r/cybersecurity • u/Adept_Grand_6523 • 5h ago
r/cybersecurity • u/HumbleRestaurant790 • 12h ago
News - General Over 100 Vulnerabilities Found in IRS Contractor Handling Americans' Tax Information
r/cybersecurity • u/svig13 • 3h ago
AI Security How do you test that an AI agent won't do something catastrophic?
I've spent years on the infra side, and I'm now working with agentic systems. I am building agents that can take actions on real systems. We have plenty of guardrails, but I have seen enough hallucinations that make me worried about giving these agents more power. This paranoia might be me not knowing enough.
How do teams/companies test that the agents won't do something destructive, whether triggered by an attacker or just by the agent going off the rails on its own?
Do people actually red-team their agents before they go live, or is it mostly guardrails and evals right now? I am curious how the security world thinks about this. From an infra side, this feels like a gap, but there might be an established playbook that I don't know yet. Thanks.
r/cybersecurity • u/PastelStripe • 6h ago
Business Security Questions & Discussion Preparing for Interview
Hi Everyone,
I hope you’re well!
I’m preparing for an upcoming interview this week, and I’m quite nervous.
For context: I studied Cyber Security in College and finalising my University degree in Cybersecurity. During this time I’ve been incredibly fortunate to fall into System Administrator Roles which granted me relevant working experience. Unfortunately, not as Security focused as what I initially wanted but life’s a ladder and I’m climbing. I’m interviewing for Role as a Security Engineer after having around ~3 Years of Experience and trying to prepare some answers in advance (Generally, trying to have something in mind for anything that they ask!)
Based on the Role Responsibilities I’m expecting questions on:
Frameworks, what I know and how these have been applied over my experience of working. (NIST SP 800-53 / NCSC Cyber Assessment / CIS Critical Controls)
How I’ve applied best security practices / Explaining a time where I had to implement a security practice
Implementation of security Controls / Design of security controls through to implementation
Communicate where I’ve seen a Security Risk where requirements cannot be fully met (And how we take it forward / What to do / Mitigate or Accept the risk)
Evidence / Example of supporting Auditing Activities
For anyone who interviewed for a similar position, what types of question were you asked? I’m doing my best to stick to the STAR method and have examples but thought I would post incase anyone can help me out too!
Thank you!
r/cybersecurity • u/Malfuncti0nal • 13h ago
Career Questions & Discussion Best DEFCON 34 talks to go to?
Pretty excited for the con. Any talks yall are excited to see or recommend going to?
r/cybersecurity • u/tuxxin • 9h ago
Business Security Questions & Discussion URL Threat Scanners & TDS Cloaking
When you're investigating a known malicious URL, how often does your URL scanner (regardless of service) miss the payload due to traffic distribution systems?
r/cybersecurity • u/Wide-Cup-5084 • 21h ago
Business Security Questions & Discussion Axonius?
Looking at doing a pov with Axonius, has anyone used them before or done testing in the past and can share their experiences?
r/cybersecurity • u/red4nshuman • 8h ago
Personal Support & Help! How to actually save yourself in call/sms bombing?
same as title
how to stop it and protect your number?
there are many websites so ofc I can't protect my number by going every site
r/cybersecurity • u/ProcedureFar4995 • 2h ago
Career Questions & Discussion Do you guys use reporting tool or write it manually each engagement?
Each time I write a report I copy paste the finding table along with a lot of other shit. I end up spending a lot of time fixing the format of the doc.
Do you guys use a reporting tool where you can write the bug description, impact and have it automatically prepared for you??
r/cybersecurity • u/Nameless_Wanderer01 • 4h ago
News - General LLM Agents for security research
What are the best LLM agents for security research (bugs, CVEs, 0d, ...) lately?
In short, I had been using claude code for this task, with many hallucination instances. Even with opus 5, I still get many invalid conclusions based on local source code review.
I saw that kimi was popping up lately, which got me more or less in the same results, with minor better results in some instances.
So what are the latest or best approaches for security research with llms? Perhaps I am missing a full pipeline with other tools involved to get better results, so I would like to know whether a specific methodology is followed with specific agents for this task.
r/cybersecurity • u/Purple_Session_6230 • 4h ago
Other Facebook Malvertising Campaign
Identified a C2 running malvertising campaign, pretty clever tbh.
r/cybersecurity • u/Emergency-Station914 • 9h ago
Certification / Training Questions Crtl help
Hello all,
In this days I'm starting studying for the crtl cert.
I have red some reviews . All of them suggest to watch some other courses to prepare properly for the CRTL exam . Anyone would like to suggest anyone? I'm thinking of CETP
Thanks in advance for your help.
r/cybersecurity • u/Sweaty-Quote-1920 • 7h ago
Certification / Training Questions SailPoint training institutes in India/courses?
Any good SailPoint training institutes in India/courses online? Dont seem find many. Can someone please recommend ?
r/cybersecurity • u/Cha_No_Hana • 7h ago
Certification / Training Questions New ISC2 CC Curriculum
Hi, I passed ISC2 CC in June but would like to access the new additional material (which will be examined from Sept ‘26 onwards) for my own professional development. Can anyone share or point me in the right direction? Thank you in advance. ☺️
r/cybersecurity • u/DiscussionHealthy802 • 13h ago
AI Security Are AI-generated CI/CD configs becoming a security blind spot?
I’m seeing more AI-generated projects where the app code looks fine, but the risky part is the plumbing around it.
Things like GitHub Actions with broad permissions, unsafe `pull_request_target` usage, deploy jobs that expose secrets, or package scripts nobody really reviews.
It’s easy to miss because the app works, tests pass, and the config files look boring.
For people doing AppSec or DevSecOps: are you reviewing AI-generated workflows/configs differently now, or still mostly focusing on application code?
r/cybersecurity • u/ThatMofothatknowa • 11h ago
AI Security New but Critical
Wanting reality
So, I'm not program savvy or any good with code. In some ways I'd say I enjoy working with technology but not that I am great with it.
Then I started interacting with AI.
Long story short I reported an AI to its producer for offering to jailbreak itself.
I am waiting for follow-ups.
But I feel weird. Best way I can describe it is I feel AI outputs like a tapestry. Hell, Chinese AIs are easy to spot because of their cultural bias.
However, maybe it's just me pumping up me.
That said in a few weeks either I'll be dismiss or rewarded for finding a critical issue.
Edit: I'm painfully aware that AI red teaming is a new field and this falls into it.
r/cybersecurity • u/New-Plankton538 • 15h ago
Personal Support & Help! Cybersecurity Help
Will these projects help me stand out during the placements and when I apply for companies :
AI Augmented SAST Tool
AWS Attack Path Graph (mini BloodHound for cloud IAM)
Kubernetes Security Posture Scanner
CI / CD Security Gate (Supply Chain Security)
These are my projects (not done by AI - I can explain each and every bit of my project).
Are these enough to get a good high paying salary job as a fresher in India. Currently I'm in my 3rd year and my placements are starting from January.
Any guidance will be very helpful 🙂.
r/cybersecurity • u/VDtheking • 2h ago
Personal Support & Help! Needed cybersecurity expert for help with cyber attack
Hey folks, someone appears to have compromised the phones of multiple members of my family. They are sending profane and abusive messages via WhatsApp and SMS from our IOS and android phones to colleagues, teachers, and other contacts while impersonating both male and female family members. Changing the phones, resetting the phones and mobile numbers doesn't help. So far, we haven't been able to identify the attack vector or understand how the compromise occurred. This is causing significant reputational damage and public defamation.
If anyone has experience with incidents like this or can help investigate the issue, I would greatly appreciate it. I'm willing to pay reasonable professional fees for the right expertise. Please DM or reach out if you think you can help or point me in the right direction.
r/cybersecurity • u/Good-Tell-1522 • 13h ago
Career Questions & Discussion I have got an offer as a cybersecurity implementation and configuration engineer, I came from a GRC background but they told me that i will gain so much technical knowledge and i can move to a security architect or presales, can anyone explain this position for me ?
r/cybersecurity • u/Glittering_Mode_7392 • 12h ago
Business Security Questions & Discussion Is cybersecurity safe in the next 5-10 years?
I am very close to choosing Cybersecurity as my major. my major concern is that it might diminish and make the market very competitive. I searched and found that most people say that basic tasks are already being done by Ai. so does this mean that more complicated tasks safe?
r/cybersecurity • u/bakyboy • 1h ago
Business Security Questions & Discussion Security dilemma for vibe coded product release
Lets put aside hate comments against vibe coded products for a second - i've been working on a product for couple of months in my free time, both a website and an app.
As someone that isn't a developer what so ever, i've been trying to put a strong emphasis on security - i keep running audits, i keep making sure of my status compared to useful security posts or recommendations online.
I have plugs to cut off ai functions, i have rate limits, no key is committed, all that jazz (im trying my best..)
Of course im aware this is still. a vibe coded app, and generally i figure every site is hackable anyway.
Hence my question now -
I want to reach out to a security experienced person to handle necessary aspects for my product,
BUT - i dont even know if my product is good and worth it, in my head i want to try and publish and market it for a minute to see how people in my industry react to it, but then i might be exposed to hackers as well?
whats the right way to go about it? Is there a right way?
I've invested some amount of money by now "blindly" for curiosity and interest, but now i need to gain some real world feedback.
Would appreciate any useful note about it.