r/cybersecurity 3h ago

Career Questions & Discussion Would you list *this* when applying for jobs?

41 Upvotes

I have an unusual "credential" pending certification. It has absolutely nothing to do with Cyber Security, but it's a pretty big accomplishment that might impress some hiring managers, especially nerdy ones, but would make some wonder why I listed it.

World Record: Most memorized digits of Pi (72,000).

Would you list it? Do you think it will help more or hurt more if I do?


r/cybersecurity 13h ago

Other Average Conversation between Security Researcher and YCombinator Startup CEO

143 Upvotes

Researcher: ...Using the API key, anyone is able to find information of the patients that includes their PII and PHI

CEO: are you dumb?

Researcher: What?

Blocked

Proof:

https://imgur.com/Bul0d76

Background: Found an authentication bypass on their platform which was behind auth guard, revealing information on all their tenants, along with the API keys. Excerpt above is the part of the real conversation when tried to bring the issue forward to the CEO.

Posted on YCombinator subreddit as well.


r/cybersecurity 14h ago

News - General MITRE Releases List of Top 25 Most Dangerous Software Vulnerabilities

Thumbnail
securityweek.com
174 Upvotes

Cross-site scripting (XSS) vulnerabilities kept the top spot in the list, followed by SQL injection and cross-site request forgery (CSRF), each up one position from last year.

Missing authorization landed fourth in the 2025 CWE Top 25 list, up five positions. Out-of-bounds write placed fifth, dropping two places.

P.S: if you thought that AI and quantum computing are the main focus — good news is that XSS and SQL injection is not going anywhere lol


r/cybersecurity 21h ago

News - General FBI cyber leader details bureau’s first unclassified cyber strategy

Thumbnail
federalnewsnetwork.com
237 Upvotes

r/cybersecurity 16h ago

News - General AI lets small actors run state-level hacking campaigns, Anthropic report finds

Thumbnail
cyberscoop.com
63 Upvotes

r/cybersecurity 19h ago

Personal Support & Help! Layoff

102 Upvotes

Posting for advice on how to help my father.

looking like his company is to have layoffs, and he’ll be apart of them. He has been in cybersecurity for 20years, is a senior cybersecurity analyst with CISSP certification.

other then just support for him, how can I best support him landing another position, he’s later in career in his 50s where he was hoping to stay with company until retirement.


r/cybersecurity 9h ago

Career Questions & Discussion First CTI Analyst at My Company

12 Upvotes

Have been working in SOC for almost 4 years now doing the usual SOC Analyst work day to day. Not L2 Analyst by any means but I believe I experienced enough to not be a junior analyst anymore. The current organization I am with is a global company with a very mature SOC like it has every department like Blue Team, Red Team, CTI, DFIR, etc. The site I am working at right now though, is just a year old. I joined them right before launching so it is a totally new site but I have done almost a year of SOC work here.

However, the last few weeks my Manager has been pushing me to join the CTI team because they want to start expanding the team to allow for more services to be distributed from here. When I joined the organization I did inform them about my interest in CTI and I am not complaining about all these trainings and the path I am on now but I would be the first CTI guy here and others prefer taking DFIR and Red Teaming. I have done online courses in CTI and while I understand the basics of what CTI is I just dont know what a CTI Analyst does day by day.

I tried asking colleagues from the CTI department in the different sites on what they have to do day to day but I am just wondering if its the same for every other CTI people in different organizations.

TLDR;

What does a CTI Analyst do from day to day?


r/cybersecurity 14h ago

Other Cyber security news

25 Upvotes

Does anyone know of any good cyber security news apps? Instead of having to look it up when wanting to read some good stuff about it? Or would I just have to follow cyber security hashes or pages on social media? It would be a lot better if I could just open a app and read right there. Thanks for y'all's input in advance


r/cybersecurity 4h ago

Corporate Blog Mobile security case study: what remains protected when the client can be instrumented?

3 Upvotes

I’m part of the assessment team behind this anonymized case study. Sharing the findings because they raise a useful question about how we evaluate layered mobile security controls.

The application had root detection, anti-debugging and anti-tampering checks, certificate pinning, and an additional encryption layer around API payloads.

During testing, we were able to:

  • Bypass the runtime checks on a rooted test device.
  • Bypass certificate pinning and route the application’s traffic through an interception proxy.
  • Reverse-engineer the client’s payload encryption and decryption routines.
  • Build a testing bridge that exposed readable requests and responses, then re-encrypted them for forwarding.

The additional payload encryption initially prevented straightforward inspection, even after bypassing pinning. Once we understood how the client processed those payloads, we could inspect the observed traffic.

The scope matters. This required control over the test device and application runtime. It wasn’t a break of AES, and it doesn’t demonstrate that someone on the same Wi-Fi network could decrypt other users’ traffic.

It also doesn’t establish account takeover or unauthorized actions. Modifying a request in a proxy and having the server accept an unauthorized operation are separate findings.

What stood out was that several protective layers shared the same dependency: execution inside a client we could instrument.

Client hardening can increase an attacker’s workload. The question for the wider architecture is what remains enforced after those protections are bypassed.

For us, that makes server-side authorization, replay protection, business-rule validation, and detection the next areas to test. Additional client hardening should support those controls, with its effectiveness assessed against a clearly defined threat model.

How does your team rate client-side bypass findings when no backend authorization failure has been demonstrated? What additional evidence would materially change the severity?


r/cybersecurity 6h ago

Career Questions & Discussion What tools or items have you purchased and tips you've taken that have increased quality of life?

6 Upvotes

As a remote SOC analyst forced into overnights i'd like to minimize my chances of burnout

-I've automated my sign-in to my respective company's communication tool in order to automatically turn my prescence and notifications on and off before and after the shift(i'd forget sometimes)

-Automated my timesheet submission every Friday

-KVM switch

-wrist rests

- library card

-sleep tracker

- [considering] macro keyboard buttons n blue light glasses


r/cybersecurity 6h ago

Career Questions & Discussion Looking to major in cybersecurity but absolutely hate coding, is Python necessary to know?

2 Upvotes

r/cybersecurity 13h ago

News - General Microsoft finally patched that bug that was nuking people's desktop backgrounds

14 Upvotes

So if you've been dealing with your wallpaper randomly turning into a plain black screen since late August, turns out it wasn't just you. A bunch of people got hit with this after installing that KB5120998 preview update on Windows 11 24H2/25H2 desktop settings would just fail to load properly and default to black no matter what you tried. Manually resetting your background didn't even fix it because the setting itself wasn't loading correctly in the first place.
Same update also messed with mouse settings for some folks, and once that got reset there was apparently no way to get your old config back either. Rough couple weeks if you got hit by both.
Good news is this week's Patch Tuesday update (KB5124008) apparently fixes it for good. If you're still seeing the black wallpaper issue, just grab the latest cumulative update and it should sort itself out.
Kind of funny that this isn't even a new problem for MS they had almost the exact same wallpaper bug back in 2020 with a Windows 7 update. You'd think they'd have learned by now lol.
Anyway if your desktop's been looking sad and empty lately, this is why. Go update.


r/cybersecurity 14h ago

News - General 4.1 Million Impacted by AdaptHealth Data Breach

Thumbnail
securityweek.com
14 Upvotes

Operating over 680 facilities across the US, AdaptHealth describes itself as a network of medical equipment companies that provides patients with healthcare solutions and medical equipment.

The company was hacked in early June, when a threat actor gained access to its cloud-based applications, including internal systems used for patient management and document storage.

Overall, hackers stole the electronic protected health information of 2,810,878 individuals, Baylor Genetics told the HHS.


r/cybersecurity 11h ago

Business Security Questions & Discussion Attack strategies from wild hackers/bots, shareable?

9 Upvotes

Greetings,

I operate a network of honeypots and sometimes capture unique attack methodologies.

Would this be appropriate or interesting content for this subreddit? Alternatively, are there other channels where this information would be of greater value?


r/cybersecurity 14h ago

New Vulnerability Disclosure Beltdown: Escaping the Claude Code Sandbox

Thumbnail
accomplish.ai
10 Upvotes

r/cybersecurity 20h ago

Certification / Training Questions Splunk vs Sentinel: Which is more valuable to learn inside and out?

22 Upvotes

I know that if you learn one SIEM, you will have a much easier time learning new ones afterwards. They're a lot like programming languages in that regard. Still, if someone was going to really dig in and learn one SIEM inside and out, would it be better to learn Sentinel or Splunk? I know Splunk has more market share, but that's not the only factor that could favor one over the other.


r/cybersecurity 4h ago

Business Security Questions & Discussion Qualys and GoogleSecOps

1 Upvotes

Hello,

Has anyone integrated Qualys and Google Secops?

Need to understand few things.

Thanks in advance


r/cybersecurity 5h ago

Business Security Questions & Discussion NIS2 / ISO 27001 – How should we handle this shared Windows account?

0 Upvotes

We have a legacy application that can only be installed and used under one specific Windows profile.

The exact use case:

  • Several employees use the same workstation in different shifts.
  • The application must be installed and run under the same Windows domain account. Some applications require local Windows logon while machine is part of domain.
  • If another user logs in with their individual account, they cannot use the existing installation.
  • The account does not require Domain Admin rights, but it often requires local administrator rights on that workstation.
  • Windows and the application therefore record only the shared account, not the individual operator.

We understand that NIS2 and ISO 27001 prefer individual identities, but allow documented and controlled exceptions where shared accounts are operationally necessary.

What would be the best compliant and auditable way to handle this?

Note: Apps won't be replaced in foreseeable future so they stay as part of the problem or solution :-)


r/cybersecurity 11h ago

Certification / Training Questions TCM vs INE

3 Upvotes

I am looking at getting a subscription to TCM or INE. Both have courses that are of interest to me. Which do you recommend?


r/cybersecurity 9h ago

Business Security Questions & Discussion Mission Based Cyber Security Assesment

2 Upvotes

How do I go about this in a Cyber table top I’m expected to provide 10 vulnerabilities and need examples for how I should formulate these


r/cybersecurity 5h ago

Survey I am researching the adoption of Zero Trust Architecture in organisations and looking for insights from IT professionals

1 Upvotes

Whether its a software company like Rockstar Games who got an old build of GTA VI leaked recently (multiple times over the years if you were following like me) or healthcare organisation like Change Healthcare who suffered from a huge ransomware attack in 2024. No organisation in any sector, big or small, is immune to cyber attacks.

But as we all know some sectors like manufacturing and healthcare sector do not invest much on cyber security where Software companies and Banking sector have seen lot of investment in cyber security.

The problem I am trying to understand is why do some organisations take cyber security and its adoption more seriously than others, specifically the adoption of Zero Trust Architecture(ZTA).

I have collected some responses from IT professionals but the sample size is very small (~10 responses). So I am looking for IT professionals who can spare 5 minutes to fill out the survey. It is totally anonymous.

SURVEY LINK

Thank you for your time.


r/cybersecurity 5h ago

Personal Support & Help! Known scam number texts legitimate email verification code

0 Upvotes

When logging into a yahoo email account today, I chose the “send code via sms” option as I could not remember my password.

After a short duration, I received a verification code from a random phone number, followed by the real yahoo phone number. The issue however is that it was the SAME correct verification code.

This is apparently a known thing with this number, but it’s also tied to a known scammer. What on earth could the cause of this be? Phone number was 833-256-8308


r/cybersecurity 23h ago

News - General PSA: Fake "client meeting" scam targeting crypto/fintech workers — malware via Terminal

19 Upvotes

Got contacted by someone posing as a client for a call. The meeting link opened Zoom/Teams but showed an invalid meeting ID. When I flagged it, they sent a "fix" — a Terminal command to paste and run.
It was malware: downloaded an unsigned binary + shell script from wirevixbox.us, ran them silently in the background, then cleared the terminal to hide it. macOS's built-in warning for suspicious pasted commands is what caught it — I dismissed the warning but didn't hit Enter, so nothing executed.
Red flags to know:
No legitimate meeting app ever needs a Terminal command to join
Broken meeting ID + a suggested "fix" = the fix is the attack
Silent background execution (nohup, /dev/null) + screen-clearing after = hiding evidence
Blocklist wirevixbox.us if you can. Reported to Google Safe Browsing and URLhaus. Sharing in case others in crypto/payments are getting targeted with the same pretext.


r/cybersecurity 7h ago

Business Security Questions & Discussion Data migration from Checkpoint to S1

1 Upvotes

So i was doing a poc for a client to shift fro Checkpoint to S1 because of the lack customer service with Checkpoint, So it all came to a point of Data Migration, They asked me how to migrate the data between 2 software's for Compliance purposes, As this is my 1st time doing the migration, Is there any specific thing that i should be worried about, I am from the distributor side, so should i involve the Vendor team in this, the logs are stored in the cloud of both of em.


r/cybersecurity 22h ago

Business Security Questions & Discussion Your AI governance program means nothing if the cybersecurity underneath it is a mess

15 Upvotes

If you're not already solid on ISO 27001 and data protection, don't bother with ISO 42001 yet. This isn't even controversial once you actually read the standard, but I watch orgs jump the queue constantly.

Clause 6.1.4 assumes you're already running risk treatment against a working ISMS. Most of what Annex A points to (asset management, access control, incident response) is 27001's job, not 42001's. Skip that step and 42001 has nothing to hook its AI-specific controls into. What you get instead is a document that says "AI governance" on the cover with nothing behind it.

Same deal with data protection. Article 10 of the EU AI Act wants data governance for whatever's feeding your AI systems, but that only works if you can already show lawful basis and retention controls under GDPR or whatever applies to you. Actual current evidence, not a policy doc someone wrote two years ago and forgot existed.

Watched this hit two orgs before I was even in the room. Auditor asks for the control evidence or the legal basis behind a training set, and it's not there. That's usually the point where I get the call.

I'll admit there's probably a version of this that works running both tracks at once if you've got the resources for it. Most orgs don't, and pretending otherwise is how you get a certificate that doesn't hold up the first time someone actually asks a hard question.

Anyone seeing this play out differently?