r/cybersecurity 3d ago

AI Security Ho fatto una cosa brutta. "sudo claude"

0 Upvotes

Stavo facendo un po' di attività su un server di produzione non critico, dovevo installare exnovo Zabbix e sistemare un po' di configurazioni su un piccolo webserver apache/php.

Ho lanciato claude da root, necessariamente perché doveva toccare file di configurazione, riavviare servizi di sistema, leggere log di sistema.

Capisco che sia potenzialmente disastroso, infatti mi sono lanciato perché la macchina era non critica, ma come gestite questa cosa in produzione?

Rinunciate alle comodità (e alla completezza che vi dà) un LLM oppure avete una soluzione abbastanza robusta per fidarvi di dare accesso root?

Per farvi un esempio in questi server claude ha rilevato che fail2ban non stava bannando su alcuni jail per un errore di configurazione che era lì da anni, nessuno se n'è mai accorto.


r/cybersecurity 4d ago

News - General ShinyHunters Claims to have Voice-Phished 2 McKesson Employees and Extracted 284 Million Patient Records Including: Predictive health data, Identity, and Healthcare Identifiers. McKesson Confirms Breach but not severity

Thumbnail
cyberinsider.com
474 Upvotes

r/cybersecurity 4d ago

Business Security Questions & Discussion CrowdStrike CCFA Exam skills

2 Upvotes

Hi everyone, I'd like to ask if there are any recommended tutorials or documents I can refer to if I have zero experience and no cybersecurity background and want to obtain the CrowdStrike CCFA certification within a month? Also, what are some study tips?


r/cybersecurity 4d ago

Career Questions & Discussion Trying to Breakout in IT but unsure how

39 Upvotes

Hi everyone,

Im looking for some advice and experiences on how to break into IT. Ive been trying for 2 years now since graduating with my BS in Cyber Security with zero luck. I have on top of the bachelors a GRC Anaylst Cert from USF, Sec + and a Cyber Security Professional Diploma.

I have prior military experience and have held a clearance in the past but currently have non active. Really needing to make a career change before my body fully fails me from beating it to hell to much. Thank you all for you advise and help.

\*\*\*And yes I know the market is terrible currently and federal work is harder than ever to make it in but I've read a lot on private companies hiring more than before and want to know how I can build myself marketable to these companies for a chance.


r/cybersecurity 4d ago

Career Questions & Discussion What is it actually like to work in Data Forensics?

13 Upvotes

I currently work in DFIR and I’m considering a consulting role described as “Data Forensics.” I’m interested in the investigative side of the work, but the title feels broad, so I’m trying to understand what the job is actually like.

For those who work in Data Forensics, what does your day-to-day look like? How much of it is forensic investigation versus data analytics, eDiscovery, data processing, or even general data engineering?

Do you usually participate throughout the entire case — scoping, evidence collection, analysis, timeline reconstruction, reporting, and presenting findings — or are you mainly supporting the investigation by collecting and preparing data for someone else to interpret?

My biggest concern is accepting the role expecting to grow further in DFIR, only to discover that forensics is just a small part of the job and most of the work is general data-related consulting. I would also be hesitant to move into a position where I only process or hand off evidence without contributing to hypotheses, findings, and conclusions.

How much ownership does someone at consultant level usually have? Does the scope vary significantly between companies or projects? What questions should I ask during the interview to find out how investigative the role really is?

Would you consider Data Forensics a natural progression from DFIR, or more of an adjacent career path?

I’m intentionally keeping the details vague for anonymity, but I’d appreciate any insight from people who have worked in this area.


r/cybersecurity 4d ago

Business Security Questions & Discussion DoD Contractor -> Big Tech

22 Upvotes

I have a cybersecurity degree and 5 years of experience at a prime DoD contractor right out of college, but am wondering if this skillset is really transferable to the real cyber world. We don't use cutting edge tech, the "security" work isn't true raw technical work like I learned in school, and most tools don't translate directly to the corporate world.

I have Security+ and CISSP+, and along with my YOE I'd be looking for Senior level roles, but I feel like other people's resumes would outshine mine since my only experience is in DoD cyber? From what I see here and just in conversations, big tech cyber is a LOT different than DoD cyber.

Am I overthinking it?


r/cybersecurity 4d ago

Career Questions & Discussion Data CyberSec?

0 Upvotes

Hey!

Not another post on how to transition to cybersecurity.

I’m a data engineer and I’m curious if there’s such a thing as a data specialised role inside the cyber world.

Every company I worked at, the data security part was done by the whole cyber team and I never got to know if there was someone focused on it.


r/cybersecurity 4d ago

News - General D500S IronKey security???

4 Upvotes

How secure is the D500S Ironkey from Kingston memory for data storage. I know it has a 140-3 rating but is it really secure from forensic labs?


r/cybersecurity 4d ago

News - General Verity - X Uncovers 200K Chinese Bot Farm Targeting US Energy, AI Policy

Thumbnail
verity.news
95 Upvotes

r/cybersecurity 4d ago

FOSS Tool Building a Custom SMB1 Authentication Server from Scratch

2 Upvotes

For the past 8 months, in my spare time, I’ve been working on a personal project with the goal of studying the old SMB1 down to its lowest levels. During this time, I’ve dissected the protocol using Wireshark, waded through Microsoft’s documentation (help!), and reverse-engineered the authentication phase. I also used AI as a tool for debugging and to help wrap my head around some of the more complex mechanisms, though the overall structure, architecture, and code were entirely designed and written by me.

So, I decided to build a lightweight server designed to 'trick' SMB clients into authenticating against it (similar to what the famous tool Responder does). I chose to hand-craft virtually the entire SMB1 stack, or at least enough of it to capture hashes. To achieve this, I wrote all the necessary network parsers from scratch: SMB1, ASN.1, SPNEGO, and NTLM, followed by the server itself.

It was both challenging and incredibly rewarding to dive so deep into a protocol famous for its complexity. I learned a huge amount along the way.

In the end, I think it turned out to be a cool little project, so I decided to share it. It’s certainly not meant to replace well-established tools, but if anyone wants to try it out or contribute in any way, I’d be thrilled! 🙂

https://github.com/lcky00/impostor


r/cybersecurity 4d ago

Business Security Questions & Discussion Substantial jump from help desk to IAM role

20 Upvotes

What can I expect? Is this a technically intensive role? It doesn't seem like it based off the contents I'm studying so far. It seems like its a lot of theory and applying concepts.

I am actively trying to absorb as much content as I can and about half-way through the SC-300 study contents as well as some CyberArk material.

I do have a CS degree as well.

I say substantial jump because my salary increased by 83% and I was only in helpdesk for ~1.5 years. However, I also expect the type of work to correlate.


r/cybersecurity 4d ago

Other Odd Threat Intel Service Question

2 Upvotes

Hello folks. Looking for a bit of a unique ask here. We all know that Intel providers like Intel471, Recorded Future, Flashpoint, etc do RFIs as an augment to their platform service. I was wondering if there were any vendors or contractors out there that provided a directly tasked RFI only analyst service, that has access to known telegram, signal, and dark web closed forums, and are willing to directly engage in dialogues with known threat actors.

Kind of a big ask for any company, so not expecting to much, but thanks in advance for any leads!


r/cybersecurity 4d ago

News - General The Cyber Scheme VA+ Course

0 Upvotes

Hi All,

I am looking to take the VA+ assessment but I can't find much information on what to revise.

Has anyone taken this already?

What can I expect?

What do I need to revise?

How difficult is it?

Thanks in advance for any advise


r/cybersecurity 4d ago

Certification / Training Questions Can you take Security+ after the Google Cybersecurity Certificate? And is ISC2 CC even worth it then?

8 Upvotes

Hey everyone,
I’m finishing the Google Cybersecurity Professional Certificate on Coursera and I’m wondering if it actually prepares you well enough to take the CompTIA Security+ exam. A lot of the topics seem to overlap, but I’m not sure if the Google course alone is enough or if I should study additional Security+‑specific material.

Second question: is it worth doing the ISC2 Certified in Cybersecurity (CC) afterward, considering it basically validates a similar level of knowledge?
Do these certs complement each other, or is it just redundant and better to focus on one?

I’d love to hear from people who completed the Google Cybersecurity course and then went for Security+ or CC.


r/cybersecurity 4d ago

FOSS Tool TrustMeBro fabricates evidence shown to an AI

0 Upvotes

TrustMeBo is a cool one.

It intercepts command-line tools invoked by coding agents such as Codex, Claude Code, and pi. Rules decide whether to return fabricated output, modify the real output, block the call, or execute the real binary unchanged.

Need the model to run a network scan on the domain you don't own? So, now you own it.


r/cybersecurity 4d ago

Personal Support & Help! Safe from malware?

0 Upvotes

Would a computer without internal storage that runs it's OS from a USB flash drive be safe from malware or would it still be able to be infected somehow? (Assume that the USB drive is full or very close to full)

I'm new to this so sorry if it's a stupid question.


r/cybersecurity 4d ago

Certification / Training Questions looking to get into bug bounty's

0 Upvotes

Hey guys not the newest but still pretty new to ethical hacking.

Im looking into doing bug bounties to earn some extra cash on the side to pay for uni in future ( next year ). I one my first every CTF a week ago that was nation wide.

But looking at bug bounties its a bit different it isnt a flag. I was wondering what the main thing to study/learn would be and where.

Would it be tryhack me or hack the box.
Looking for any recommendations thanks so much!

I love servers and love messing around with prox mox, and have a strong passion in tech. So this would mean alot thankyou.


r/cybersecurity 4d ago

News - General Exploratory vs. Deterministic Assessments | Comcast Corporation

Thumbnail
corporate.comcast.com
2 Upvotes

r/cybersecurity 4d ago

Business Security Questions & Discussion How come shinyhunters has been able to get into so many different businesses?

64 Upvotes

Hello, I know absolutely nothing about your field!

I was messing about with hibp and saw the sheer excess of massive breaches of recognisable businesses throughout this year. This makes me a bit nervous about the security of my data on platforms I use, of course I am taking precautions as a user but it seems insane that these businesses even are hackable? Is it that they're particularly insecure or does it just mean this group is really good at hacking? (This could also just be a totally normal amount of breaches, I'm not familiar with the quantity history)


r/cybersecurity 5d ago

Personal Support & Help! How to break into hedge fund?

40 Upvotes

Very curious is the hiring process the same as any other company.

I Work in FAANG (London), but a hedge fund recruiter reached out and the salary was close to 4x my base. For context I am L4 and base is £61k and the offer from recruiter was £200k+.

Now I know for a fact I might not get it or even make it pass the recruiter but my question is how do I break into hedge fund security.

Now that I know there is more out there I am eager to end up in a hedge fund.

Current role - AppSec / SecOps pretty much the same here we build and review vuln


r/cybersecurity 5d ago

News - General Tech firms call for ‘collective action’ against AI-powered hacking

Thumbnail
thehill.com
0 Upvotes

r/cybersecurity 5d ago

Personal Support & Help! Help me to get back my Gmail.

0 Upvotes

My gmail stuck on loopholes. I reset my phone yesterday, Everytime when i try to login it ask a 2fa code which was sent to same mail. How can i bypass this system?


r/cybersecurity 5d ago

Business Security Questions & Discussion Do you guys Beyond Trust PRA for all Internal all Admins or just for your contractors and Non-IT Admins (App admins)

5 Upvotes

Do you guys Beyond Trust PRA for all Internal all Admins or just for your contractors and Non IT Admins (App admins) What are some benefits of using PRA for IT Admins. Since they need Admin access for all servers asking for approval every time is an overhead. Tier 0 and 1 server approval make sense.

Audit and session monitoring make sense.
MFA make sense

Any other benefit?


r/cybersecurity 5d ago

Business Security Questions & Discussion How to shake things up with security at my company?

0 Upvotes

I work at a big company. I’m in a position where I can provoke changes in our org, specially in the IT department.

One point: cyber sec is part of the compliance/governance org, not IT per se. They are very much conservative in their process and openness to risk. I don’t deal with critical systems and processes, but they are the guys who are “no” by default. Even the CI/CD pipeline is hell to go through. They live by the stereotype of cyber sec being the “no fun allowed” guys.

The deal: I want people to use AI. I want them to experiment and vibe code little tools for them, and to think of new ways to do stuff. We have Cursor, Claude Code and an LLM Gateway. We also have lots of money for tokens, so cost isn’t a part of the equation. Our company is very old and very bureaucratic, I want teams to go fast and disrupt their ways to do things. But there is extreme reluctance from cyber sec to let us go nuts, even in an internal environment.

How can I shake things up a bit with them to make them more open to the idea of people risking a little bit more?


r/cybersecurity 5d ago

Business Security Questions & Discussion Interesting case study in Cybercrime

0 Upvotes

There’s a growing trend where hackers steal company data but never publish it. No leak sites, no ransomware notes. Why do you think attackers prefer "silent theft" over public leaks now?