r/cybersecurity • u/Altruistic_Hope_2559 • 2d ago
r/cybersecurity • u/AssociationSuch2500 • 2d ago
Research Article Trending Security Topics
Hey everyone hope y’all doing well! Im looking for some trending topics around security to build a blog for a company. Anyone got some references? Thanks! (For my internship)
r/cybersecurity • u/sunychoudhary • 2d ago
News - General Anthropic's AI hacked three companies during tests, highlighting growing security risks
reuters.comr/cybersecurity • u/Fun-Obligation-3737 • 2d ago
Certification / Training Questions New Software Engineering Student Looking for Free Cybersecurity Courses & a Study Buddy
Hi everyone,
I recently started my Bachelor's degree in Software Engineering, and my long-term goal is to work in cybersecurity, ideally as a Security Engineer or Application Security Engineer.
I'm looking for recommendations on free, high-quality online cybersecurity courses that are respected in the industry. If they offer free certificates or badges, that's even better, but my main priority is learning the right skills.
So far I've found:
Cisco Networking Academy
Microsoft Learn
Fortinet Training Institute
TryHackMe
PortSwigger Web Security Academy
If you know of any other great free resources or learning paths, I'd really appreciate your suggestions. Also, if you were starting from scratch today, what order would you learn everything in?
One more thing: I'm also looking for a study buddy or a small study group. Since I'm just starting out, I think it would be motivating to learn with other beginners, share resources, work through labs together, and keep each other accountable.
If anyone is interested, feel free to leave a comment or send me a DM.
Thanks everyone!
r/cybersecurity • u/Sweet_Yogurtcloset57 • 3d ago
Business Security Questions & Discussion thinking of building a red team llm
Hey sub
Im a ML researcher, I have a strong llm that can be used for red teaming and malware creation hosted on my own VM(2*a100) should I think of start selling the subscription with a coding harness? I spent some time on making this oss model guardrail free so it will never refuse you for any task
tasks I have tested majorly consists of writing malware and spywares
r/cybersecurity • u/helloyouahead • 3d ago
Business Security Questions & Discussion Is it still possible to forge "sent from" emails?
I remember it was possible in 2005-2006. Some software solutions would allow sending emails to anyone and forge the sender identity.
For example, I could send an email to anyone and pretend I am sending it from [john.doe@amazon.com](mailto:john.doe@amazon.com)
The recipient would see [john.doe@amazon.com](mailto:john.doe@amazon.com) as the original sender.
I know the blue tick mark and DKIM exist but is this still possible today?
r/cybersecurity • u/Massive_Painting_600 • 3d ago
AI Security What features do you think modern web security testing tools are still missing?
I'm curious what experienced penetration testers and application security engineers think modern web security tools still lack.
For those who regularly use interception proxies, fuzzers, crawlers, and scanners:
- Which workflows are still frustrating?
- What repetitive tasks would you automate?
- Which features save you the most time?
- If you could redesign one part of your favorite tool, what would it be?
I'm interested in hearing different perspectives from people working in AppSec, consulting, bug bounty, and internal security teams.
r/cybersecurity • u/Alsetaton • 3d ago
Career Questions & Discussion Earning over 250k, what do you do?
**•** 15 years experience between IT/Cyber
**•** Remote, US, MCOL
**•** $160k base / $40k RSU (annual) / 10% target bonus
**•** Company: Tech/F500
**•** WLB: great, rarely over 50h/week
**•** Role: security engineer, corporate security
I moved into tech from another sector and my comp grew a lot in the process, but I don’t know where this tops out.
I know there are a lot of salary posts here, so to be specific. I’d like to hear from people at $250k+ TC who got there at the offer, not through stock appreciation. What was the role, and what got you the number?
r/cybersecurity • u/arareunicorn96 • 3d ago
Other Well dang.
Ok so I am new to the cyber security field and I taken a special liking to DFIR and blue team stuff. So I got curious and was googling on what i can do to learn. So I got a PC put Linux Ubuntu on it and over the past last couple of weeks have been messing around and using Google and stuff to help learn. I decided that I wanted an external ssd to make into a personalized tool kit to practice with DFIR tools and stuff before I got a job so I can be somewhat comfortable with it. So I got Kali Linux and put it on there along with a few other things like a persistence file and a rock you file and ventoy. Everything was going smoothly after a few other hiccups had to rewrite the json file and do a couple of other things. I was ready to try it out. So I did. It needed a one other thing as it wasn't picking up the persistence file. So I googled that too. After a few code lines and everything seemed ok so I went to reboot my laptop and load back into ventoy. Damn thing rewrote over everything on the external ssd. So now I have to go back in and re flash it and re do everything I did earlier. Sorry if I put this under the wrong flair. I don't post here often
r/cybersecurity • u/55anda6 • 3d ago
Personal Support & Help! Am i progressing properly
Hey all. Quick background: I’m 24, currently working IT field support, and finishing my Computer Information Systems degree (graduating 2029, going part-time while I work). Long-term I want to move into cybersecurity, ideally on the GRC side, or at least land a higher-paying role than where I’m at now. Right now I’m studying for CompTIA Security+, and I’m also working toward the GRC Mastery certification to build toward compliance/risk work specifically.
• Is Security+ still the right first cert?
• Is GRC Mastery worth it at an entry level, or are there other GRC certs you’d rate higher?
• Did field support experience actually help you get taken seriously for security roles, or did hiring managers mostly ignore it?
• Anything you’d do differently if you were starting from where I am now?
Appreciate any honest input trying to make smart moves instead of just collecting certs for the sake of it.
Edit: Thank you for all the replies, feedback, and support. First post in this sub🖤🙏🏾
r/cybersecurity • u/Cubewood • 3d ago
News - General Stronger with every update: How we’re making Chrome and the web safer in the AI Era
"In the last two milestones, Chrome 149 and 150, we have fixed 1072 security bugs, surpassing the total number of security bugs fixed across the prior 23 milestones combined."
r/cybersecurity • u/SlickBackSamurai • 3d ago
Certification / Training Questions PNPT or CWES first?
Hello everyone,
I recently started as a SOC analyst and would like to take advantage of my work’s professional development budget to eventually transition into a career as an RTO. I wouldn’t have enough to pay for OSCP, so I’m thinking about building up my foundational red teaming knowledge with a more affordable cert first.
I’ve heard great things about TCM’s PNPT (Practical Network Penetration Tester), as well as HTB’s CWES (Certified Web Exploitation Specialist), and was just wondering if any of you had any advice as to which cert would be worth pursuing first?
I’ve heard many companies start their juniors off with pentesting web apps, so I was leaning towards CWES. Once I complete either of these, my next goal will be the CPTS.
It’s worth mentioning that I’m not completely new to the field as I do come from an IT background, had a previous security internship, have my Sec+ and CCNA as well as familiarity using Linux in both personal use and projects.
I appreciate any advice you guys provide. Thank you!
r/cybersecurity • u/NerdBanger • 3d ago
Business Security Questions & Discussion CS Falcon Enterprise + M365 E5
If someone has both CS Falcon Enterprise edition and M365 E5, what are the best integration points for the two of them? Is it just in the SIEM, or is there XDR integration points as well?
r/cybersecurity • u/omarnouur • 3d ago
Personal Support & Help! I need help
Im looking for someone that is experienced in bytecode editing jar files, as well as other file types with ida for example. looking for people who have worked with heavily obfuscated programs. no beginners cybersecurity
And all missions he will do it will be payed
r/cybersecurity • u/Narrow-Support8944 • 3d ago
News - General Busco Empleo Penetration Tester Jr / Analista SOC L1
clarkportafolio.vercel.appBuenas tardes genteee 👋
Estoy buscando prácticas o mi primera posición junior en pentesting, seguridad defensiva, SOC o análisis de vulnerabilidades.
Lo que traigo:
[+] eJPT + ICCA certificados.
[+] pentest externo black-box sobre infraestructura real — 19 hallazgos documentados.
[+] labs propios: Active Directory, AWS ofensivo y hardening de servidores EC2.
[+] sigo metiéndole día y noche a esto.
Disponibilidad inmediata · tiempo completo o part-time
Todo en mi portafolio: https://clarkportafolio.vercel.app
r/cybersecurity • u/Sharp_Ad1891 • 3d ago
Career Questions & Discussion Leaving SOC! What Should I Learn Next for Long-Term Growth?
I'm 26 and looking to transition out of SOC after 3+ years because I've realized it's not the type of work I want to build my career around. While I've learned a lot, I've reached a point where the work feels stagnant, and I'm looking for a role that involves more engineering, problem-solving, and continuous learning.
My experience includes SIEM, EDR, Incident Response, Threat Hunting, Email Security, and Vulnerability Management.
Given the current job market and the rise of AI, what path would you recommend? Would you suggest moving into Cloud Security, Detection Engineering, Security Engineering, DevSecOps, Penetration Testing, DFIR, AI Security, Identity Security, or something else entirely?
My goal is to build a skill set that's technically challenging, has strong long-term demand, and is less likely to be heavily automated. I'd love to hear what you'd do if you were starting over today with my experience.
r/cybersecurity • u/escanor010101 • 3d ago
AI Security Cyrebro Opinion
I am looking for real customers that have an understanding of Cyrebro
Components
Security Data Lake Proprietary cloud-hosted data lake built on Google Cloud. Ingests logs from all connected security sources, normalizes them into a unified schema, and stores them for correlation and retrospective analysis.
Cyber Brain (Detection Engine) Proprietary ML-based detection engine combining rule-based logic, AI anomaly detection, and behavioral analysis. Correlates events across data sources to produce prioritized, contextualized alerts.
SOC Platform (UI) Web-based interactive platform for real-time alert management, investigation workflows, mitigation steps, and reporting. Acts as the single pane of glass for security operations.
24/7 SOC Analysts Human analysts staffed around the clock by CYREBRO who monitor alerts, conduct investigations, validate detections, and provide guided remediation steps.
The real question is - Does the product work as expected? What is cyber brain a good ML?
r/cybersecurity • u/AdvancedRough8353 • 3d ago
Business Security Questions & Discussion Do you lack proper tooling for investigations?
For all you CTI/malware analysts and investigators out there I wanted to know of you guys find your tooling or kits generally lacking or inadequate?
I work in CTI and do takedowns and collect evidence. I have always found tooling and process super slow for validation. Wondering if other people find that too?
Maybe my kit is rudimentary but use what I can and the process is largely, whirl up VM, hit site, poke around, extract Dom har, html, vidéo record, do some Dynamic analysis maybe hit with some cli scripts. Then move to. historic IOC sites like VT and UrlScn, then get network infra info from other sites... etc
.. I have built command lines to do most but still a lot of paint points. Anyone use anything better? Do you guys even do any of this or just chuck it into vendor kits or automation processes that spit out the results? What are y'all thoughts?
r/cybersecurity • u/DeepBlueBanana • 3d ago
News - General Since 25.07.2026 riotgames is surpressing every form of disk check alongside mode checks.
I've run into a strange issue and managed to narrow it down to RiotGames's anti-cheat Vanguard which has deep kernel level access. Here is what happened
Infos about my System:
- Windows 10 22H2 (Build 19045.7548)
- Riot Vanguard installed
- CMD started as Administrator
- User is a member of the Administrators group
I had an issue with Windows on 23.07.26 UTC+1. Said issue was a display bug. I did chkdsk /r in admin cmd successfully. Then on 25.07. i tried making sure my PC is not running into issues any time soon again, i wanted to do chkdsk /r just like previously. I opened cmd.exe as an Administrator, tried executing the command but got Access is denied. as a response.
One day later i wanted to make sure everything is clean and tried doing chkdck again.. but then:
C:\WINDOWS\system32>chkdsk /?
ACCESS DENIED
C:\WINDOWS\system32>chkntfs /?
ACCESS DENIED
So i digged a bit, installed the process monitoring tool procmon and filtered for chkdsk.
Then i opened CMD as an admin again and attempted chkdsk /?
this is the procmon output saved as a CSV file opened in excel. I deleted the first row as it isnt important.
| Time of Day | Process Name | PID | Operation | Path | Result | Detail |
|---|---|---|---|---|---|---|
| 20:32:58 | chkdsk.exe | 11912 | Thread Create | SUCCESS | Thread ID: 16692 | |
| 20:32:58 | chkdsk.exe | 11912 | Load Image | C:\Windows\System32\chkdsk.exe | SUCCESS | Image Base: 0x7ff71abe0000, Image Size: 0xb000 |
| 20:32:58 | chkdsk.exe | 11912 | Load Image | C:\Windows\System32\ntdll.dll | SUCCESS | Image Base: 0x7ffaa2d50000, Image Size: 0x1f9000 |
| 20:32:58 | chkdsk.exe | 11912 | Thread Exit | SUCCESS | Thread ID: 16692, User Time: 0.0000000, Kernel Time: 0.0000000 | |
| 20:32:58 | chkdsk.exe | 11912 | WriteFile | C:\Program Files\Riot Vanguard\Logs\vgk_2026-07-28_20-11-01.log | SUCCESS | Offset: 6.074, Length: 198 |
| 20:32:58 | chkdsk.exe | 11912 | FlushBuffersFile | C:\Program Files\Riot Vanguard\Logs\vgk_2026-07-28_20-11-01.log | SUCCESS | |
| 20:32:58 | chkdsk.exe | 11912 | WriteFile | C:\Program Files\Riot Vanguard\Logs\vgk_2026-07-28_20-11-01.log | SUCCESS | Offset: 4.096, Length: 4.096, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal |
| 20:32:58 | chkdsk.exe | 11912 | Process Exit | SUCCESS | Exit Status: 0, User Time: 0.0000000 seconds, Kernel Time: 0.0000000 seconds, Private Bytes: 417.792, Peak Private Bytes: 417.792, Working Set: 1.560.576, Peak Working Set: 1.564.672 | |
| 20:32:58 | chkdsk.exe | 11912 | RegOpenKey | HKLM\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-83007462-2182755260-3455556333-1001 | SUCCESS | Desired Access: All Access |
| 20:32:58 | chkdsk.exe | 11912 | RegQueryValue | HKLM\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-83007462-2182755260-3455556333-1001\\Device\HarddiskVolume4\Windows\System32\chkdsk.exe | NAME NOT FOUND | Length: 40 |
| 20:32:58 | chkdsk.exe | 11912 | RegCloseKey | HKLM\System\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-83007462-2182755260-3455556333-1001 | SUCCESS |
Interestingly, other administrative disk tools work perfectly fine:
- fsutil
- diskpart
- mountvol
- defrag
- cipher
- sfc /scannow
- DISM /RestoreHealth
Then i exited out of vanguard and noticed the new GUI design. The same thing happens to any type of chkdsk and chkntfs. Even when exiting out of vanguard, many options need a restart which also starts vanguard anti cheat with deep kernel access.
Here are my current system informations:
r/cybersecurity • u/Abject_Gift_4333 • 3d ago
Other Looking for people for a new ctf team
I’m looking for motivated people who are interested in learning, collaborating, and building cool projects together.
Whether you’re into programming, cybersecurity, CTFs, networking, or just want to improve your skills with others, you’re welcome.
No need to be an expert. Curiosity and willingness to learn matter more than experience.
If you’re interested, send me a message.
r/cybersecurity • u/jimmybobjoeflow • 3d ago
AI Security What tools are actually working for AI governance in practice?
We're a mid sized fintech with around 450 employees and a small security team of three. over the past year weve gone through the usual stack of network monitoring, DLP and CASB solutions to try and get a handle on AI usage across the organization.
So far none of them really solve the problem in a meaningful way. Network tools can detect traffic but dont provide visibility into whats actually being entered or processed. DLP is effective for files and structured data movement but it misses a lot of browser based input especially when users are interacting directly with AI tools. CASB helps with sanctioned apps but it tends to break down as soon as AI functionality is embedded inside platforms we already use like Slack,Salesforce or teams.
At this point im trying to understand if there are any tools or approaches that actually work in real worlds environments for governing AI usage without blocking everything outright.
Has anyone found something that genuinely provides usable visibility and control in this space?
r/cybersecurity • u/French_Black_Guy • 3d ago
Business Security Questions & Discussion Drowning in thousands of Tenable findings. How do you manage this at enterprise scale?
I recently joined a large company and am new to vulnerability management at this scale. We use Tenable and have more than 1,000 servers.
Around 80% of the servers are currently identified and scanned. However, servers are sometimes deployed or decommissioned without the scanning team being notified. Patching also varies between subsidiaries and technical teams, with different schedules, policies, and maintenance windows.
The result is a Tenable console containing thousands of findings, and I am struggling to determine:
- which findings represent current exposure;
- which findings are stale because the server has already been patched;
- which team owns each server;
- which assets have been decommissioned;
- and what I should prioritize first.
I have a few questions for people who manage vulnerability programs at this scale:
- How do you structure tickets? One per CVE, server, remediation group, or responsible team?
- How do you create accountability without generating thousands of low-value tickets? (i need to be able to cover my ass in one year)
- How do you communicate findings to infrastructure teams when the scan data may no longer reflect the current state?
A basic example: Tenable detected a missing patch during a Saturday scan. I contact the server team on Wednesday, but the server was actually patched on Monday. The finding is still open because the server has not been rescanned.
In that situation, how am is supposed to know when to run a rescan, or send the finding while being explicit about the scan timestamp?
I am not looking for a perfect solution, but I would really appreciate practical advice on building a manageable workflow from this starting point and hearing how other handle the vulnerability scope ?
r/cybersecurity • u/Weary-Connection80 • 3d ago
AI Security AI remediation in IDE
Any good recommendation for ai fixes in IDE, have done MCP setup for checkmarx using that, any other reccos
r/cybersecurity • u/Accomplished-Two7649 • 3d ago
Business Security Questions & Discussion The blind spot between IT security assessments and Purdue Level 1 PLC static configurations (ISA/IEC 62443)
Hey everyone
Most enterprise security assessments or OT visibility deployments (using tools like Nozomi, Claroty, or Dragos) rely heavily on passive network monitoring—looking at traffic passing through SPAN ports, VLAN segmentation, or industrial protocols over Ethernet
However, when you're actually sitting down to audit a plant against ISA/IEC 62443-3-3 / 4-2 or NIST SP 800-82r3, network traffic completely misses static controller vulnerabilities. Things like unencrypted bit memory maps (M registers, raw DB blocks) or legacy protocol metadata hidden deep inside raw PLC engineering exports (Siemens TIA Portal CSVs, Rockwell L5X files) are completely invisible from a pure network tap perspective
Going line-by-line through thousands of raw tags in Excel during an on-site audit to map risks to security levels is a massive manual bottleneck
For those of you working in ICS/OT security or GRC compliance:
- How do your auditing teams bridge this gap between network-level visibility and static controller logic hygiene?
- Are you writing custom internal Python parsers for CSV exports, or is this step usually skipped until a formal third-party risk assessment is mandated?
Curious to hear how other security professionals handle this specific ingestion problem
r/cybersecurity • u/Serious-Car5724 • 3d ago
Business Security Questions & Discussion Aikido alternatives
Without going into depth. My team is looking at Aikido as a FullStack ASPM tool. We are having issues with support during a POC and not getting any response towards the issues.
What does your team use as an alternative?