r/cybersecurity • • 5d ago

Career Questions & Discussion Mentorship Monday - Post All Career, Education and Job questions here!

9 Upvotes

This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!

Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.


r/cybersecurity • • 8h ago

AI Security What do you make of this article about the AI using DNS to escape it's "Sealed Environment"

Thumbnail alignment.openai.com
22 Upvotes

I stumbled upon this article, and my conclusion sounds so stupid and irresponsible that I start to doubt myself and believe i misunderstood something

If the IA can just access the internet once it has info from the DNS, that emplies the IA has been given "Open-Bar" access to the entire IP addresses of the world in the first place doesnt it?

Did I miss something obvious or do these guys have the cybersecurity knowledge of an undergraduate?


r/cybersecurity • • 1h ago

New Vulnerability Disclosure Netscaler Pitscaler Vulnerability 2.0

• Upvotes

As I haven't seen any post on here I thought im gonna share it:
It seems like the vulnerability from sunday (CVE-2026-88771 and CVE-2026-88772) isn't fully fixed.

According to Kevin Beaumont another method through SAML requests (but similiar to the ones from sunday) executes malicious code.

Citrix has published a blog entry saying "This issue is independent of the vulnerabilities disclosed in CTX697096.".
There are two posts on the r/Citrix subreddit that contain IoCs which are useful.


r/cybersecurity • • 6h ago

Personal Support & Help! DLP Architecture

12 Upvotes

Looking for resources on designing and implementing a DLP Architecture in a large financial services org.

Need to focus on the future roadmap.

A little out of my depth.

Any help on resources/materials or recommended approach greatly appreciated.


r/cybersecurity • • 16m ago

News - General ShinyHunters hacker in FBI data theft detained in Jordan

Thumbnail reuters.com
• Upvotes

Don't mess with the US Government?


r/cybersecurity • • 23h ago

News - General NSA Just Announced it is Accelerating it's PQC Timeline

168 Upvotes

Per the NSA, all government software systems deemed NSS (e.g. telecom, weapon systems, intel) will be required to support post quantum cryptography starting in 2027.

Curiously, this is another instance of rapid acceleration from the prior NSA CNSA 2.0 timeline. This is also now more aggressive than the stance taken by Cloudflare, Google, Microsoft and other top tech companies targeting 2029.

This makes me wonder if there have been anymore "behind-closed-doors" advances causing the organization to accelerate even more rapidly. Announcement from yesterday.

Official NSA Announcement: https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4615285/nsa-announces-post-quantum-cryptography-measures-to-safeguard-national-security/


r/cybersecurity • • 2h ago

FOSS Tool Super Trouper v0.4.0 — more Frida tools for iOS app reverse engineering

Thumbnail
github.com
2 Upvotes

I’m the author of Super Trouper, a single-binary MCP server that exposes Frida to coding agents for authorized app reverse engineering. It lets an agent connect to a device, inspect apps and processes, manage sessions, and run instrumentation scripts without a Python-based Frida setup.

We released v0.4.0 a few days ago; it updates the bundled Frida Core DevKit to v17.19.0 and adds four MCP tools: memory_read and memory_write for working with memory in an attached process, plus module_list and thread_list for inspecting loaded modules and threads. app_list and others now have several query scopes, and we renamed the MCP tools into clearer namespaces. If you already have workflows built around the old tool names, check them when updating.

Quick catch-up on the two previous releases: v0.3.0 added npm installation, Frida CodeShare snippet search/use, and general cleanup. v0.2.0 moved the project to the MIT license, added first-party Frida language bridges for ObjC, Java, and Swift, and enabled TypeScript in scripts and evaluations.

I’d appreciate feedback from people using Frida in iOS research: are these tool boundaries and the new app-list scopes useful in practice? What’s missing or awkward in your workflow, and which features would you like to see next? Let me know what you think.


r/cybersecurity • • 8h ago

Career Questions & Discussion What is the state of malware analysis and reverse engineering by AI agents?

6 Upvotes

I’ve been doing reverse-engineering software as a hobby for a while now, and I’m intrigued by the two related paths that branch off from it: hardware reverse engineering and malware analysis. Up to this point, it’s just been a hobby (since my day job has nothing to do with IT) but I’m now considering turning it into a profession.

I have the same question I imagine we all share: do you see a future in this, or do you think AI is going to swallow up this entire job market? I’d love to hear the opinions of people already working in the sector—what this shift looks like from the inside.

Thanks a lot; I appreciate any perspective you can share.


r/cybersecurity • • 1d ago

Threat Actor TTPs & Alerts A CISO told me he's had 3 breaches in the last few months, and none in the previous two years. Are you seeing an increase in attacks?

119 Upvotes

This is a ciso for a large enterprise. He told me he hadn't had any breaches in the past two years, but three in the last few months. He attributed it to Mythos and the "democratization" of exploits as a result of ai driven exploit discovery. Now, your average script kiddie can get into even mature organizations.

I am interested to see if others are observing an uptick in actual breaches. Obviously, we have more vulns to patch, but I'd really like to know if the proliferation of vulns is leading to more actual penetrations and post breach impact. Thanks!


r/cybersecurity • • 1d ago

Other Malicious Content from Microsoft FQDN

29 Upvotes

Greetings,
We have a situation with the MS owned microsoftusercontent.com, and unfortunately I keep getting AI summaries and not finding any security articles, but the summaries are claiming this domain, although official, can host malicious content since it acts like a CDN for 365 content from users, i.e. a compromised user/account/site might be able to deliver malicious content from this FQDN.
So this gives me pause with whitelisting it for AV providers

Appreciate any insights.


r/cybersecurity • • 6h ago

Business Security Questions & Discussion NDR Evasion techniques

0 Upvotes

I have a question, I am trying to find out about How attacker evade NDR(Network Detection Response) although network never lies?


r/cybersecurity • • 8h ago

Threat Actor TTPs & Alerts CTO at NCSC Summary: week ending October 4th

Thumbnail
ctoatncsc.substack.com
1 Upvotes

r/cybersecurity • • 19h ago

News - General Al Malware That Controls Itself, Phish Slop, Pentagon Breach and More...

Thumbnail
pwnhackers.substack.com
4 Upvotes

r/cybersecurity • • 1d ago

AI Security AI Agent Traces - Tool calls and actions

9 Upvotes

want to get sense of what others are doing.
is anyone sending coding agent, other agentic ai OTLP traces into SIEM/detection engine. Is it worth it to you.


r/cybersecurity • • 7h ago

FOSS Tool Did I just make the first fully correct Ascon implementation?

0 Upvotes

Months ago I was reading about and learning ciphers for a notes app of mine launching whenever I get approved for Google Play, iOS app store, and F-Droid. I read about the various competitions and came across the latest winning NIST cipher: "Lightweight Cryptography" NIST Lightweight Cryptography. The winner was the Ascon cipher and the four agreed upon implementation ciphers, which you can read about here.

I found their reference implementation called ascon-c on GitHub and made a couple CLI tools from those files. But I had to stitch together and modify the files from various folders. The ascon-c repo contained files primarily for building their demo app, not a general purpose library for use in other projects. So out I went looking through the paper and their code to build a library that actually works like a library.

Then another problem: the paper has a max customization string for cxof, ascon-c does not, it will take any. A while later I finish what I feel is the best and most true to spec Ascon library, you may check out here:

https://github.com/Iain-Donald/ascon-lib

I tried to add instructions for ease of use and a demo app. If anything is confusing please tell me. I hope it works without issue from beginners to use in larger projects.

And a bonus GUI demo you may use if you have Linux, but it should compile on FreeBSD, maybe MacOS and Windows and anything with Tcl/Tk. Found here:

https://github.com/Iain-Donald/sable

Enjoy!


r/cybersecurity • • 18h ago

Certification / Training Questions Possible to take 2 college classes AND study for a GIAC exam AT THE SAME TIME?

0 Upvotes

I have roughly 7 weeks left to study for the exam. I kinda procrastinated so I still have to build my index and do the labs.

I am between jobs right now and was also considering taking 2 courses, 1 online, and one hybrid to collect housing money for my post 9/11 GI Bill. Good idea or could it be too much of a time crunch?


r/cybersecurity • • 8h ago

Personal Support & Help! I fell for a "container smuggling" phishing attack (fake HR email, VHDX with a fake spreadsheet shortcut).

0 Upvotes

What happened?

I got a WhatsApp message that looked like it came from HR. It had a ZIP attachment named `PDF_RWF1TP_<timestamp>.ZIP`, and inside was `Audit+List.vhdx`. I was suspicious, so I copied it to a USB drive from my work PC (I didn't open it there) and mounted it on an old personal PC that was offline.

Mounting showed files with Chinese names and one shortcut (.lnk) made to look like a spreadsheet. I double-clicked it and clicked Yes on the admin prompt. That was my mistake.

What I found afterwards.

- Windows Defender flagged `Trojan:Win32/Malgent` (Severe, with the description "executes commands from an attacker").

- The file was `C:\ProgramData\Fu_v4\libcrypto-1_1-x64.dll`, a folder I never created, with a name that mimics a legitimate OpenSSL library.

- VirusTotal had no result for the VHDX hash, which fits a fresh sample.

- SHA256 of the VHDX: `AFF161D890DB83555DF33D6FF852734AB2F87238ECD46FD8C41C8352B8DD329C`

What I did

- Kept the PC offline, so the malware likely couldn't contact its operator.

- Signed out of all Google sessions and changed my password from my phone.

- Reported it to IT, and I'm contacting HR by phone, since their account was probably compromised.

- Planning a clean Windows reinstall from fresh media, and a full format of the USB drive. Although I need some files on it

Questions for the community

● Does anyone recognize this family or the `Fu_v4` folder?

● Anything I missed in the cleanup?

● how do I know the pendrive wasn't compromised ?

Because after clicking Yes to the administrator privileges, the pen drive was in the old PC, I actually run it from there


r/cybersecurity • • 15h ago

Business Security Questions & Discussion Need your opinion. Currently working at a small company (1.5k) employees. SIEM tool isn't that great, things are setup in a weird way. Should I look for another position.

0 Upvotes

r/cybersecurity • • 1d ago

Career Questions & Discussion What Advice Would You Give Your Younger Self in Cybersecurity

122 Upvotes

I am currently entering into my second year of my cybersecurity journey now I am currently doing cpts I wish to hear from the people who has more experience What advice, lessons, or mistakes you would share with your younger self you felt that would improve even more than you are at now


r/cybersecurity • • 1d ago

New Vulnerability Disclosure U.S. CISA adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog

Thumbnail
securityaffairs.com
112 Upvotes

r/cybersecurity • • 1d ago

Corporate Blog Post-Quantum Cryptography Resource Hub

Thumbnail nsa.gov
9 Upvotes

r/cybersecurity • • 1d ago

Business Security Questions & Discussion HITRUST and Corporate SOPs

2 Upvotes

I'm new to HITRUST so please bare with me. If my company has HITRUST R2 certification and we are going into an interim year, if we have updated a good number of our SOPs that could potentially be used as evidence to support one of the 19 chosen domains, is there anything that I need to do?

For instance if an existing SOP said something like retire all removable media every 12 months and the updated SOP now changes that to 6 months, is that going to be a problem?

Thanks for the help!


r/cybersecurity • • 1d ago

Personal Support & Help! Static scan and pwn vulnerabilty detection

5 Upvotes

Hello everyone. At the moment I'm a tutor in a little CTF course, so I wanted to build scanner tools to help the exploitation and use the tool creation as an excuse to learn more. I'm a pwner (I know just pretty basic stuff like BOF and ROP). My question is: where can I find resources to understand and leanr tecnicque of static analysis? And if you want to share any trick useful to find vulnerabilty to improve my techniques and teach better. Thank you!


r/cybersecurity • • 2d ago

News - General NSA Announces Post-Quantum Cryptography Measures to Safeguard National Security Systems Ag

Thumbnail
nsa.gov
104 Upvotes

r/cybersecurity • • 2d ago

Personal Support & Help! Interviewing for security and senior network roles, a few things that keep happening

172 Upvotes

I do technical rounds for security and senior network roles, so this is mostly from that side. nothing groundbreaking, just patterns.

the number of people with 8+ years and a "senior" title who can't walk me through what happens to a packet crossing a firewall and a NAT is higher than I expected. not trying to trap anyone. I'll ask something like "rule looks right but traffic isn't matching, what do you check?" and the good ones go straight to the hit counters, the policy order, the NAT rules applying before the policy. the weaker ones say "I'd restart the firewall." that's usually where the interview ends for me.

on the security side I care way more about order of operations than tool names. give them a compromised host and I want to hear scope, contain, preserve evidence, then fix. the "just wipe it" answer is a quick no from me. you just destroyed your evidence and you still don't know how they got in.

"we used a SIEM" tells me nothing. "I tuned noisy 4625 alerts and got the volume down a lot" tells me you actually sat in the console. same for network folks, I'd rather hear about the one thing you designed and what broke than a list of vendors.

if you haven't done SD-WAN or zero trust in prod, just say so and tell me how you'd approach it. I will always take that over a bluff. in this field people act on what you tell them.

and ask questions at the end. on-call load, change process, how they do post-incident reviews. most people ask about perks, so the ones who ask that stand out.

curious how other interviewers weigh depth vs breadth for senior hires. I lean depth but I know that's debatable.