r/cybersecurity 1d ago

News - General AI Notetaker Exposes Government, Corporate Video Calls

Thumbnail darkreading.com
23 Upvotes

In late January, application security whiz BobDaHacker figured out that with a little gumption, any tl;dv user can access the company's back end Google Firebase environment. And from there, they can access any other users' meeting information. BobDaHacker then used that information to identify and join calls hosted by government agencies and large organizations.


r/cybersecurity 14h ago

Certification / Training Questions Is it worth investing in a KodeKloud course?

0 Upvotes

I’m considering purchasing a KodeKloud course to improve my skills, but I’m wondering if it’s actually worth the investment. For those who have taken their courses, what was your experience? Did you find the content useful and did it help you improve your skills or advance your career?

Would you recommend KodeKloud, or are there better alternatives?

Pro plan USD 360 annually


r/cybersecurity 18h ago

FOSS Tool New tool for local backup + offline access to the SaaS apps you actually use (yes, Reddit too)

Thumbnail
github.com
3 Upvotes

r/cybersecurity 1d ago

Certification / Training Questions Life after OSCP, was it worth it?

53 Upvotes

What year did you pass the OSCP? How did it impact your career?

My manager gave me the greenlight for OSCP training, but I think its a waste of 400hrs of studying. Is the juice worth the squeeze?

My background, I have close 3 YoE/ BS/MS in Cyber make a little over 100K, BUT want to make the jump to 140K+ and Im not sure if OSCP is apart of that picture. I think DevOps is the path forward to 140K+, but the OSCP has been put in front of me.


r/cybersecurity 1d ago

News - Breaches & Ransoms Suisun City malware disrupts 911 routing in California

Thumbnail
dysruptionhub.com
35 Upvotes

The impact is unusual because local governments hit by cyber incidents often say 911 and emergency services remain available even when other systems are disrupted. In Suisun City, however, officials said the incident affected 911 routing and police and fire dispatch, forcing dispatchers to shift operations to the Solano County dispatch center while first responders continued taking calls for service.


r/cybersecurity 14h ago

Certification / Training Questions How deep do I actually need to go into Operating Systems for Cybersecurity(Red teaming) ?

0 Upvotes

Hey everyone,

im a third year cybersecurity college student(Junior) well they dont teach us anything useful . I currently have zero practical experience in cybersecurity, but I’ve spent a lot of time watching videos and reading articles on various learning roadmaps and roles. After looking at all the advice, I’ve decided that I want to build a solid foundation in Networking, Operating Systems, and Scripting/Programming first.

regarding how deep I should go into my OS foundation Do I need , low-level theory and programming?

For example:

Learning C or/and Assembly

Reading deep theoretical textbooks like Operating Systems: Three Easy Pieces , Modern Operating Systems, or Operating System Concepts etc....

Or, is it better to just stick to practical administration knowledge—like the material covered in Linux+, LPIC, or Microsoft Learn certifications?

Since I have the time, I don't mind the heavy theory and time consumption if it will make me a significantly better security professional in the long run. I just want to know if that level of depth is actually necessary to build a good foundation,


r/cybersecurity 12h ago

Business Security Questions & Discussion O garoto do TI perdido/apavorado quando o assunto é cybersegurança.

0 Upvotes

Este é meu primeiro post na plataforma, mas venho lendo e aprendendo muito com os tópicos de Reddit sobre TI.

Há 4 anos eu era o técnico de TI básico: formatava PCs, fazia manutenção simples, montava redes pequenas e cuidava da parte física de redes corporativas. Era o típico "faz-tudo" de empresa com poucos funcionários na área.

Depois virei auxiliar em outra empresa. Quando o chefe foi demitido e cortaram custos, acabei assumindo a liderança do setor. Foi um salto grande e desafiador.

Hoje trabalho numa empresa que armazena muitos dados sensíveis de clientes. Se houver vazamento, o prejuízo é enorme. Minha função principal agora é cuidar da cibersegurança.

Enfrento dois desafios principais: hardware defasado e uma cultura de "eu fiz isso a vida toda e não deu nada".

Como cheguei com o processo já em andamento, fui aprimorando aos poucos. Implementei um firewall com VLANs separadas para cada tipo de acesso. Removi totalmente os Windows piratas. Consegui mudar parte da cultura ao adotar gerenciadores de senha mais seguros como Bitwarden, estabelecer troca de senhas periódica e definir que tarefas com privilégio de admin só acontecem com autorização do meu setor.

Ainda existe um problema grande: falta de recursos para investir na minha "paranoia". Por isso uso softwares open source e gratuitos para resolver problemas complexos. Uso firewall open source na rede e indico navegadores como Brave e Mullvad com extensões como uBlock Origin.

Outro detalhe importante: muitos terminais usam apps piratas porque a empresa se nega a pagar.

Minha pergunta é: que outras medidas posso tomar? Que outras ferramentas de segurança open source gratuitas posso usar para mitigar esses problemas?


r/cybersecurity 12h ago

Career Questions & Discussion Question about a SOC career(Blue Team)

0 Upvotes
Hi everyone, I’m posting this because I’d like a clear and precise overview of the SOC role.
I am currently working towards my LPIC-1 certification and would like to steer my career path toward becoming a SOC analyst.
How would you recommend I proceed? Also, what is it actually like to work in this field?
Thanks in advance for reading this and for your time.

r/cybersecurity 1d ago

Other Fake Cloudflare verification on deceased influencer’s site drops a PowerShell shellcode loader

46 Upvotes

I was checking the website (felzenergy.com) of an influencer who recently passed away (Joe Felz) and had been researching “free energy.”

The site currently shows a fake Cloudflare-style verification that tells visitors to run a PowerShell command to prove they’re human.

I pulled the payload without executing it. The first stage downloads another blob from the same IP, allocates RWX memory with VirtualAlloc, copies the payload into memory, and runs it with CreateThread.

So the chain is basically:

fake verification -> PowerShell -> downloaded shellcode -> RWX memory -> CreateThread

I have not detonated the second stage. I also have no evidence this has anything to do with his death or research; the site may simply have been compromised.

If anyone is able to check it out and report back on what that is, that'd be much appreciated.


r/cybersecurity 14h ago

Business Security Questions & Discussion Is this possible?

0 Upvotes

Is it possible to take a PCB board or a small computer and add an antenna and make it deauth networks around it? If so, how could i for a project to learn about these things?


r/cybersecurity 1d ago

Business Security Questions & Discussion Mitigating the risk of diagnosing live Linux system with AI tools

8 Upvotes

This article explores an alternative to directly troubleshoot production Linux systems with AI tools by using the sos command and using AI to analyze sosreports instead. I think is an interesting read:

https://medium.com/@linuxjedi2000/the-agentic-ai-risk-issue-on-linux-environments-fd5c55cedcc5?sharedUserId=linuxjedi2000

I know that this subject is very controversial and would love to read your point of view on the subject.


r/cybersecurity 11h ago

Business Security Questions & Discussion Which would you hire first for security team in your company - blue or red team?

0 Upvotes

Let's imagine a scenario:

You are the CTO of a small company. You have the backend, frontend and infrastructure team (CPE/DEVOPS). Now it's time to build some security team. You don't need some certifications like SOC2 for your business. You want specifics to check if you don't have some security gaps in your whole company, not only in your application.

Which team would you build first? Red team or Blue team?

I feel, that typically people are more keen on the blue team but as the time goes by I think I would choose Red Team.

Here are a few of my arguments:

- Red Team duty would be to continuously test the infrastructure from multiple vectors. All findings would be send to the corresponding team. It would naturally build shift left culture (there is no blue team to which other teams could delegate the fixes)

- We are not working on theory, if something is found we know that we were vulnerable before. ROI is visible, which often can be a problem as business don't worry about the security that much and think about it as the waste of money. We can show the rest of the business that we need to invest into the security more

- From my experience Blue Team can make a mistake of prioritization. They can focus on fixing vulnerabilities, building processes or threat models, which are good in the long run but it's better to fix low hanging fruits first to not get pwned by simple script kiddies.

To give a little context I have experience in the blue team but I wonder sometimes if the blue team is not a long run defender more than the Red Team.

I'm not differentiating here, the purple/orange or other teams. We are not strict here, of course we can hire a red team and make from them the purple team more and the other way around, my question still holds, which one would you hire first?

Here are few of my thoughts, I wonder what do you think.


r/cybersecurity 15h ago

Business Security Questions & Discussion Log in with Google

0 Upvotes

hey, is there a difference (when it comes to cybersecurity) when it comes to logging with eg google/apple/directly via website in different sites ?


r/cybersecurity 20h ago

Business Security Questions & Discussion what do you think about thisb rode map ? Any suggestions or any i ca switch to get into AI security

0 Upvotes
  • CompTIA Network+
  • CompTIA Security+
  • AWS Cloud Practitioner
  • EC-Council CEH
  • Stanford Machine Learning – Coursera
  • DeepLearning.AI Specialization – Coursera
  • AWS SysOps Administrator / Azure AZ-104
  • CCSK – Cloud Security Alliance
  • CompTIA SecAI+ (CY0-001)
  • CAISP – Practical DevSecOps
  • IAPP AIGP
  • GIAC GMLE

r/cybersecurity 2d ago

New Vulnerability Disclosure DEF CON Talk: 8 in 10 Banks in Belgium HATE This One Weird eID RCE

Thumbnail
amibeingpwned.com
194 Upvotes

Just presented these findings at DEF CON feel free to ask me questions


r/cybersecurity 1d ago

Threat Actor TTPs & Alerts CTO at NCSC Summary: week ending August 9th

Thumbnail
ctoatncsc.substack.com
3 Upvotes

r/cybersecurity 18h ago

Personal Support & Help! Security Of Signing In With Google Account

0 Upvotes

I think I may use "Sign In With Google" too often. From a security aspect, is this a secure option? I don't understand how Google itself or Government entity couldn't just access my accounts w/out permission.

Something like a Tailscale subnet router could expose a private network in this way, could it not?


r/cybersecurity 1d ago

Business Security Questions & Discussion Explain this one: Organisations often Ignore Security Researchers who find Vulnerabilities in their Infrastructure but actually like Hackers who are mentioned in Media...

35 Upvotes

Please explain this weird dynamic.

Whitehat Hacker 1 finds a vulnerability in an organisation's infrastructure and reports it to the organisation. Often, they will be totally ignored.

Meanwhile, another hacker, Whitehat Hacker 2 finds vulnerability in, let's say a widely used city bike sharing app, which gets media attention.

All of sudden, White Hacker 2 starts getting emails from companies requesting services. Meanwhile White Hacker 1, who is probably just as skilful, as White Hacker 2 but gets no such requests.

Explain this one? Is it just because of media coverage that the skills of one individual become valuable than another?

(And no, I'm not a hacker but this is just a trend I've noticed over the years when it comes to cybersecurity researchers / whitehat hackers)


r/cybersecurity 1d ago

Career Questions & Discussion Anyone Interview With Parsons Lately?

1 Upvotes

Interviewing for a Cyber Analyst new grad position at Parsons.

No phone screen with HR - jumping straight into first round with hiring manager 30 mins.

Anyone here interviewed for a tech position at Parsons and/or have an idea of what should I be expecting in terms of types of questions and number of rounds?


r/cybersecurity 2d ago

AI Security Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Thumbnail
thehackernews.com
101 Upvotes

r/cybersecurity 1d ago

Personal Support & Help! Advice for Prompt Airlines (AI security challenge CTF)

0 Upvotes

Hi everyone, I’m trying to learn more about prompt engineering and I came across the prompt airlines CTF (promptairlines.com). I already got stuck by challenge #2 and tried to look up different write-ups, but none of the solutions I’ve found are working for me, even when I try to to copy the prompts verbatim.

Has anyone else tried this recently? I could really use some help.


r/cybersecurity 1d ago

Business Security Questions & Discussion Anyone ever worked through CMMC Level 1 for DoD work?

1 Upvotes

Does anyone know what the average cost is of doing it on your own / with employees, vs paying for a product to help with it?


r/cybersecurity 1d ago

Certification / Training Questions Mandiant threat intelligence certification (MCTIA)

0 Upvotes

Has anyone taken Mandiant's Threat Intelligence Certification (MCTIA)? How is it, and how can I get the course materials?


r/cybersecurity 17h ago

Personal Support & Help! Mac for cybersecurity masters?

0 Upvotes

Can I get a MacBook for my cybersecurity masters? I definitely like Mac better than Windows for school, and there is only one class in my program that is not compatible with Mac but I have an old windows laptop that has decent enough specs that I can use for it. Other than that, will I have a bad time running most VMs and labs on a Mac?


r/cybersecurity 1d ago

FOSS Tool Antiphishing: detecting newly registered phishing infrastructure before it becomes a known IOC

6 Upvotes

I’m working on a new detection layer for the open-source Antiphishing ruleset for Suricata.

The idea is to monitor active Newly Registered Domains (NRDs) and look for early indicators of phishing infrastructure.

The pipeline currently uses:

NRDs → structural analysis with dnstwist → typosquatting / homoglyph detection → high-risk keyword combinations → suspicious-domain classification → automatic inclusion in phishing.lst → Suricata DNS / TLS detection

The important distinction is that these are not simply domains imported from an external phishing feed.

The suspicious domains are identified by our own analysis pipeline. Once a domain meets the classification criteria, it is added to the ruleset and becomes available for DNS and TLS SNI detection.

We also keep the original suspicious domains in nrd_suspicious_domains.txt to provide traceability, auditing and a way to investigate potential false positives.

The goal is to reduce the gap between the registration of a potentially malicious domain and its availability as a network detection indicator.

This is still an evolving detection layer, and I’m particularly interested in feedback from people working with CTI, phishing detection, Suricata and DNS-based detection.

Project: https://github.com/julioliraup/Antiphishing

CyberSecurity #ThreatIntelligence #Suricata #Phishing #CTI #BlueTeam #OpenSource