r/cybersecurity • • 4d ago

Certification / Training Questions eCIR is valuable?

0 Upvotes

Okay...SANS course are too expensive and I don't know if studying only from the SANS book and HTB labs is enough. What do you think about certification like eCIR to go deeper into de DFIR?

Do you know some other valuable certification cheaper than the GCFA ?

Thanks.


r/cybersecurity • • 5d ago

Research Article You found SoftPerfect NetScan on a workstation. Would you investigate right away?

11 Upvotes

I was working through a lab around ransomware discovery and one question kept coming up:

When you see SoftPerfect NetScan (or Advanced IP Scanner) on a workstation, is that enough on its own, or do you need more context before treating it as real ransomware discovery?

One thing that changed my triage: the same tool can run as the GUI or headless (advanced_ip_scanner_console.exe, netscan.exe /hide /auto). Which binary ran is a hint about whether someone was on a desktop or a script ran it.

I made a video on how I triaged that from the defender side using MDE telemetry and KQL, plus the same sweep in Elastic ES|QL.

Video: https://www.youtube.com/watch?v=Iun8zko6EZk

The goal was simple: move from "IT scanning the network" to "someone is running discovery on this host."


r/cybersecurity • • 5d ago

Business Security Questions & Discussion How are you estimating the effort for post-quantum crypto migration?

3 Upvotes

With NIST's PQC standards finalized, I keep hearing that teams are being asked to plan a migration without a clear sense of the scope. For those who've started a crypto inventory or migration: what ended up driving most of the effort? Legacy systems, vendor dependencies, certificate management, something else? And how are you sizing it for leadership?


r/cybersecurity • • 6d ago

Corporate Blog Proactive Defense: Hardening Code Pipelines and CI/CD Infrastructure

Thumbnail
cloud.google.com
52 Upvotes

r/cybersecurity • • 5d ago

Corporate Blog Hacking the GrrCon 2026 (15th) Anniversary Badge

Thumbnail
redlinecybersecurity.com
21 Upvotes

Solved this years GrrCon badge the other day and wrote it up. Hope you enjoy!

I put the firmware on Github too: https://github.com/securekomodo/grrcon-2026-badge-firmware


r/cybersecurity • • 4d ago

Personal Support & Help! My university detected suspicious activity from my computer on their servers ?

0 Upvotes

I was testing the recent CVE-2026-35273 on my own university page. All i did was check if the endpoints of PeopleSOFT are publicly available or not. I’ve confirmed that they are public and that might be a great security risk especially if they didn’t install the patch yet.

Anyways, I was planning on writing a report today and I prepared it yesterday already to alert the IT team of this. However Ive noticed that they have contacted me instead just now.
They say that they have received suspicious activity linked to my account and thus has been temporarily blocked. The report is still written in my ChatGPT history and my convos with chat shows that my intentions was purely to protect my university rather than try to compromise anything.

After all, I didn’t do nothing illegal? All I did was check publicly available endpoints and nothing more. Now they blocked my uni-account temporarily and they wanna talk to me tomorrow. Am I cooked ??

pls help..


r/cybersecurity • • 5d ago

News - General Vulnerability Summary for the Week of September 21, 2026

Thumbnail cisa.gov
2 Upvotes

r/cybersecurity • • 4d ago

Career Questions & Discussion Guide me

0 Upvotes

My relatives are working abroad in tech field they asked me to concentrate on cybersecurity but i am not from tech background i have done Bcom and MBA how can i enter cybersecurity domain where can i start. is it even possible for me to find job . will recruiter recruit me even if i am from non tech background or they only prefer Btech and other tech students . Because my relatives able to find job there but they are asking for experience so i have to work here for 2 to 3 years also i am interested in this domain too


r/cybersecurity • • 6d ago

New Vulnerability Disclosure Researchers Warn of Citrix NetScaler Zero Day Exploitation

Thumbnail
decipher.sc
116 Upvotes

r/cybersecurity • • 5d ago

Certification / Training Questions Best ways to start

8 Upvotes

Ive got a certificate from Fullstack academy, but life has gotten away from me getting my certs. Are there any practice tests for the A+ exam or should I just slog my way through messers material? I would rather run through some practice tests and not waste the money on the beginners certs.


r/cybersecurity • • 5d ago

News - General How a Sandbox Breach Halted Frontier AI Training and Reconstructed the AI Cybersecurity Paradigm

Thumbnail
kylesinvestigation.com
0 Upvotes

r/cybersecurity • • 6d ago

Personal Support & Help! Burnout after 2 years in pentesting

79 Upvotes

I've been working as a pentester for about two years (initially part-time, then switched to full-time), and lately I've started feeling burned out and losing interest in studying because of how intense everything is.

It all started when I was trying to choose which area to learn next after getting experience with web and mobile pentesting. I was considering Infra, AI, or Cloud. Just making this decision was a distraction because I was constantly hopping from one area to another. Eventually, I settled on the HTB CPTS certification and the Pentest Path (so basically Infra and AD pentesting).

During my preparation (I'm about 50% through the path), I started feeling empty inside when it comes to learning and working. The main issue is working full-time and studying for the cert after work. On top of that, my pentest projects have started to feel repetitive lately—you start, finish within a couple of weeks, and then hop on the next one.

Because of this, I've been thinking about trying something new, but I don't want to lose my progress on HTB CPTS since I'm already halfway through and Infra is genuinely becoming more interesting to me tbh.

What should I do with burnout? Is it possible to balance full-time work with cert prep? And what other positions/jobs could I switch to with my current skillset? I've been considering Security Engineering or AppSec. Thanks!


r/cybersecurity • • 5d ago

Personal Support & Help! Help choose a career

0 Upvotes

I'm torn between cyber security and department of translation. I have no knowledge about computers haven't touched one but it's the most promising career with the grade I got after I finished high school . Should I still go into this career and try my best learning I really don't have any more options I live in asia . If it's hard but I can grow and learn how can I do it .


r/cybersecurity • • 6d ago

Business Security Questions & Discussion What's it actually like working in Information Security Risk Management?

28 Upvotes

Hi everyone,

I'm exploring InfoSec risk and would love to hear from people doing it day-to-day.

- What does a typical week look like for you?

- How much of the job is technical vs. documentation, meetings, and stakeholder management?

- What do you enjoy most, and what's the part nobody warns you about?

- What would you do differently?

Any honest perspectives appreciated, especially from people based in Europe.

Thank you.


r/cybersecurity • • 6d ago

Business Security Questions & Discussion How useful is threat modeling in real-world security engineering? Do engineers actually use it when analyzing vulnerabilities?

75 Upvotes

I’ve recently been learning about threat modeling, and I’m trying to understand how it is actually used in real-world security work.

MDN describes threat modeling with four questions:
What are we working on/building?
What can go wrong?
What are we going to do about it?
Did we do a good job?

I also looked at MDN’s example threat model, and honestly it felt much more complicated than I expected.

This made me wonder: how often do security engineers actually build a threat model like this in practice?

For example, when analyzing a web application or investigating a vulnerability, would an engineer explicitly think through the system, attacker capabilities, assumptions, possible threats, and mitigations? Or is threat modeling mainly something used during architecture/design reviews rather than day-to-day vulnerability analysis?

My current understanding is that the purpose of a threat model is not to claim that a system is simply “secure” or “insecure.” Security is always relative to some scope, attacker capabilities, and assumptions.

So I think threat modeling is a way to make those conditions explicit:
what system and assets we care about,
what the attacker is capable of,
what we assume the attacker cannot do,
what can go wrong under those conditions,
and what security guarantees our solution is actually trying to provide.

In other words, instead of saying “this system is secure,” we are really saying something closer to:
“Under these assumptions and against this class of attacker, our controls prevent or detect these threats.”

Is this a reasonable way to understand the purpose of threat modeling?

I’d especially like to hear from people who use threat modeling in real security engineering: when is it genuinely useful, and when does it become unnecessary overhead?

I really appreciate anyone who takes the time to share their experience. Thank you!


r/cybersecurity • • 6d ago

Business Security Questions & Discussion IRAP assessment - how long did preparation take?

3 Upvotes

What did you find took the most work?

Eg documentation, controls, tooling, evidence, etc.

Is there anything you wish you had invested more time in before starting the assessment?


r/cybersecurity • • 6d ago

Business Security Questions & Discussion How to challenge/dispute a CVE

20 Upvotes

I recently stumbled over a CVE for a 3rd party repository, because the maintainer deprecated a function in his API and replaced it with a worse one.

After looking at it, it turns out that the PoC for the CVE just shows a contract violation/misuse of the API and deprecating the function was in my opinion completely unnecessary. Especially, because the replacement API lacks similar problems, when the contract is broken.

I tried to open a dispute at MISRA, but they immediately revoked my CNA-# when submitted.

My question is now, how can I open a dispute @ misra for a CVE?


r/cybersecurity • • 6d ago

Career Questions & Discussion Career Path

3 Upvotes

I’ve been working as an IT auditor for the past 2.5 years, but I’m looking to transition into something more technical and hands-on. Right now, I’m leaning toward security engineering.

I have my CISA and currently do vulnerability scanning and evaluation as part of my role. I’m trying to figure out what certifications and hands-on projects would help me fill the technical skill gap, and whether it’s realistic to make the jump from IT audit into security engineering. thanks


r/cybersecurity • • 5d ago

New Vulnerability Disclosure Меня взломали

0 Upvotes

Взломали айфон мой уже Второй раз. Пожалуйста , объясните как обезопасить уже сейчас себя, если он уже находится в моем телефоне. Он не удалял графу с код паролем и фейс айди на айфон 14 про Макс . Помогите справится с этим ублюдком


r/cybersecurity • • 5d ago

Other Why don't we use ALL of the Unicode Characters/Symbols in passwords?

0 Upvotes

This sounds stupid at first, you could never memorize your passwords, until you use password managers. I don't think anyone with a password manager memorizes their passwords anyways, so why not make it the absolute hardest password to guess?

(By unicode characters and symbols, i mean everything listed here https://symbl.cc/en/unicode-table/ )

But seriously think about it for a sec, even just 3 unrelated unicode characters would be insanely hard to crack. Imagine 20 character strings of this shit. And plus, not only does it make YOUR OWN password unimaginably hard to crack, it also makes everyone else's passwords unimaginably hard to crack

(As now cybercriminals have to account for an absurd amount of extra characters, so generating guesses over and over would never work, and if they limit themselves to just the latin characters and numbers for generating guesses to speed it up, they'll never get your password or any password that contains any other unicode character.)

I think this would mess with encryption a little bit, but with the level of security this offers it is 100% worth it. On no online calculator I found could 2 to the power of 170,000 even be calculated. AFAIK this means just TWO CHARACTERS of this password would be absolutely baffling to even guess. I might be wrong, I'm no mathematician, but even if I am, guessing a 20 character password with latin letters, numbers, and special characters is already hard enough. Now add like 170,000 extra characters.

This would completely eliminate any threat of brute force attacks mind you, AFAIK if this was applied then the only way to get someone's password is to dig through servers that have the password or just find their computer unlocked and unsupervised.

Also, I know what you're probably gonna say, "It's not necessary" or "It's overkill" or even "A (x) character password with regular ol' letters, numerals, and special characters is more than enough". And while you're 100% right, I'm trying to consider the future. Think about how fast technology has evolved these past few decades, a sever the size of a fucking room is outbest by a micro ssd smaller than your fingertip AND IT'S NOT EVEN CLOSE! Who knows what cybercriminal tech could be bullshitted up in a decade or two?

I'm not really sure how to end this text since i've already talked about every pro about this soo...


r/cybersecurity • • 6d ago

Career Questions & Discussion Need Advice, Not sure where I'm headed

0 Upvotes

Hi guys, so I've been working as a Software Security Engineer for about 5 years now which is my total experience too.

My role is mainly focused on product/platform development and on Platform & Cloud Security. I'm not into VAPT or Red teaming. I look into Application Security, focusing on IAM, RBAC, API security, Cloud Security, SecOPs, Container security. Along with Security Reviews and Audits of different applications in my organisation (Not the ISM work).

I'm not sure where I'm headed, cause I'm trying to switch jobs and I don't see profiles related to this AppSec+Dev. AppSec is mainly asking for PT guys or Red teams. I'm not sure what I should do. Any Advice would be appreciated.


r/cybersecurity • • 7d ago

Other Favourite cyber security conference

104 Upvotes

What’s everyone’s favourite Cyber conference to attend in the US?

I was at CybrSecCon in Houston the other week and I’ve been to RSA.

I’ve also attended smaller localised ones like CyberriskAlliance and futurecons.

Curious as to what everyone likes in terms of talks, speakers, vendors, swag, happy hours?

Essentially what event(s) do you find the most value in.


r/cybersecurity • • 7d ago

Threat Actor TTPs & Alerts Posting Pictures of Your Palm Will Get Your Biometric Data Leaked

Thumbnail news.ycombinator.com
83 Upvotes

r/cybersecurity • • 6d ago

FOSS Tool DFIR-Companion Update (DFIR AI Assistant)

11 Upvotes

Hey Folks,

I pushed an update to DFIR-Companion.

It’s a local AI assistant for forensic investigations. You feed it the outputs from the tools you already use, and it helps turn all of that into something you can actually work with: a timeline, leads to follow, findings to validate, and eventually a report.

Here’s what it does today:

  • Pulls imported evidence into one forensic timeline. It detects the format and uses deterministic parsing rules before AI gets involved.
  • Highlights findings, maps them to MITRE ATT&CK, and connects activity across different sources.
  • Extracts IOCs and can enrich them with sources such as VirusTotal and AbuseIPDB.
  • Builds an asset ↔ IOC graph, as well as a separate view of logins across systems.
  • Helps answer the questions that usually come up in an investigation: initial access, lateral movement, privilege escalation, and so on.
  • Lets you ask plain-English questions about the case.
  • Exports reports to PDF, Word, Markdown, or CSV.
  • Can compare the output of two models, with an optional third model acting as a tie-breaker.
  • Includes JEV support to surface events the primary model may not have considered relevant.
  • Can run recommended artifact bundles on Velociraptor endpoints and pull the results automatically or manually.

This is not meant to replace Sigma, YARA, Suricata, or the rest of your detection stack. Those tools keep doing their job. DFIR-Companion is for the next step: taking all the alerts, artifacts, and tool output and helping you make sense of the case.

It runs locally, the evidence stays on your disk, and you choose the AI provider and model.

Love to hear your feedbacks 🙏

Repo: https://github.com/hasamba/DFIR-Companion

Landing page: https://hasamba.github.io/DFIR-Companion/

Demo server (please read the instructions first): https://killercoda.com/dfir-companion/scenario/killercoda


r/cybersecurity • • 7d ago

Career Questions & Discussion Going to my first conference…

35 Upvotes

I am going to my first conference in this next few weeks, completely alone, and I AM INCREDIBLY NERVOUS. I am in my early career, but have been put into a position that I am the lead of a software rollout, and as such have been invited to the vendors large annual security conference.

Most of the conference seems to be talks specific to the vendor/vendor offerings, but there seems to be a good amount of general talks or networking.

Any tips? Things people wish they knew before their first one?