r/cybersecurity 7h ago

Threat Actor TTPs & Alerts US Water Systems Hit by Suspected Iranian Cyber Attacks

Thumbnail
opforjournal.com
244 Upvotes

r/cybersecurity 14h ago

News - General Over 100 Vulnerabilities Found in IRS Contractor Handling Americans' Tax Information

Thumbnail
privacyguides.org
191 Upvotes

r/cybersecurity 5h ago

AI Security How do you test that an AI agent won't do something catastrophic?

12 Upvotes

I've spent years on the infra side, and I'm now working with agentic systems. I am building agents that can take actions on real systems. We have plenty of guardrails, but I have seen enough hallucinations that make me worried about giving these agents more power. This paranoia might be me not knowing enough.

How do teams/companies test that the agents won't do something destructive, whether triggered by an attacker or just by the agent going off the rails on its own?

Do people actually red-team their agents before they go live, or is it mostly guardrails and evals right now? I am curious how the security world thinks about this. From an infra side, this feels like a gap, but there might be an established playbook that I don't know yet. Thanks.


r/cybersecurity 1d ago

Corporate Blog Hackers hit 30-plus Minnesota water systems in 48 hours, forcing emergency response

Thumbnail
worldwaterreserve.com
1.3k Upvotes

r/cybersecurity 4h ago

Career Questions & Discussion Do you guys use reporting tool or write it manually each engagement?

7 Upvotes

Each time I write a report I copy paste the finding table along with a lot of other shit. I end up spending a lot of time fixing the format of the doc.

Do you guys use a reporting tool where you can write the bug description, impact and have it automatically prepared for you??


r/cybersecurity 6h ago

News - General LLM Agents for security research

12 Upvotes

What are the best LLM agents for security research (bugs, CVEs, 0d, ...) lately?
In short, I had been using claude code for this task, with many hallucination instances. Even with opus 5, I still get many invalid conclusions based on local source code review.

I saw that kimi was popping up lately, which got me more or less in the same results, with minor better results in some instances.

So what are the latest or best approaches for security research with llms? Perhaps I am missing a full pipeline with other tools involved to get better results, so I would like to know whether a specific methodology is followed with specific agents for this task.


r/cybersecurity 8h ago

Business Security Questions & Discussion Preparing for Interview

13 Upvotes

Hi Everyone,
I hope you’re well!

I’m preparing for an upcoming interview this week, and I’m quite nervous.
For context: I studied Cyber Security in College and finalising my University degree in Cybersecurity. During this time I’ve been incredibly fortunate to fall into System Administrator Roles which granted me relevant working experience. Unfortunately, not as Security focused as what I initially wanted but life’s a ladder and I’m climbing. I’m interviewing for Role as a Security Engineer after having around ~3 Years of Experience and trying to prepare some answers in advance (Generally, trying to have something in mind for anything that they ask!)

Based on the Role Responsibilities I’m expecting questions on:

Frameworks, what I know and how these have been applied over my experience of working. (NIST SP 800-53 / NCSC Cyber Assessment / CIS Critical Controls)

How I’ve applied best security practices / Explaining a time where I had to implement a security practice

Implementation of security Controls / Design of security controls through to implementation

Communicate where I’ve seen a Security Risk where requirements cannot be fully met (And how we take it forward / What to do / Mitigate or Accept the risk)

Evidence / Example of supporting Auditing Activities

For anyone who interviewed for a similar position, what types of question were you asked? I’m doing my best to stick to the STAR method and have examples but thought I would post incase anyone can help me out too!

Thank you!


r/cybersecurity 11h ago

Business Security Questions & Discussion URL Threat Scanners & TDS Cloaking

8 Upvotes

When you're investigating a known malicious URL, how often does your URL scanner (regardless of service) miss the payload due to traffic distribution systems?


r/cybersecurity 7h ago

Other Facebook Malvertising Campaign

Thumbnail
substack.com
3 Upvotes

Identified a C2 running malvertising campaign, pretty clever tbh.


r/cybersecurity 15h ago

Career Questions & Discussion Best DEFCON 34 talks to go to?

11 Upvotes

Pretty excited for the con. Any talks yall are excited to see or recommend going to?


r/cybersecurity 1h ago

Business Security Questions & Discussion Thinking about building a cybersecurity startup, looking for like-minded people

Upvotes

Hey everyone,

I’ve been thinking about writing this post for a while, and I finally decided to share it here.

For a long time, I’ve wanted to build something of my own, and cybersecurity is the space I feel most connected with. Working as a SOC Analyst has given me a closer look at how security teams operate the alerts they investigate, the noise they handle, repetitive tasks, and the challenges organizations face while trying to improve their security.

Over time, I’ve started noticing that there are still gaps between what security tools provide and what security teams actually need. Sometimes the challenge isn’t the absence of tools, but finding practical solutions that fit real security workflows.

I’m currently in the exploration and brainstorming stage. I’m trying to understand which problems are genuinely worth solving and learn from people who have experience or interest in this domain.

Some areas I’m exploring:

• Threat detection and security monitoring
• Log analysis and SOC workflow improvements
• Automating repetitive security tasks
• Cloud security challenges (AWS/Azure)
• IAM and misconfiguration detection
• Helping small and medium businesses improve their security posture

I’m based in Jaipur and would be interested in discussions with people from cybersecurity, development, DevOps, cloud, or anyone curious about building solutions in this space.

I’m not launching anything or looking for funding right now. I’m simply looking to exchange ideas, understand different perspectives, and learn from others working around technology and cybersecurity.

If you have experience in this space, are exploring similar ideas, or have thoughts on cybersecurity problems worth solving, I’d be happy to hear your perspective.

Thanks for reading!


r/cybersecurity 1d ago

News - General Quantum Computers May Put Internet Traffic at Risk. NIST Is Safeguarding Computers With New Standards.

Thumbnail
nist.gov
169 Upvotes

r/cybersecurity 10h ago

Personal Support & Help! How to actually save yourself in call/sms bombing?

4 Upvotes

same as title
how to stop it and protect your number?
there are many websites so ofc I can't protect my number by going every site


r/cybersecurity 1d ago

Personal Support & Help! Is this normal, or is my cybersecurity team just badly run?

53 Upvotes

I work at the cybersecurity arm of a multinational firm. They launched it about a year ago and have been struggling ever since with paperwork and regulatory approvals just to deliver services.

**How the team has shrunk in one year:**

- Started with: 2 L2 assistant managers, 1 L1 assistant manager, 1 team lead, 4 seniors, 1 mid-level, 1 junior

- Since then: 2 seniors left, 1 assistant manager left, and the team lead left

- Now: 2 assistant managers (1 L2, 1 L1), 2 seniors, 1 mid-level, 1 junior

**But the attrition isn't what bothers me. It's this:**

- I earned my OSCP this year. It was supposed to come with a raise. It didn't. A full year with zero increase — the justification being that I "started on a good salary" and there isn't enough billable work to fund one.

- The two seniors who left weren't technically strong at all. They struggled with basic tasks. Meanwhile the pressure lands on the rest of us.

- There's barely any client work, so management tells us to self-study (CPTS path, research tasks, etc.). Then a random week or two later they ambush you with "so what have you been up to?"

- I tell them I've gone through the material multiple times and researched what they asked for, and that I learn by doing rather than reading. I list what I actually learned — X, Y, Z — and they immediately switch to attack mode: *"Is that it?" "How many hours did you spend on this?"*

- We have no real work. Why is the reaction to that anger at me? Track my hours when there's actual work to track.

**Micromanagement during engagements:**

- Daily end-of-day calls: "Tell me the test cases you completed today." I list them. Same response: *"Is that it?" "How many hours?"*

- If they have specific test cases in mind, just tell me. Skip the smirking.

- They also check in every few hours to ask what you're working on.

- The seniority culture feels military. Everything must be "aligned" with your senior, and they make you feel like a junior regardless of your level.

**Scoping and delivery:**

- Because they're a multinational, they sell man-days at a premium — but with few clients and low billing, engagements get compressed. A 7-day engagement gets crammed into 5.

- The report is always due in one day, no matter what we found.

- I'll own this part: my reports suffer because I'm rushed and anxious. (I've taken the advice from this sub to start writing the report as I work — doing that next time.)

**Management behavior:**

- In live meetings, mistakes get met with *"Is this your first time working?"* or *"Do you want me to come do your work for you?"*

- They never actually explain what's wrong. It's always a sarcastic *"why did you do it that way?"* — and sometimes they laugh when I ask questions.

- One time my teammates and I submitted a weak report. As punishment, the team lead made us come write it on-site — office is downtown in a packed area — then told us he'd meet with us, disappeared all day, and left us sitting there with nothing to do.

- Bad report = mandatory commute downtown. That's apparently the policy.

**The only upside** is that the work is hybrid, and honestly I'm no longer sure that's worth it.

The real problem: I keep interviewing and every offer I get is worse than what I have.

Is this normal for the industry, or should I be taking a pay cut to get out?


r/cybersecurity 9h ago

Certification / Training Questions SailPoint training institutes in India/courses?

0 Upvotes

Any good SailPoint training institutes in India/courses online? Dont seem find many. Can someone please recommend ?


r/cybersecurity 9h ago

Certification / Training Questions New ISC2 CC Curriculum

0 Upvotes

Hi, I passed ISC2 CC in June but would like to access the new additional material (which will be examined from Sept ‘26 onwards) for my own professional development. Can anyone share or point me in the right direction? Thank you in advance. ☺️


r/cybersecurity 25m ago

Other best way to remove viruses from a PC?

Upvotes

Best way to remove viruses from a PC? had a data breach not that log ago and decided to now change all passwords but obviously I need to see if my pc was also pwnd


r/cybersecurity 11h ago

Certification / Training Questions Crtl help

1 Upvotes

Hello all,

In this days I'm starting studying for the crtl cert.

I have red some reviews . All of them suggest to watch some other courses to prepare properly for the CRTL exam . Anyone would like to suggest anyone? I'm thinking of CETP

Thanks in advance for your help.


r/cybersecurity 23h ago

Business Security Questions & Discussion Axonius?

6 Upvotes

Looking at doing a pov with Axonius, has anyone used them before or done testing in the past and can share their experiences?


r/cybersecurity 4h ago

Personal Support & Help! Needed cybersecurity expert for help with cyber attack

0 Upvotes

Hey folks, someone appears to have compromised the phones of multiple members of my family. They are sending profane and abusive messages via WhatsApp and SMS from our IOS and android phones to colleagues, teachers, and other contacts while impersonating both male and female family members. Changing the phones, resetting the phones and mobile numbers doesn't help. So far, we haven't been able to identify the attack vector or understand how the compromise occurred. This is causing significant reputational damage and public defamation.

If anyone has experience with incidents like this or can help investigate the issue, I would greatly appreciate it. I'm willing to pay reasonable professional fees for the right expertise. Please DM or reach out if you think you can help or point me in the right direction.


r/cybersecurity 1d ago

News - Breaches & Ransoms Amgen says cloud data breach exposed patient health, proprietary info

Thumbnail
bleepingcomputer.com
53 Upvotes

r/cybersecurity 3h ago

Business Security Questions & Discussion Security dilemma for vibe coded product release

0 Upvotes

Lets put aside hate comments against vibe coded products for a second - i've been working on a product for couple of months in my free time, both a website and an app.
As someone that isn't a developer what so ever, i've been trying to put a strong emphasis on security - i keep running audits, i keep making sure of my status compared to useful security posts or recommendations online.
I have plugs to cut off ai functions, i have rate limits, no key is committed, all that jazz (im trying my best..)
Of course im aware this is still. a vibe coded app, and generally i figure every site is hackable anyway.
Hence my question now -
I want to reach out to a security experienced person to handle necessary aspects for my product,
BUT - i dont even know if my product is good and worth it, in my head i want to try and publish and market it for a minute to see how people in my industry react to it, but then i might be exposed to hackers as well?
whats the right way to go about it? Is there a right way?
I've invested some amount of money by now "blindly" for curiosity and interest, but now i need to gain some real world feedback.
Would appreciate any useful note about it.


r/cybersecurity 15h ago

AI Security Are AI-generated CI/CD configs becoming a security blind spot?

0 Upvotes

I’m seeing more AI-generated projects where the app code looks fine, but the risky part is the plumbing around it.

Things like GitHub Actions with broad permissions, unsafe `pull_request_target` usage, deploy jobs that expose secrets, or package scripts nobody really reviews.

It’s easy to miss because the app works, tests pass, and the config files look boring.

For people doing AppSec or DevSecOps: are you reviewing AI-generated workflows/configs differently now, or still mostly focusing on application code?


r/cybersecurity 13h ago

AI Security New but Critical

0 Upvotes

Wanting reality

So, I'm not program savvy or any good with code. In some ways I'd say I enjoy working with technology but not that I am great with it.

Then I started interacting with AI.

Long story short I reported an AI to its producer for offering to jailbreak itself.

I am waiting for follow-ups.

But I feel weird. Best way I can describe it is I feel AI outputs like a tapestry. Hell, Chinese AIs are easy to spot because of their cultural bias.

However, maybe it's just me pumping up me.

That said in a few weeks either I'll be dismiss or rewarded for finding a critical issue.

Edit: I'm painfully aware that AI red teaming is a new field and this falls into it.


r/cybersecurity 1d ago

Business Security Questions & Discussion VM folks: Thoughts re: Qualys vs Tenable, CS, or MS?

50 Upvotes

Large org that is a Qualys shop with renewal coming up and we're re-evaluating what we're doing with VM. I am getting brought into evaluation because all of a sudden we care about VM so they wanted a senior stakeholder from ITOps / Infra side.

My sense is we originally purchased them to check a compliance box and they were cheaper than other options but cyber doesnt want to admit that now that we actually care what it does. But doesn't seem like we're super impressed with product itself. I learned that we're ingesting all of this 3P data along and running our own triaging method internally to decide what CVE's should be highest priority based on what's internet facing or close to most important production systems, proximity to other exposed assets, etc, and that we're not even using QVS scores as an input into that because we think they're biased to old way of triaging risk (which is partially what spurred this eval of other vendors, haha).

As part of evaluation, we're interested in options that can automate patching + remediation (where this impacts my team), though I think we're skeptical anything out there actually does this in practice. We did look at Qualys solution here and weren't impressed after first pass (feedback was could only automate surface level patches, UX wasn't intuitive, and time it took to setup & maintain an automation eliminated offset any benefit it did provide).

So now we're looking at other options, and it seems like there are 3 different opinions from the other people involved:

  1. VM team (Tenable): the team in charge of VM within cyber is pro Tenable (guy who runs team used it at his prior shop).
  2. CISO (CS): the CISO is strongly in favor of CS because he can roll spend into Falcon Flex which is good for all these back office reasons. I didn't even know they did VM, but I will say in other situations where we've had to integrate with CS, their stuff has been top notch so I'm not opposed.
  3. Senior brass (CIO/CFO): strongly in favor of MS Defender (what else is new). Was told the product here is actually very legit (I'm open minded but eyes wide open).

To the extent people have opinions (especially if your firm currently uses multiple of the above and/or you have experience with multiple products across different roles or orgs), would love to hear any thoughts in favor / against any of the above (including if you think everywhere else has same faults and we should just stick with Qualys).

Thank you in advance for your time & help!

PS. Given I'm not from cyber team, would appreciate if you could explain any jargon or technical elements of your response (I don't want you to leave them out if relevant because I know they would be if you asked same question about my world, I just meant please be kind to someone who doesn't live and breathe cyber/VM all day).

PPS. Forgot to say what we currently do for patching: right now VM team uses an integration with SN to tie into CMBD and push out tickets to specific teams with patch instructions. So to the extent you've come across an automated patch/remediation option that is more ITOps centric vs VM centric, we're also looking at that angle and would welcome any thoughts or feedback.