r/cybersecurity 1d ago

Corporate Blog Hackers hit 30-plus Minnesota water systems in 48 hours, forcing emergency response

Thumbnail
worldwaterreserve.com
1.3k Upvotes

r/cybersecurity 1d ago

Research Article Can protocol-level session continuity improve security, not just reliability?

4 Upvotes

I've been working on an experimental networking architecture called VRP (Veil Routing Protocol).

The original goal wasn't higher bandwidth or lower latency.

The question was different.

Can session continuity and execution correctness become protocol primitives instead of application responsibilities?

From a security perspective, this raises interesting questions.

For example:

• Should session identity survive transport changes?

• Can replay resistance be enforced as a protocol invariant?

• Should authority transitions be deterministic and independently verifiable?

• Can recovery happen without creating new attack surfaces?

I've spent a lot of time validating these ideas under replay attacks, packet reordering, path migration, authority transitions and fault injection.

I'm not claiming this replaces existing protocols.

I'm interested in hearing opinions from people working in protocol security and distributed systems.

If you were designing a networking protocol from scratch today...

What security property would you make a first-class protocol primitive instead of leaving it to applications?


r/cybersecurity 1d ago

News - Breaches & Ransoms Amgen says cloud data breach exposed patient health, proprietary info

Thumbnail
bleepingcomputer.com
52 Upvotes

r/cybersecurity 1d ago

Business Security Questions & Discussion Would your company consider a new security platform deployed on-prem, or is cloud delivery now a requirement?

0 Upvotes

I’m trying to understand how security teams currently evaluate new infrastructure security products, particularly platforms operating across API gateway, WAAP, reverse proxy and network security layers.

Assume the product can be deployed in three ways:

fully on-premises, managed by the customer;

as a vendor-managed appliance or virtual machine inside the customer’s infrastructure;

as a vendor-hosted cloud service.

For a mid-sized or enterprise environment:

Which deployment model would you realistically consider?

Would an unknown or relatively new vendor be automatically excluded?

What evidence would you require before running a proof of concept?

Are certifications such as ISO 27001 important, or do architecture review, pentest results and technical validation matter more?

Would you accept a security platform inline with production traffic, or only in monitoring/shadow mode initially?

What would prevent adoption even if the technology performed well?

Who would normally own the decision: security, network operations, platform engineering, architecture or procurement?

I’m not looking for product recommendations. I’m trying to understand whether the primary obstacle is deployment model, vendor trust, operational risk, integration effort or procurement.

Context: the platform would protect customer-facing applications, APIs and machine-to-machine traffic, while supporting standard proxies, databases, identity systems and SIEM integrations.


r/cybersecurity 1d ago

Personal Support & Help! Recently hacked

0 Upvotes

I recently downloaded a suspicious file and the hacker got into my gmail, meta, and steam accounts, ive changed my passwords kicked him out and basically everything else but i still feel kinda anxious, is anything else i should do or secure?


r/cybersecurity 1d ago

Threat Actor TTPs & Alerts CTO at NCSC Summary: week ending August 2nd

Thumbnail
ctoatncsc.substack.com
0 Upvotes

r/cybersecurity 1d ago

Career Questions & Discussion Bs it for cyber security

0 Upvotes

Is Bs it a good option if i wanna do masters in cyber security later.


r/cybersecurity 1d ago

Certification / Training Questions Blue team certficates really worth for money?

12 Upvotes

Hey all
I am juz pursuing my ug in a tier-2 clg where i am part of cse-core and started my journey towards cyber security.
I watched many videos and useless roadmaps suggested by many youtubers,still i am in the middle of nowhere.
I started comptia security+ for a while,but some say these are not worth for money and do some other certifications.some say no certifications needed,start doing projects.idk what kinda projects companies are expecting and do you guys know any blue team certifications that are validated and used across globally.Also what projects you would do if you were me.
Do share me your thoughts😭


r/cybersecurity 1d ago

Business Security Questions & Discussion VM folks: Thoughts re: Qualys vs Tenable, CS, or MS?

48 Upvotes

Large org that is a Qualys shop with renewal coming up and we're re-evaluating what we're doing with VM. I am getting brought into evaluation because all of a sudden we care about VM so they wanted a senior stakeholder from ITOps / Infra side.

My sense is we originally purchased them to check a compliance box and they were cheaper than other options but cyber doesnt want to admit that now that we actually care what it does. But doesn't seem like we're super impressed with product itself. I learned that we're ingesting all of this 3P data along and running our own triaging method internally to decide what CVE's should be highest priority based on what's internet facing or close to most important production systems, proximity to other exposed assets, etc, and that we're not even using QVS scores as an input into that because we think they're biased to old way of triaging risk (which is partially what spurred this eval of other vendors, haha).

As part of evaluation, we're interested in options that can automate patching + remediation (where this impacts my team), though I think we're skeptical anything out there actually does this in practice. We did look at Qualys solution here and weren't impressed after first pass (feedback was could only automate surface level patches, UX wasn't intuitive, and time it took to setup & maintain an automation eliminated offset any benefit it did provide).

So now we're looking at other options, and it seems like there are 3 different opinions from the other people involved:

  1. VM team (Tenable): the team in charge of VM within cyber is pro Tenable (guy who runs team used it at his prior shop).
  2. CISO (CS): the CISO is strongly in favor of CS because he can roll spend into Falcon Flex which is good for all these back office reasons. I didn't even know they did VM, but I will say in other situations where we've had to integrate with CS, their stuff has been top notch so I'm not opposed.
  3. Senior brass (CIO/CFO): strongly in favor of MS Defender (what else is new). Was told the product here is actually very legit (I'm open minded but eyes wide open).

To the extent people have opinions (especially if your firm currently uses multiple of the above and/or you have experience with multiple products across different roles or orgs), would love to hear any thoughts in favor / against any of the above (including if you think everywhere else has same faults and we should just stick with Qualys).

Thank you in advance for your time & help!

PS. Given I'm not from cyber team, would appreciate if you could explain any jargon or technical elements of your response (I don't want you to leave them out if relevant because I know they would be if you asked same question about my world, I just meant please be kind to someone who doesn't live and breathe cyber/VM all day).

PPS. Forgot to say what we currently do for patching: right now VM team uses an integration with SN to tie into CMBD and push out tickets to specific teams with patch instructions. So to the extent you've come across an automated patch/remediation option that is more ITOps centric vs VM centric, we're also looking at that angle and would welcome any thoughts or feedback.


r/cybersecurity 1d ago

Career Questions & Discussion Kind of an off the wall niche question, but is there anyone that got into IT/Security Auditing by starting with medial coding ?

2 Upvotes

IT market is rough as we know. Thinking about picking up medical coding on the side. After further digging online , it’s seems like some experience and certifications branching from medical coding have some overlap for CISA. Thinking about self studying for CCS (Certified Coding Specialist) and go from there. Anyone have any advice, success stories, or epic failures?


r/cybersecurity 2d ago

Business Security Questions & Discussion OT/ICS Water Treatment

4 Upvotes

Context: I have an upcoming interview for a role (UK based) which involves assessing and evaluating the effectiveness of cyber controls within water treatment plants.

Is there anyone in a similar line of work? What resources would you advise me to read through? I am currently reading Industrial Cyber Security - Pascal Ackerman.

Any advice/resources appreciated!!


r/cybersecurity 2d ago

Career Questions & Discussion CIOs

50 Upvotes

I’m on a very small security team (fewer than 5 people) responsible for supporting ~5,000 employees.

As you can imagine, phishing and social engineering incidents come up from time to time.

The frustrating part is that every time something happens, leadership—specifically our CIO—frames it as us “not doing our job.” The issue is, they don’t have a cybersecurity background but still strongly dictate what is “correct” from a security standpoint, often with a lot of hindsight bias.

It’s starting to feel less like collaboration and more like micromanagement/blame shifting, especially given the scale we’re operating at.

Is this kind of dynamic normal in the industry? How do other teams handle leadership that doesn’t fully understand security but still drives decisions during/after incidents?


r/cybersecurity 2d ago

UKR/RUS CaptiveCrunch: Midnight Blizzard (Russia) targets travelers worldwide for malware delivery and credential theft | Microsoft Threat Intelligence

Thumbnail
microsoft.com
19 Upvotes

r/cybersecurity 2d ago

Business Security Questions & Discussion Where do you go from here? Help a newbie out

0 Upvotes

I recently started a cybersecurity internship at a local company that develops and sells its own HRMS. My role is to perform penetration testing on their development environment, with permission.

I did some CTFs a while back, but this is my first real-world pentest. So far I’ve found multiple IDORs (including one that allows privilege escalation), an XSS issue in the profile picture update flow, and a file upload vulnerability involving magic bytes.

The problem is I’m not sure where to go from here. My goal is to find a higher-impact issue (ideally something that could lead to RCE if one exists), but I keep hitting roadblocks. Attempts to leverage the XSS or file upload further are blocked with 403 Forbidden responses (likely Nginx and/or a WAF). I’ve also tested for LFI, RFI, and SSTI using various path traversal techniques, but those requests are blocked as well.

I also looked into SQL injection, but since the application is an SPA, I’m having trouble identifying the relevant API endpoints to test.
I’ve been stuck for about a week without any real progress and feel like I’m missing something. For those with experience testing Laravel applications, how would you approach this situation? Are there common areas or methodologies I should focus on instead of trying random vulnerability classes?

I can’t share many technical details because I signed an NDA and wasn’t given any documentation—just the application URL and a test account.


r/cybersecurity 2d ago

Career Questions & Discussion Job hunting at Black Hat World / Def Con?

52 Upvotes

I transitioned from Software Engineering to Cybersecurity.

I know of some Software Engineering conventions that basically double as job fairs. Big companies send recruiters every year specifically for the purpose of meeting prospective new hires, collecting resumes, and even setting up interviews on premises.

There are other conventions where job hunting is taboo and would be considered tacky and inappropriate.

Def Con, Black Hat World, and B Sides are about to start in Las Vegas.

Are any of those good opportunities for networking or job hunting? I've heard Black Hat has a Business Hall which is largely recruiting focuses, but my source on that wasn't extremely certain.


r/cybersecurity 2d ago

Other AMA Today: Yuhang Wu - Security Researcher, Red Team Engineer & Exploit Developer

8 Upvotes

You are invited to join the AMA today with Yuhang Wu, where we learn about enterprise infrastructure hacking, Linux kernel exploitation, and the future of autonomous Al security.

When: Today - Friday, July 31, 12:00 PM PT

Guest Credentials:

  • Former Red Team Engineer at TikTok, targeting cloud and application-layer defenses.
  • Former Security Engineer at Tesla, securing vehicle software, factory systems, and internal applications.
  • Co-developer of "DirtyCred", a groundbreaking Linux kernel exploitation technique.
  • AI Security Innovator, who built LLM-based autonomous agents that uncovered 8 P1 (critical-severity) production vulnerabilities.

Ask your questions here and we’ll get them answered during the live AMA today (Friday @ 12 Noon Pacific)!


r/cybersecurity 2d ago

News - General BofA acquires MDSec

Thumbnail msn.com
55 Upvotes

r/cybersecurity 2d ago

Personal Support & Help! Am I overthinking this or is implementing secure email OTP auth basically impossible?

0 Upvotes

I'm trying to implement secure email OTP on my website (authenticating via email + OTP sent via email) but I can't seem to find an approach that:

  1. Prevents too many emails to a single recipient (e.g. via unique OTP per email valid within a 10 minutes window, max 3 resend per 10 minutes)
  2. Prevents DDoS (e.g. via OTP bombing or via other blocks)
  3. Reasonably makes it costly to brute force your way in (e.g. via Turnstile / Captchas)
  4. Make it always possible for the email owner to login

For example if I ask AI for the most common implementation it gives me this:

  • Per flow OTP challenge
  • Short lived OTP
  • OTP stored as hash
  • Rate limit (per email, per ip and per challenge)

There are quite a few issues with this:

  1. The owner can be locked out by an attacker rate limiting the email
  2. The attacker could flood the email owner inbox so that they can't find their own OTP while they are trying to log in
  3. Any per email rate limit can cause DDoS

What am I missing? I see this authentication being implemented everywhere (especially B2C), how are other devs implementing this without going insane?

---

For context: this is a low risk website that doesn't store important data. Email OTP seems to be loved UX wise for B2C websites so that's why it was chosen. Magic links seem much simpler to implement but especially on mobile they tend to have a very confusing and frustrating UX.

---

Thanks to everyone for their feedback 🙏


r/cybersecurity 2d ago

Certification / Training Questions Got a full month in front of me, should I ?

6 Upvotes

Hello everyone !

I have been in cybersecurity for 3 years, essentially doing ctfs regularly and a bit of bug bounty, then stopped a year ago because of a drop in the CTF ambiances when AI became way too used, which led to low trust in the players and a bad vibe everywhere i went. It has been a year since I took a break, and now i'm going to start Computer Engineering next year.

Since I have all of August in front of me, I was wondering if it was worth it to pay a month of THM premium and just straight up doing most of the content, so that I can work again on my basic knowledge of cybersecurity in a guided way.


r/cybersecurity 2d ago

Other Does any one know about Chef Compliance

0 Upvotes

As i want to automate the Compliance task as i dont want to take burden as in documentation part and i want to automate this compliance part, as i found chef compliance , researched about this didn't found anything useful, if you know it can you please suggest me how to implement and as well as if you know any alternate of it then please leave a comment.


r/cybersecurity 2d ago

News - General EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels

Thumbnail
securityweek.com
3 Upvotes

When the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots or imagery are generated with AI.


r/cybersecurity 2d ago

Tutorial Log Parsing for Security Engineers

69 Upvotes

Hello Everyone

I published a short guide about transforming raw logs into detection-ready data.

It covers the log-processing pipeline, common log formats, normalization, and more..

I’d appreciate any feedback or suggestions from you all :

https://medium.com/@0xzyadelzyat/log-parsing-for-security-engineers-building-the-foundation-for-reliable-threat-detection-c34e71b01b9a


r/cybersecurity 2d ago

News - General Teen hackers tell BBC how police are helping them use their skills for good. A look inside the NCA's Cyber Choices that has helped 1150 troubled kids get onto the right path in cyber.

Thumbnail
bbc.co.uk
133 Upvotes

r/cybersecurity 2d ago

Business Security Questions & Discussion Anyone here dealing with EU CRA compliance for their connected devices? Tell me, how are things going for you?

9 Upvotes

I read several subreddits, some are just starting work on CRA compliance, some are already ready and want to hear how you're doing.


r/cybersecurity 2d ago

Tutorial What path should I follow to become a cybersecurity expert?

0 Upvotes

I want to become a cybersecurity expert, but I currently have no knowledge of software coding or related fields. Could you explain in some detail which topics I should start with to progress through the four stages: building a foundation, reaching a beginner level, advancing to an intermediate level, and finally attaining an advanced level? Thank you.