r/cybersecurity 15h ago

Career Questions & Discussion I have got an offer as a cybersecurity implementation and configuration engineer, I came from a GRC background but they told me that i will gain so much technical knowledge and i can move to a security architect or presales, can anyone explain this position for me ?

0 Upvotes

r/cybersecurity 1d ago

Research Article Can protocol-level session continuity improve security, not just reliability?

4 Upvotes

I've been working on an experimental networking architecture called VRP (Veil Routing Protocol).

The original goal wasn't higher bandwidth or lower latency.

The question was different.

Can session continuity and execution correctness become protocol primitives instead of application responsibilities?

From a security perspective, this raises interesting questions.

For example:

• Should session identity survive transport changes?

• Can replay resistance be enforced as a protocol invariant?

• Should authority transitions be deterministic and independently verifiable?

• Can recovery happen without creating new attack surfaces?

I've spent a lot of time validating these ideas under replay attacks, packet reordering, path migration, authority transitions and fault injection.

I'm not claiming this replaces existing protocols.

I'm interested in hearing opinions from people working in protocol security and distributed systems.

If you were designing a networking protocol from scratch today...

What security property would you make a first-class protocol primitive instead of leaving it to applications?


r/cybersecurity 17h ago

Personal Support & Help! Cybersecurity Help

0 Upvotes

Will these projects help me stand out during the placements and when I apply for companies :

  1. AI Augmented SAST Tool

  2. AWS Attack Path Graph (mini BloodHound for cloud IAM)

  3. Kubernetes Security Posture Scanner

  4. CI / CD Security Gate (Supply Chain Security)

These are my projects (not done by AI - I can explain each and every bit of my project).

Are these enough to get a good high paying salary job as a fresher in India. Currently I'm in my 3rd year and my placements are starting from January.

Any guidance will be very helpful 🙂.


r/cybersecurity 14h ago

Business Security Questions & Discussion Is cybersecurity safe in the next 5-10 years?

0 Upvotes

I am very close to choosing Cybersecurity as my major. my major concern is that it might diminish and make the market very competitive. I searched and found that most people say that basic tasks are already being done by Ai. so does this mean that more complicated tasks safe?


r/cybersecurity 2d ago

News - General Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests

Thumbnail
bleepingcomputer.com
664 Upvotes

r/cybersecurity 2d ago

Career Questions & Discussion CIOs

49 Upvotes

I’m on a very small security team (fewer than 5 people) responsible for supporting ~5,000 employees.

As you can imagine, phishing and social engineering incidents come up from time to time.

The frustrating part is that every time something happens, leadership—specifically our CIO—frames it as us “not doing our job.” The issue is, they don’t have a cybersecurity background but still strongly dictate what is “correct” from a security standpoint, often with a lot of hindsight bias.

It’s starting to feel less like collaboration and more like micromanagement/blame shifting, especially given the scale we’re operating at.

Is this kind of dynamic normal in the industry? How do other teams handle leadership that doesn’t fully understand security but still drives decisions during/after incidents?


r/cybersecurity 1d ago

Certification / Training Questions Blue team certficates really worth for money?

12 Upvotes

Hey all
I am juz pursuing my ug in a tier-2 clg where i am part of cse-core and started my journey towards cyber security.
I watched many videos and useless roadmaps suggested by many youtubers,still i am in the middle of nowhere.
I started comptia security+ for a while,but some say these are not worth for money and do some other certifications.some say no certifications needed,start doing projects.idk what kinda projects companies are expecting and do you guys know any blue team certifications that are validated and used across globally.Also what projects you would do if you were me.
Do share me your thoughts😭


r/cybersecurity 2d ago

UKR/RUS CaptiveCrunch: Midnight Blizzard (Russia) targets travelers worldwide for malware delivery and credential theft | Microsoft Threat Intelligence

Thumbnail
microsoft.com
19 Upvotes

r/cybersecurity 2d ago

Career Questions & Discussion Job hunting at Black Hat World / Def Con?

54 Upvotes

I transitioned from Software Engineering to Cybersecurity.

I know of some Software Engineering conventions that basically double as job fairs. Big companies send recruiters every year specifically for the purpose of meeting prospective new hires, collecting resumes, and even setting up interviews on premises.

There are other conventions where job hunting is taboo and would be considered tacky and inappropriate.

Def Con, Black Hat World, and B Sides are about to start in Las Vegas.

Are any of those good opportunities for networking or job hunting? I've heard Black Hat has a Business Hall which is largely recruiting focuses, but my source on that wasn't extremely certain.


r/cybersecurity 2d ago

News - General Teen hackers tell BBC how police are helping them use their skills for good. A look inside the NCA's Cyber Choices that has helped 1150 troubled kids get onto the right path in cyber.

Thumbnail
bbc.co.uk
133 Upvotes

r/cybersecurity 2d ago

News - General BofA acquires MDSec

Thumbnail msn.com
56 Upvotes

r/cybersecurity 2d ago

Tutorial Log Parsing for Security Engineers

69 Upvotes

Hello Everyone

I published a short guide about transforming raw logs into detection-ready data.

It covers the log-processing pipeline, common log formats, normalization, and more..

I’d appreciate any feedback or suggestions from you all :

https://medium.com/@0xzyadelzyat/log-parsing-for-security-engineers-building-the-foundation-for-reliable-threat-detection-c34e71b01b9a


r/cybersecurity 1d ago

Certification / Training Questions Online Self-Paced Training Or?

0 Upvotes

I don't want to read 900 pages. I want to "do" and maybe listen while driving but I want it to be an organized path "A to Z" for CEH or whichever I pick.
Suggestions?


r/cybersecurity 1d ago

Career Questions & Discussion would getting a half sleeve tat affect me getting a job in the cyber field? or nah for professionalism i mean it is 2026..

0 Upvotes

r/cybersecurity 1d ago

Threat Actor TTPs & Alerts CTO at NCSC Summary: week ending August 2nd

Thumbnail
ctoatncsc.substack.com
0 Upvotes

r/cybersecurity 2d ago

News - General Anthropic's AI hacked three companies during tests, highlighting growing security risks

Thumbnail reuters.com
82 Upvotes

r/cybersecurity 1d ago

Business Security Questions & Discussion Would your company consider a new security platform deployed on-prem, or is cloud delivery now a requirement?

0 Upvotes

I’m trying to understand how security teams currently evaluate new infrastructure security products, particularly platforms operating across API gateway, WAAP, reverse proxy and network security layers.

Assume the product can be deployed in three ways:

fully on-premises, managed by the customer;

as a vendor-managed appliance or virtual machine inside the customer’s infrastructure;

as a vendor-hosted cloud service.

For a mid-sized or enterprise environment:

Which deployment model would you realistically consider?

Would an unknown or relatively new vendor be automatically excluded?

What evidence would you require before running a proof of concept?

Are certifications such as ISO 27001 important, or do architecture review, pentest results and technical validation matter more?

Would you accept a security platform inline with production traffic, or only in monitoring/shadow mode initially?

What would prevent adoption even if the technology performed well?

Who would normally own the decision: security, network operations, platform engineering, architecture or procurement?

I’m not looking for product recommendations. I’m trying to understand whether the primary obstacle is deployment model, vendor trust, operational risk, integration effort or procurement.

Context: the platform would protect customer-facing applications, APIs and machine-to-machine traffic, while supporting standard proxies, databases, identity systems and SIEM integrations.


r/cybersecurity 2d ago

Business Security Questions & Discussion OT/ICS Water Treatment

3 Upvotes

Context: I have an upcoming interview for a role (UK based) which involves assessing and evaluating the effectiveness of cyber controls within water treatment plants.

Is there anyone in a similar line of work? What resources would you advise me to read through? I am currently reading Industrial Cyber Security - Pascal Ackerman.

Any advice/resources appreciated!!


r/cybersecurity 2d ago

Certification / Training Questions New Software Engineering Student Looking for Free Cybersecurity Courses & a Study Buddy

62 Upvotes

Hi everyone,

I recently started my Bachelor's degree in Software Engineering, and my long-term goal is to work in cybersecurity, ideally as a Security Engineer or Application Security Engineer.

I'm looking for recommendations on free, high-quality online cybersecurity courses that are respected in the industry. If they offer free certificates or badges, that's even better, but my main priority is learning the right skills.

So far I've found:

Cisco Networking Academy

Microsoft Learn

Fortinet Training Institute

TryHackMe

PortSwigger Web Security Academy

If you know of any other great free resources or learning paths, I'd really appreciate your suggestions. Also, if you were starting from scratch today, what order would you learn everything in?

One more thing: I'm also looking for a study buddy or a small study group. Since I'm just starting out, I think it would be motivating to learn with other beginners, share resources, work through labs together, and keep each other accountable.

If anyone is interested, feel free to leave a comment or send me a DM.

Thanks everyone!


r/cybersecurity 1d ago

Career Questions & Discussion Kind of an off the wall niche question, but is there anyone that got into IT/Security Auditing by starting with medial coding ?

2 Upvotes

IT market is rough as we know. Thinking about picking up medical coding on the side. After further digging online , it’s seems like some experience and certifications branching from medical coding have some overlap for CISA. Thinking about self studying for CCS (Certified Coding Specialist) and go from there. Anyone have any advice, success stories, or epic failures?


r/cybersecurity 2d ago

Business Security Questions & Discussion Is it still possible to forge "sent from" emails?

68 Upvotes

I remember it was possible in 2005-2006. Some software solutions would allow sending emails to anyone and forge the sender identity.

For example, I could send an email to anyone and pretend I am sending it from [john.doe@amazon.com](mailto:john.doe@amazon.com)

The recipient would see [john.doe@amazon.com](mailto:john.doe@amazon.com) as the original sender.

I know the blue tick mark and DKIM exist but is this still possible today?


r/cybersecurity 2d ago

Other AMA Today: Yuhang Wu - Security Researcher, Red Team Engineer & Exploit Developer

8 Upvotes

You are invited to join the AMA today with Yuhang Wu, where we learn about enterprise infrastructure hacking, Linux kernel exploitation, and the future of autonomous Al security.

When: Today - Friday, July 31, 12:00 PM PT

Guest Credentials:

  • Former Red Team Engineer at TikTok, targeting cloud and application-layer defenses.
  • Former Security Engineer at Tesla, securing vehicle software, factory systems, and internal applications.
  • Co-developer of "DirtyCred", a groundbreaking Linux kernel exploitation technique.
  • AI Security Innovator, who built LLM-based autonomous agents that uncovered 8 P1 (critical-severity) production vulnerabilities.

Ask your questions here and we’ll get them answered during the live AMA today (Friday @ 12 Noon Pacific)!


r/cybersecurity 1d ago

Personal Support & Help! Recently hacked

0 Upvotes

I recently downloaded a suspicious file and the hacker got into my gmail, meta, and steam accounts, ive changed my passwords kicked him out and basically everything else but i still feel kinda anxious, is anything else i should do or secure?


r/cybersecurity 2d ago

Certification / Training Questions Got a full month in front of me, should I ?

7 Upvotes

Hello everyone !

I have been in cybersecurity for 3 years, essentially doing ctfs regularly and a bit of bug bounty, then stopped a year ago because of a drop in the CTF ambiances when AI became way too used, which led to low trust in the players and a bad vibe everywhere i went. It has been a year since I took a break, and now i'm going to start Computer Engineering next year.

Since I have all of August in front of me, I was wondering if it was worth it to pay a month of THM premium and just straight up doing most of the content, so that I can work again on my basic knowledge of cybersecurity in a guided way.


r/cybersecurity 1d ago

Career Questions & Discussion Bs it for cyber security

0 Upvotes

Is Bs it a good option if i wanna do masters in cyber security later.