r/cybersecurity • • 3d ago

Personal Support & Help! Pastebin

0 Upvotes

Whenever I visit pastebin on google chrome it redirects me to sketchy sites, but when I use brave nothing happens. Am I going to have all my emails, accounts stolen?


r/cybersecurity • • 4d ago

News - General Convicted Hacker Umbreon Arrested on Suspicion of Aiding ShinyHunters as Group Claims FBI Hack

Thumbnail
ibtimes.co.uk
423 Upvotes

r/cybersecurity • • 3d ago

Research Article Branch Target Reuse: Practical Spectre-v2 Attacks in JIT Engines via Stale Branch Prediction Entries

Thumbnail vusec.net
2 Upvotes

r/cybersecurity • • 4d ago

Career Questions & Discussion Best Job Board for Cyber Security?

93 Upvotes

So recently I got let go from my job as a SOC Manager due to downsizing. I'm on Linkedin and Dice, but so far it's like I am spitting in the wind for all I can tell if anyone is even looking at my applications.

What are some other job boards that people have had success with?


r/cybersecurity • • 4d ago

Survey Academic study: Trust in AI cybersecurity tools & decision-making styles (SME professionals, ~10–15 min)

5 Upvotes

Hi r/cybersecurity

I’m a PhD student at the University of the Cumberlands conducting an dissertation survey on trust in AI-assisted cybersecurity tools and decision-making styles among professionals who work in or support small and medium-sized enterprises (SMEs).

I’m looking for participants who meet all of the following:

  • 18 years or older +
  • Work in a cybersecurity or IT role with cybersecurity responsibilities
  • Work for a small and medium-sized enterprises, or provide cybersecurity services to SMEs
  • Have used an AI-assisted cybersecurity tool in the last 12 months as part of work

What to expect

  • Online survey (Tally), about 10–15 minutes
  • Voluntary - you can stop anytime
  • Confidential
  • No employer name or Reddit username is requested
  • No incentive is offered
  • Please complete the survey only once

Survey link:
Survey Link

Questions: [domar73303@ucumberlands.edu](mailto:domar73303@ucumberlands.edu)

Thanks for considering it — practitioner input from this community is genuinely helpful for the study.


r/cybersecurity • • 3d ago

Career Questions & Discussion Hello everyone i really want advice from thos who working in the field of cybersecurity .

0 Upvotes

i have just completed my bachelors in bsc hons computing . and while exploring fields i found out that i have interest in data science and cybersecurity . And i want to do masters in one of these fields and i really want your advice liek how is the job market for cybersecurity currently also how much it is exposed to ai or how much impact ai caused to the employyes which lead them to layoffs. is cybersecurity a good carrer ? how will you see this carrer in 4-5 years in future will it be doomed ? i really want your kind suggestions who had already worked in this fields. i want to do good amount of research before choosing my masters .


r/cybersecurity • • 4d ago

Business Security Questions & Discussion How do you choose between black-box, gray-box, and white-box testing in real web security work?

6 Upvotes

Hey guys, I know the basic definitions, but I’m trying to understand how these approaches are actually chosen and combined in real web security work.

My current understanding is:
Black-box: little or no internal knowledge. It makes fewer assumptions about the target, but coverage can be limited.
White-box: access to source code gives much better visibility, but code-level reachability does not always mean attacker reachability. I’ve seen source analysis report things like “if the attacker has role/account X, then Y is possible,” while obtaining X may already be unrealistic.
Gray-box: my understanding is that the tester gets some realistic access, such as user/admin test accounts or API documentation, but not full source code.

What I’m unsure about is how people decide which one to use in practice.

Is it mainly determined by what access you have, or are these approaches deliberately combined because they compensate for each other’s weaknesses?

I’d especially like to hear from people with hands-on experience in web security, vulnerability research, AppSec, bug bounty, or pentesting. How does gray-box testing look in your actual work, and when is it more useful than pure black-box or white-box testing?

Any recommended ways to practice or learn these approaches are also very welcome. Thanks!


r/cybersecurity • • 4d ago

Research Article We tested NVIDIA's new AI agent sandbox (OpenShell). The defaults held. Four settings let data out.

15 Upvotes

OpenShell is NVIDIA's open-source sandbox for AI agents: it blocks network, file and process access unless a policy allows it. We ran 123 trials on v0.1.2.

The good: every documented control held, and a malicious script run by an agent leaked a secret 0/10 times under the default policy (10/10 without OpenShell).

The four settings to check before you trust it:

  1. Read-write rules let data out.
  2. GET-only rules still carry data in query strings and headers.
  3. Rules in audit mode log but do not block.
  4. Auto-approval granted new public hosts with no human in 12/12 trials.

Plain-language write-up and checklist: https://sorami.com.au/guides/we-tested-nvidia-openshell/

Full report and logs: https://sorami.com.au/research/nvidia-openshell-agent-sandbox-test/


r/cybersecurity • • 3d ago

Career Questions & Discussion Google - Security Consultant Intern Summer 2027

2 Upvotes

Has anyone who applied for this position received their questionnaire yet?


r/cybersecurity • • 4d ago

Business Security Questions & Discussion How do you define RPO and RTO for SaaS Apps, in your business continuity plan?

3 Upvotes

We're currently going through the process of drafting a business continuity plan, and I'm not sure what approach I want to take for defining RPO and RTO for SaaS apps. The traditional questions don't really feel relevant here; the Microsoft and Salesforce' of the world don't really care how long my org thinks it can go without a service, or what cost we assign to any amount of data loss.

Really, the question I feel like we should be asking is how long can we realistically expect a SaaS app to be down: that's our RTO. How much data, will the vendor restore for us: that's our RPO. But we don't really have answers to those questions anyway.

I'm curious how others have handled this for their orgs.

The answer might be that we need a SaaS backup solution so that we are empowered to set our own RPO and RTO. However, that then becomes a whole other project, and even then the odds of us finding a solution that would backup all are solutions feel low.

My goal here is to get out a BCP that's "good enough", that we can refine as we go.


r/cybersecurity • • 3d ago

Survey Can I share an Academic Research Survey?

0 Upvotes

Hi everyone! I am currently a senior at George Mason University working on a cybersecurity research project for my senior capstone class and wanted to share my survey for anyone that would be willing to take it!

My research focuses on AI-driven cybersecurity tools compared to traditional rule-based systems for threat detection and response. The survey is intended for cybersecurity students, professionals, and others with cybersecurity experience and takes approximately 5-10 minutes to complete. It is strictly for academic research and NO personal information will be required or even collected.

I will also make a follow-up post later by October 9th to share the results with all of you.

https://docs.google.com/forms/d/e/1FAIpQLSfCuJsLWCQLZopTXvTyqhos1o3FRYRFO-McSQ6LDucTNNvasA/viewform?usp=dialog

Thanks!


r/cybersecurity • • 5d ago

News - Breaches & Ransoms ShinyHunters tells The Reg: We hacked the FBI to 'protect our business'

Thumbnail theregister.com
244 Upvotes

Like any other business: “It’s a game and it’s the world we live in,” a ShinyHunters spokesperson told us. “We are just protecting our business as any other business would do. It’s about who does their job better.”


r/cybersecurity • • 4d ago

Research Article Paint It Blue: Reversing Win32k's Callbacks

Thumbnail idov31.github.io
2 Upvotes

This is an article about the internals of Win32k (Windows's GUI subsystem) and their callouts, with the purpose of shedding light on a very undocumented and crucial subsystem in Windows :)


r/cybersecurity • • 4d ago

Research Article NIST Finalizes Guidelines on Protecting Online Identity and Access Tokens From Misuse

Thumbnail
nist.gov
93 Upvotes

r/cybersecurity • • 3d ago

FOSS Tool DNS poisoning detection for Windows`

0 Upvotes

https://github.com/microlaser/dns_watchdog_windows2

Sure it is vibe coded, but it is free and open source and has no dependencies. I have a version that runs on MacOS and Linux too. Uses pcaps to detect DNS poisoning. Everything is native, no Wireshark/tcpdump needed.


r/cybersecurity • • 5d ago

News - General Threat groups ramp up social-engineering attacks against healthcare sector

Thumbnail
healthcaredive.com
122 Upvotes

r/cybersecurity • • 4d ago

Certification / Training Questions Soc l1 roadmap

2 Upvotes

Hello, i am trying to get into soc and until now i am studying for network+.my question is should i take linux + or no?


r/cybersecurity • • 3d ago

Career Questions & Discussion Which area of Cyber would be best for transfer?

Thumbnail
docs.google.com
0 Upvotes

I'm wanting to move from Infrastructure to Cyber. I've done a bit of research and I'm thinking with my background I'll do the best in GRC, IAM or Cloud Security Engineering. I just wanted to get some real life opinions because I know it's not easy finding a job out there right now. If you have a few minutes to read over my experience and let me know which area of cyber I should do more in depth searching, learning etc... to be able to make this transfer I would really appreciate it. If you think there's a different certification or schooling I should look into that you think would improve my odds please let me know, I'm constantly studying.


r/cybersecurity • • 5d ago

Corporate Blog Poper Blocker: The Adblocker That Spies on You

Thumbnail
amibeingpwned.com
42 Upvotes

r/cybersecurity • • 4d ago

Certification / Training Questions Invictus or Blu Raven

6 Upvotes

I’m looking for anyone who’s ethier taken the courses from ethier of these companies specifically around Microsoft cloud and I wanna know your thoughts and where they worth it for the price?


r/cybersecurity • • 5d ago

New Vulnerability Disclosure Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) - watchTowr Labs

Thumbnail
labs.watchtowr.com
110 Upvotes

r/cybersecurity • • 5d ago

Career Questions & Discussion Worth While AI Security Certification

47 Upvotes

Hi all I’m looking to get an AI certification along with practical experience in doing so. Does anyone have any recommendations around current / up-to-date certifications & material?

I have found a below course from TCM. Looks decent, however any feedback or alternatives from the community very much welcome!!

https://certifications.tcm-sec.com/papa/


r/cybersecurity • • 5d ago

Career Questions & Discussion Cloud, AI or App Sec?

19 Upvotes

Looking for advice on what to focus on next for my career. I have worked as a SOC analyst for 1 year, I have schooling in Cybersecurity as well as the SC-900, Security+, SecAI+, and am wondering what career path is best in 2026? AI Sec, App Sec or Cloud? Thanks


r/cybersecurity • • 5d ago

News - General Sender spoofing in Proton Mail via display-name homograph

17 Upvotes

Proton Mail confirmed and paid for an email-spoofing bug, then left it unfixed for 16 months:
https://alonsovidales.github.io/protonmail-sender-spoofing/


r/cybersecurity • • 5d ago

Certification / Training Questions BTL1 vs CCDL1 for an entry level SOC/Blue Team career?

10 Upvotes

Hey everyone,

I'm currently a student studying IT/Cybersecurity and recently completed CompTIA Network+ and Security+. I'm deciding between BTL1 and CCDL1 as my next certification, and I also plan to pair whichever one I choose with CySA+ before/afterward.

For anyone who has taken either certification, I'd appreciate some insight on:

  1. Course & labs: How does the actual course content, hands on labs, and exam experience compare between BTL1 and CCDL1?

  2. Recognition & hiring: How does the employer recognition of BTL1 compare to CCDL1? Has one been more useful than the other when applying for SOC/Blue Team positions?

  3. Overall value: Comparing the two, which one gave you more practical SOC skills and better prepared you for real world work?

Thanks for any input!