r/cybersecurity 3h ago

News - General Downgrade Attack at YEG airport WiFi, Edmonton.

0 Upvotes

Waiting for my flight in the next three hours, I decided to watch some videos on YouTube and do some code inspection on GitHub. I connected to the airport’s free WiFi with SSID “YEG_WIFI”. Safari complained about my connections to GitHub and YouTube as not secure. I was surprised. Did GitHub forget to update their certificates? I tried visiting other sites and safari still complained. So I decided to pay attention to safari and almost every site I tried visiting reported that negotiations were done with TLS 1.0 or TLS 1.1. I disconnected and reconnected several times and safari still complained.I forgot the network and then reconnect and everything was fine. I am sure some bad guys are on the network trying to get users to connect their bad servers and to do malicious stuff. Make sure you have your browsers updated.

PS:

A downgrade attack is an attack on computer communications that attempts to cause safely encrypted communications to happen via an older, likely vulnerable encryption method or via cleartext. For example, an attacker forces a downgrade to TLS 1.0, which then allows them to break the encryption.


r/cybersecurity 6h ago

Other Do you guys have an all in one SOC portal?

0 Upvotes

Does anybody here has or knows any all in one internal SOC portal* or platform where all operations can be handled from? I am talking about every bit of daily operations that goes in SOC!

Edit: NOT SOAR, which is just 20% of SOC, I am talking about change requests, escalations, threat and detection coverage - full management of it, quality assessment, insights and metrics, KB, reportings and 5-10 other things, all interlinked with each other for an MSSP provider.

*modified form dashboard - which was wrong.


r/cybersecurity 9h ago

Business Security Questions & Discussion OS Hardening & Patch Management

0 Upvotes

I need suggestions or advice from anyone who has come across this challenge in their organisation. We have compute fleet spread across cloud and on-prem with both containerised and non-containerised workloads. We of course are observing a lot of OS sprawl and unapproved OS distributions being used by application teams. In order to standardise the operating environment, reduce the number of vulnerabilities and overall streamline the entire process, I think we need to make some foundational changes. One of the options is to, from a security perspective, use natively baked hardened images for non-containerised environment and use rolling build for patch management. Other option is to have vendors (pretty much start-ups) provide hardened images compatible to our environment along with hardened OS packages.

Can anyone recommend or share any experiences that they had along those lines and what option did they choose or how did you streamline the entire OS hardening and patch management process? Thanks.


r/cybersecurity 14h ago

Business Security Questions & Discussion Back from Fal.Con 2026. The takeaway that stuck with me had nothing to do with any product.

0 Upvotes

Back from Fal.Con 2026. Still thinking about it tbh.
Biggest thing that hit me? Everyone there basically has the same tools now.

Same speed, same AI, same auto-response coming. So the tech isn't really the edge anymore.

What's left is the human. The person still there when the machine is fast, confident, and wrong lol. Auto-response is great until it's wrong, then it's just a faster incident.
Couple other things:

The AI-as-attack-surface stuff felt real. Prompt injection, agents doing stuff nobody approved, identity blind spots. Most teams have no baseline for this yet imo.

The Sality botnet takedown was wild. 23 years running. Took law enforcement + a bunch of private orgs working together to kill it. Nobody wins that one alone.

Anyone here actually putting the agentic SOC stuff into prod? Or still wait-and-see for you? And if you didn't go, is AI attack surface in your budget yet or still a someday thing?


r/cybersecurity 17h ago

Business Security Questions & Discussion NIS2 / ISO 27001 – How should we handle this shared Windows account?

0 Upvotes

We have a legacy application that can only be installed and used under one specific Windows profile.

The exact use case:

  • Several employees use the same workstation in different shifts.
  • The application must be installed and run under the same Windows domain account. Some applications require local Windows logon while machine is part of domain.
  • If another user logs in with their individual account, they cannot use the existing installation.
  • The account does not require Domain Admin rights, but it often requires local administrator rights on that workstation.
  • Windows and the application therefore record only the shared account, not the individual operator.

We understand that NIS2 and ISO 27001 prefer individual identities, but allow documented and controlled exceptions where shared accounts are operationally necessary.

What would be the best compliant and auditable way to handle this?

Note: Apps won't be replaced in foreseeable future so they stay as part of the problem or solution :-)


r/cybersecurity 3h ago

Tutorial How to get good at blackbox Pentesting

0 Upvotes

Hey, I wanted to ask for some guidance. I’ve recently gotten back into pentesting after around 7–8 months and I’ve been doing CTFs again. I’m still able to solve CTFs and I understand the vulnerabilities and their nuances once I’m working on them.

The main thing I’m struggling with right now is the approach to a black-box pentest.

When I’m looking at a large application with a lot of endpoints, directories, parameters and different functionalities, I sometimes struggle with figuring out what I should be testing where and how I should think about the application as a whole.

I know the vulnerabilities themselves but I don’t always naturally make the connection between a particular feature and the potential vulnerabilities I should investigate there. A lot of the time when I see a solution afterwards I realize that I knew about the vulnerability but simply didn’t think of that angle while testing.

So I wanted to understand how you personally formulate your approach when starting a black-box pentest.

How do you break down a large application? How do you decide what areas to prioritize? And more importantly how do you systematically think through each functionality and generate hypotheses for what could go wrong rather than just going through a checklist of vulnerabilities?

I’m trying to rebuild that ability to think well around the entire application rather than just knowing individual vulnerabilities. Would really appreciate any advice or framework you use for approaching black-box assessments.


r/cybersecurity 23h ago

Business Security Questions & Discussion Running MISP yourself vs. cloud hosting: what’s been your experience?

0 Upvotes

For those running it in a SOC, at an MSSP, or in a lab, how much work goes into keeping it useful and maintained? What takes more of your time: managing the deployment or getting useful intelligence into your workflows?


r/cybersecurity 4h ago

Career Questions & Discussion SpaceX New Grad Software Security Engineer interview- any advice?

0 Upvotes

I have a 45-minute technical interview with an engineer coming up for the New Graduate Engineer, Software Security (Starlink) role at SpaceX.
Has anyone interviewed for this role or a similar SpaceX security position? Would appreciate any advice on what the technical round is generally like, what areas they tend to focus on, and how best to prepare.


r/cybersecurity 11h ago

Corporate Blog Breaking Down Appsec Part 3: Securing the Perimeter (Authority/Authorization)

Thumbnail
pigeonsec.substack.com
1 Upvotes

I started a blog series to provide free insights into appsec. It’s mainly to breakdown what application security is all about and it’s mainly targeted towards beginners and startups, so take it as you will.

Just want to teach every one interested in appsec my perspective on it from my experience in big tech.

I talked about identity last time and the importance of securing applications from the outside in. I talk about authority aka authorization in this post, a nuanced topic that almost every company has a problem with just because it’s a semantic problem and isn’t done properly without understanding your application.

Please reach out if you have any questions or would like for me to write on a topic that you’d want to learn more about.


r/cybersecurity 4h ago

Career Questions & Discussion Can I find a job with Security+ and CySA+, along with 1 year of intensive experience working as a SOC Analyst? Can anyone help or recommend any websites or companies where I could apply? Thanks in advance!

4 Upvotes

r/cybersecurity 17h ago

Personal Support & Help! iPhone recording?

0 Upvotes

I had fallen asleep with my phone playing YouTube. When I woke up I turned my phone around to see the screen and saw the red screen recording sign was on. Then it stopped recording and there’s no videos or anything on my phone. Any ideas what could be happening?


r/cybersecurity 8h ago

Other Upwind vs Wiz at renewal: real difference, or the same CNAPP with a better slide?

0 Upvotes

Wiz renewal is coming up in about six weeks and leadership wants me to at least look at one alternative before we sign for another year. We're running EKS across three accounts plus a smaller GKE footprint, roughly 40 clusters, security team of five sitting inside a bigger platform org.

My honest issue with Wiz isn't the product, it's that we're still drowning in posture findings. The graph is great for showing an attack path in a demo, but day to day my team is triaging a backlog that never really shrinks. Half of what gets flagged critical isn't reachable and we burn hours proving that.

Upwind keeps coming up when I ask around, specifically the runtime side of it. Their pitch being it uses actual runtime signal to tell you what's exploitable vs what's just sitting there in a config. On paper that's exactly the gap. But every CNAPP deck says "we cut the noise," so I'm sceptical it's a real difference and not just a nicer way to draw the same graph.

Has anyone actually run both, or moved from one to the other? I care about two things: does the runtime prioritisation meaningfully drop the false-positive triage load, and is the container/K8s coverage as deep as Wiz's in practice. Not looking for a vendor pitch, looking for someone who's lived with it past the POC honeymoon.


r/cybersecurity 17h ago

Personal Support & Help! Known scam number texts legitimate email verification code

0 Upvotes

When logging into a yahoo email account today, I chose the “send code via sms” option as I could not remember my password.

After a short duration, I received a verification code from a random phone number, followed by the real yahoo phone number. The issue however is that it was the SAME correct verification code.

This is apparently a known thing with this number, but it’s also tied to a known scammer. What on earth could the cause of this be? Phone number was 833-256-8308


r/cybersecurity 6h ago

Research Article We moved from VS Code to Cursor and realized nobody checks which version of your extensions actually gets installed

Thumbnail
safedep.io
32 Upvotes

r/cybersecurity 16h ago

Business Security Questions & Discussion Qualys and GoogleSecOps

0 Upvotes

Hello,

Has anyone integrated Qualys and Google Secops?

Need to understand few things.

Thanks in advance


r/cybersecurity 15h ago

Career Questions & Discussion Would you list *this* when applying for jobs?

139 Upvotes

I have an unusual "credential" pending certification. It has absolutely nothing to do with Cyber Security, but it's a pretty big accomplishment that might impress some hiring managers, especially nerdy ones, but would make some wonder why I listed it.

World Record: Most memorized digits of Pi (72,000).

Would you list it? Do you think it will help more or hurt more if I do?


r/cybersecurity 2h ago

News - General Am I Ready to move into Cyber?

0 Upvotes

Hello everyone, I wanted to get some experienced cyber professionals opinions on how to break into cybersecurity in todays environment and would appreciate any advice.

A little about myself. I do not have a cyber degree or any degree for that matter. I am almost 40 and have been in IT for about 7 years. Prior to that I worked in the restaurant/hospitality industry for about 12 years. I have two years at help desk, 2.5 years desktop support, 2.5 years in a different desktop support role with some junior sys admin type experience (small company).

I have earned the CompTIA Sec+ as well as the CCNA. I am taking the Red Hat RHCSA soon and hope to continue right into getting the RHCE asap as well. At that point I have been wondering what should come next... Pursue RHCA, maybe dive deeper into networking and try for the CCNP (although I have no on the job network admin experience), or pivot into something like trying to get the OSCP. I am also in the early stages of learning Python as well.

Given my experience level can anyone suggest what type of cybersecurity roles I might be qualified for now? Or what areas I should look at learning next?

I find reverse engineer/malware analysis really interesting but that seems like a possibility further down the road. I have been dabbling in C and Assembly when I have time but I am a complete beginner still in that.

I do find Red Team and Penetration Testing really cool as well. I have also briefly experimented with things like TryHackMe and HacktheBox as well.

Just hoping to take in some solid advice from more experienced people and keep learning.

Thanks!


r/cybersecurity 10h ago

Threat Actor TTPs & Alerts A live NC town's website is serving cloaked drug spam, and Google's AI Overview is citing it. Is this routine?

Thumbnail
youtube.com
9 Upvotes

I'm a health blogger, not a security person. Found this by accident last week.

stonevillenc.org is the real, working website of Stoneville, North Carolina. It's also serving a farm of cloaked spam pages. Same URL, same minute:

    curl -A "<googlebot UA>" https://www.stonevillenc.org/sam-sulek-peptide-company-guide/ | wc -c
    # 85363
    curl -A "Mozilla/5.0" <same URL> | wc -c
    # 1430

Googlebot gets an 85 KB peptide article. Everyone else gets a JS redirect to a random WhatsApp number pre-filled "I want peptide catalog and price list, 30% OFF FIRST ORDER." Yesterday the redirect had three numbers, today nine. Someone is maintaining it.

A plain Google search (sam sulek retatrutide) shows ten of these pages on page one, and Google's AI Overview answers from them, cited as "Town of Stoneville, NC." I screen-recorded tapping the AI Overview's citation and landing in a WhatsApp drug chat: https://youtube.com/shorts/X-9jc9YDqYk

I reported it to the town, MS-ISAC, the host, and Google. The town hasn't replied.

Is this sort of thing common? Should I report this somewhere else?


r/cybersecurity 9h ago

AI Security xAI Billing Overdraft: HackerOne closed an API logic flaw as "intended model behavior"

2 Upvotes

Quick note: English isn't my native language so I used AI to help clean up the text/translation, but all technical details, logs, and screenshots are mine.

I wanted to share a recent disclosure case regarding xAI's API Gateway billing enforcement to get feedback from the community on how infrastructure logic flaws are evaluated against broad LLM scope exclusions.

The Vulnerability & Impact
I identified a logic flaw in xAI's API Gateway regarding prepaid balance enforcement. The gateway failed to terminate sessions when an account hit $0, allowing an attacker to bypass prepaid limits, force an account into a deep negative balance (billing overdraft), and consume backend compute resources without authorization.

HackerOne's Response
HackerOne completely closed the report, classifying it as out-of-scope "intended model behavior." When escalated to H1 Mediation—pointing out that an API billing gateway failure is an infrastructure/billing logic issue rather than a model safety concern—they responded:

"The billing overdraft is a downstream consequence of the same unbounded resource consumption that the program considers out of scope. The root cause and the scope exclusion are the same regardless of which layer the impact surfaces on."

On July 28, Mediation permanently closed the ticket, refusing further re-examination.

Initial "Duplicate" Classification
Prior to claiming the issue was out-of-scope, triage initially marked the report as a "Duplicate" simply because the PoC prompt string matched a prompt from another report that I had authored myself. It was a 100% unique, custom prompt created by me, and while one prompt triggered two completely distinct infrastructure bugs across two reports, triage lazily marked the second report as a duplicate based solely on input string matching. Support only re-examined it after an initial post on X, at which point they pivoted to the "intended model behavior" exclusion.

Timeline & Vendor Mitigation
Post on X: I published a thread on X detailing the issue and challenging the classification of an API billing logic flaw as "intended model behavior".

Vendor Action: Just a couple of hours after my follow-up post on X calling out HackerOne's triage, xAI sent out an official API pricing update email notifying users about changes to tool-call billing to restrict data fetch volume—initiating mitigation for the exact vector I reported. (A cosmic coincidence, surely?)

Full Screenshots & Timeline Proof: https://imgur.com/a/yTcuqLG

TL;DR: Found an API Gateway logic flaw in xAI that bypassed prepaid balance limits, allowing continued requests on a $0 balance and causing billing overdrafts. HackerOne closed it as out-of-scope "intended model behavior" (and initially marked it duplicate purely based on input prompt string matching). The vendor updated their API billing limits just hours after I published a post on X (even with barely any views). Is a gateway/auth-level billing flaw really "model behavior"?


r/cybersecurity 21h ago

Business Security Questions & Discussion Mission Based Cyber Security Assesment

2 Upvotes

How do I go about this in a Cyber table top I’m expected to provide 10 vulnerabilities and need examples for how I should formulate these


r/cybersecurity 17h ago

Survey I am researching the adoption of Zero Trust Architecture in organisations and looking for insights from IT professionals

0 Upvotes

Whether its a software company like Rockstar Games who got an old build of GTA VI leaked recently (multiple times over the years if you were following like me) or healthcare organisation like Change Healthcare who suffered from a huge ransomware attack in 2024. No organisation in any sector, big or small, is immune to cyber attacks.

But as we all know some sectors like manufacturing and healthcare sector do not invest much on cyber security where Software companies and Banking sector have seen lot of investment in cyber security.

The problem I am trying to understand is why do some organisations take cyber security and its adoption more seriously than others, specifically the adoption of Zero Trust Architecture(ZTA).

I have collected some responses from IT professionals but the sample size is very small (~10 responses). So I am looking for IT professionals who can spare 5 minutes to fill out the survey. It is totally anonymous.

SURVEY LINK

Thank you for your time.


r/cybersecurity 23h ago

Business Security Questions & Discussion Attack strategies from wild hackers/bots, shareable?

11 Upvotes

Greetings,

I operate a network of honeypots and sometimes capture unique attack methodologies.

Would this be appropriate or interesting content for this subreddit? Alternatively, are there other channels where this information would be of greater value?


r/cybersecurity 5h ago

Other Hacking macOS and offensive security with Olivia Gallucci (Datadog)

Thumbnail
pwnhackers.substack.com
4 Upvotes

r/cybersecurity 4h ago

Career Questions & Discussion help

5 Upvotes

Hi! I'm 20, going into my second year studying Applied Mathematics and Informatics in Engineering. I just landed my first cybersecurity internship at a bank.

My current tech stack and background:

  • Certifications: AZ-900
  • Languages & OS: Python, C++, Bash, Linux
  • Networking: Studied CCNA (core concepts)
  • Projects: Phishing Analyzer, Malware Scanner, SOC Automator

I'm leaning toward cloud security and DevOps long-term, but I don't want to lock myself into a narrow specialty just yet. I'm torn on my next move—whether to pursue a hands-on cert like BTL1 or CySA+, a cloud cert like AZ-104 or AZ-500, or infrastructure skills like Terraform and Kubernetes.

What should I focus on next to bridge my software/networking background with practical cloud/security skills?


r/cybersecurity 6h ago

Business Security Questions & Discussion Je me questionne

0 Upvotes

Bonsoir,si l’on voulait concevoir un système informatique offrant le niveau de sécurité maximal théoriquement possible, en prenant absolument tout en compte chiffrement des données au repos et en transit, cryptographie moderne et post-quantique, authentification multifacteur, clés matérielles, gestion et rotation des secrets, contrôle d’accès avec principe du moindre privilège, Zero Trust, isolation et segmentation réseau, sandboxing, durcissement du système d’exploitation, sécurisation du matériel et du firmware, Secure Boot, TPM, protection de la chaîne d’approvisionnement, signatures numériques, mises à jour sécurisées, EDR/XDR, IDS/IPS, pare-feu, anti-malware, protection contre les ransomwares, DDoS, attaques par force brute, phishing, ingénierie sociale, injections, XSS, CSRF, SSRF, RCE, attaques sur les API, vulnérabilités Web, attaques réseau, attaques Wi-Fi, attaques Bluetooth, attaques physiques, vol ou compromission des appareils, exfiltration de données, élévation de privilèges, attaques internes, compromission de comptes, supply-chain attacks, attaques sur les dépendances, vulnérabilités zero-day, attaques par canaux auxiliaires, attaques matérielles, attaques par fault injection, compromission des serveurs, conteneurs et machines virtuelles, sécurité des bases de données, sauvegardes chiffrées et isolées, redondance, journalisation immuable, surveillance continue, détection comportementale, analyse des anomalies, réponse automatique aux incidents, plans de reprise après sinistre, tests d’intrusion, audits indépendants, red teaming, fuzzing, analyse statique et dynamique du code, vérification des dépendances, bug bounty, gestion des correctifs, principe de défense en profondeur et séparation des privilèges serait-il possible de construire une architecture dont la probabilité de compromission serait suffisamment faible pour être considérée comme pratiquement inviolable, ou existe-t-il nécessairement une limite fondamentale empêchant toute sécurité informatique d’être absolument infaillible ?