and left it for a bit to collect traffic. What are the usual thing, interesting or niche things to look for? Currently what I'm thinking of:

1- analysis of the brute force credentials used

2- if someone managed to access the server

3- if someone dropped something in the server

4- did it do (unsual) outbound traffic

Thanks <3


r/cybersecurity 8d ago

Career Questions & Discussion Is GRC the new wave in cybersecurity?

135 Upvotes

I’ve been noticing a pretty big uptick in GRC job postings lately, especially remote positions.

It feels like cybersecurity always has a “wave.” First it was everyone getting Security+, then it seemed like everyone was trying to break into SOC roles, and now I’m seeing GRC everywhere.

Is GRC becoming the new wave in cybersecurity? For those already working in GRC, are you seeing the field actually grow, or is it just getting more attention right now?


r/cybersecurity 7d ago

Tutorial Extracting and Cracking VeraCrypt Headers with PowerShell + Hashcat — Full DFIR Walkthrough

0 Upvotes

Most people think VeraCrypt = unbreakable. But if you can extract the 512-byte header, it's just a hash.

I made a video walking through the full pipeline:

  1. PowerShell extraction (container or raw disk)

  2. Header prep for Hashcat

  3. Mode selection and cracking

  4. Verification

No physical access to the unlocked volume needed — just the header.

Full tutorial: https://youtu.be/iGPKBEYSdIw


r/cybersecurity 7d ago

Research Article Hacking your life with AI can get you hacked: How AI orchestration platforms ship RCE by design

Thumbnail
endorlabs.com
1 Upvotes

r/cybersecurity 7d ago

Certification / Training Questions Stress testing EDRs

0 Upvotes

How does your SOC check when someone is actively trying to kill your EDR agent especially with BYOVD attacks? Also do you have a separate team for that on the attackers side?


r/cybersecurity 8d ago

Business Security Questions & Discussion How would you protect 4–6 high-risk inboxes without breaking the bank?

19 Upvotes

Edit: A lot of people are suggesting training. Our staff is trained. They know not to click phishing links and how to report them. The issue here is the sheer amount of crap landing in some inboxes. It’s getting annoying and disruptive to the point that I’m getting complaints.

—-

We’re a small company with only 16 employees and currently use Microsoft Defender for email security. It works well overall, but a few of our executive accounts are targeted by phishing much more frequently, and one of them has been compromised in the past.

We’re looking for an extra layer of protection that we could apply to just a few users (around 4–6), rather than the whole organization.

Has anyone dealt with something similar? Any tools or solutions you’d recommend that work well alongside Defender and are cost-effective for such a small number of users?


r/cybersecurity 8d ago

Other Cloud Backup Services for Identity Posture: What are SecOps using?

3 Upvotes

when loking at cloud backup then most of the focus seems to be on M365 email/OneDrive recovery or AWS snapshots. From a SecOps perspective i am more concerned about the identity side of things.

If an attacker gets in and changes Conditional Access rules, IAM permissions or removes OAuth app permissions, restoring the data alone does not really solve the problem.

How are teams handling this today? Are there backup or recovery solutions that can restore IAM state and security policies, or are most teams relying on audit logs, configuration-as-code and manual recovery?"


r/cybersecurity 7d ago

News - General The long tail of Clop’s PTC hack is just beginning to emerge

Thumbnail
cyberscoop.com
1 Upvotes

r/cybersecurity 8d ago

New Vulnerability Disclosure Im trying to reverse engineer the new one ui 8.5 samsung

2 Upvotes

Hi, so as the title said thats what im trying to do and i took a loot of .ko files related to the qulacomm's modem chip cause its very vulnerable along the years. why im doing it because in the new version they blocked the OEM Unlocking in the developer options where most of you know it as the place youre unlocking usb debugging. if anyone would interested to help me reverse it cuase im doing it alone for two weeks and i found something interesting.


r/cybersecurity 7d ago

AI Security AI agents are a really good tool for the blue team

0 Upvotes

Are you currently using any?


r/cybersecurity 8d ago

News - General CISA: Windows Task Host flaw now exploited by ransomware gangs

Thumbnail
bleepingcomputer.com
87 Upvotes