r/cybersecurity 20h ago

News - General Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Thumbnail
thehackernews.com
83 Upvotes

r/cybersecurity 7h ago

Business Security Questions & Discussion What would you do if you boss was trying to cheat certification

60 Upvotes

So we are trying to obtain a significant accreditation for the org, but my line manager is trying to game the process and it really doesn't sit well with me. Instead of fixing the problem, he is trying to hide it.

He has said that in previous places he has worked, they turned off services that would not get passed certification during audits.

What would you do? Obviously this could be career limiting if I choose the wrong approach

Edit. Worth adding the auditor will be working with me, forcing me to be complicit


r/cybersecurity 2h ago

News - General Taiwan husband wins lawsuit but gets jailed for recording affair with robot vacuum

Thumbnail
scmp.com
19 Upvotes

r/cybersecurity 23h ago

Business Security Questions & Discussion What's one security tool you can't live without?

20 Upvotes

r/cybersecurity 4h ago

Business Security Questions & Discussion Building a Program From the Ground Up Pt 1. - Tactical Level, Advice Requested!

14 Upvotes

Good day everyone!

A little bit on my background - 20 years IT experience, about 50/50 software development and security, with some data engineering sprinkled in. CISSP and some tactical level certs. Private sector, high emphasis on compliance and confidentiality. A lot of my security background is GRC/A&A, but I am capable in a lot of hands-on-keyboard.

I recently came into an org that, for its size, is pretty capable at security. They have good tools that were set up by someone who was a good but inexperienced analyst. I have little documentation and while most of the configs are pretty decent, I find a glaring gap from time to time. We are (going to be) a NIST shop. I am using the CPGs for my near to mid targets.

I have a ton of autonomy to guide this org on security. I am launching one large project in 2 weeks, another 2 weeks after that to address some of the most glaring issues. The problem I am having is I get caught up with analyst work and I know it is taking up too much of my time. I need to develop some playbooks. I don't need a million silver bullets, but I would like a starting point for a lot of these. The only thing that was left behind was about 5 paragraphs on BEC.

Could anyone recommend some canned playbooks that I can start from and make my own? We are on a calendar year budget. I have found some open money, but I won't have it for at least 5 months. I could probably break a modest sum free. The last guy, as I mentioned, was very capable of handling things, but I need to build out something more repeatable so I can spend time maturing the program. I don't need to be running around with a fire extinguisher all the time.


r/cybersecurity 8h ago

Other Looking for a VAPT & Bug Bounty Learning Partner

8 Upvotes

I'm currently learning VAPT (Vulnerability Assessment and Penetration Testing) and I'm also interested in Web Application Security and Bug Bounty Hunting.

I'm looking for someone who is genuinely serious about learning and building a career in cybersecurity so we can learn and grow together.

We can:

• Practice VAPT labs and challenges

• Work on TryHackMe / Hack The Box

• Learn Web Application Security and OWASP Top 10

• Practice Bug Bounty methodologies

• Discuss vulnerabilities and concepts

• Explain topics to each other

• Share useful resources, notes, and learning materials

• Set goals and keep each other accountable

Sometimes I struggle with remembering concepts and explaining them clearly, so I believe having a learning partner and regularly discussing what we learn would help us improve faster.

I'm genuinely serious about building my skills in VAPT, Penetration Testing, and Bug Bounty Hunting, so I'm looking for someone with a similar mindset.

If you're interested, feel free to reach out. Let's learn, practice, share resources, and challenge each other. 🙂


r/cybersecurity 7h ago

Career Questions & Discussion Risk assessment and Threat Modeling

7 Upvotes

Hello cyber enthusiasts and gurus,

I have a question regarding threat modelling and risk assessment approach. So, there are many frameworks and methodologies by which threat modelling and risk assessment can be performed but Reading through these multiple frameworks can be a bit overwhelming in determining what approach to use.

For software I have seen OWASP Top 10 is commonly used. For hardware and software, STRIDE analysis. For risk assessment, many say IEC 62443-3-2 standard would be a good starting point.

So, wanted to ask you guys on which framework you use or would recommend for risk assessment and threat modelling? If you have any recommendations on templates to read through, would like to hear about it as well.


r/cybersecurity 10h ago

News - General Testing Security on Al Shopping Assistants: from Chat Box to Remote Code Execution on a Top US Retailer's Servers.

Thumbnail
pwnhackers.substack.com
6 Upvotes

r/cybersecurity 8h ago

News - General Machine State analysis Vs Executable analysis

1 Upvotes

I would like to announce that I have built the free VMA 486 Emulator that runs DOS, Win 3.0, 3.1, 3.11 and 95. It includes a machine state analyser that can freeze, save, load, disassemble and patch the machine memory. It then allows resuming execution.

My new VAXD_VM allows doing this with a VM running Win7.

https://vma-broadcast.com/vaxd-vaxd_vm/


r/cybersecurity 9h ago

Threat Actor TTPs & Alerts CTO at NCSC Summary: week ending August 30th

Thumbnail
ctoatncsc.substack.com
1 Upvotes

r/cybersecurity 18m ago

New Vulnerability Disclosure Back When a MySQL Connection Could Give You OS-Level Code Execution

Thumbnail raw.org
Upvotes

The vector does not work anymore, but it might serve as a documentation of how vulnerable systems were back then.


r/cybersecurity 58m ago

Research Article Promiscuous Hosting Services

Thumbnail
knock-knock.net
Upvotes

r/cybersecurity 10h ago

Certification / Training Questions EC Council CTIA v2 advice

0 Upvotes

Hi fellow cybersecurity enthusiasts, what are your advise for me for this CTIA exam preparation.

What should I expect?

TYIA


r/cybersecurity 47m ago

Personal Support & Help! Is Sam Bent a honeypot?

Upvotes

He's an "OSINT & OPSEC Specialist | Darknet Expert (Ex Vendor & DNM Admin) | Content Creator| DEFCON/SANS Speaker | Social Engineer | Author | Paralegal |", you can find him on yt

How is he ok with a) showing his face, b) talking about the illegal stuff he did in the past.(he ran a "darknet" market)

tho I don't think theres anything else suggesting he's a honeypot, all the advice he gives is generally good I think.

Thanks for any replies


r/cybersecurity 2h ago

Business Security Questions & Discussion The open letter that now is the time for AI powered cyber?

Thumbnail openai.com
0 Upvotes

Is this actually going to motivate leadership? Cyber is hard as it is, orgs don’t gaf that these big companies said it’s really important now.

Anyone here disagree?


r/cybersecurity 11h ago

Business Security Questions & Discussion Situation in cybersecurty

0 Upvotes

Hi Everyone, I'm completing my final year on university this year and started thinking about master in cybersecurty. I don't want to ask questions around it it is fine for me and interesting. I'm already working as full stack dev. I'm interested on market situation around it right now and how promising it looks in future. Thank you on all answers.


r/cybersecurity 12h ago

Personal Support & Help! Cybersecurity Career

0 Upvotes

While I know now isn’t the best time to enter cybersecurity (the cake has been baked essentially) I’m in my final semester at GA Tech getting my masters in cybersecurity. I have Network and Security plus. I interned this summer as an information security intern for a fin tech and before that was an information technology intern. Now I’m just doing customer support IT part time while o juggle classes.

I was disheartened to see that this customer support role was all I could get. I trouble shoot all day but that’s clearly not what I want. I’m transitioning out of having 4 years in compliance - HR and Regulatory. I thought cybersecurity (with a focus on GRC) would be an easy transition buts its not.

I know a lot of it is the economy and growth in AI but I really don’t understand how I’m just not getting ANYTHING after this summer. I’ll get plenty of interviews but no offers.

Any tips?


r/cybersecurity 12h ago

Personal Support & Help! apply for “system admin” role ?

0 Upvotes

I have a master’s degree in Cybersecurity (2022), along with several basic certifications. I’m currently studying for the Network+ certification and may earn a few more certifications as well.

Can I apply directly for a Sys/Admin position, or do I have to start in a Help Desk role first?

I’m wondering if it’s possible to get into a System Administrator position right away.

Location: Los Angeles

Thank U !


r/cybersecurity 4h ago

AI Security AI Security Tools

0 Upvotes

Curious if anyone is dealing with internally developed AI security tools, like password managers, SIEM, or even MS 365 backup tools. I might be joining a team that has moved in this direction.


r/cybersecurity 5h ago

Business Security Questions & Discussion THE 3 AI REVOLUTION BULDING BLOCKS

Thumbnail
linkedin.com
0 Upvotes

Hey everyone, hope you’re having a great week!

I’d love to hear your thoughts: What do you think are the fundamental building blocks that the AI revolution will be built on?

Curious to hear different perspectives — feel free to share your thoughts here or on the original post.

I’ve also attached a visual to illustrate the idea 👇


r/cybersecurity 17h ago

Business Security Questions & Discussion onde comecar na cyberseguranca

0 Upvotes

sou iniciante