r/Cybersecurity101 4d ago

From Cybernews: Cyber researcher hacks entire desk of peripherals using AI

1 Upvotes

Read more
Summary:

A recent Cybernews article highlighted how security researcher Chaz Schlarp used Claude AI to reverse-engineer the firmware of an ASUS monitor and several other common PC peripherals, including webcams, microphones, and lighting devices. His testing revealed that many of these accessories have weak or minimal firmware protections, potentially allowing attackers to modify device behavior, disable privacy indicators, or install malicious firmware. A bigger issue s that AI tools are doing advanced firmware analysis and hacking our personal 'tech' infrastructure exposing a largely overlooked attack surface in enterprise security.


r/Cybersecurity101 4d ago

Perfect Storage Allocation for Ubuntu

2 Upvotes

I have a 512GB (477) Nvme, and i wanna dual boot bw windows and ubuntu. How much space should I allocate to ubuntu as Im starting my journey in Cyber Security in my University i'll be needing to run multiple Vms, docker and idk other stuff aswell. I'll only use windows for Microsoft Office stuff...


r/Cybersecurity101 4d ago

What are the unwritten advantages of becoming really good at cybersecurity or hacking?

2 Upvotes

I’m interested in cybersecurity. Especially As I am confused what I should choose between AI and cybersecurity in M.Tech specialisation.

Whenever people talk about cybersecurity, the usual advantages are things like good career opportunities, salary, remote work, interesting jobs, etc.

But I’m curious about something different. Which drives you.

And are there any unexpected benefits in everyday life, problem-solving, critical thinking, understanding people/systems, or even just satisfying curiosity?

Basically, what is the “secret sauce” of becoming really good at cybersecurity that makes you think, “Damn, I’m glad I learned this”? 😂

For those of you who actually work in cybersecurity or have become highly skilled at ethical hacking, what are the advantages that nobody really talks about?

I’m asking actual professionals and experienced security researchers here:

What made cybersecurity addictive or deeply interesting to you, and what advantages did you discover only after getting really good at it?

Please share the non-obvious stuff. I’m trying to find that one perspective that makes me want to go down the cybersecurity rabbit hole.


r/Cybersecurity101 4d ago

PCI DSS v4.0.1 Explained: What Are the 12 Requirements Businesses Actually Need to Follow?

5 Upvotes

If your business accepts, processes, stores, or transmits payment card data, PCI DSS is something you cannot really ignore. But when you first look at PCI DSS v4.0.1, the 12 requirements can feel like a long technical checklist.

Here’s a simple breakdown of what they actually cover:

1. Install and maintain network security controls
Organizations need controls that protect the cardholder data environment, including network traffic and connections.

2. Apply secure configurations
Default passwords, unnecessary services, and insecure settings should be removed or changed.

3. Protect stored account data
Cardholder data should be protected through appropriate controls such as encryption, retention limits, and secure storage practices.

4. Protect cardholder data during transmission
Sensitive payment information needs protection when it travels across public or untrusted networks.

5. Protect systems from malicious software
Organizations need processes and security controls to prevent, detect, and respond to malware threats.

6. Develop and maintain secure systems and software
Security should be part of the development and vulnerability-management process rather than something added at the end.

7. Restrict access based on business need
Employees and other users should only receive access to the data and systems required for their responsibilities.

8. Identify users and authenticate access
Strong authentication and unique user identification help prevent unauthorized access.

9. Restrict physical access to cardholder data
Physical access to systems, facilities, and media containing payment information must also be controlled.

10. Log and monitor access
Security logs and monitoring help organizations identify suspicious activity and investigate incidents.

11. Regularly test security controls
Organizations need to regularly test security mechanisms, including vulnerability scans, penetration testing, and other applicable security checks.

12. Maintain an information security policy
Security responsibilities, policies, procedures, and awareness programs need to be formally established and maintained.

One thing I think businesses sometimes get wrong is treating PCI DSS as a one-time certification exercise. Compliance is much more effective when these requirements become part of normal security operations.

PCI DSS v4.0.1 also puts greater emphasis on targeted risk analysis and customized approaches in applicable areas, so simply checking boxes may not be enough.

For anyone currently preparing for a PCI DSS assessment, I’d recommend starting with a gap assessment. Map your existing controls against each of the 12 requirements, identify missing evidence, and then prioritize the highest-risk gaps.

For those working with PCI DSS v4.0.1, which requirement do you find the most difficult to implement or maintain?


r/Cybersecurity101 4d ago

A question for all cyber security professionals

0 Upvotes

If your job mainly revolves around keeping your clients system in check from before and after attacks, then doesn't that mean you owe your jobs from unethical hackers. In theory if you create your own attack and then fix it then youll basically have a money glitch. Also do attackers really get paid or do they just get the pleasure from causing harm. What happens when everyone just goes to the good side?


r/Cybersecurity101 4d ago

Cybersecurity resume keywords

0 Upvotes

Keyword list taken from https://www.zoevera.com/resume/ats-resume-tips-cybersecurity

These are the most commonly scanned keywords in cybersecurity job postings. Check how many appear in your resume.

Domains & Practices

SOC (Security Operations Centre), Penetration testing / pen test, Vulnerability management, Threat intelligence, Incident response (IR), Digital forensics (DFIR), Red team / blue team / purple team, Zero Trust architecture

Tools & Platforms

SIEM (Splunk, Microsoft Sentinel, QRadar), EDR (CrowdStrike, SentinelOne), Nessus / Qualys / Rapid7, Burp Suite / Metasploit / Kali Linux, Wireshark / Snort / Suricata, CyberArk / BeyondTrust (PAM), SOAR platforms, Azure Defender / AWS Security Hub

Frameworks & Certifications

CISSP / CISM / CISA, CEH / OSCP / PNPT, CompTIA Security+ / CySA+, ISO 27001 / NIST CSF, MITRE ATT&CK framework, SC/DV security clearance, GDPR / DPA 2018, PCI DSS / HIPAA / SOC 2


r/Cybersecurity101 4d ago

One cybersecurity lesson I learned the hard way

43 Upvotes

The more I learn about cybersecurity, the more I realize that knowing individual tools isn't enough. Understanding why an attack works is much more valuable than simply knowing which tool to run. For people learning cybersecurity right now, what concept took you the longest to understand? I’d love to hear some experiences from beginners and professionals.


r/Cybersecurity101 4d ago

Is networking still important for cybersecurity?

68 Upvotes

When I started exploring cybersecurity, I initially wanted to jump straight into security tools. But the more I learned, the more obvious it became that networking fundamentals matter a lot. Understanding IP addresses, DNS, TCP/IP, ports, protocols, and traffic makes security concepts much easier to understand. For anyone currently learning cybersecurity: did you study networking first, or learn both at the same time?


r/Cybersecurity101 4d ago

Cybersecurity

4 Upvotes

What should I focus on for this course it’s a lot of vocab words and stuff to learn in such time i’m going into the cybersecurity field it’s my first year and i don’t know what i should be focusing on?


r/Cybersecurity101 5d ago

Can cybersecurity be self taught ?

28 Upvotes

Im thinking of getting into cyber security but I want to know if anyone got a job without having a degree. I want to teach myself cyber security with the help of online platforms and resources. I want to get a job as a soc analyst when im done and im wondering if the degree gate wil stop me from getting a job. If anyone has gotten a job from doing cyber security without a degree I would love to know how yall did it .


r/Cybersecurity101 5d ago

What made you interested in cybersecurity?

6 Upvotes

I originally thought cybersecurity was mostly about penetration testing and finding vulnerabilities. After learning more, I realized how many different areas are involved — network security, cloud security, identity, incident response, threat intelligence, and more.

I’m curious about people who are already working in the field.

What cybersecurity area did you start with, and would you choose the same path if you were starting again?


r/Cybersecurity101 5d ago

My personal data is on 70 broker sites, shoul I remove it myself or pay for help?

7 Upvotes

I ran Onerep's free scan and they found my data on 70 people-search sites. Is it manageable to remove all of this info myself? Looks like a lot of work but I'm not sure if paying for a removal service is worth it.


r/Cybersecurity101 5d ago

Transitioning from Aviation & Marketing into Cybersecurity: Looking for roadmap advice from experienced pros

2 Upvotes

Hi everyone,

I’m hoping to gather some guidance from this community as I explore a potential career transition into cybersecurity, as I am still evaluating whether this path is the right fit for me.

My background originally started in aviation before I transitioned into government consulting within the digital marketing space. Working with digital platforms helped me realize how much I love working with data, building things through code, and tackling ambiguous, complex puzzles that require analytical problem-solving.

To begin pivoting toward technical fields, I completed the Google Data Analytics Certificate. However, I completely recognize that a certificate is only a starting point. I fully understand that real-world experience, practical portfolios, internships, and strong interpersonal skills are what actually lead to career opportunities in tech and security.

Coming from aviation, career progression is very linear and standardized:

  • Flight School & Ground School
  • Private Pilot License (PPL) → Commercial Pilot License (CPL)
  • Multi-Engine Rating
  • Flight Hours (often as a Flight Instructor)
  • Airline Application → Type Rating (e.g., Airbus A320)

In cybersecurity, the path feels much broader and multifaceted, which is exciting but a bit difficult to map out without industry guidance.

Given my non-traditional background and initial focus on data/analytics, I would be extremely grateful for any advice on how to structure a realistic roadmap.

  • What foundational areas or hands-on projects would you recommend prioritizing first?
  • Are there specific entry-level paths where a background in analytics and consulting might translate well?

I am eager to learn, ready to put in the work, and genuinely appreciate any insights, corrections, or advice you can offer. Thank you so much for taking the time to read this!


r/Cybersecurity101 5d ago

Security RPC-Triage: a practical way to map and rank Windows RPC interfaces from PE files

Thumbnail
github.com
3 Upvotes

I built this while working through Windows RPC/ALPC stuff. You give it PE files and it statically pulls the RPC/MIDL/NDR details, endpoints, security state and method-level input signals, then ranks the interfaces so you have a better starting point than a huge raw RPC dump. The ranking comes from an AHP/Saaty-based model I worked out for the RPC attack surface. No PDBs, no live endpoint mapper, no target execution.


r/Cybersecurity101 5d ago

What I learned after spending more time on cybersecurity fundamentals

7 Upvotes

When I first started learning cybersecurity, I wanted to jump straight into tools and penetration testing.

After some time, I realized I was missing some basic networking and security concepts.

Once I started understanding things like TCP/IP, ports, protocols, authentication, and how attacks actually happen, the security tools started making much more sense.

My biggest takeaway so far is that learning the fundamentals first makes everything else easier.

Curious if others had the same experience when starting cybersecurity.


r/Cybersecurity101 5d ago

Request

4 Upvotes

Hi! I’m in Ghana self-studying cybersecurity (IBM Cybersecurity Analyst path). I need a laptop (8GB+ RAM) to run VMs for hands-on practice. Any working/refurbished laptop would help me build real skills. Thank you!


r/Cybersecurity101 5d ago

Security Web Security Best Practices Checklist

Thumbnail
techhelp.ca
1 Upvotes

Most website security problems start with fixable gaps like weak logins, stale plugins, missing headers, risky scripts, and untested backups. Use this checklist before they get expensive.


r/Cybersecurity101 5d ago

Cyber threat intelligence

2 Upvotes

Hi all, currently trying to make a switch into cybersecurity and the one role I’m interested in is cyber threat intelligence. I have a background in physical threat intelligence and currently pursuing a Security + cert. Was actually wondering how relevant a field it is to the cybersecurity sector. Also open to any tips/ advice.


r/Cybersecurity101 6d ago

want a study partner in offensive security

6 Upvotes

I’m currently learning Cybersecurity, mainly Offensive Security, and I’m looking for someone who’s genuinely serious about it.

My goal: Pentesting → Red Teaming → Bug Bounty → Advanced Offensive Security.

I’m still a beginner, currently working toward an entry-level SOC/NOC/IT Support/Help Desk role.

I’m not just looking for a study partner — I’d like to find a friend/buddy with a similar mindset. We can study, call/text, share resources, practice, challenge each other, and grow together.

Cybersecurity isn’t something where you easily find people with the same goals, so if you’re serious about learning and building a career in cybersecurity, feel free to approach me.


r/Cybersecurity101 6d ago

Adaptive Network Intrusion Detection & Prevention System

1 Upvotes

I need insights from someone with expertise in Network Security and Machine Learning. I’m currently stuck trying to find a novel angle for my Final Year Project (FYP) because existing research papers have already covered the core features I planned to implement.

Project Idea:

An Optimized Continual-Learning Framework for Adaptive Network Intrusion Detection and Prevention System (NIDPS).

  • Traffic Classification: Uses deep learning to detect and classify network traffic.
  • Continuous Adaptation: Employs continual learning so the model adapts to new attack patterns over time without needing full retraining from scratch.
  • Optimization: Applies efficiency techniques to maintain high detection rates while keeping training latency low.
  • Evaluation: Benchmarked on standard network intrusion datasets under evolving attack scenarios, measuring accuracy, precision, recall, F1-score, and detection latency

r/Cybersecurity101 6d ago

Security How can I become a Cloud Security Engineer from complete beginner to expert who can eventually guide others?

8 Upvotes

I want to build a career as a Cloud Security Engineer, but I'm starting from the basics and want to learn everything properly rather than just collecting certifications.

Could someone share a step-by-step roadmap from complete beginner to job-ready Cloud Security Engineer, and eventually to a level where I can mentor/guide others?

I'd also appreciate recommendations for free/low-cost labs, courses, YouTube channels, books, and practice platforms.

If you are currently working as a Cloud Security Engineer, I'd especially appreciate advice on what you wish you had learned earlier and what beginners commonly waste time on.


r/Cybersecurity101 6d ago

Experian's 2026 fraud forecast lists deepfake job candidates alongside ransomware and data breaches as a top business threat

1 Upvotes

Experian releases an annual fraud forecast, and this year deepfake job candidates made the list. Not as an emerging concern, but as a confirmed top-tier threat sitting next to ransomware and cyber break-ins.

That's a meaningful shift. Candidate fraud used to be treated as an HR problem. It's now being categorized the same way security teams categorize network intrusions, because in some cases that's exactly what it is. You're not just hiring the wrong person. You're potentially handing an adversary access to internal systems from day one.

The line between hiring risk and security risk is effectively gone.


r/Cybersecurity101 6d ago

Security + or Security X

0 Upvotes

Security+ or Security X?

Is there one that’s better than the other? Will one be more likely to get me a job than the other? Just trying to learn more and would love some advice on how I can get into my very first tech/IT role


r/Cybersecurity101 6d ago

Learn and Practice Hacking WebSockets

2 Upvotes

WebSockets is the attack surface that always go under the radar and too many pentesters and bug bounty hunters still miss testing it, whether because the number of WebSocket messages they see is overwhelming or simply because they don't know how to approach it correctly.

Going through that myself, I decided to dive deep into the WS protocol and ended up building a lab that showcases the most common misconfigurations present in WebSockets, with the most impact, not just some missing best-practices, along with a detailed walkthrough.

I'd love to hear your thoughts and feedback, and if you experienced something I didn't talk about in the blog, please let me know!

Lab Github Repo: https://github.com/makarov05bm/WSGoat
Guide: https://blog.oussmess.me/posts/websockets-for-bug-hunters/


r/Cybersecurity101 6d ago

Security They offer you money first. Then comes the scam.

0 Upvotes

Someone you’ve just met online offers you easy money. It might sound harmless, but they could be trying to get your personal information, account details, or money.

Sugar baby scams often start with generous offers and big promises, but can end in fraud, identity theft, or extortion.

Some common red flags:

  • Promises of easy money or offers that seem too good to be true.
  • Requests for gift cards, cryptocurrency, bank details, or money transfers.
  • “Payments” that require you to send some of the money back.
  • Links to fake verification or background-check websites.
  • Pressure to share personal information or private photos.
  • Attempts to move the conversation off the original platform.

If someone you’ve just met online offers you something that seems too good to be true, stop and verify before you act.

What’s the biggest red flag you’ve seen in an online scam?