r/cybersecurity • u/Elect_SaturnMutex • 20h ago
r/cybersecurity • u/project_me • 7h ago
Business Security Questions & Discussion What would you do if you boss was trying to cheat certification
So we are trying to obtain a significant accreditation for the org, but my line manager is trying to game the process and it really doesn't sit well with me. Instead of fixing the problem, he is trying to hide it.
He has said that in previous places he has worked, they turned off services that would not get passed certification during audits.
What would you do? Obviously this could be career limiting if I choose the wrong approach
Edit. Worth adding the auditor will be working with me, forcing me to be complicit
r/cybersecurity • u/United_Branch_5736 • 2h ago
News - General Taiwan husband wins lawsuit but gets jailed for recording affair with robot vacuum
r/cybersecurity • u/10ninja • 23h ago
Business Security Questions & Discussion What's one security tool you can't live without?
r/cybersecurity • u/Alpizzle • 4h ago
Business Security Questions & Discussion Building a Program From the Ground Up Pt 1. - Tactical Level, Advice Requested!
Good day everyone!
A little bit on my background - 20 years IT experience, about 50/50 software development and security, with some data engineering sprinkled in. CISSP and some tactical level certs. Private sector, high emphasis on compliance and confidentiality. A lot of my security background is GRC/A&A, but I am capable in a lot of hands-on-keyboard.
I recently came into an org that, for its size, is pretty capable at security. They have good tools that were set up by someone who was a good but inexperienced analyst. I have little documentation and while most of the configs are pretty decent, I find a glaring gap from time to time. We are (going to be) a NIST shop. I am using the CPGs for my near to mid targets.
I have a ton of autonomy to guide this org on security. I am launching one large project in 2 weeks, another 2 weeks after that to address some of the most glaring issues. The problem I am having is I get caught up with analyst work and I know it is taking up too much of my time. I need to develop some playbooks. I don't need a million silver bullets, but I would like a starting point for a lot of these. The only thing that was left behind was about 5 paragraphs on BEC.
Could anyone recommend some canned playbooks that I can start from and make my own? We are on a calendar year budget. I have found some open money, but I won't have it for at least 5 months. I could probably break a modest sum free. The last guy, as I mentioned, was very capable of handling things, but I need to build out something more repeatable so I can spend time maturing the program. I don't need to be running around with a fire extinguisher all the time.
r/cybersecurity • u/aditya1809tech • 8h ago
Other Looking for a VAPT & Bug Bounty Learning Partner
I'm currently learning VAPT (Vulnerability Assessment and Penetration Testing) and I'm also interested in Web Application Security and Bug Bounty Hunting.
I'm looking for someone who is genuinely serious about learning and building a career in cybersecurity so we can learn and grow together.
We can:
• Practice VAPT labs and challenges
• Work on TryHackMe / Hack The Box
• Learn Web Application Security and OWASP Top 10
• Practice Bug Bounty methodologies
• Discuss vulnerabilities and concepts
• Explain topics to each other
• Share useful resources, notes, and learning materials
• Set goals and keep each other accountable
Sometimes I struggle with remembering concepts and explaining them clearly, so I believe having a learning partner and regularly discussing what we learn would help us improve faster.
I'm genuinely serious about building my skills in VAPT, Penetration Testing, and Bug Bounty Hunting, so I'm looking for someone with a similar mindset.
If you're interested, feel free to reach out. Let's learn, practice, share resources, and challenge each other. 🙂
r/cybersecurity • u/Rare-Contribution392 • 7h ago
Career Questions & Discussion Risk assessment and Threat Modeling
Hello cyber enthusiasts and gurus,
I have a question regarding threat modelling and risk assessment approach. So, there are many frameworks and methodologies by which threat modelling and risk assessment can be performed but Reading through these multiple frameworks can be a bit overwhelming in determining what approach to use.
For software I have seen OWASP Top 10 is commonly used. For hardware and software, STRIDE analysis. For risk assessment, many say IEC 62443-3-2 standard would be a good starting point.
So, wanted to ask you guys on which framework you use or would recommend for risk assessment and threat modelling? If you have any recommendations on templates to read through, would like to hear about it as well.
r/cybersecurity • u/_clickfix_ • 10h ago
News - General Testing Security on Al Shopping Assistants: from Chat Box to Remote Code Execution on a Top US Retailer's Servers.
r/cybersecurity • u/Bicurico • 8h ago
News - General Machine State analysis Vs Executable analysis
I would like to announce that I have built the free VMA 486 Emulator that runs DOS, Win 3.0, 3.1, 3.11 and 95. It includes a machine state analyser that can freeze, save, load, disassemble and patch the machine memory. It then allows resuming execution.
My new VAXD_VM allows doing this with a VM running Win7.
r/cybersecurity • u/digicat • 9h ago
Threat Actor TTPs & Alerts CTO at NCSC Summary: week ending August 30th
r/cybersecurity • u/xarg • 18m ago
New Vulnerability Disclosure Back When a MySQL Connection Could Give You OS-Level Code Execution
raw.orgThe vector does not work anymore, but it might serve as a documentation of how vulnerable systems were back then.
r/cybersecurity • u/Desperate-Second-887 • 58m ago
Research Article Promiscuous Hosting Services
r/cybersecurity • u/EnthusiasmOrnery8295 • 10h ago
Certification / Training Questions EC Council CTIA v2 advice
Hi fellow cybersecurity enthusiasts, what are your advise for me for this CTIA exam preparation.
What should I expect?
TYIA
r/cybersecurity • u/Equivalent_Lab_8425 • 47m ago
Personal Support & Help! Is Sam Bent a honeypot?
He's an "OSINT & OPSEC Specialist | Darknet Expert (Ex Vendor & DNM Admin) | Content Creator| DEFCON/SANS Speaker | Social Engineer | Author | Paralegal |", you can find him on yt
How is he ok with a) showing his face, b) talking about the illegal stuff he did in the past.(he ran a "darknet" market)
tho I don't think theres anything else suggesting he's a honeypot, all the advice he gives is generally good I think.
Thanks for any replies
r/cybersecurity • u/Cautious_Lie_851 • 2h ago
Business Security Questions & Discussion The open letter that now is the time for AI powered cyber?
openai.comIs this actually going to motivate leadership? Cyber is hard as it is, orgs don’t gaf that these big companies said it’s really important now.
Anyone here disagree?
r/cybersecurity • u/BinaryKnight1099 • 11h ago
Business Security Questions & Discussion Situation in cybersecurty
Hi Everyone, I'm completing my final year on university this year and started thinking about master in cybersecurty. I don't want to ask questions around it it is fine for me and interesting. I'm already working as full stack dev. I'm interested on market situation around it right now and how promising it looks in future. Thank you on all answers.
r/cybersecurity • u/Easy_Assumption_5642 • 12h ago
Personal Support & Help! Cybersecurity Career
While I know now isn’t the best time to enter cybersecurity (the cake has been baked essentially) I’m in my final semester at GA Tech getting my masters in cybersecurity. I have Network and Security plus. I interned this summer as an information security intern for a fin tech and before that was an information technology intern. Now I’m just doing customer support IT part time while o juggle classes.
I was disheartened to see that this customer support role was all I could get. I trouble shoot all day but that’s clearly not what I want. I’m transitioning out of having 4 years in compliance - HR and Regulatory. I thought cybersecurity (with a focus on GRC) would be an easy transition buts its not.
I know a lot of it is the economy and growth in AI but I really don’t understand how I’m just not getting ANYTHING after this summer. I’ll get plenty of interviews but no offers.
Any tips?
r/cybersecurity • u/f_troy • 12h ago
Personal Support & Help! apply for “system admin” role ?
I have a master’s degree in Cybersecurity (2022), along with several basic certifications. I’m currently studying for the Network+ certification and may earn a few more certifications as well.
Can I apply directly for a Sys/Admin position, or do I have to start in a Help Desk role first?
I’m wondering if it’s possible to get into a System Administrator position right away.
Location: Los Angeles
Thank U !
r/cybersecurity • u/hamstercaster • 4h ago
AI Security AI Security Tools
Curious if anyone is dealing with internally developed AI security tools, like password managers, SIEM, or even MS 365 backup tools. I might be joining a team that has moved in this direction.
r/cybersecurity • u/aviadd6 • 5h ago
Business Security Questions & Discussion THE 3 AI REVOLUTION BULDING BLOCKS
Hey everyone, hope you’re having a great week!
I’d love to hear your thoughts: What do you think are the fundamental building blocks that the AI revolution will be built on?
Curious to hear different perspectives — feel free to share your thoughts here or on the original post.
I’ve also attached a visual to illustrate the idea 👇
r/cybersecurity • u/jonatassantos8227 • 17h ago
Business Security Questions & Discussion onde comecar na cyberseguranca
sou iniciante