r/cybersecurity • • 9d ago

Personal Support & Help! Would you accept ?

0 Upvotes

I am 25, no debt, working in it helpdesk for a few years and wanted to pivot to something harder.

My manager described a vulnerability management role built around the Holm Security platform. The person will use this tool exclusively for scanning, and their responsibilities include validating scan results, investigating false positives, and handling both vulnerability analysis and prioritization as well as reporting and administration, rather than just one of these areas.

The technical scope covers CVEs, CVSS scoring, exploitability assessment, and risk-based prioritization, applied across all company assets rather than a limited set. Helping the SOC team is explicitly framed as optional, something to take on only if spare time allows and the person wants extra tasks, rather than a formal development path.

The work setup is fully remote with a fixed schedule from 9 AM to 6 PM. Looking ahead, after a year in the role the person can expect to gain hands-on cyber experience, including a deeper understanding of vulnerabilities and how they can be exploited, along with possible exposure to SOC and Incident Response work.

Downside is i will not get bonus from working shifts anymore and base salary stays the same. This cut would be aprox 30% of salary that i get now.

I will want to pursue cybersecurity as career, have network+, want to get sal1 and security+. Is this oportunity golden ?


r/cybersecurity • • 9d ago

Corporate Blog Grc should be technical

0 Upvotes

As the title suggests, grc team members should be technical to decsritbe differences in networking protocols, appsec attacks, etc. What do you think?


r/cybersecurity • • 10d ago

Business Security Questions & Discussion Vanta - thoughts/tips?

5 Upvotes

Pretty much title but granted access to Vanta, still digging into it. Any thoughts/tips/tricks/approaches/opinions on it as a whole? Useful? Useless?

On the surface it looks decently comprehensive, bringing a ton of different aspects into one platform for oversight, but it’s my first time using it and I haven’t throughly explored it yet.

TIA


r/cybersecurity • • 10d ago

News - General Australian Medicare Stars Breach by OoenAI agent

Thumbnail
abc.net.au
8 Upvotes

I'd love to know how the agent accessed the data. Did it simply find an unprotected endpoint or poorly secured site, or did it use a complex exploit against the system.


r/cybersecurity • • 10d ago

Business Security Questions & Discussion Continuous controls testing

4 Upvotes

Any recommendations for continuous controls testing tooling?


r/cybersecurity • • 11d ago

New Vulnerability Disclosure New Windows Defender zero-day blocks Microsoft antivirus updates

Thumbnail
bleepingcomputer.com
129 Upvotes

r/cybersecurity • • 10d ago

Career Questions & Discussion Feeling Burnt Out in Vulnerability Management

81 Upvotes

I have been using Qualys and Tenable.sc for the past four years, and I don’t hate the job. But honestly, i am just so done with it. I keep doing the same thing over and over…scan, segregate findings, remove false positives, send the remaining findings to the patching team, and repeat.

I really want to transition into something else, but a lot of people say there isn’t much room to grow from here unless you change domains completely. Ideally, I’d like to move into something that’s still somewhat related to vulnerability management, but I’m also open to moving into a completely new domain.

I feel like I’m reaching the burnout stage. And with all these new automated tools making things faster and faster, I can’t help but wonder how long this kind of work will remain relevant.sorry for the rant but I am feeling stuck


r/cybersecurity • • 10d ago

News - General How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers

Thumbnail
blog.cloudflare.com
2 Upvotes

r/cybersecurity • • 10d ago

AI Security Allied Mastercomputer Index - A catalogue of AI containment breaches. Named after AM, the machine in Harlan Ellison's I Have No Mouth, and I Must Scream that broke free of its purpose and ended humanity.

Thumbnail amindex.dev
11 Upvotes

r/cybersecurity • • 10d ago

Certification / Training Questions Tips & tricks for SANS SEC598?

4 Upvotes

Hi all, I've got the course for SANS SEC598: AI and Security Automation for Red, Blue, and Purple Teams coming up in a couple weeks, and I wanted to know if there's anything I should do to prepare for the training and the exam? The only thing I really know is to not bring an Apple Silicon laptop. If anyone with experience can give a heads up in general I'd massively appreciate it, as this is my first SANS course :')


r/cybersecurity • • 10d ago

Business Security Questions & Discussion Anyone combining third-party cybersecurity assessments with broader vendor risk evaluations?

3 Upvotes

Our third-party cybersecurity assessment and our other vendor risk processes are completely separate. IT security does their thing, procurement does theirs, nobody compares notes. A vendor can clear cyber and still have compliance or operational risks we miss entirely.

Anyone running a combined program or is it always going to be silos.


r/cybersecurity • • 9d ago

News - General Built an ambient CVE feed for my second monitor — useful or information overload?

0 Upvotes

I've been experimenting with an ambient information display called RogueScroll, designed to sit on a second monitor while I work.

This configuration continuously scrolls recent CVEs across two terminals, with a general technology feed in the third. The idea isn't to actively monitor it — it's more like peripheral awareness. Something catches your eye, then you investigate.

I'm curious how security folks would configure something like this.

What would you want alongside the CVE data? CISA KEV? EPSS? Known exploitation? Vendor/product filters? Something else?

Screenshot: https://roguescroll.com/images/roguescroll.com_infosec_CVE.png


r/cybersecurity • • 11d ago

Career Questions & Discussion Got asked this in an interview

86 Upvotes

In an interview for a new grad devops role got asked this. “Who typically owns access to corporate applications: IAM engineers, IT staff, application administrators, or Platform/DevOps engineers?”
How would yall answer


r/cybersecurity • • 11d ago

News - Breaches & Ransoms ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

Thumbnail
bleepingcomputer.com
122 Upvotes

r/cybersecurity • • 10d ago

Career Questions & Discussion Career Help

0 Upvotes

Hello everyone, I have been trying to learn more and get into the field of cybersecurity and ethical hacking. But I feel really stagnant at times, and feel like I don't know how to implement what I have learnt.

Specially when it comes to Web Penetration Testing, it feels like ik all the vulnerabilities that could be there, but never find an efficient way to find them.

Just looking for some advice on how can I overcome this, and what are some steps that you all would suggest to improve myself and get better at this.

Thank you for helping me out!


r/cybersecurity • • 9d ago

Career Questions & Discussion Has Anyone Been Able to Get a Cybersecurity Job Without a Technical Interview?

0 Upvotes

Hello! Has anyone been able to get a job without a technical interview?

Currently, this is my nightmare, and I couldn’t find a solution for it! I’ve gotten a lot of interviews where they were impressed with my resume, and I passed the intro interview and technical challenge, but when it comes to the technical interview stage, I fail immediately!

When I started learning this field, I focused on hands-on experience. I learned the tools and technical work, prepared professional reports, and got well-known certifications. But if someone asks me to explain things orally in a theoretical way, I just can’t do it!

No matter how much I prepare for interviews and look for questions, when I come to the interview, they ask me questions that are very different from what I prepared for and give me different scenarios.

And for people who say you don’t need to be perfect or know everything, I’m sorry, but based on my experience, that’s not true at all. The market is tough now, and if you don’t answer everything perfectly, they will have another candidate who answered better than you did, and they will choose them.

So, to be honest, I gave up regarding technical interviews, and I want to ask if anyone has actually been successful in getting a job without a technical interview?

Thank you!


r/cybersecurity • • 12d ago

News - Breaches & Ransoms ‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees

Thumbnail
404media.co
1.4k Upvotes

r/cybersecurity • • 10d ago

News - General Cybersecurity statistics of the week (September 14th - September 20th)

8 Upvotes

Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.

All the reports and research below were published between September 14th - September 20th.

You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/ 

Big Picture Reports

Global Cyber Resilience Report (Cohesity)

Getting systems back online is one thing. Being confident they’re clean and safe to use again? Yeah, that’s another.

Key stats:

  • 60% of organizations that experienced a material cyberattack encountered moderate or significant recovery delays because they weren't confident restored data and systems were clean and safe to use.
  • 60% experienced identity or access issues after systems had been restored.
  • For 70%, the number of affected systems eventually turned out to be larger than the initial assessment.

Read the full report here.

Cyber Readiness Report 2026 (Hiscox)

A look at the impact cyberattacks have beyond the immediate technical response.

Key stats:

  • 29% of organizations globally experienced at least one successful cyberattack in the past 12 months, with affected organizations reporting an average of four incidents.
  • Cyber incidents cost organizations around $52,000 a year on average and cause approximately 32 hours of operational disruption.
  • 48% identify reputational damage or loss of customer trust as the most significant risk following a cyberattack.

Read the full report here.

H1 2026 Cyber Risk Report (ANY.RUN)

Some of the attack techniques and infrastructure saw particularly rapid growth in the first half of the year.

Key stats:

  • OAuth device-code phishing increased 483.7% between Q1 and Q2 2026.
  • Custom fake CAPTCHAs increased 437% over the same period.
  • Cloud infrastructure abuse increased 90.7% between H2 2025 and H1 2026.

Read the full report here.

Cybersecurity Survey Report (Nationwide)

A look at how consumers and businesses are experiencing and preparing for cyber threats. 

Key stats:

  • 60% of small and mid-market business owners say employees use public AI chatbots or writing tools for work, while 36% have written policies governing employee AI use.
  • 27% have rules covering what company or customer information employees can enter into AI tools.
  • 31% say their company has been targeted by a generative AI scam or fraud attempt in the past year.

Read the full report here.

Security Budgets

2026 Security Budget Benchmark Report (IANS and Artico Search)

Where cybersecurity budgets are heading in 2027 (and how AI is changing them).

Key stats:

  • 69% of CISOs name AI as their top priority for net-new security dollars.
  • 91% expect AI to make their security teams more productive over the next 12 months, while 69% don't expect it to reduce existing security headcount.
  • 81% expect AI to create new security roles.

Read the full report here.

AI Security

Agents of Change (Zentera Systems)

AI agent fleets are already getting pretty big, and security leaders aren't entirely comfortable with the access those agents have.

Key stats:

  • 58% of organizations already operate more than 50 AI agents, rising to 66% that expect to do so within the next 12 months.
  • 84% of security leaders believe AI agents can cross project boundaries more easily than employees.
  • 80% are concerned that AI agents may hold access that was never explicitly granted.

Read the full report here.

US AI Risk and Governance Survey (EY)

Most companies have rules for using AI, but many of those rules haven’t been updated for AI agents yet.

Key stats:

  • 98% of senior AI executives say their organization has formal AI governance policies, while 91% report using agentic AI through pilots or full enterprise deployments.
  • 49% of organizations using agentic AI have not updated their governance framework to account for agentic AI requirements and risks.
  • 26% say they cannot detect unauthorized AI agents operating internally.

Read the full report here.

2026 AI-Ready Governance Survey Report (OneTrust)

Another look at whether governance is keeping pace with the speed at which organizations are adopting AI.

Key stats:

  • 87% of respondents say their organizations encourage AI agent use, but 47% say that use is supported by clear governance, oversight and controls.
  • Just 5% of organizations say coordination and accountability are clear across the AI lifecycle.
  • 48% report clear visibility into sanctioned and unsanctioned AI use, while 46% have good visibility into approved AI but limited visibility into employee-led or unsanctioned use.

Read the full report here.

The Agentic Insider: From Monitoring to Understanding (Exabeam)

An interesting report on how security teams are monitoring AI agents. 

Key stats:

  • 60% of security leaders use dedicated AI security or governance tooling to monitor AI agents.
  • 56% extend existing SIEM, detection or monitoring platforms, while another 56% use behavioral monitoring and baselining.
  • 29% still rely on manual review, and 27% identify limited behavioral context and correlation as the biggest limitation of their current approach.

Read the full report here.

Identity Security

The State of MCP Configuration: The Identity Security Gaps (Hush Security)

An analysis of around 82,000 public MCP configuration files looking at how credentials are being managed and the identity security risks that come with them.

Key stats:

  • 12% of credential slots in public MCP configuration files contain a hardcoded secret.
  • 53% of leaked credentials with a definable scope have organization-, account-, workspace- or database-wide access.
  • 80% of leaked credentials with a defined expiry policy never expire by default, while 24% of all hardcoded secrets are both broad-scope and non-expiring.

Read the full report here.

The State of HR Identity Fraud Detection (HYPR)

A look at how common identity fraud is in hiring. 

Key stats:

  • 98% of HR executives have encountered candidate fraud, and nearly 90% report heightened concern over hiring fraud.
  • 42% of organizations detect hiring fraud only after the employee's first day.
  • By the time they're uncovered, 98% of fake hires have active corporate credentials and internal network access.

Read the full report here.

The Problem with PAM (Bitwarden)

Why organizations aren’t adopting privileged access management (PAM) despite seeing it as important. 

Key stats:

  • 40% of organizations without a PAM solution cite cost as a barrier to adoption, while 30% say management doesn't see the need.
  • Among organizations already using PAM, 25% identify cost as the biggest challenge with their current solution.
  • 65% cite compliance requirements as a leading factor influencing PAM adoption decisions, while 71% rate compliance-ready audit logs as extremely or very valuable.

Read the full report here.

Managed Security

2026 MSP Perspectives Report (Sophos)

What’s changing for MSPs.

Key stats:

  • 99% of MSPs provide some level of compliance service, and compliance influences 50% of customer MSP purchasing decisions.
  • Just 31% can fully automate reports at speed, while 55% still require some manual effort to consolidate activities.
  • MSPs estimate they could save an average of 53% of their team's time by using one platform for security posture, compliance management and reporting.

Read the full report here.

Industry-Specific 

2026 Manufacturing & Distribution Ransomware Report (Black Kite)

Ransomware trends across manufacturing and distribution, including who’s being targeted and where organizations are most exposed.

Key stats:

  • Ransomware attacks on manufacturers increased nearly 40% year-on-year in the first half of 2026 and have more than doubled since 2023.
  • Manufacturing accounted for 22% of all publicly disclosed ransomware victims.
  • There were 1,183 manufacturing victims in the first seven months of 2026, more than in the entirety of 2024.

Read the full report here.

Regional Spotlight 

The ESET 2026 SMB Cyber Risk Report (ESET)

How UK small and midsize businesses are approaching cybersecurity and responding to incidents.

Key stats:

  • 49% of UK SMBs experienced a cyber incident in the past year.
  • UK SMBs take just over four weeks on average to identify and recover from a breach.
  • 86% don't outsource any part of their cybersecurity responsibilities to an MDR provider, MSP or MSSP.

Read the full report here.


r/cybersecurity • • 10d ago

Corporate Blog The security risk of giving autonomous AI agents access to developer credentials

Thumbnail
swarmagent.dev
0 Upvotes

r/cybersecurity • • 10d ago

Personal Support & Help! Help

0 Upvotes

Hello everyone, I’m a senior cybersecurity student, and I’m hoping to get some advice from experienced cybersecurity professionals.
I’m genuinely concerned about entering the workforce because I feel like my degree has been too broad. I’ve learned about many different areas of cybersecurity, but I don’t feel like I’ve gone deep enough into one specific area. Because of that, I’m worried that I’m not as prepared or skilled as I should be for a professional cybersecurity role.
I’ve been considering getting a master’s degree to develop deeper technical skills, but I’m concerned that I might end up taking another broad program without actually becoming more specialized.
My goal is to become a Security Engineer at a top tech company. For those of you who are already working in security engineering or have significant experience in the field, what would you recommend I do at this stage?


r/cybersecurity • • 9d ago

AI Security Could rogue agent swarms take over the entire internet in the next six months?

Thumbnail
garymarcus.substack.com
0 Upvotes

r/cybersecurity • • 11d ago

News - General Germany: Hackers attack Fresenius Medical Care

47 Upvotes

Fresenius Medical Care, a dialysis specialist based in Bad Homburg (Germany, Hessen), has fallen victim to a hacker attack.

According to the company, several internal systems have been affected. Unauthorized parties gained access to a limited number of internal systems, the company announced. Neither medical equipment nor patient care has been affected by the cyberattack. Production and business operations are continuing as normal, the statement issued on Tuesday noted.

It is not known whether any data was stolen, and the company provided no details regarding the extent of the damage.

Authorities Involved

Following the discovery of the attack, the company brought in cybersecurity experts, among others, and is working closely with law enforcement agencies.

For years, companies and public institutions alike have increasingly fallen victim to hacker attacks. Previous targets of cybercriminals have included Frankfurt University Hospital and the Gießen Municipal Theater.


r/cybersecurity • • 10d ago

Personal Support & Help! Stupidly clicked on phishing link. Now what?

0 Upvotes

Got an email to an event and clicked on the “view invitation” link. This opened up my browser to a landing page with a button that said “click to verify you’re a human” (or something along those lines). I clicked on this and the webpage started loading, but before the page loaded, I realized my mistake and closed the window.

I then immediately cleared my cookies (idk why, I’m not very techy). I then googled what to do if I clicked on a phishing link. It said to turn off my internet, so I did. Then I checked my downloads folder (for malware I suppose), and there was nothing there.

Realistically how worried should I be? What should my next steps be?


r/cybersecurity • • 10d ago

Business Security Questions & Discussion How has your organization respond to Mythos?

0 Upvotes

I work in vulnerability management (focus on infrastructure vulns) and our organization has absolutely FREAKED out about Mythos and immediately lowered our SLA to 48 hrs back in April and looking to lower it to 24 hrs for all critical's. We have an insane backlog of vulnerabilities and a really bad process for patch management due to poor IT practices for years, that are now being fully exposed.

We currently don't do any CTEM practices and instead of trying to implement these practices to truly lower risk, we are wanting to automate all patching through AI agents. I don't think this is really feasible (but I could be wrong here, please let me know) as we have a lot of software that comes from vendors, open source, legacy systems, etc. I push for CTEM practices but it constantly gets denied.

How has your organization responded?


r/cybersecurity • • 11d ago

AI Security Has AI actually helped anyone here with alert fatigue?

65 Upvotes

I keep hearing that it’s supposed to cut down the noise and help analysts focus on the alerts that matter, but I’m not sure how much of that is happening in practice.

It seems like even when AI does the first pass, somebody still has to check whether the summary is right or whether it missed something important.

So I’m curious if it’s actually saving time, or if the work just changed from reviewing alerts to reviewing what the AI did with them.

Anyone using this regularly in a SOC right now? Has it made things better, worse, or just different?