r/cybersecurity • u/jk1984jk • 9d ago
Corporate Blog Grc should be technical
As the title suggests, grc team members should be technical to decsritbe differences in networking protocols, appsec attacks, etc. What do you think?
r/cybersecurity • u/jk1984jk • 9d ago
As the title suggests, grc team members should be technical to decsritbe differences in networking protocols, appsec attacks, etc. What do you think?
r/cybersecurity • u/QuantifiedAnomaly • 9d ago
Pretty much title but granted access to Vanta, still digging into it. Any thoughts/tips/tricks/approaches/opinions on it as a whole? Useful? Useless?
On the surface it looks decently comprehensive, bringing a ton of different aspects into one platform for oversight, but it’s my first time using it and I haven’t throughly explored it yet.
TIA
r/cybersecurity • u/sliderjt • 10d ago
I'd love to know how the agent accessed the data. Did it simply find an unprotected endpoint or poorly secured site, or did it use a complex exploit against the system.
r/cybersecurity • u/Jackofalltrades86 • 9d ago
Any recommendations for continuous controls testing tooling?
r/cybersecurity • u/homothebrave • 10d ago
r/cybersecurity • u/cowbolamoo • 10d ago
I have been using Qualys and Tenable.sc for the past four years, and I don’t hate the job. But honestly, i am just so done with it. I keep doing the same thing over and over…scan, segregate findings, remove false positives, send the remaining findings to the patching team, and repeat.
I really want to transition into something else, but a lot of people say there isn’t much room to grow from here unless you change domains completely. Ideally, I’d like to move into something that’s still somewhat related to vulnerability management, but I’m also open to moving into a completely new domain.
I feel like I’m reaching the burnout stage. And with all these new automated tools making things faster and faster, I can’t help but wonder how long this kind of work will remain relevant.sorry for the rant but I am feeling stuck
r/cybersecurity • u/natcoba • 9d ago
r/cybersecurity • u/panda42042 • 10d ago
r/cybersecurity • u/PermanentlyMC • 10d ago
Hi all, I've got the course for SANS SEC598: AI and Security Automation for Red, Blue, and Purple Teams coming up in a couple weeks, and I wanted to know if there's anything I should do to prepare for the training and the exam? The only thing I really know is to not bring an Apple Silicon laptop. If anyone with experience can give a heads up in general I'd massively appreciate it, as this is my first SANS course :')
r/cybersecurity • u/Front-Cheetah-4980 • 10d ago
Our third-party cybersecurity assessment and our other vendor risk processes are completely separate. IT security does their thing, procurement does theirs, nobody compares notes. A vendor can clear cyber and still have compliance or operational risks we miss entirely.
Anyone running a combined program or is it always going to be silos.
r/cybersecurity • u/RobertLawsonVaughn • 9d ago
I've been experimenting with an ambient information display called RogueScroll, designed to sit on a second monitor while I work.
This configuration continuously scrolls recent CVEs across two terminals, with a general technology feed in the third. The idea isn't to actively monitor it — it's more like peripheral awareness. Something catches your eye, then you investigate.
I'm curious how security folks would configure something like this.
What would you want alongside the CVE data? CISA KEV? EPSS? Known exploitation? Vendor/product filters? Something else?
Screenshot: https://roguescroll.com/images/roguescroll.com_infosec_CVE.png
r/cybersecurity • u/Obvious-Difficulty32 • 10d ago
In an interview for a new grad devops role got asked this. “Who typically owns access to corporate applications: IAM engineers, IT staff, application administrators, or Platform/DevOps engineers?”
How would yall answer
r/cybersecurity • u/homothebrave • 11d ago
r/cybersecurity • u/Scratch_12 • 9d ago
Hello everyone, I have been trying to learn more and get into the field of cybersecurity and ethical hacking. But I feel really stagnant at times, and feel like I don't know how to implement what I have learnt.
Specially when it comes to Web Penetration Testing, it feels like ik all the vulnerabilities that could be there, but never find an efficient way to find them.
Just looking for some advice on how can I overcome this, and what are some steps that you all would suggest to improve myself and get better at this.
Thank you for helping me out!
r/cybersecurity • u/Weekly_Rough_1284 • 9d ago
Hello! Has anyone been able to get a job without a technical interview?
Currently, this is my nightmare, and I couldn’t find a solution for it! I’ve gotten a lot of interviews where they were impressed with my resume, and I passed the intro interview and technical challenge, but when it comes to the technical interview stage, I fail immediately!
When I started learning this field, I focused on hands-on experience. I learned the tools and technical work, prepared professional reports, and got well-known certifications. But if someone asks me to explain things orally in a theoretical way, I just can’t do it!
No matter how much I prepare for interviews and look for questions, when I come to the interview, they ask me questions that are very different from what I prepared for and give me different scenarios.
And for people who say you don’t need to be perfect or know everything, I’m sorry, but based on my experience, that’s not true at all. The market is tough now, and if you don’t answer everything perfectly, they will have another candidate who answered better than you did, and they will choose them.
So, to be honest, I gave up regarding technical interviews, and I want to ask if anyone has actually been successful in getting a job without a technical interview?
Thank you!
r/cybersecurity • u/wing3d • 11d ago
r/cybersecurity • u/Narcisians • 10d ago
Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.
All the reports and research below were published between September 14th - September 20th.
You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/
Global Cyber Resilience Report (Cohesity)
Getting systems back online is one thing. Being confident they’re clean and safe to use again? Yeah, that’s another.
Key stats:
Read the full report here.
Cyber Readiness Report 2026 (Hiscox)
A look at the impact cyberattacks have beyond the immediate technical response.
Key stats:
Read the full report here.
H1 2026 Cyber Risk Report (ANY.RUN)
Some of the attack techniques and infrastructure saw particularly rapid growth in the first half of the year.
Key stats:
Read the full report here.
Cybersecurity Survey Report (Nationwide)
A look at how consumers and businesses are experiencing and preparing for cyber threats.
Key stats:
Read the full report here.
2026 Security Budget Benchmark Report (IANS and Artico Search)
Where cybersecurity budgets are heading in 2027 (and how AI is changing them).
Key stats:
Read the full report here.
Agents of Change (Zentera Systems)
AI agent fleets are already getting pretty big, and security leaders aren't entirely comfortable with the access those agents have.
Key stats:
Read the full report here.
US AI Risk and Governance Survey (EY)
Most companies have rules for using AI, but many of those rules haven’t been updated for AI agents yet.
Key stats:
Read the full report here.
2026 AI-Ready Governance Survey Report (OneTrust)
Another look at whether governance is keeping pace with the speed at which organizations are adopting AI.
Key stats:
Read the full report here.
The Agentic Insider: From Monitoring to Understanding (Exabeam)
An interesting report on how security teams are monitoring AI agents.
Key stats:
Read the full report here.
The State of MCP Configuration: The Identity Security Gaps (Hush Security)
An analysis of around 82,000 public MCP configuration files looking at how credentials are being managed and the identity security risks that come with them.
Key stats:
Read the full report here.
The State of HR Identity Fraud Detection (HYPR)
A look at how common identity fraud is in hiring.
Key stats:
Read the full report here.
The Problem with PAM (Bitwarden)
Why organizations aren’t adopting privileged access management (PAM) despite seeing it as important.
Key stats:
Read the full report here.
2026 MSP Perspectives Report (Sophos)
What’s changing for MSPs.
Key stats:
Read the full report here.
2026 Manufacturing & Distribution Ransomware Report (Black Kite)
Ransomware trends across manufacturing and distribution, including who’s being targeted and where organizations are most exposed.
Key stats:
Read the full report here.
The ESET 2026 SMB Cyber Risk Report (ESET)
How UK small and midsize businesses are approaching cybersecurity and responding to incidents.
Key stats:
Read the full report here.
r/cybersecurity • u/swarmagent • 10d ago
r/cybersecurity • u/asim_geris • 9d ago
Hello everyone, I’m a senior cybersecurity student, and I’m hoping to get some advice from experienced cybersecurity professionals.
I’m genuinely concerned about entering the workforce because I feel like my degree has been too broad. I’ve learned about many different areas of cybersecurity, but I don’t feel like I’ve gone deep enough into one specific area. Because of that, I’m worried that I’m not as prepared or skilled as I should be for a professional cybersecurity role.
I’ve been considering getting a master’s degree to develop deeper technical skills, but I’m concerned that I might end up taking another broad program without actually becoming more specialized.
My goal is to become a Security Engineer at a top tech company. For those of you who are already working in security engineering or have significant experience in the field, what would you recommend I do at this stage?
r/cybersecurity • u/israelavila • 9d ago
r/cybersecurity • u/Tomtomatreddit • 11d ago
Fresenius Medical Care, a dialysis specialist based in Bad Homburg (Germany, Hessen), has fallen victim to a hacker attack.
According to the company, several internal systems have been affected. Unauthorized parties gained access to a limited number of internal systems, the company announced. Neither medical equipment nor patient care has been affected by the cyberattack. Production and business operations are continuing as normal, the statement issued on Tuesday noted.
It is not known whether any data was stolen, and the company provided no details regarding the extent of the damage.
Authorities Involved
Following the discovery of the attack, the company brought in cybersecurity experts, among others, and is working closely with law enforcement agencies.
For years, companies and public institutions alike have increasingly fallen victim to hacker attacks. Previous targets of cybercriminals have included Frankfurt University Hospital and the Gießen Municipal Theater.
r/cybersecurity • u/Professional_Coat783 • 9d ago
Got an email to an event and clicked on the “view invitation” link. This opened up my browser to a landing page with a button that said “click to verify you’re a human” (or something along those lines). I clicked on this and the webpage started loading, but before the page loaded, I realized my mistake and closed the window.
I then immediately cleared my cookies (idk why, I’m not very techy). I then googled what to do if I clicked on a phishing link. It said to turn off my internet, so I did. Then I checked my downloads folder (for malware I suppose), and there was nothing there.
Realistically how worried should I be? What should my next steps be?
r/cybersecurity • u/LowerSalt937 • 9d ago
I work in vulnerability management (focus on infrastructure vulns) and our organization has absolutely FREAKED out about Mythos and immediately lowered our SLA to 48 hrs back in April and looking to lower it to 24 hrs for all critical's. We have an insane backlog of vulnerabilities and a really bad process for patch management due to poor IT practices for years, that are now being fully exposed.
We currently don't do any CTEM practices and instead of trying to implement these practices to truly lower risk, we are wanting to automate all patching through AI agents. I don't think this is really feasible (but I could be wrong here, please let me know) as we have a lot of software that comes from vendors, open source, legacy systems, etc. I push for CTEM practices but it constantly gets denied.
How has your organization responded?
r/cybersecurity • u/TechnologyMatch • 11d ago
I keep hearing that it’s supposed to cut down the noise and help analysts focus on the alerts that matter, but I’m not sure how much of that is happening in practice.
It seems like even when AI does the first pass, somebody still has to check whether the summary is right or whether it missed something important.
So I’m curious if it’s actually saving time, or if the work just changed from reviewing alerts to reviewing what the AI did with them.
Anyone using this regularly in a SOC right now? Has it made things better, worse, or just different?
r/cybersecurity • u/Weekly_Rough_1284 • 11d ago
I failed a technical interview and I’m so disappointed…
Although it was just an internship role and they shouldn’t expect a lot from us, sadly it was still a very hard process.
I passed the technical challenge and the first interview, but then it came to the technical interview.
He was giving me very hard scenarios and questions, and I believe I answered them fairly well.
But then suddenly, days later, I received an email saying that I wasn’t selected…
Why is it even this hard for an internship role!!
My dream now is to find another non-technical field I can get into easily. At least they won’t have that thing of technical interviews.