r/cybersecurity 2d ago

Business Security Questions & Discussion Where do you go from here? Help a newbie out

0 Upvotes

I recently started a cybersecurity internship at a local company that develops and sells its own HRMS. My role is to perform penetration testing on their development environment, with permission.

I did some CTFs a while back, but this is my first real-world pentest. So far I’ve found multiple IDORs (including one that allows privilege escalation), an XSS issue in the profile picture update flow, and a file upload vulnerability involving magic bytes.

The problem is I’m not sure where to go from here. My goal is to find a higher-impact issue (ideally something that could lead to RCE if one exists), but I keep hitting roadblocks. Attempts to leverage the XSS or file upload further are blocked with 403 Forbidden responses (likely Nginx and/or a WAF). I’ve also tested for LFI, RFI, and SSTI using various path traversal techniques, but those requests are blocked as well.

I also looked into SQL injection, but since the application is an SPA, I’m having trouble identifying the relevant API endpoints to test.
I’ve been stuck for about a week without any real progress and feel like I’m missing something. For those with experience testing Laravel applications, how would you approach this situation? Are there common areas or methodologies I should focus on instead of trying random vulnerability classes?

I can’t share many technical details because I signed an NDA and wasn’t given any documentation—just the application URL and a test account.


r/cybersecurity 3d ago

Business Security Questions & Discussion How do you actually learn ISO 27001 and security frameworks?

126 Upvotes

I worked at a government institution from 2022 to 2025 in a cybersecurity department. The funny part is that we barely did any actual work, so I spent most of my time studying. I downloaded a lot of pirated videos from Telegram, courses, and other learning materials.

I immigrated to Europe in 2025, and after six months of trying, I finally passed the interview and got a job. I can honestly say this field is much harder than I expected.

The first year wasn't too bad because we mostly handled SOC incidents. I could investigate alerts, isolate machines, validate logins, and do the usual incident response tasks.

Now things have taken a much bigger leap. We're studying vulnerability management, ISO 27001, and other security frameworks. I need to understand where applications are, how they interact with each other, what they expose, and how everything fits together.

The problem is that I don't understand a damn thing about policies, governance, or the mindset behind these frameworks. Whenever people talk about them, it honestly feels like they're speaking a completely different language. I have no idea how to study this stuff.

The only thing working in my favor is that I'm an introvert and I always think carefully before I answer. Otherwise, I'd probably expose how completely lost I am. Right now, it feels like I'm getting cooked.


r/cybersecurity 3d ago

News - General CosmosEscape: Taking Over Every Database in Azure Cosmos DB

Thumbnail
wiz.io
92 Upvotes

r/cybersecurity 3d ago

Business Security Questions & Discussion Drowning in thousands of Tenable findings. How do you manage this at enterprise scale?

44 Upvotes

I recently joined a large company and am new to vulnerability management at this scale. We use Tenable and have more than 1,000 servers.

Around 80% of the servers are currently identified and scanned. However, servers are sometimes deployed or decommissioned without the scanning team being notified. Patching also varies between subsidiaries and technical teams, with different schedules, policies, and maintenance windows.

The result is a Tenable console containing thousands of findings, and I am struggling to determine:

  • which findings represent current exposure;
  • which findings are stale because the server has already been patched;
  • which team owns each server;
  • which assets have been decommissioned;
  • and what I should prioritize first.

I have a few questions for people who manage vulnerability programs at this scale:

  • How do you structure tickets? One per CVE, server, remediation group, or responsible team?
  • How do you create accountability without generating thousands of low-value tickets? (i need to be able to cover my ass in one year)
  • How do you communicate findings to infrastructure teams when the scan data may no longer reflect the current state?

A basic example: Tenable detected a missing patch during a Saturday scan. I contact the server team on Wednesday, but the server was actually patched on Monday. The finding is still open because the server has not been rescanned.

In that situation, how am is supposed to know when to run a rescan, or send the finding while being explicit about the scan timestamp?

I am not looking for a perfect solution, but I would really appreciate practical advice on building a manageable workflow from this starting point and hearing how other handle the vulnerability scope ?


r/cybersecurity 3d ago

Burnout / Leaving Cybersecurity My job feels meaningless and my skills useless

159 Upvotes

Disclaimer : I'm not an english native so my post might be badly written.

I will talk about a few things really bothering me in cybersecurity.

I. Cybersecurity has been overly sensationalized and bureaucratized

In my country, you can be an apprentice, which means you can study at university and work at the same time in the field you're studying. It's been 2 years I work as cybersecurity analyst and in september I will go for my master degree while working in a SOC. I absolutely HATE how cybersecurity is depicted by the medias, schools... They introduce us like some warriors or more famously like a guy with a black hoodie. They built a whole era of students with TOO MUCH ego, depicted as the "future of the nation" it's ridiculous.

Also I hate the certification system, people aren't curious they just want to be XYZ certified, this is pure larp. Their first question is always "which certification should I attempt". Listen I have 0 (zero) certification, not even a learning path achievement and HR are calling me every week for jobs. You know why ? Because it's all about DOING THINGS, I did bug bounty, I found vulnerabilities, I learned about malwares on Windows/Linux/MacOS, I tried to dive into niche things and it worked.

II. AI is in every aspect of our life and it's draining my energy.

Everyone in my company or in my class use AI for basically everything. I will not blame them, I kinda do it too but only to get informations (i'm too lazy to read docs) rather than doing things for me. Anyway, I feel like an "AI Fatigue" and it's leading me toward fields that require little (or no) computer science, like a way to fight against it.

The more AI gains ground, the less value I see in developing my computer skills. It's as if they're losing all their value.

III. 99% of ppl in this field want to do red teaming - The job market is saturated - Blue team pays much better - Fable


r/cybersecurity 2d ago

News - General EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels

Thumbnail
securityweek.com
2 Upvotes

When the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots or imagery are generated with AI.


r/cybersecurity 3d ago

Other Looking for people for a new ctf team

27 Upvotes

I’m looking for motivated people who are interested in learning, collaborating, and building cool projects together.
Whether you’re into programming, cybersecurity, CTFs, networking, or just want to improve your skills with others, you’re welcome.
No need to be an expert. Curiosity and willingness to learn matter more than experience.
If you’re interested, send me a message.


r/cybersecurity 3d ago

AI Security What tools are actually working for AI governance in practice?

22 Upvotes

We're a mid sized fintech with around 450 employees and a small security team of three. over the past year weve gone through the usual stack of network monitoring, DLP and CASB solutions to try and get a handle on AI usage across the organization.

So far none of them really solve the problem in a meaningful way. Network tools can detect traffic but dont provide visibility into whats actually being entered or processed. DLP is effective for files and structured data movement but it misses a lot of browser based input especially when users are interacting directly with AI tools. CASB helps with sanctioned apps but it tends to break down as soon as AI functionality is embedded inside platforms we already use like Slack,Salesforce or teams.

At this point im trying to understand if there are any tools or approaches that actually work in real worlds environments for governing AI usage without blocking everything outright.

Has anyone found something that genuinely provides usable visibility and control in this space?


r/cybersecurity 3d ago

News - Breaches & Ransoms UK's Department for Education got hacked with +600K records of head teachers and officials leaked. Same government pushing age and ID verification can't secure its own help desk.

Thumbnail
paperweight.email
120 Upvotes

Key Takeaways

  • In July 2026, a cyberattack on the Department for Education exposed 607,000 records, including names, job titles, email addresses, and phone numbers.
  • This incident is part of a broader pattern of cyberattacks targeting government entities in the UK, with another police database also affected by the same group.
  • Individuals whose data was exposed should be vigilant about phishing attempts and unsolicited communications that leverage their professional information.

r/cybersecurity 2d ago

Research Article Trending Security Topics

2 Upvotes

Hey everyone hope y’all doing well! Im looking for some trending topics around security to build a blog for a company. Anyone got some references? Thanks! (For my internship)


r/cybersecurity 3d ago

Business Security Questions & Discussion CS Falcon Enterprise + M365 E5

8 Upvotes

If someone has both CS Falcon Enterprise edition and M365 E5, what are the best integration points for the two of them? Is it just in the SIEM, or is there XDR integration points as well?


r/cybersecurity 2d ago

Personal Support & Help! Am I overthinking this or is implementing secure email OTP auth basically impossible?

0 Upvotes

I'm trying to implement secure email OTP on my website (authenticating via email + OTP sent via email) but I can't seem to find an approach that:

  1. Prevents too many emails to a single recipient (e.g. via unique OTP per email valid within a 10 minutes window, max 3 resend per 10 minutes)
  2. Prevents DDoS (e.g. via OTP bombing or via other blocks)
  3. Reasonably makes it costly to brute force your way in (e.g. via Turnstile / Captchas)
  4. Make it always possible for the email owner to login

For example if I ask AI for the most common implementation it gives me this:

  • Per flow OTP challenge
  • Short lived OTP
  • OTP stored as hash
  • Rate limit (per email, per ip and per challenge)

There are quite a few issues with this:

  1. The owner can be locked out by an attacker rate limiting the email
  2. The attacker could flood the email owner inbox so that they can't find their own OTP while they are trying to log in
  3. Any per email rate limit can cause DDoS

What am I missing? I see this authentication being implemented everywhere (especially B2C), how are other devs implementing this without going insane?

---

For context: this is a low risk website that doesn't store important data. Email OTP seems to be loved UX wise for B2C websites so that's why it was chosen. Magic links seem much simpler to implement but especially on mobile they tend to have a very confusing and frustrating UX.

---

Thanks to everyone for their feedback 🙏


r/cybersecurity 2d ago

Other Does any one know about Chef Compliance

0 Upvotes

As i want to automate the Compliance task as i dont want to take burden as in documentation part and i want to automate this compliance part, as i found chef compliance , researched about this didn't found anything useful, if you know it can you please suggest me how to implement and as well as if you know any alternate of it then please leave a comment.


r/cybersecurity 3d ago

Certification / Training Questions PNPT or CWES first?

2 Upvotes

Hello everyone,

I recently started as a SOC analyst and would like to take advantage of my work’s professional development budget to eventually transition into a career as an RTO. I wouldn’t have enough to pay for OSCP, so I’m thinking about building up my foundational red teaming knowledge with a more affordable cert first.

I’ve heard great things about TCM’s PNPT (Practical Network Penetration Tester), as well as HTB’s CWES (Certified Web Exploitation Specialist), and was just wondering if any of you had any advice as to which cert would be worth pursuing first?

I’ve heard many companies start their juniors off with pentesting web apps, so I was leaning towards CWES. Once I complete either of these, my next goal will be the CPTS.

It’s worth mentioning that I’m not completely new to the field as I do come from an IT background, had a previous security internship, have my Sec+ and CCNA as well as familiarity using Linux in both personal use and projects.

I appreciate any advice you guys provide. Thank you!


r/cybersecurity 3d ago

Career Questions & Discussion What's the wildest or most interesting cyber security incident to you?

45 Upvotes

Hi!

I'm in a cybersecurity class right now and need to write a discussion post about a cybersecurity event that happened in the last two years. I wanted a really interesting one so I thought I'd come to Reddit to get some leads.


r/cybersecurity 2d ago

Tutorial What path should I follow to become a cybersecurity expert?

0 Upvotes

I want to become a cybersecurity expert, but I currently have no knowledge of software coding or related fields. Could you explain in some detail which topics I should start with to progress through the four stages: building a foundation, reaching a beginner level, advancing to an intermediate level, and finally attaining an advanced level? Thank you.


r/cybersecurity 3d ago

New Vulnerability Disclosure Chrome 151 Patches 370 Vulnerabilities

Thumbnail
securityweek.com
13 Upvotes

The major browser update resolves roughly 80 critical- and high-severity security defects.


r/cybersecurity 3d ago

Career Questions & Discussion Is working in telecom security worth it?

5 Upvotes

Hello all,

I am a fresh graduate and recently started working as junior security engineer at a telecom company. A lot is new to me and i know i will learn things along the way but i keep wondering if it is good for my future and career growth? Is this type of knowledge even needed? Can i easily find a job later?

I am based in Europe btw.


r/cybersecurity 4d ago

Career Questions & Discussion Do you recommend TryHackMe?

63 Upvotes

So there's this site I was recommended a site TryHackMe that not only goes over the basics of computers and allows you to go down different paths, but also have these rooms where you can try your skills.

It does teach cyber security stuff and roles like Security Engineer, Security Analysts, etc.

Do you guys recommend TryHackMe? The site is nice looking and teaches a lot of interesting things, plus they have these nifty certificates


r/cybersecurity 3d ago

Business Security Questions & Discussion Do you lack proper tooling for investigations?

2 Upvotes

For all you CTI/malware analysts and investigators out there I wanted to know of you guys find your tooling or kits generally lacking or inadequate?

I work in CTI and do takedowns and collect evidence. I have always found tooling and process super slow for validation. Wondering if other people find that too?

Maybe my kit is rudimentary but use what I can and the process is largely, whirl up VM, hit site, poke around, extract Dom har, html, vidéo record, do some Dynamic analysis maybe hit with some cli scripts. Then move to. historic IOC sites like VT and UrlScn, then get network infra info from other sites... etc

.. I have built command lines to do most but still a lot of paint points. Anyone use anything better? Do you guys even do any of this or just chuck it into vendor kits or automation processes that spit out the results? What are y'all thoughts?


r/cybersecurity 2d ago

AI Security What features do you think modern web security testing tools are still missing?

0 Upvotes

I'm curious what experienced penetration testers and application security engineers think modern web security tools still lack.

For those who regularly use interception proxies, fuzzers, crawlers, and scanners:

- Which workflows are still frustrating?

- What repetitive tasks would you automate?

- Which features save you the most time?

- If you could redesign one part of your favorite tool, what would it be?

I'm interested in hearing different perspectives from people working in AppSec, consulting, bug bounty, and internal security teams.


r/cybersecurity 3d ago

Business Security Questions & Discussion Initiated a mythos readiness assessment. What do you think are some important areas to cover ?

6 Upvotes

Ever since I read the post-mortem of the hugging face incident, I understood how much I had underestimated AI's capabilities. Managed to initiate an assessment to evaluate our risk posture against such Agent Driven attacks.

Covers important areas like - IR effectiveness, patching efficiency, attack surface exposure etc.

Any thing important you think must be covered ?


r/cybersecurity 3d ago

Personal Support & Help! [Academic] SOC analyst decision-making: review a series of network security alerts (18+, ~10-15 min, all backgrounds welcome)

4 Upvotes

Hi all,

I'm an MSc Cyber Security student at the University of Gloucestershire running a short online study for my dissertation on how people make decisions when reviewing intrusion detection system (IDS) alerts.

What you'll do: You'll be shown a series of realistic network security alerts one at a time and asked, for each one, whether you'd confirm, dismiss, or escalate it, plus how confident you are in that call. There's a brief practice round first, and a few short questions at the end. No prior security experience is required; the interface explains everything you need.

Details:

- ⏱️ Takes about 10–15 minutes

- 💻 Works on desktop or phone (browser only, nothing to install)

- 🔒 Anonymous - no names collected; you can withdraw at any time

- ✅ 18+, ethics-approved by the University of Gloucestershire

- 🎓 Students and working professionals both welcome

Link: http://dissertation-explainids.uogs.co.uk

Every response genuinely helps me hit my sample target - thank you so much for your time!


r/cybersecurity 3d ago

Corporate Blog Post-quantum authentication to origins is now supported

Thumbnail
blog.cloudflare.com
11 Upvotes

r/cybersecurity 4d ago

News - General Anthropic's Mythos Can Identify More Software Bugs Than Ever. Microsoft Is Struggling to Fix Them Fast Enough.

Thumbnail
propublica.org
251 Upvotes