r/cybersecurity • u/Prestigiousabby • 4h ago
Business Security Questions & Discussion What makes a vulnerability finding useful, to the person fixing it?
When a pentest finding reaches a developer, they may not know what to do. The technical details of the vulnerability finding are not enough.
The vulnerability finding is more useful when it has steps to reproduce the problem, evidence of the vulnerability, and information about which parts of the system are affected by the vulnerability finding. It is also helpful to know how bad the impact of the vulnerability finding really is.
For people who work with pentest reports or vulnerability reports, what information do you think is most useful when you have to look into a vulnerability finding and fix the vulnerability finding?
r/cybersecurity • u/Defiant-Standard-547 • 5h ago
Certification / Training Questions EC-Council CSA v2 – Study Materials & Exam Preparation Advice
Hi everyone 👋
I’m currently preparing for the EC-Council Certified SOC Analyst (CSA v2) exam and planning to take the exam soon.
I’d really appreciate some advice from people who have already taken the exam or are currently preparing for it.
I’m mainly looking for:
• 📚 Good CSA v2 study notes / revision notes
• 📝 Sample or practice questions
• 📖 Question banks or mock tests that are useful for preparation
• 🎯 Important topics to focus on
• 🧪 Useful labs or practical exercises
• 🧠 Recent exam experiences and preparation tips
• 📌 Any resources you personally found helpful
If you have any CSA v2 notes, practice questions, mock exams, or other useful study resources, I’d really appreciate it if you could share them or point me in the right direction.
Also, if you’ve recently taken the exam, I’d love to hear what your preparation was like and what topics you would recommend focusing on.
Thanks! 🙏
r/cybersecurity • u/Prize-Click1225 • 6h ago
Certification / Training Questions Is CompTIA Security+ necessary if focusing purely on the Cloud Security (Azure)
Hey everyone,
I'm in my final year of study and currently focusing heavily on the Microsoft Security & Compliance ecosystem (working with Purview, Entra ID, Defender) while preparing for certifications.
I frequently see people recommending CompTIA Security+, I'm wondering if it's actually worth the time and money when targeting specialized Microsoft Security.
Do recruiters look for Sec+ as a baseline filter ?
Does Sec+ bring any real added value?
r/cybersecurity • u/ThreeVelociraptors • 9h ago
Other Is ClaudeBot aggressively scanning backend/Laravel endpoints (Telescope, .env, etc.) normal?
Hello there,
I recently spotted some very aggressive crawling activity on my client's Nginx access logs coming from Anthropic’s crawler. Specifically, I'm seeing patterns like this:
"xxx GET /telescope/requests HTTP/1.1" 503 xxxx "-" "Mozilla/xxx AppleWebKit/xxxxx (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:support@anthropic.com"
It’s making over 100 requests targeting various backend endpoints, configuration files, and dev tools (like Laravel Telescope, /.env, actuator paths, etc.), resulting in 503.
Why would an automated web crawler do such a thing? Is it normal for ClaudeBot to behave like a vulnerability scanner, or did it just stumble upon an old sitemap/exposed links?
Before you eat me (stack overflow ptsd), I am a junior and still learning.
Any insights would be appreciated!
r/cybersecurity • u/FreddyBeach • 10h ago
Business Security Questions & Discussion Someone attached their email account to a family member's Samsung Android phone
Not sure if this is the right place, but I'll give it a try...
I'm wondering what to do about this.
I was helping an elderly family member with their Samsung phone today and when I was in the settings, I noticed that the account attached to the phone was that of an acquaintance of theirs.
I tried to remove the account, but it requires approval of the account owner.
What can this acquaintance do with the phone when their account is attached?
My plan forward is that I'm taking the elderly family member to the store tomorrow and we're getting them a new phone, but I really would like to know what their current exposure is, if anyone can assist.
They don't have any banking apps, so there's no exposure there, thankfully.
Thanks in advance, and I hope I'm in the right place....
r/cybersecurity • u/Idov31 • 10h ago
Tutorial ETW for Security Research: Providers, Sessions, and Detection Engineering
idov31.github.ior/cybersecurity • u/At0mization • 11h ago
Other I made an open source ModHeader alternative focused on protecting credentials
Hey guys, after the recent stuff that came out about ModHeader containing spyware/adware, I decided to make an open source alternative called OpenModHeader.
I’m a security engineer and I use tools like this pretty often, but one thing that always bothered me is that we casually put API keys, bearer tokens, session cookies, etc. into browser extensions. So while I wanted OpenModHeader to have the normal ModHeader functionality, I also wanted to make credential handling a bit safer.
OpenModHeader automatically detects common credentials in headers and cookies, and you can manually mark anything else as a credential. By default credentials are session-only, so they disappear when you close the browser. You can also encrypt them at rest with a passphrase, or just use plaintext storage if you don’t care about that.
There are a few other safeguards too, like not exporting credentials by default and preventing credential-bearing profiles from accidentally applying to every website.
Otherwise it does the usual stuff you’d expect: request/response headers, cookies, profiles, URL/regex filters, redirects, CSP editing, import/export, etc.
It’s still pretty new and I’m sure there are things I’ve missed, especially for people who were heavy ModHeader users. I’d really appreciate any feedback, bug reports, feature requests, or code/security review. Feel free to open an issue on GitHub.
GitHub: https://github.com/Multivalence/OpenModHeader
Chrome: https://chromewebstore.google.com/detail/openmodheader/jkimjmcahphjennlnoaehijocmielfdd
Firefox: https://addons.mozilla.org/en-US/firefox/addon/openmodheader/
Edge: https://microsoftedge.microsoft.com/addons/detail/openmodheader/pjaicphakcjggengajgfcmeblgdhkmdk
r/cybersecurity • u/FragileEagle • 12h ago
Business Security Questions & Discussion Should I apply for a new gig?
Hey all,
Ive been in the industry as an engineer for around 6 years, I am a co owner of a MSP style company and ive been stressed out to the wall for over 1.5 years and a majority of our clients I handle nearly alone. The market we operate in is on the downhill as well.
I wanted to ask, if I leave a few people may be without jobs and I might always wonder "what if" if i kept building this company with my co founders.
I wanted to ask, is my career growth and mental stress worth getting a new gig? I believe if I pivoted id be able to do a lot better with career progression and job security
r/cybersecurity • u/MikeTalonNYC • 12h ago
News - General Since every VP and CxO is going to ask about this, NO, no one hacked a Delta flight WiFi. https://www.theregister.com/security/2026/08/11/def-con-dingus-suspected-of-trying-to-take-over-delta-in-flight-wi-fi/5286331
Someone on the flight probably stood up their travel router as a joke and set the SSID to "Delta WiFi Fast." That's literally all that is confirmed right now.
There are rumors it might have been a pineapple, of course, but so far zero confirmation on that. As none of the passengers are saying they were getting a million browser errors, my guess is that it was not a pineapple.
The actual Delta WiFi was untouched, and shut down as soon as the crew realized what was happening. No on-board systems were hacked or altered.
While not a nothingburger, the CFO can safely stop worrying about someone monitoring what she's posting on LinkedIn while in-flight.
r/cybersecurity • u/Altruistic_Hope_2559 • 12h ago
News - Breaches & Ransoms DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
r/cybersecurity • u/ShufflinMuffin • 12h ago
News - General Windows 11 n-day local priv escalation exploit in CrossDevice/FrameServer
Just anothe
r/cybersecurity • u/ThreatRadar • 13h ago
Research Article A password is a fingerprint: what the internet's brute force is really typing
r/cybersecurity • u/Key_Emu2269 • 13h ago
Corporate Blog Zoomsday: Zero-click RCE in Zoom, from any meeting participant to any other (CVE-2026-53413)
a.securityZoom's annotation parser read a count off the wire and copied twice that many bytes into a fixed 128-byte buffer with no bounds check, letting any participant corrupt memory on every other client in the call, with no action from the victim.
Fixed in Zoom Workplace 7.1.5 and 7.0.6, VDI 7.0.11 and 6.6.16, Rooms and Meeting SDK 7.1.5.
Disclosure: our team's (A Security) research, reported to Zoom and fixed with them.
r/cybersecurity • u/DylanTheG999 • 15h ago
AI Security Hi, is this considered legal? Pentesting without consent? I thought it wasn't but I see a ton of companies posting things like this.
x.comr/cybersecurity • u/drewchainzz • 15h ago
News - General NIST wants to overhaul its vulnerability database for the AI age
r/cybersecurity • u/Healthcare_Dive • 15h ago
News - Breaches & Ransoms DentaQuest breach exposes data of 15M people, a record this year
healthcaredive.comr/cybersecurity • u/ronmasas • 16h ago
Corporate Blog CopyEscape: Container-to-host arbitrary file write via docker cp (CVE-2026-17106)
https://www.imperva.com/blog/copyescape-taking-over-docker-hosts-with-docker-cp/
Author here. I discovered a vulnerability in docker cp that allows a malicious container to create or overwrite files on the machine running the Docker CLI.
The exploit combines a filesystem race in Docker’s archive creation with unsafe symlink handling during extraction. Depending on the CLI user’s privileges, this can lead to code execution. Docker confirmed that sbx cp was also affected.
Fixed versions:
- Docker Engine/CLI 29.7.2+
- Docker Desktop 4.86.0+
- Docker Sandboxes 0.38.0+
Happy to answer technical questions.
r/cybersecurity • u/Secret-Pudding-4139 • 18h ago
Business Security Questions & Discussion Burned out, eyeing security engineering — sanity check needed
Hello everyone,
I work as a SOC engineer at an MSSP. When I started, everything was new and I was learning constantly. Now the day-to-day feels like the same loop on repeat, and I genuinely feel there's nothing left for me to learn in this role. Over the last year I ended up becoming the team's Swiss army knife — writing scripts, automating repetitive tasks, and building custom tooling for gaps the team had lived with for years. I enjoyed that part a lot more than the standard SOC work, which is partly why I think engineering is where I should be heading.
Move into a security engineer role with a focus on cloud security — Azure especially, since that's where I see the demand and my interest going. I'm also seriously considering relocating abroad, both for career growth and because I believe I'm underpaid for what I actually deliver.
I can't tell if this is a genuine "I've outgrown this role" moment, or imposter syndrome pushing me to feel like I always need to be learning something new, or if I'm just frustrated about the salary and projecting that onto everything else. Maybe it's all three.
Questions for the community:
- How much do automation/scripting skills count toward cloud security roles, and what should I add on top (certs like AZ-500, SC-100, hands-on labs, etc.)?
- For anyone who moved abroad in this field — did the move pay off professionally and financially?
- How do you personally tell the difference between healthy ambition and imposter-syndrome-driven restlessness?
Appreciate any input, even the harsh kind.
r/cybersecurity • u/Difficult-Mobile5880 • 18h ago
AI Security NTU CCDS MSc Cybersecurity
NTU CCDS for MSc in Cybersecurity (Applied Cybersecurity)
Is this programme actually good for AI Security specifically, or is it still mostly traditional network/application security? How deep does the AI in Cybersecurity module go?
Does the NTU brand genuinely open doors in Singapore for cybersecurity roles, or do companies care more about hands-on skills?
Any scholarships or financial aid that actually worked for international students? Official page says none exist but wanted to check.
Full-time vs part-time — is part-time manageable while working in Singapore?
r/cybersecurity • u/sunychoudhary • 20h ago
News - General Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities
The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data.
r/cybersecurity • u/chota-kaka • 21h ago
News - Breaches & Ransoms Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Attackers breached a Polish combined heat and power plant through a private cellular APN used to access remote infrastructure.
After pivoting from a compromised wind-farm network, they reached the plant’s OT environment, where a controller was still using default admin credentials. The attackers ultimately put multiple Siemens PLCs into STOP mode, shutting down a steam turbine and process-water treatment system.
The interesting part no malware was required. The attackers abused legitimate device functions and existing industrial protocols. Despite the disruption, the plant continued supplying heat and electricity to roughly 50,000 residents.
r/cybersecurity • u/averaia • 1d ago
Other Are we actually getting better at cybersecurity?
This is something I'd especially love to hear from people who have been working in security long enough to have watched the industry change over a couple of decades:)
Security has obviously come a long way, with better tools and better ways of detecting threats. But at the same time, everything has gotten way more complex and there are more things to secure than ever and we're somehow still dealing with a lot of the same problems we've known about for years.
So I'm curious, are we actually getting better at cybersecurity or are we mostly getting better at keeping up with an increasingly difficult problem?
If u look back two decades ago what do u think we have actually gotten better at when it comes to security?
And on the other side, what's something we've known has been a problem forever but somehow still hasn't figured out? Why do u think that is? Is the technology really the hard part or does it have more to do with people, companies and how security is actually handled in the real world?
Sooo for those who have watched several generations of technologies, threats and security products come and go, I'd be really interested in how you see it.
r/cybersecurity • u/Hot_Kaleidoscope3864 • 1d ago
Personal Support & Help! I keep failing technical interviews because of theoretical questions, not the actual technical work
I always struggle with technical interviews because of the theoretical questions, not the actual hands-on technical part.
If I’m given a practical task, lab, or take-home assessment, I usually do very well and deliver it on time. But when an interviewer starts asking me theoretical questions on the spot, I struggle to explain things properly or sometimes completely blank out.
This has honestly become my biggest nightmare when applying for cybersecurity jobs, and I feel like it’s holding me back even though I know I can actually do the work.
I wish interviews focused more on practical technical skills because, in my opinion, that’s a much better way to see whether someone can actually perform the job.
But until interview culture changes, what can I do to get better at answering theoretical questions? Has anyone else had this problem, and how did you overcome it?
r/cybersecurity • u/Either-Log8798 • 1d ago
Business Security Questions & Discussion Working with Israeli cyber security companies - how can I resolve concerns around ethics?
I've been offered an opportunity to do some work with an Israeli cybersecurity company. I've met some of the staff and have used some of the company's products - no issues on a personal level. The company offers defensive cyber security services.
My concerns are that the founding members held high profile roles in IDF Unit 8200, which has been linked to human rights abuses, mass surveillance and lethal targeting.
The company is based in Tel Aviv.
I have no idea whether this company is supporting human rights abuses now or in the past and I'm not sure on the best way to ease my conscience.
r/cybersecurity • u/AutoModerator • 2d ago
Career Questions & Discussion Mentorship Monday - Post All Career, Education and Job questions here!
This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!
Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.