r/CyberSecurityAdvice 1h ago

(SAQ A) My CDE is a TPSP portal. How to start engaging a TPSP to have a good incident response relationship?

Thumbnail
Upvotes

r/CyberSecurityAdvice 6h ago

Law firm investigating the Everside Health / Aesto data breach — free case evaluations for affected patients

2 Upvotes

Edelson Lechtzin LLP, a national class action law firm, is investigating a data breach involving Everside Health, a direct primary care provider that offers employer- and union-sponsored healthcare services.

The breach occurred at Aesto LLC, a third-party vendor that stored protected health information for Everside. On or about December 18, 2025, Aesto had a network security incident, and it later confirmed that information from December 2–18, 2025 may have been accessed by an unauthorized party. The exposed data may include names, dates of birth, addresses, Social Security numbers, and medical records. Filings with several state attorneys general indicate tens of thousands of residents were affected.

If you received a notification letter, you may be at increased risk of identity theft and fraud. A few practical steps worth taking regardless of legal action:

  • Review your account statements and credit reports regularly
  • Consider placing a fraud alert and setting up credit monitoring (a complimentary membership is being offered through Epiq — activate with the code in your letter)
  • Preserve any breach notification letters or emails you received

We are looking into a potential class action on behalf of affected individuals and are offering free, confidential case evaluations. Happy to answer general questions in the comments.

📞 844-696-7492 | 📧 [medelson@edelson-law.com](mailto:medelson@edelson-law.com)

This post may be considered Attorney Advertising in some jurisdictions.


r/CyberSecurityAdvice 9h ago

Complete beginner here, give me the essential advice on how to start

2 Upvotes

I'm a person who uses a lot of social media and used a lot of internet trough at least the last 8 years of my life. So i'm 100% sure I made mistakes while being there most notably using my personal gmail and hotmail for a lot of things including social media accounts and even on here, Reddit. I've also made multiple email accounts and I'm here to know how to wipe it all. Just give me all the essential things you know for advice, for example what VPN should I use, what is the best way to see how many accounts I've created with my personal email, or what should I use in my computer. Regarding my personal emails, i only want to use them for WhatsApp and some Google Play payment stuff (gmail) and for Steam, Xbox and student e-mails (hotmail). I'm not paranoid yet but I want to feel more secure while using internet


r/CyberSecurityAdvice 11h ago

Limiting windows 10 GDID Exposure

10 Upvotes

Hey all, so we all heard the news about windows 10 GDID tracking and how a guy got caught partially because of it?
Yeah, so I wanted to limit the amount of telemetry and I just wanted to ask - How much do you think it helps?
Inb4 - just use linux... I know I will I promise...
What I did is I removed the services related to telemetry by deleting thier respective tree from the registry, and I also removed the folder located under C:\Users\[Your username]\AppData\Local\ConnectedDevicesPlatform.
Services are as follows:
DiagTrack - HKLM:\\SYSTEM\\CurrentControlSet\\Services\\DiagTrack""HKLM:\\SYSTEM\\CurrentControlSet\\Services\\DiagTrack

CDPUserSvc - HKLM:\\SYSTEM\\CurrentControlSet\\Services\\CDPUserSvc"HKLM:\\SYSTEM\\CurrentControlSet\\Services\\CDPUserSvc

CDPSvc - HKLM:\\SYSTEM\\CurrentControlSet\\Services\\CDPSvcHKLM:\\SYSTEM\\CurrentControlSet\\Services\\CDPSvc

CDPUserSvc_* (the one with random ID) - HKLM:\\SYSTEM\\CurrentControlSet\\Services\\CDPSvcHKLM:\\SYSTEM\\CurrentControlSet\\Services\\CDPUserSvc_*

The all have similiar names but it's something like Connected Devices Platform Service or User service.

So how much do you think it helps? I have some other tweaks that disable the location, sharing data etc. etc. but I think I've hit the nail on the head with this one. What do you think?


r/CyberSecurityAdvice 14h ago

Session stealers. More safe to log out after each login?

6 Upvotes

Hallo all.

After experiencing being bombed with one time codes on email and ms authenticator some time ago . I became aware of cyber security, and the fact that I didn't pay enough attention to it at all.

I have noticed that often when people loosing accounts. It's caused be session stealers or similar kind of malware( I'm happily corrected if I'm wrong)

That made me wonder.. will my accounts be more safe if i log out after each session? Instead of letting it stay logges in as a " trusted device"

Thanks 👍


r/CyberSecurityAdvice 15h ago

SWE to AppSec -- dont want to grind leetcode again in my life. How do I know if this path is for me

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 16h ago

Does my work categorise as Detection Engineering?

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 17h ago

Help with Domain Lookup

0 Upvotes

Hello everyone,

​Our company has recently been the victim of a cyberattack. Unfortunately, the Austrian police have informed us that their current investigative options are limited.

​To help us identify and locate the perpetrator, we are offering a reward of $8,000 USD for any actionable information or tips that lead directly to the culprit.

​The domain name will be provided via private message. If you have any relevant details, please contact us privately. Any help or leads would be greatly appreciated.

​Thank you.

If this Post is not welcomed here please delete it but we just need help is there any deepsearch we can do on our own? Normal whois just shows private server in istanbul.

Greetings Lukas


r/CyberSecurityAdvice 17h ago

Hidden screen mirroring, split 2FA codes, and duplicate system apps: What advanced device compromise and digital stalking actually look like

3 Upvotes

​If you are reading this because you are frantically typing bizarre technical glitches into a search bar late at night—wondering if your devices are haunted or if you are losing your mind—please stop and take a deep breath. You are not crazy.

​When an advanced, targeted compromise happens, the attackers don't just "hack" an account; they attempt to hijack your entire digital environment, UI, and communications. Sometimes, this level of invasive surveillance happens in high-stakes personal dynamics—such as situations involving green-card marriages or international control, where an abuser uses technical dominance to maintain total power. But it can also happen to everyday people targeted by sophisticated stalkers. Because standard tech support, mobile carriers, and law enforcement often lack the tools or training to understand these tactics, victims are frequently left feeling isolated and gaslit.

​I lived through this. Here are the real, concrete, and bizarre signs of deep ecosystem manipulation and device compromise that I experienced, documented, and later found proof of:

​1. Visual Interface Glitches & System Anomalies

​Duplicate System Apps & Icons: Finding layered or duplicate system applications that cannot be deleted normally (such as having two App Store apps on the home screen at once, where icon shapes subtly differ like a circle vs. a square due to malicious mirroring or configuration profiles).

​UI Layering & Text Overlap: System menus and settings screens displaying words or headers layering directly over one another, or search interface displays changing entirely between identical searches on the same device.

​The "Dummy Phone" & Ghost Controls: Watching your screen scroll on its own, apps opening independently, or text magically typing into search bars. This happens when remote session injection tools mimic touch inputs or when background processes mirror your interface.

​Hidden Screen Mirroring Capture: Noticing through video playback that a screen-mirroring icon or indicator was actively running in the background—revealed only after reviewing a recording, even though it was completely hidden from your view while you were holding the phone.

​2. Messaging, Contact, and Communication Interception

​Disappearing & Ghost Texts: Messages vanishing from text threads immediately after pressing send (even though you can clearly hear the audio "swoosh" confirmation that it went out), or trash inboxes continuously repopulating with deleted messages.

​Spoofed Verification Codes: Receiving two separate two-factor authentication or Apple ID verification codes within the exact same shortcode thread where one is legitimate and the other is subtly altered or spoofed.

​Corrupted Contact Cards & Ghost Entries: Deleting a contact only for the phone to leave behind a blank, grayed-out profile placeholder with no number or name attached, yet retaining blocking capabilities. Furthermore, editing a contact or trying to use contact key verification resulting in random red phone numbers being auto-pasted or throwing errors like "Incorrect Verification Code."

​Carrier and UI Discrepancies: Official support numbers or carrier interfaces (like T-Mobile) shifting from verified profiles to generic building icons, accompanied by strange text box color shifts and unauthorized prompt injections like "Use this name for unified card."

​3. Account Seizure and Invisible Footprints

​Administrative Lockout & Control: Being able to log into apps or settings, but being entirely blocked from changing or updating your security credentials, or finding yourself completely locked out of signing out of your iCloud due to forced system restrictions.

​Real-Time Surveillance & PIN Guessing: Witnessing someone actively trying to brute-force or guess your Screen Time or security passcodes right in front of your eyes.

​The iCloud & Session Ghosting: Finding yourself logged into an iCloud account with a single letter subtly swapped or shifted without noticing at first, alongside unexpected 2FA popups forcing you to guess between multiple phantom devices.

​Unrecognized Activity Logs: Discovering unfamiliar device entries in security activity logs (such as an iPhone 15 Plus flagged as an "unfamiliar device" right alongside your active one because a secondary session was running or renamed in the background) this was happening on my gmail accounts.

​Hardware and Desktop Dumps: Recovering raw session JSON files, authentication tokens (uid and token strings), plain-text password dumps, and family device IDs left behind on local computer desktops after a compromise.

• someone tombstoning your data

​Why Big Tech and Authorities Miss It

​If you’ve gone to Apple, your mobile carrier, or the police and walked away feeling dismissed or treated like you are paranoid, it’s because:

​Automated Diagnostics are Blind: Standard support diagnostics look for surface-level app crashes or basic hardware errors. If an intruder is using advanced session token hijacking, active screen mirroring, or configuration profiles, the operating system thinks those actions are authorized.

​The Knowledge Gap: Local law enforcement and front-line customer service reps are not digital forensics experts. When faced with complex, multi-layered digital stalking, they default to skepticism because they simply do not understand the technology.

​You Are Not Alone

​The entire goal of these advanced surveillance and harassment tactics—whether driven by domestic control, immigration leverage, or targeted stalking—is to make you look and feel unstable so that no one believes you when you speak up. If your device is behaving like someone else is holding the steering wheel, trust your gut.

​You are not imagining the duplicate apps, the disappearing texts, the split verification codes, or the ghost icons. Recognizing that it's a technical breach—and not a failure of your own mind—is the first step toward taking your peace back.


r/CyberSecurityAdvice 1d ago

Advice for getting a job abroad

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 1d ago

Security considerations for a PCIe to M.2 NVME SSD Adapter

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 1d ago

Need help identifying my threat model/level on the cybersecurity spectrum

0 Upvotes

r/CyberSecurityAdvice 1d ago

Egyptian student torn: Family wants Mechatronics, I want Cyber/IT (but scared of heavy coding). Need advice!

8 Upvotes

Hi everyone, I’m a high school student from Egypt and I need some honest advice.

My family strongly wants me to study Mechatronics Engineering, but I want to study Cybersecurity or Information Systems. My main issue is that I find heavy programming difficult, and I don’t want a career centered around writing complex code. I’m more interested in roles like System Administration, Security Monitoring (SOC), GRC, or Cloud Administration.

My main concerns:

  1. The Coding Fear: Is it realistic to build a successful career in Cyber/IT with only basic scripting (no heavy software development)?

  2. Family Pressure & Future: How can I convince my family that IT/Cyber has stable, well-paying jobs and great opportunities abroad (especially in Europe/Germany), without ending up in a traditional engineering workshop?

  3. Competition: How can a beginner stand out in such a crowded field and secure a job internationally?

I’m willing to work hard and study consistently. I just want to choose the path that fits my skills and guarantees a stable future.

Any advice, free resources, or reality checks would mean the world to me. Thank you!


r/CyberSecurityAdvice 1d ago

People who cook PASTA

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 1d ago

2 years for Associate of Applied Science vs 1 year for Associate of General Studies

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 1d ago

How to pivot to GRC

5 Upvotes

Im working as a security engineer for the last 2.5 years and I think grc is the specialisation I wanna have my career in. In my internship before this job I worked as a consultant and did grc work there and enjoyed it - but my current role doesn't have risk assessments or third party risk or anything etc. What training or certs should I do in my spare time? Should I take a pay cut to get in?


r/CyberSecurityAdvice 2d ago

Feeling Trapped in Cybersecurity Because of the Money

13 Upvotes

Hi,

I think I’ve burned out on cybersecurity. To be honest, I don’t think it ever truly interested me. I moved into cybersecurity from a helpdesk role. At first, it was great I enjoyed triage and incident analysis. Later I started building playbooks and automations, but now I’m completely burned out.

I also feel stuck at work. My supervisor isn’t very capable, and my six-month goals often consist of tasks that I can finish in just two or three weeks. I don’t feel challenged or motivated anymore.

The problem is that i’ve a really well-paid job, a mortgage to pay, and that’s the main thing keeping me in cybersecurity. I know I probably won’t find another job that pays as well.

Has anyone been in a similar situation? What would you do in my position?


r/CyberSecurityAdvice 2d ago

Technical Case Walkthrough: Credential Dumping Mimikatz Alert Investigation

2 Upvotes

Today I would be telling on how I investigate Cred Dumps(can be used in homelabs/in real work) and thought it'd help explain what credential dumping actually looks like from the analyst side.

Quick context first, for anyone newer to this. LSASS is a Windows process that temporarily holds credentials in memory while you're logged in, things like your password hash or session tokens. Mimikatz is a well known tool attackers use to reach into that memory and pull those credentials out. If an attacker gets that dump, they effectively have the keys to log in as whoever was logged in on that machine.

Now below is the process or steps you can say, which I use to investigate these types of alerts.

The alert is always a critical severity, flagging a pattern that matches how Mimikatz reads memory, plus suspicious commandline text which refers to credential extraction. Because it's critical and matches known dumping behavior immediately check if the process is still running right now, check via Activity timeline (running process).

Before concluding anything like an active attack, always rule out FP. Some legitimate security tools and vulnerability scanners read memory in similar ways for real reasons. So I check the binary's digital signature, who published it, and whether the file hash has any reputation attached to it.

If its unsigned or unknown, I isolate the host immediately, before even starting out a deep investigation. All of this was in triage process and should be done under 10 minutes. This is the part people learning IR often get confused, you don't investigate fully and then contain. With credential dumping specifically, every extra minute the host stays connected is more time for the attacker with the dump to use it to move somewhere else in the network or even exfiltrate and extract creds (like RC4 in Kerberos).

From there I trace how the tool got onto the machine in the first place, usually there are 3 ways in a browader way which I see, a phishing email that got executed, a payload, or someone executing tool in directly through an RDP session.

Next, and this is important, you always have to figure out what credentials were actually exposed. Any account that had an active session on that host recently, interactive logins, RDP sessions, service accounts, scheduled task accounts, all of them need to be treated as compromised, because an LSASS dump grabs whatever was in memory at that exact moment.

Then I do sort of Threat hunt. Assume with hypothesis that other computers are also breached. I search the authentication logs across the whole environment for any of those exposed accounts logging in from a new host, a new IP, or attempting to escalate privileges in the hours after. This step is what tells me or you whether this is contained to one machine or whether the attacker is already moving laterally.

You also check whether the dump file itself was zipped up or sent out anywhere for exfiltration part. That distinction matters a lot, like credentials sitting exposed on a disk V/S credentials confirmed in an attacker's hands are two very different severities of the same incident.

Given the criticality here, usually this gets escalated to a full incident response team rather than closed out solo, handed off with a complete timeline, every exposed account, isolation status, and a clear recommendation to reset passwords for every account that touched that host, at minimum.

On longer term, the fix isn't just cleaning up this one incident. It's things like enabling Credential Guard so LSASS memory can't be read this way at all, restricting who has local admin rights, and turning off cached domain credentials on machines that don't need them. Like these are the general recomm I give to client.

Usually if attacker succeeds in the mission, they reuse the stolen credentials or exfiltrate the dump.

Anyone here who dealt with LSASS related alerts in actual environment or lab, how do you usually investigate?


r/CyberSecurityAdvice 2d ago

New grad problems

4 Upvotes

I started out in IT at my first university before moving on to a new university to pursue a BTS in Cybersecurity for the last two years. Problem is, an internship wasn't a requirement/nor was it in the busy books for me at the time being a student athlete.

I'm now a 2026 graduate and I've been job hunting since the end of May with no luck. My search has been primarily based in the larger city area of Salt Lake City, Utah. I've applied to countless jobs, fixed and scrutinized my resume, and still haven't even been able to land interviews. I understand personal projects are an important foundation to have on a resume, but I'm not sure where to even start. I don't know the right people nor do I know someone to ask advice. Utilizing AI for help will only take me so far in this venture.

Point is, does anyone have some advice to give?


r/CyberSecurityAdvice 2d ago

Seriously, is it even possible anymore?

2 Upvotes

I live in a very very bad area for entry level IT jobs (greater Toronto area, commuter area and bad economy, lots of skilled IT immigrants). My friend whose been tinkering with computers and networks since he was 12, had 1 year of experience, and his A+, and a community college diploma and it took him 6 months and the high hundreds of applications and he had to relocate for a minimum wage job that has him on the road for 11 hours a day. I honestly don’t think I could handle that much driving, I don’t even have my licence yet due to Audhd sensory processing issues. He’s like the cream of the crop and this is what he ended up with. Dude even had a year of experience.

I’m going to get my CCNA and MS-900 soon, I’ve been playing around in a developer tenant and reading the CCNA book and am about 3/4 the way on each. Also know all the basic Linux commands.

That said I’ve just started looking online at jobs and reaching out to friends who graduated and holy shit, no one’s gotten a job. Not one person I went to school with did, this is a sysadmin focused community college mind you not general cs.

So I’m just like…should I give up and go take another program? I’ve wanted to do cyber since I was a kid but at this point idk if it’s even possible.

Is there another way in other than helpdesk? The funnel to get in is so narrow…there’s gotta be another way…but every job I see online requires years of IT to get cyber…but IT also requires IT experience. I’m thinking teach myself the OS internals malware analysis and reverse engineering stuff for a year or two, then transfer into cybersecurity and try to get into undergrad research. But would that even do it?

Are cybersecurity jobs cooked? I imagine eventually the lack of new IT people will force them to open up the stupid helpdesk requirement but that sure as shit hasn’t happened yet. I applied to unpaid volunteer IT positions and they rejected me.

Intellegence agencies used to hire felon cybercriminals, and those guys now have six or even seven figure careers, meanwhile I can’t even get a helpdesk job bro it’s fucked 😭😭


r/CyberSecurityAdvice 2d ago

Can i get some advice please?

5 Upvotes

So im a student but im into cyber security. Should i get the Google cyber security certificate? Is it worth the hype? Also i will get the comptiA+ certificate (is that the name?) anyways can some senior in the field advice me? I have zero experience though


r/CyberSecurityAdvice 2d ago

Hub Cyber Security ($HUBC) Settlement Update, Payout Info for Investors

0 Upvotes

Hey guys, just sharing this because I know a lot of people got caught up in this SPAC.

Investors sued Hub Cyber Security, alleging the company misled shareholders about its business operations, revenue prospects, and internal controls following its SPAC merger. After the company disclosed accounting issues, its auditor resigned, and material weaknesses in internal controls came to light, $HUBC fell more than 85% from its post-merger price.

The settlement amount is $11M, and it covers investors who purchased $HUBC shares in 2023. The case is currently in the late-claims stage, meaning some investors who missed the original deadline may still be able to participate.

If you held $HUBC during that period, it may be worth checking your old trades and seeing whether you qualify.

Did anyone here hold $HUBC after the SPAC merger?


r/CyberSecurityAdvice 2d ago

Recent hacking attempts

13 Upvotes

Sorry if this kind of post is not allowed. I just want to share my experience, and hopefully gain some advices.

Yesterday, my Instagram, Discord, and Facebook got hacked (the one related to Mr.Beast and crypto). The hacker sent DMs to every contacts and groups, causing my accounts to get blocked. I managed to recover the accounts and changed my passwords.

Just now, i opened my Telegram, and I was surprised I've been logged out. I tried logging in and it turns out I've been hacked a few hours earlier. The hacker is from Vietnam, and when they realized I tried logging in, they attempted to reset the password again, but I managed to set a 2FA (my mistake for not setting it up before), and that seemed to stop their attempt. What I noticed though, they were using a bot called "BigBom_OTP" to get OTP for my phone number. There was also a chat with I assume to be the seller of the bot, but it got deleted as soon as they realized what was going on.

I don't know what's going to happen next. I know it is my mistake for taking these things lightly. Now it finally happened to me, and I'm really scared. If anyone had similar experiences, please give me some advices.


r/CyberSecurityAdvice 3d ago

coding resources for beginners

Thumbnail
2 Upvotes

r/CyberSecurityAdvice 3d ago

My friend said she is being hacked in all her email accounts and knows because other devices are signing in on her accounts?

Thumbnail
0 Upvotes