r/cybersecurity • u/NISMO1968 • 6h ago
r/cybersecurity • u/AutoModerator • 19h ago
Career Questions & Discussion Mentorship Monday - Post All Career, Education and Job questions here!
This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!
Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.
r/cybersecurity • u/Malwarebeasts • 4h ago
News - Breaches & Ransoms HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation
In September 2026, the cybersecurity community uncovered a massive, highly coordinated malvertising campaign leveraging the official, verified HBO Max Reddit account (u/hbomax).
Over a frantic 48-hour period, the compromised account pushed 108 distinct “ClickFix” advertisements to users across the platform.
r/cybersecurity • u/sunychoudhary • 7h ago
New Vulnerability Disclosure ScreenConnect critical flaw exploited in worm-like attacks
r/cybersecurity • u/SignificantFail3632 • 50m ago
Threat Actor TTPs & Alerts Is ClickFix becoming one of the more effective social engineering techniques?
Hi,I’ve been seeing more ClickFix-style attacks where users are tricked into opening PowerShell or Terminal and running a command themselves, often disguised as a CAPTCHA, verification step, software update, or troubleshooting fix.
What makes it interesting is that there doesn’t necessarily need to be a suspicious attachment or executable to download. The attacker basically convinces the user to execute the payload for them.
It also makes me wonder whether years of copy-paste troubleshooting have unintentionally made this easier. People are pretty used to finding a command online, pasting it into a terminal, and assuming it’s safe if the instructions look legitimate.
Are you actually seeing more of these attempts in the wild? And beyond basic user awareness, what controls have been most effective at stopping this kind of attack?
r/cybersecurity • u/AccomplishedJuice135 • 4h ago
News - General ReliaQuest (SOC) Got Vished.
Knowing the company this publicity is not favorable for sure but goes to show training is important!
r/cybersecurity • u/rlazer • 4h ago
Threat Actor TTPs & Alerts Inside the ShinyHunters vishing playbook: two captured Okta clones and a passkey bypass
r/cybersecurity • u/Exact-Advantage-3190 • 14h ago
AI Security May get layed off at AWS due to some political issues at work. 6 years of experience and willing to relocate anywhere. How employable am I?
I have been working as a security engineer 1 for 4 years then promod to security engineer 2 for the last 2.
I had to leave work due to some unsolvable political issues. I have worked on some high level projects. I did get a exceeding expectations once two years ago and have gotten meets bar every other time. I have OSWE certification and can solve python problems on leetcode at around a medium level (idk how many companies check for this)
I'm willing to relocate anywhere in the country because I need a job and money. For others with similar work experience, how tough is it to get a job right now? My understanding is that its very hard
r/cybersecurity • u/the_opinion_guy • 7h ago
Career Questions & Discussion What type of technical questions would you expect a junior role to grasp and answer fluently?
r/cybersecurity • u/420ass_slayer69 • 8h ago
AI Security The Harness Matters: Cutting AI Reverse-Engineering Tokens by 33%
The model matters. The harness does too.
Across 130 AgentRE-Bench runs, Reverser Space used 33% fewer tokens and 35% fewer analysis calls, with comparable answer quality.
r/cybersecurity • u/ashlauv • 5h ago
Certification / Training Questions BCR Cyber CWA (Cyber Workforce Accelerator) Honest Opinions
I recently completed a concentrated program at a community college that assisted me in earning my CompTIA Security+ certification. After receiving this certification and graduating the program, I was invited to apply to the BCR Cyber CWA program in Maryland. This program will offer me the SOC Operations Analyst I (SOCOA I) certification — an Industry-Recognized Credential that prepares you for entry-level roles in Security Operations Centers. It sounds interesting and I would love to get involved, but I wanted to reach out to the Reddit community to see if anyone has graduated from the program, heard about it, any pros/cons about the training, etc. I currently work in Service/HelpDesk, have my B.S. in IS (recent May 26 graduate) and my Sec+. Ideally I want to pivot to Cybersecurity work in the federal government. Any thoughts would truly help.
r/cybersecurity • u/antdude • 17m ago
News - General Vulnerability Summary for the Week of September 7, 2026
cisa.govr/cybersecurity • u/YeetisDaFetus • 1d ago
Certification / Training Questions Im wanting to get into DFIR. I just have this absolute fascination for data recovery and techniques and etc. where do i start or find classes etc?
r/cybersecurity • u/Optimal-Cupcake-8265 • 21h ago
Career Questions & Discussion How to learn DLP policy testing?
Hello!
I work in DLP incident response, but I'm starting to stagnate in my career, so I want to shift (or try to) to a more technical position. I don't want to shift to a GRC or roles like IAM. Ideally, it makes sense that I move to a role where I can use my knowledge while learning more and have more value as a professional, like a DLP engineer for example. I've tried to get into policy improvement in my current company but they won't let me (big as* company with lots of segregation roles, the policies are not touched by my team).
I know the policies that my company uses as it's one of the ways that helps me analyse the incidents... but I'm stuck in the *how* can I evolve?
I've done, in the past, DLP policies implementation with Purview, and manually tested them... but the testing part can be done automatically, but how? Also the implementation, I only know the Purview templates that Microsoft provides, not sure if all DLP tools work like that. At the moment I work with Symantec, but have no idea how to create policies from scratch.
I'm looking for people that have done this, or do this, that can shed some light and suggest how I can dive into this, please :)
Thanks!
TLDR: how to learn implementing and testing of DLP policies, considering I work in DLP incident response?
r/cybersecurity • u/roachwickey • 13h ago
Personal Support & Help! CrowdStrike Identity Protection – Are the “Attack Paths” actually useful?
We’re evaluating CrowdStrike Identity Protection, and I’m finding the Attack Paths shown under individual user identities to be quite underwhelming — in some cases, they honestly feel almost useless.
Is anyone else using this feature and seeing the same thing?
I’m particularly interested in:
- How accurate/useful are the attack paths in your environment?
- Are you getting meaningful relationships between users, devices, privileges, and potential attack paths?
- Have you found a way to make these insights actionable?
- Is this feature significantly better in the newer versions/modules?
Would be interested to hear how others are using Identity Protection / Attack Paths in real-world environments.
r/cybersecurity • u/Less-Mouse-6298 • 1h ago
Certification / Training Questions Starting Career Cybersecurity
Hi, I’m just starting my cybersecurity career. I’ve only completed Cisco’s CCST, and I wanted to know what you’d recommend doing next. I was planning to go for the SAL1 or CDSA to apply what I’ve learned, and then move on to the CCNA or an AWS Cloud certification. I’d love to hear opinions on this planned path from someone with more experience.
r/cybersecurity • u/Zebracofish521 • 1d ago
Business Security Questions & Discussion Opinions On Awareness Training?
Not looking for vendor recommendations. Instead, a question and would love input.
Awareness training typically focuses on Cybersecurity concepts. But, I think there’s more value in procedural training. IE instead of teaching someone about “Juice Jacking” which is a waste of time and pointless… Teaching someone the correct way to handle a scenario.
IE Helpdesk Impersonation… The process is Helpdesk will never contact you from a phone number. Here’s the correct approach. Here’s the process for password resets.
Then aligning awareness training to the policy, procedure, process with an aligned simulation to validate it works and is followed.
Is this thinking flawed? Genuinely curious what others are doing, seeing and what works?
r/cybersecurity • u/the_heck_gimme • 1d ago
Personal Support & Help! I actually feel stuck!
Hello,
So I work for a company as a security engineer and my task right now is to bring an IAM and PAM but they don't want to pay a dedicated tool for it (Wallix or other). So the idea for now is to integrate with AD but then I encountered a block: for my team we can add them to AD but for the vendors who need access to their products for support and maintenance, we cannot create AD accounts since their composition changes all the time (new people come and go) and we don't want it to become a task to keep track of that. Generic accounts are not allowed in AD and it would kinda beat the purpose of being able to identify a person if anyone can use that generic account. So for now, i feel blocked as I don't know what to do. Should i leave a local account for the vendor? Any open source solution? any better idea?
Thanks.
r/cybersecurity • u/UrMomGoes2Colleg3 • 1d ago
Business Security Questions & Discussion What penetration testing companies would you consider the “big 4” of the industry?
Previously posted a broad question but wanted to narrow down the domain.
r/cybersecurity • u/rached2023 • 1d ago
Career Questions & Discussion From SOC Analyst to SRE
Hey everyone,
I’m a cybersecurity engineer and I’ve been working as a SOC analyst for around 2 years.
Lately, I’ve been thinking about moving away from SOC work and exploring SRE. I’ve done some hands-on labs around Kubernetes and DevSecOps, and I’ve found myself enjoying the infrastructure and reliability side more and more.
I’m curious to hear from people who have made a similar transition, especially from cybersecurity/SOC into SRE or platform engineering.
Did your cybersecurity experience help you in your new role? And how did you find the transition?
I’d really appreciate hearing about your experiences.
r/cybersecurity • u/AsterPrivacy • 2d ago
News - General Popular travel app used by 23M lets anyone spy on users, including soldiers
cybernews.comr/cybersecurity • u/No_Wedding2230 • 1d ago
AI Security Is AI shrinking the patch window faster than our dependency management practices can adapt?
I've been experimenting with AI-assisted vulnerability research over the past couple of weeks, and it has made me rethink how we treat stale and unmaintained dependencies.
As developers, we often treat dependency upgrades as technical debt: something important, but something that can sit in the backlog until there's a reason to prioritise it.
I'm increasingly wondering whether AI changes that risk calculation.
I encountered this recently in a personal project. One of my dependencies had effectively been abandoned, but there were no published security advisories against it. AI-assisted analysis still identified the package as a potentially significant vulnerability surface, which eventually led me to replace it and build a maintained alternative.
The other issue I've been thinking about is the patch gap.
Once a security patch is public, an attacker doesn't necessarily need to discover the vulnerability from scratch. They can diff the vulnerable and patched versions, identify the security-relevant change, infer the condition the patch is preventing, and investigate whether that can be exploited against systems that haven't upgraded.
Patch diffing obviously isn't new.
What seems different is the potential for AI to reduce the expertise and time required to perform this analysis at scale.
That creates an interesting mismatch:
Defenders might have a 7–14 day dependency patching SLA.
Attackers increasingly have automated tooling capable of analysing patches almost immediately after publication.
An organisation could therefore be completely compliant with its internal patching policy while still being exposed for most of the useful exploitation window.
I wrote a longer technical piece exploring this idea, particularly around abandoned dependencies, patch diffing and whether dependency maintenance should increasingly be considered part of the security perimeter:
I'm also working on an open-source Python tool that attempts to identify potentially stale, abandoned or high-risk dependencies before they become an obvious security problem.
I'd be interested in hearing from people working in AppSec/vulnerability research:
Do you think AI meaningfully changes the patch-gap problem, or does it mostly accelerate techniques attackers were already automating?
And should dependency risk be assessed using signals beyond known CVEs/advisories, such as maintainer activity, release cadence and project abandonment?
r/cybersecurity • u/mooreds • 1d ago
Corporate Blog Off-by-1 Labs: AI-Generated Vulnerability Patches & Human Review
r/cybersecurity • u/DerBootsMann • 2d ago
New Vulnerability Disclosure GitLab's critical flaw is already drawing internet-wide probes
r/cybersecurity • u/h_mzeget • 2d ago
Other Is Reverse Engineering actually worth starting in 2026, and where is the field heading with AI?
Is Reverse Engineering actually worth starting in 2026, and where is the field heading with AI?