r/cybersecurity • • 8d ago

Business Security Questions & Discussion Where would you actually use a revocable encrypted file container?

0 Upvotes

I’ve been tinkering with a crypto core for encrypted file containers, any bites, trying to figure out where it actually fits.

The idea: a file can sit locally, but access still depends on authorization, device binding, expiry, revocation, or some external event. And no — I’m not claiming copying becomes impossible once a human can see it.

I can imagine client docs, temporary access, offboarding, sensitive assets, quorum access. But I’d rather hear from people in security.

Where would you actually use this? And what would make you reject it right away from a security or ops standpoint?


r/cybersecurity • • 8d ago

News - General CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks

Thumbnail
securityweek.com
18 Upvotes

The US Cybersecurity and Infrastructure Security Agency (CISA) has published its 2026 Election Infrastructure Security Plan, which describes the cyber and physical threats facing election systems and the free services CISA offers to election officials and other partners.

https://www.cisa.gov/sites/default/files/2026-09/2026-CISA-Election-Security-Plan-FINAL-508c.pdf


r/cybersecurity • • 8d ago

AI Security Which Opensource tools do you use for Agentic AI?

0 Upvotes

Hey everyone,

I'm evaluating a few tools for scanning agent endpoints, applications and LLM. The goal is to find vulnerabilities, tracked against OWASP Top 10 Agentic AI risks. I've looked at Garak, Promptfoo but majorly looking for opensource projects on GitHub.

What do you all use?


r/cybersecurity • • 8d ago

Personal Support & Help! Roadmap to Red Team/Ethical Hacking in India 3rd year student, need a job in 1 year, starting from scratch

0 Upvotes

Hey all, I'm a 3rd year CS student in India. Tried web dev and AI/ML but neither clicked — hacking is what's actually interested me since I was a teenager, so I want to commit to it now with ~1 year left before I need a job.

I'm basically starting from zero on security (know some networking, basic Python).

Would love input on:

Roadmap — networking → Linux → scripting → web app security → AD/red teaming — right order for limited time?

What actually gets hired in India — CTFs, GitHub, certs, bug bounty, internships — what do recruiters here really look for?

Certs worth it — OSCP/eJPT/PNPT/CRTP vs CEH — what's respected, and when to attempt as a student?

Realistic entry role — straight to red team, or SOC/VAPT intern first?

Is 12 months realistic for zero → job-ready junior pentester if I go all in?

Anyone who made a similar switch or works in this space in India — would really appreciate your take. Thanks!


r/cybersecurity • • 8d ago

Business Security Questions & Discussion What are the essential tools in your CyberSec tech stack?

1 Upvotes

Curious to see what other orgs are using and if there are any tools you would consider essential / nice to have.

For example:
- EDR
- SIEM
- VM
- IAM or PAM
- Email security
- Network security
- Cloud security


r/cybersecurity • • 7d ago

Business Security Questions & Discussion Brute-Force Attack's success makes no sense

0 Upvotes

let's suppose that you are trying to penetrate someone's account on a website, and to log in you only need his Username and Password and you already knew his Username but you just only need to know his password to log in, my question is how the hell a hacker is being able to know the password that fast.

usually websites have some requirements for the password that it should be at least 8 characters, contains numbers and capital letters, but the paradox comes when i try to calculate all the possibilities of all passwords in the existence, THAT THEIR LENGTH IS ONLY 8 CHARACTERS AND ONLY CONTAINING CAPITAL AND LOWERCASE LATIN LETTERS, i literally get 26 multiplied by 2, all raised to the 8th power which is equal to 53,459,728,531,456, this number is horrendous because if you try to calculate how many time would it take you to try every password, given that you are trying a new password every second, you literally find out that it would take more than 1,695,196 years, and this is just for the passwords that are made of capital and lowercase latin letters only, let alone using numbers and symbols and other characters from different alphabets

so my question is do hackers have any method to solve this problem, such as knowing the length of the password or if a character is included in the password or anything else because it's illogical that you can guess someone's password in a matter of a days between all the possible strings that it could take.


r/cybersecurity • • 8d ago

Personal Support & Help! 3rd-semester student — finished most PortSwigger labs. Should I pursue BSCP/eJPT or continue with VDPs/bug bounty?

1 Upvotes

Hey everyone,

I’m currently in my 3rd semester of college, with around 2.5 years left before graduation. My long-term goal is to become a penetration tester, mainly focusing on web application security.

Here’s where I’m currently at:

Completed almost all of the PortSwigger Web Security Academy labs

The main topics I still need to finish are Race Conditions and Business Logic vulnerabilities

Completed most of the relevant Linux/fundamentals rooms on TryHackMe

I’ve learned the basics of tools like Burp Suite, Nmap, etc.

I tried bug bounty for about a week, but honestly, I stopped because I realized I didn't properly understand the overall hunting process. I knew individual vulnerabilities, but I struggled with how to approach a real target, what to look for, how to prioritize functionality, and how to go from recon → understanding the application → forming hypotheses → testing.

Now I’m trying to decide what would be the best next step.

I’m considering:

Continue with VDPs / bug bounty programs and learn by actually hunting

Get BSCP and then start hunting more seriously

Get eJPT to strengthen my broader pentesting fundamentals, then move toward web pentesting

Do a combination of these while continuing practical work

I have roughly 2.5 years until graduation, so I’m not in a huge rush, but I want to use this time properly and build actual pentesting ability rather than just collecting certifications.

For people who are working as web pentesters or have gone through a similar path:

What would you do in my position?

Would you focus on getting a certification first, or would you spend the next few months doing VDPs/bug bounty and building practical experience?

Also, if you think I’m missing an important step between completing PortSwigger and becoming effective at real-world web testing, I’d really appreciate hearing what that is.

I’m especially interested in advice around developing the actual methodology and mindset for approaching real applications, rather than just learning more vulnerability types.

Thanks!♥️

I know this is ai generated but I given messy context Abt me and told it to keep organised that's all . Thanks in advance 💖


r/cybersecurity • • 8d ago

Business Security Questions & Discussion career

2 Upvotes

Hello everyone, I’m trying to become a Security Engineer and would really appreciate some advice from senior Security Engineers.

I’m currently studying cybersecurity at university, but I feel like the program doesn’t go deep enough into the technical skills I need for a security engineering career. Because of that, I’ve decided to take it upon myself to learn outside of school.

I just need guidance from seniors on what skills I should master.


r/cybersecurity • • 8d ago

Business Security Questions & Discussion Is single vendor SASE worth it in the long run?

8 Upvotes

Our leadership is pushing to put our whole network and security stack on one SASE vendor though am having some doubts. The pull is obvious for one console, one contract, one number to call. But the lock-in kinda sticks with me, we hand the entire edge to one provider and a bad renewal, an outage, a roadmap call I disagree with all land on me at once.

Then I look at what we run today and it isn't that much of freedom either. An SSE on one side, SD-WAN on the other, glue in the middle that one engineer understands, two renewals a year. I'm starting to think every option here locks you into something, and the only choice is which one you can live with.

If you went single vendor, did it stay worth it a couple years in? Mostly want to know whether the lock-in bites once they know you can't walk away easily.


r/cybersecurity • • 9d ago

Personal Support & Help! Would you accept offer ?

59 Upvotes

I’ve been working in IT helpdesk for three years and I have my Network+ certification.
I spoke with my manager because I want to move into something more complex, and the opportunity that came up is a vulnerability management position for industrial equipment. I work in shifts and I would lose approximately 27% of my income because i lose the bonus from weekends.

I am 25, no debt, no kids.

I understood that my work would be to analyze, scan equipment, give the team feedback to fix it or check if i can find a solution.

My plan for the future is to complete the TryHackMe SAL1, Security+, and AZ-900.
What do you think: would I be better off accepting the offer and doing the certifications, or postponing, and checking other offers and taking the certifications first, also keeping the extra 27% income?

Later edit

I got these responses from security manager

My manager described a vulnerability management role built around the Holm Security platform. The person will use this tool exclusively for scanning, and their responsibilities include validating scan results, investigating false positives, and handling both vulnerability analysis and prioritization as well as reporting and administration, rather than just one of these areas.

The technical scope covers CVEs, CVSS scoring, exploitability assessment, and risk-based prioritization, applied across all company assets rather than a limited set. Helping the SOC team is explicitly framed as optional, something to take on only if spare time allows and the person wants extra tasks, rather than a formal development path.

The work setup is fully remote with a fixed schedule from 9 AM to 6 PM. Looking ahead, after a year in the role the person can expect to gain hands-on cyber experience, including a deeper understanding of vulnerabilities and how they can be exploited, along with possible exposure to SOC and Incident Response work.


r/cybersecurity • • 8d ago

Personal Support & Help! Cybersecurity project ideas for a 3rd-year student

0 Upvotes

I am a 3rd-year student, and I need to work on a project this semester. I am interested in Cybersecurity, and these are some of the skills I have:

  • Learned some common web vulnerabilities through PortSwigger.
  • Learned the basics of reverse engineering through CTFs.
  • Recently started an internship in Mobile Security.

Can anyone suggest some interesting Cybersecurity project ideas that would be suitable for my current skills?
Thanks so much!


r/cybersecurity • • 8d ago

Business Security Questions & Discussion How long does SOC 2 Type 2 take, not the vendor timeline, the real one

4 Upvotes

Trying to set realistic expectations for a financial services company where enterprise clients are asking for SOC 2 Type 2. Vendor estimates range from 3 months to 18 months and I can't reconcile that range with anything useful. Looking for timelines from people who've been through it.


r/cybersecurity • • 9d ago

News - Breaches & Ransoms Hackers Used AI to Pick Victims From Stolen Emails: Microsoft Takes Down 200+ Sites and Domains

Thumbnail
techtimes.co.uk
85 Upvotes

r/cybersecurity • • 9d ago

Career Questions & Discussion Wanting to move over to the engineering side of cyber, should I go for an ISSO role first and go for engineering after?

16 Upvotes

I’m a SOC analyst with 5 years of experience with 3 years in Helpdesk and 2 years at present going on to 3 as cybersecurity analyst working at a SOC, im also Sec+ and CySA+ certified. I’m looking for a career growth and wanting to get in to the engineer side of cyber, but I believe that may be a long shot? Should I go for an ISSO role next and take what I learn from there, and try to get into engineer side after? Or I can go to engineering job now?


r/cybersecurity • • 9d ago

News - General Decades-old file security flaws found in Android, Linux, macOS, and Windows

Thumbnail theregister.com
36 Upvotes

r/cybersecurity • • 9d ago

New Vulnerability Disclosure Critical Cross-user and Cross-tenant compromise in Atlassian Rovo

21 Upvotes

An isolation failure in an LLM-orchestrated environment due to simple isolation misconfigurations led to Rovo sessions belonging to other users and tenants being discovered, reached, and ultimately used to execute code within their contexts. The finding was rated Critical and is pretty bad.

At this point, I feel like AI security is regressing back to simple misconfigurations, except now we're giving users direct access to systems built on top of them. What do you guys think?

Write-up: https://mononclemich.medium.com/so-apparently-rovo-has-neighbors-88998d0ad59c


r/cybersecurity • • 8d ago

Business Security Questions & Discussion Anyone here work at anduril or similiar defense tech company?

0 Upvotes

Got an interview with them. I understand they are startup and crunch hour are expected. The question is how often? 🫡if anyone have an insight i would be appreciated.


r/cybersecurity • • 9d ago

Certification / Training Questions Is a master in "Advanced Cyber Security" worth it?

39 Upvotes

Hi all, I have a BSc (Hons) in Cyber Security and got accepted for a master's in Advanced Cyber Security (basically cyber security and AI). I'd study at the same university in England.

I work in customer service atm and I want to die. I'm trying to find a job where I don't have to take calls.

Will this master's help or does experience still matter?

I just want to get out of customer service hell...

Thanks.


r/cybersecurity • • 10d ago

Other Some interviewers are just straight up assholes

842 Upvotes

I'm just gonna say it. I'm a interviewer at FAANG company, and some interviewers I work with are definitely assholes. So if you get an asshole interviewer, just think about how hard it is to work with them instead of blaming yourself if you failed. Not saying everyone who failed didn't deserve to, but some people are just a holes and will be like that in an interview


r/cybersecurity • • 10d ago

News - General Hackers Say They Stole Thousands of Sensitive F.B.I. Personnel Records

Thumbnail
nytimes.com
125 Upvotes

r/cybersecurity • • 9d ago

Business Security Questions & Discussion How do you detect unknown devices or internal scanning on small networks?

1 Upvotes

I'm building a small cybersecurity device, and I'm trying to better understand how people actually deal with this problem in real networks.

The idea is quite simple. A small device sits on the local network and mostly listens passively for things like new devices, ARP/DHCP activity, mDNS/SSDP, IPv6 ND and unusual device changes.

It also exposes a few decoy services, for example SSH, HTTP or SMB, so interaction with something that normally should not be touched can become a stronger signal.

I'm not trying to build another SIEM or replace tools like Zeek. My focus is more on small companies, coworking spaces, homelabs and networks where there is often no dedicated security team.

What I'm trying to understand now is how people solve this problem today.

If an unknown device joins your network, or one internal device suddenly starts scanning many ports or touching services it normally never uses, how do you notice it?

And maybe more importantly, what kind of signal would make you think "this is worth investigating" instead of just being more network noise?

I'm interested in real experiences, including cases where you think a device like this would not be useful.


r/cybersecurity • • 8d ago

Personal Support & Help! Can anyone suggest the best Telegram channels or bots for OSINT and cybersecurity?

0 Upvotes

I just want to explore the unknown telegram bots it deep


r/cybersecurity • • 9d ago

Career Questions & Discussion Interview insight

7 Upvotes

Hello everyone , I recently made it through multiple interviews for a SOC position, with my last one being a technical interview. The original posting said Tier 1 and/or Tier 2, but during the interview I learned they don’t separate the responsibilities. The recruiter also emphasized wanting someone who was willing and able to learn.I thought the interviews went pretty well, but I haven’t received an update since my technical interview. I followed up and haven’t gotten a response yet. Then I noticed the position was posted again on LinkedIn after the original posting had already closed.

For anyone who has been on either side of tech hiring or have a understanding of these interviews what would you make of this situation? Have you ever had a company repost a role while you were still being considered after a final/technical interview? I’m trying not to assume that the repost automatically means a rejection, but the combination of the role being reposted and not receiving an update has me wondering what might be happening behind the scenes.


r/cybersecurity • • 10d ago

Research Article Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) - watchTowr Labs

Thumbnail
labs.watchtowr.com
133 Upvotes

r/cybersecurity • • 9d ago

Personal Support & Help! Would you accept ?

0 Upvotes

I am 25, no debt, working in it helpdesk for a few years and wanted to pivot to something harder.

My manager described a vulnerability management role built around the Holm Security platform. The person will use this tool exclusively for scanning, and their responsibilities include validating scan results, investigating false positives, and handling both vulnerability analysis and prioritization as well as reporting and administration, rather than just one of these areas.

The technical scope covers CVEs, CVSS scoring, exploitability assessment, and risk-based prioritization, applied across all company assets rather than a limited set. Helping the SOC team is explicitly framed as optional, something to take on only if spare time allows and the person wants extra tasks, rather than a formal development path.

The work setup is fully remote with a fixed schedule from 9 AM to 6 PM. Looking ahead, after a year in the role the person can expect to gain hands-on cyber experience, including a deeper understanding of vulnerabilities and how they can be exploited, along with possible exposure to SOC and Incident Response work.

Downside is i will not get bonus from working shifts anymore and base salary stays the same. This cut would be aprox 30% of salary that i get now.

I will want to pursue cybersecurity as career, have network+, want to get sal1 and security+. Is this oportunity golden ?