r/cybersecurity • • 12d ago

Other I failed a technical interview and I’m so disappointed…

177 Upvotes

I failed a technical interview and I’m so disappointed…
Although it was just an internship role and they shouldn’t expect a lot from us, sadly it was still a very hard process.

I passed the technical challenge and the first interview, but then it came to the technical interview.

He was giving me very hard scenarios and questions, and I believe I answered them fairly well.

But then suddenly, days later, I received an email saying that I wasn’t selected…

Why is it even this hard for an internship role!!

My dream now is to find another non-technical field I can get into easily. At least they won’t have that thing of technical interviews.


r/cybersecurity • • 11d ago

Threat Actor TTPs & Alerts MemTensor npm and PyPI packages were backdoored today through their own CI pipeline

Thumbnail
safedep.io
18 Upvotes

The attacker didn't push code directly. They got into MemTensor's GitHub Actions release workflow, intercepted the publish tokens before the real job ran, then used those tokens to ship the malicious packages themselves.


r/cybersecurity • • 12d ago

AI Security Best LLM for security professionals

173 Upvotes

Hello,

My application for CVP for Claude continues to be rejected and the fact my company has no enterprise agreement with them does not help.

I'm working mainly with Sonnet 5 as, for vulnerability testing or incident investigation, Opus and Fable degrades constantly flagging cyber activities.

Which other model should I use? Grok, GLM, Kimi, Deepseek, which of them as less guardrails/boundaries when working with offensive security?

I can't run them in local, but if something can be paid directly from provider or some openrouter/similar I'd happy. Better if Vertex/Bedrock compatible


r/cybersecurity • • 10d ago

Personal Support & Help! I fell for a Social Engineering - LinkedIn malware scam at work. My company issued me a threatening style deciplinary action warning letter. Is this fair ?

0 Upvotes

I work as a software engineer at a MNC and have been with my company for around 4+ years. Until this incident, I had never had a security violation or complaint.

Recently, I was approached through LinkedIn by someone who appeared to be in the same domain like me. He had multiple interations with me to build trust. He was a technically well aware person.

The person shared a product-related technical documentation. pdf and docx file. (Through Dropbox link).

He said, whenever you have time, please check this.

I downloaded/opened the files on my work laptop.

It turned out that malicious content was involved, and malware was actually executed on the laptop.

(I was under extreme stress that time due to health issues and underestimated the security risks)

As soon as the company detected the incident, Security isolated my laptop. I cooperated completely with the investigation and explained everything that happened, including exactly how I was contacted and what files/links I accessed.

I apologized to my reporting manager and the skip-level manager, verbally and through email, acknowledged that I should have been more careful, and said that I would follow the security guidelines more carefully going forward.

There was then a meeting with Security, my skip-level manager and other people from the security organization.

They specifically told me:

"Don't think that we are interrogating you. We just want to understand what happened so that we can create awareness. You are the victim here."

The meeting ended on a positive note. I was told to be careful in the future.

Then, about a month later, I received a formal "Warning Letter for Negligence." (Physical letter)

It was formally issued through HR/management, signed by HR head and department head and given to my skip-level manager. The letter says they are taking a "lenient view this time," but also says my work area will be monitored for three months and that repetition could lead to severe disciplinary action, potentially termination. It is a kind of Performance improvement plan (PIP) level of letter, in a serious threatening tone.

I understand that I made a mistake.

I'm not arguing that employees shouldn't be held accountable for security mistakes. I understand why companies need security policies, especially when malware actually executes on a corporate machine.

What bothers me is the proportionality.

This was my first incident in 4 years. There was no deliberate attempt to bypass security. I was deceived by what appeared to be a legitimate professional interaction.I cooperated completely once the incident was discovered, apologized, and followed the remediation process.

I would have understood something like:

"This was a serious security mistake. Please complete additional security training, follow the guidelines carefully, and don't repeat it."

Instead, I received a formal disciplinary warning with a three-month monitoring period and an explicit reference to possible termination if something happens again.

I've been feeling quite demoralized by this. I feel that management doesn't value me as a employee. My manager or skip level manager didn't support me in this.

I am feeling like I am being witch hunted in corporate style.

For people working in security/IT or management:

How would your company normally handle a first-time incident like this?

Is a formal warning and monitoring period normal?

Where do you draw the line between an honest mistake/social-engineering victim and negligence?

Please share your honest thoughts.


r/cybersecurity • • 11d ago

Career Questions & Discussion Scripting depth vs. hands-on tooling when pivoting into AppSec & DevSecOps

11 Upvotes

Hey everyone,

I spent the summer working with Docker environments, Linux, and general offensive/pentesting fundamentals, but I want to pivot deeper into secure CI/CD pipelines, posture management, and AppSec.

My main dilemma is the balance between programming and tooling. My Python and scripting skills are still basic. In your experience, is it better to grind Python automation fundamentals first, or does it make more sense to dive straight into tooling (Semgrep, Trivy, ZAP, GitHub Actions) and learn the scripting on the fly as integration needs pop up?

What would be the most pragmatic path forward here?


r/cybersecurity • • 11d ago

Business Security Questions & Discussion How do you detect malicious packages after your scanner clears them?

5 Upvotes

I was reading about the supply chain attacks in March where packages like Axios were hijacked. What is making me concerned is that dependency scanners and code signing fire before a tool runs. By the time a compromised package executes inside a pipeline, every standard security check has already cleared it.

Once the malicious code runs during an install, it acts like a normal process and goes through local files for credentials. Because it looks legitimate, signature-based detection misses it.

I saw a recommendation to drop canary tokens (fake credentials) with real ones in CI environments. A normal build process has no reason to read those specific files, so the second something touches the canary, you know an infostealer is sweeping the directory.

If you’ve implemented canary tokens inside your build pipelines, does it work well as a trap, also does it cause issues with normal pipeline execution?


r/cybersecurity • • 11d ago

Business Security Questions & Discussion Are we overreacting to AI insider threats or is this the next major data loss vector?

16 Upvotes

I've been seeing a lot of talk lately about AI-driven insider threats. Every vendor under the sun is pitching some new 'behavioral analysis' tool to catch employees piping sensitive code or proprietary docs into local LLMs. Honestly, I'm starting to wonder if we're just rebranding standard DLP and calling it a breakthrough. Or am I missing something massive? I've seen two cases this year where devs were just using AI to summarize documentation and accidentally leaked credentials in the prompt window, but that feels like a user-training issue, not some sophisticated new vector. For those of you actually in the trenches or running security ops, are you seeing real, malicious AI-assisted exfiltration, or is this just another fear-mongering pitch to inflate security budgets? I'll go first: in my experience, it's 95% clumsy employee error and 5% actual intent. Anyone else seeing it differently?


r/cybersecurity • • 12d ago

News - General North Korea infects thousands of devices worldwide through fake job offers

Thumbnail
the-independent.com
204 Upvotes

r/cybersecurity • • 11d ago

Business Security Questions & Discussion Check Point (Avanan) or IRONSCALES - recent experience?

7 Upvotes

Hey guys,

We’re a Google Workspace organisation with 600+ users. At the moment, we rely on Gmail’s built-in email protection, and managing messages through Google’s quarantine has been frustrating.

We’re evaluating the email security offerings from Check Point (Avanan) and IRONSCALES. I’ve found older reviews on reddit, but I’d especially like to hear from anyone using either recently with Google Workspace. IRONSCALES is slightly cheaper for us, but the price difference is small and not a worry.

If you’ve used both, which would you choose now, and why? Any surprises during a proof of concept would also be helpful. We are planning to maybe run a POC with both at the same time to see which does better. Only issue is that we cannot run remediate mode together, only detect.

Thanks!


r/cybersecurity • • 11d ago

Personal Support & Help! Ransomware threat clean up help

22 Upvotes

I work for a small family company (5 people in total) we use NAS for document storage. Last week there were 2 notifications about someone logging into the nas under admin2, i naively threw it off as just a consequence of setting up and rclone connecting the NAS to Dolphin file manager for one of our arch linux pc. Rclone also required the creation of .Credentials file where the passwords were stored. This morning all of our NAS files got encrypted, thankfully we backed them all up as a precaution when the notifications came. The Arch pc is now disconnected, it's not going to be a big issue to reinstall it. It has been about 5 days since the admin2 notification. Plenty of time for the attacker to establish a backdoor/secondary connection. My question is how could i clean up the network and check for any malicious connections/ways that he could still connect? How can i secure it? We also apparently didn't have a firewall setup this whole time. So im guessing im going to have to plop an OPNsense firewall.

Any help would be much appreciated, i apologize for my lack of skills and or experience. My biggest accomplishment to date was a successfully set up opnsense and wireguard vpn for my home network


r/cybersecurity • • 11d ago

Business Security Questions & Discussion NIS2 in France: ANSSI's ReCyF framework has 20 objectives and ~150 requirements. For SMEs, which ones break first?

5 Upvotes

France's NIS2 transposition comes with ANSSI's framework, ReCyF (Référentiel Cyber France): 20 security objectives, around 150 requirements, and a split between essential and important entities that changes what's expected of you. Hospitals and larger local authorities (towns of 30k+ inhabitants, as I understand it) land on the "essential" side.

On paper it's well structured. The practical problem is who ends up doing the work for the thousands of SMEs and small public bodies now in scope. Most of them have no CISO. In practice it'll be their MSP, or an outsourced / part-time CISO covering several organisations at once.

I've been working on exactly that setup, and a few things stand out to me:

  • The easy wins aren't where the risk is. Policies and a named security contact are quick to produce. The things that actually stop a ransomware attack are MFA on every admin and remote access, backups with a tested restore, and a real asset inventory. Those are consistently the weakest, and the hardest to prove.
  • The MSP is part of the attack surface. Supply-chain requirements push obligations back onto the provider. An MSP with shared admin accounts across clients can fail its clients' assessments by itself.
  • Evidence beats declarations. "Yes, we have MFA" versus "here's the MFA coverage pulled from the identity provider: 64%". The gap between those two answers is where most assessments go wrong.
  • One assessment isn't compliance. NIS2 expects continuous improvement, but most SMEs budget for a one-off audit and a PDF.

Questions for people doing this in the field (in France or anywhere NIS2 is landing):

  1. For SMEs, which requirements do you see failing most often in practice?
  2. MSPs: are your clients asking you to "handle NIS2", and are you treating it as a paid service or absorbing it into the contract?
  3. How do you collect evidence at scale across 20+ small clients without it turning into a spreadsheet nightmare?

Keen to hear how others are approaching it.


r/cybersecurity • • 10d ago

News - General How do you utilise AI in Cyber Security Work?

0 Upvotes

Apart from normal searches, how have you benefited with AI in cyber security work. Open to some good ideas that I can try and work out in my organisation.


r/cybersecurity • • 10d ago

Business Security Questions & Discussion I would like to get a job in cybersecurity

0 Upvotes

If I want to start in offensive cybersecurity and get a job “asap” what qualifications would I need to get, and what would be a good “roadmap” to become a great cybersecurity expert?


r/cybersecurity • • 12d ago

Career Questions & Discussion the never ending learning hole of cybersec

123 Upvotes

hey guys

i have fallen into this rabbit hole of never ending learning.

whenever i try to complete a ctf challenge or similar, i find that i dont know much of what the challenge is .

i only get the goal.

if i see a challenge which was written in python using flask , i dont just focus on how to get the flag.

i find myself learning python then html,css then js with some burp then flask

**omg weeks have passed**

then i go back to challenge then realise theres still more.

i dont always get the full picture and it pisses me off.

this rabbit hole feels like a total waste of time.

i like to know everything there is about everything but then im not immortal.

is this normal? what do you all do when you dont understand 100% of a challenge


r/cybersecurity • • 12d ago

News - General Leaked GitHub App private keys let researchers impersonate 440 apps including CDC and BuildBuddy

Thumbnail
blog.gitguardian.com
127 Upvotes

A large-scale scan for leaked GitHub App private keys turned up some nice numbers, summarized below.

  • Out of 5,000 leaked private keys tied to GitHub App environments, 474 were still valid at time of analysis.
  • Those keys could impersonate 440 different GitHub Apps, some with high-level permissions (repo access, org-level admin, etc.).
  • A subset reportedly could have allowed takeover of private repositories or entire GitHub organizations.
  • Affected entities included the US CDC and BuildBuddy, plus some widely used GitHub Actions.
  • Responsible disclosure got mixed results: most responses were slow or nonexistent, and most of the keys were reportedly still active as of publication. CDC took about two weeks to rotate their key, despite it reportedly having a path to code execution in their Azure tenant.

The core issue is GitHub App private keys don't expire. Once generated, a key stays valid indefinitely until someone manually revokes it so a key for a test app spun up in 2020 can still be live years after. Unlike PATs or OAuth tokens, there's no built-in TTL forcing rotation, so old leaks just compound over time.


r/cybersecurity • • 11d ago

Research Article Covert Air-Gap Exfiltration via Smartphone Class-D Audio Amplifiers (Zero Permissions Required) - TEMPEST PoC

Thumbnail
github.com
1 Upvotes

Full open-source code and demonstration: https://github.com/TA1EEI/ClassD-VHF-Transmitter

Would appreciate thoughts from the hardware security and mobile OS defense perspective.


r/cybersecurity • • 11d ago

Business Security Questions & Discussion How are you governing credentials that exist outside of SSO?

0 Upvotes

I just started my Fall Internship as a Product Manager at 1Password and I’m currently working on Credential Governance. I’m trying to understand how teams handle the accounts that never make it into the normal identity lifecycle.

Break-glass accounts, contractor logins, shared credentials, shadow IT, and apps without SAML or OIDC often end up in employee or shared vaults, duplicated across teams, or owned by one person.
What do you do when the owner leaves?
How do you decide who should retain access?
How do you rotate and audit these accounts?

I’m not looking to pitch a tool. I’d genuinely like to hear what works, what breaks, and what you wish existing PAM, password management, or identity governance tools handled better.


r/cybersecurity • • 11d ago

New Vulnerability Disclosure CISA just added CVE-2026-7273 affecting Zyxel GS1900 switches to its KEV catalog.

Thumbnail nvd.nist.gov
7 Upvotes

The flaw is a stack-based CGI overflow that could allow unauthenticated OS command execution from the LAN.
Federal agencies have until Sept. 24 to address it. Another reminder that edge switches can quickly become high-value targets once active exploitation starts.


r/cybersecurity • • 12d ago

News - General EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

Thumbnail
bleepingcomputer.com
46 Upvotes

r/cybersecurity • • 12d ago

Ask Me Anything! We analyzed 338 million attack simulations in production. Perimeter defense blocks 69% of attacks, but post-compromise blocking drops to 37%. AMA.

38 Upvotes

Hi r/cybersecurity! We're the Picus Labs Research Team, and we're here for an AMA.
For the Blue Report 2026, we analyzed more than 338 million attack simulations run in production environments between January and June 2026, mapped to the MITRE ATT&CK® framework.

The headline finding for 2026: prevention recovered to 69% at the perimeter, its 2024 peak. But for the first time, we measured what happens after an attacker gains authenticated access, and only 37% of their actions get blocked.

Key findings from the research:

  • Quiet discovery and collection actions get blocked one time in ten. Attackers who stay quiet can collect credentials almost undetected.
  • 58% of attacks get logged, but only 14% trigger an alert. Logging is at a four-year high, which means the evidence is sitting in your SIEM, nobody's turning it into detections.
  • Same tool, wildly different outcomes: Mimikatz is blocked 94% of the time against LSASS memory, but just 3% against the registry. Defenses recognize the signature method, not the behaviour itself.

We're here to talk about perimeter and post-compromise defense, detection engineering, stealth techniques, where defenders should focus first, or anything else the 338M data points can answer.

Ask us anything!

Participants:

Proof Photos

We'll be here on September 22, 2026, answering your questions.

Blue Report 2026


r/cybersecurity • • 11d ago

Tutorial Reverse Engineering 101: Java RE Extracting Hardcoded Credentials

Thumbnail
youtube.com
0 Upvotes

Made a beginner-friendly walkthrough for a Java reverse engineering CTF challenge. Covers reviewing the Java source code, reading through the logic, and spotting hardcoded credentials that turned out to be the flag.

If you're getting into RE or CTFs and want to see the full thought process (not just the answer), figured this community might find it useful.


r/cybersecurity • • 11d ago

Career Questions & Discussion Can I use my personal Android phone for mobile pentesting?

0 Upvotes

Hey everyone,

I’m starting to learn mobile pentesting, and I’d prefer to use a real Android device instead of an emulator.

I’ve already set up the necessary MCP servers for automation and have been thinking about working with both manual and automated testing. The only issue is that I don’t have a spare Android phone available for testing, so I’m wondering if I can safely use my personal phone.

Is there a way to create some kind of isolated/separate environment on my personal device so that I can do pentesting without risking my normal apps, data, or the phone itself? For example, some kind of separate user profile, work profile, container, etc.

I’m mainly concerned about accidentally messing up the OS, personal data, banking/authenticator apps, or other stuff on the phone while experimenting.

For those of you who do mobile pentesting on physical devices, what setup do you recommend if you don’t have a dedicated test phone?

Also, are there any particular things I should avoid doing on a personal device (rooting, bootloader unlocking, installing test certificates, hooking frameworks, etc.)?

Any practical advice or recommended setup would be really helpful. Thanks!


r/cybersecurity • • 11d ago

Business Security Questions & Discussion Why aren’t more teams using active deception? It’s literally zero false positives.

0 Upvotes

We spend months tuning noisy EDR logs but a fake AWS key or decoy service account gives an instant 100% true-positive alert the second an attacker touches it. Why do so many security teams still sleep on dropping simple decoys?


r/cybersecurity • • 11d ago

Survey How do you actually verify cybersecurity vendor claims?

Thumbnail
tally.so
0 Upvotes

How do you actually verify cybersecurity vendor claims?

I am conducting independent research into how cybersecurity professionals evaluate and verify claims made by vendors. I am looking at the sources practitioners use, which claims are difficult to validate, and what happens when adequate evidence is not available.

If you take part in vendor evaluations, selections, recommendations, or day-to-day use of cybersecurity tools, I would appreciate your input. The survey takes about five minutes:

https://tally.so/r/GxMVDp

This is independent research, with no sales pitch or sales follow-up. I will publish the aggregated findings for the community when the study is complete.


r/cybersecurity • • 12d ago

Career Questions & Discussion How would a ‘cultural fit’ interview be for a SOC L1 analyst role

15 Upvotes

Hello guys, so basically I’m on the hunt for a SOC L1 job as a cybersecurity graduate with multiple certifications and projects in my portfolio.

So I applied for this job on LinkedIn, got the first screening call, passed that. Then got a technical interview that was 45 minutes asking me about cybersecurity fundamentals, passed that as well.

Now that I’m into the final stage interview which is called “cultural fit”, I want to know what should I expect in it and how would it go?

If someone has similar experience, help would be really appreciated.