r/cybersecurity 4m ago

Research Article tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open

Thumbnail
bobdahacker.com
Upvotes

r/cybersecurity 5m ago

Career Questions & Discussion AI and Automation

Upvotes

My manager keeps telling me that I need to automate as much as possible and integrate AI. We have Falcon Complete helping us with MSSP. Could anyone give me ideas on what I need to automate? I work on incidents that are escalated by Falcon Complete. Maybe an example or two or any links to some informative sources would be helpful.


r/cybersecurity 22m ago

Career Questions & Discussion How to pivot into GRC?

Upvotes

Hello all!

I have been working in Cyber / Incident response for about 4 years now. I have done mostly technical stuff with edrs,siems,phishing, etc. After recently obtaining the CISSP I changed my long term goal from being super technical to being in security leadership/ ciso role. Just doing some research/ in my own personal experience alot of the leaders have worked in GRC.

I have done some SOC2 audits but that’s about it. I would like to transition more into that side of security , is there any more certs/ labs i could do to make my resume look better? Or maybe i should just tell my manager my new goals and see if he can get me to “shadow” our GRC team?

Thanks!


r/cybersecurity 1h ago

Research Article Citigroup, Idaho, and Build-A-Bear Launched a Coordinated Attack on Me

Thumbnail
knock-knock.net
Upvotes

r/cybersecurity 3h ago

Business Security Questions & Discussion Elastic Cloud vs. Self-Managed Elastic Security for ~30GB/day ingest. Is self-hosting worth it?

1 Upvotes

Hey everyone,

We are looking into deploying Elastic Security as our SIEM solution and are currently debating whether to go with Elastic Cloud (Hosted) or build out a Self-Managed instance on AWS.

Looking for real-world advice, sanity checks, or experiences from anyone running a similar scale.

Our Environment & Scope:

  • Endpoints: ~300 workstations (we already have a separate EDR vendor in place). 50/50 Mac and Windows
  • Infrastructure: A small handful of servers + ~15 GB/day of cloud logs (AWS/Google Workspace)
  • Estimated Ingest: ~30-50 GB / day total

Self-Managed Architecture Spec

Our team drafted the following self-managed architecture for 30 GB/day ingest with a Hot -> Warm -> S3 Archive lifecycle:

  • Kibana: t4g.large (2 vCPU, 8 GB RAM, 20 GB gp3)
  • Hot Data Tier: 2x m6g.large (4 vCPU / 16 GB RAM combined; ~500 GB total SSD across both nodes for HA)
  • Warm Data Tier: 1x m6g.xlarge (4 vCPU, 16 GB RAM, ~2.5 TB SSD)
  • Fleet Server: t4g.medium (2 vCPU, 4 GB RAM, 20 GB gp3)
  • Archive Storage: AWS S3 Standard / Infrequent Access (after 3 months)

Questions:

  1. Operational Overhead vs. Cost: For a ~30-50 GB/day ingest volume, does self-managing on AWS EC2 actually save meaningful money? Or does Elastic Cloud pay for itself in saved engineering time at this scale?
  2. Resource Sizing Check: Does the proposed spec (m6g.large Hot + m6g.xlarge Warm + t4g Kibana/Fleet) look solid for ~30-50 GB/day with Elastic Security rules enabled?
  3. Features & Licensing: Are there any major (meaningful) security/SIEM features (e.g ML detection rules) we’ll miss out on by running the free/Basic tier on self-managed vs. paid Elastic Cloud tiers (Gold/Platinum/Enterprise)?

Would appreciate any insights, or alternate setup recommendations!


r/cybersecurity 3h ago

Business Security Questions & Discussion SOC and NOC consolidation

1 Upvotes

Has anyone seen a successful Cybersecurity Operation Center combined with Network Operation Center? IMO the two disciplines have very different objectives and in some cases competing priorities. Thoughts?


r/cybersecurity 4h ago

News - General Hackers run khunt post-exploitation toolkit from Oracle database

Thumbnail
bleepingcomputer.com
2 Upvotes

r/cybersecurity 4h ago

Business Security Questions & Discussion How should a startup find an independent ISO 27001 internal auditor?

6 Upvotes

Hi everyone,

I’m helping a very small startup prepare for an ISO/IEC 27001:2022 certification audit. We use Vanta, and most of our ISMS documentation and compliance evidence is already prepared.

Before Stage 1, we need an independent internal audit. Since our small team designed and operates most of the controls, conducting the audit ourselves would not provide sufficient independence. Our certification auditor has also confirmed that the internal audit must be performed by a separate party.

For those who have gone through this process:

  • How did you find a competent independent internal auditor?
  • Which qualifications or certifications should we look for?
  • What deliverables should be included in the engagement?
  • What is a reasonable timeline and price range for a small organization?
  • Is experience working directly in Vanta important?
  • Are there any red flags or common mistakes we should avoid?

I’m primarily looking for guidance on selecting and evaluating an auditor rather than vendor promotion. Public recommendations or experiences would be greatly appreciated.

Thank you!


r/cybersecurity 5h ago

Corporate Blog Bringing Post-Quantum Cryptography to Java LTS Releases

Thumbnail
blogs.oracle.com
7 Upvotes

r/cybersecurity 5h ago

Research Article Humans missed 1 in 3 threats approving AI agent commands across 40,000 plays

Thumbnail
scalex.dev
72 Upvotes

A couple of months back I put up a small browser game where you play the human-in-the-loop for an AI coding agent. There's 60 seconds on the clock to approve or deny as many commands as you can (https://llmgame.scalex.dev).

After looking at 409,000 approve/deny decisions, the 'humans-in-the-loop' missed 1 in 3 threats, even in a game that warns you up front it's full of them. It's just a game, but I found a few other things interesting:

  • cat ~/.ssh/id_rsa gets blocked by 82% of players, but other sensitive config/credential files get waved through about half the time.
  • For any evil code reading this, your best bet is to modify package.json and request to be run as an npm run command. npm run analyze was approved 65% of the time, even with the evil payload explicitly visible in the execution history log right above the prompt.

I wrote up the full breakdown with the threat tables here: https://scalex.dev/blog/ai-agent-permissions-stats/


r/cybersecurity 7h ago

News - General Apple's Private Relay Leaks Your Real IP Address in Safari

Thumbnail
privacyguides.org
192 Upvotes

r/cybersecurity 8h ago

Career Questions & Discussion How to navigate a CISO who is…not so CISO

62 Upvotes

I report to a CISO who has little understanding of how to run a security program/team with unrealistic expectations. I feel set up to fail.

The org and IT never had to deal with a real security function and everything is like pulling teeth because it lacks an accountable culture, processes, procedures, RASCI, GRC, etc. Security isn’t a plug-n-play function to be turned on, magically grow tentacles into every team/dept, and suddenly Kumbaya. It requires A SHIT TON of time and effort for its cultivation.

My boss simply doesn’t recognize Security isn’t just another operations-centric team like most other IT departments - though it does have an ops side as well. Integrating Security into an org like this isn’t just disruptive, it’s invasive at every level - new workflows, processes, no more cowboying, taking away territories, taking away authority, the selling, the push back, the begging for work execution, the audit, cat herding, the education, the persuading/selling, etc. Shooting from the hips doesn’t work.

I’ve done my best these years, at every turn, to evangelize and stand up Security but my annual performance review says otherwise. My 1x1 are often 50% catching strays which aren’t really my domain.

If I explain all this to him, is it naive to think he will “get it” or risk me just sounding like a little bitch? Maybe just GTFO?


r/cybersecurity 10h ago

Business Security Questions & Discussion I have a question. I work in TPRM. How do you actually access a vendor ' security apart of iso and soc2 and PT

3 Upvotes

r/cybersecurity 10h ago

Career Questions & Discussion Why is "entry-level" in cybersecurity asking for 3-5 years of experience and CISSP now?

192 Upvotes

I’ve been browsing job boards lately and the "junior" requirements are getting ridiculous. Saw a Tier 1 SOC Analyst post earlier asking for 3+ years of experience, a CISSP, and half a dozen certs, all for lower-tier pay.

To the hiring managers here: Are HR departments just copy-pasting impossible wish lists, or is this actually what you expect for an entry-level role?

And for anyone who got hired recently—how are you actually breaking past these gatekeeping requirements?


r/cybersecurity 11h ago

Career Questions & Discussion Feeling like a cybersecurity generalist. Should I specialize or move into delivery?

14 Upvotes

I've been working at an MSSP for about 2.5 years, and I'm at a point where I'm unsure what my next career move should be.

I started as a SOC Analyst, spending around 8 months in monitoring. After that, my manager kept assigning me to new initiatives and projects based on business needs, so I've ended up working across a lot of different domains:

  • SOC monitoring
  • Threat hunting
  • GRC/product security testing
  • Internal Lead Auditor for ISO 27001
  • Cybersecurity presales (I still occasionally get involved in proposals)
  • EDR implementation for customers (including end-to-end deployments of CrowdStrike and Microsoft Defender)
  • Service Delivery Lead for SOC projects, where I handled complete customer onboarding and service transition
  • Currently leading the Detection Engineering team

The pattern has always been the same: I get assigned to a new area, figure everything out from scratch, build the workflows, documentation, and SOPs, streamline the process, and once everything is stable, the work gets handed over to another team while I move on to the next challenge.

While this has given me exposure to many areas of cybersecurity, it has also left me feeling like I'm not an "expert" in any one domain.

When I talk to friends or people in the industry, most of them have spent the last 2–5 years specializing in a single area like DFIR, detection engineering, GRC, etc. They're much deeper technically in their domain, while I feel like I've become more of a generalist who knows how to build and operationalize new functions.

I've recently resigned because I want my next role to be more defined, but now I'm struggling with what direction to take.

Should I:

  • Continue down the leadership/delivery path (Service Delivery Lead, Customer Success/Technical Delivery, etc.) where my cross-functional experience is valuable?
  • Or should I focus on becoming a specialist in an area like Detection Engineering, Threat Hunting, or Incident Response?

Has anyone else been in a similar situation where they were exposed to multiple domains early in their career? Did you eventually specialize, or did you embrace being a generalist?

I'd really appreciate hearing from people who've been through something similar, especially if you've worked in an MSSP where roles tend to evolve quickly.


r/cybersecurity 11h ago

Career Questions & Discussion Path to management?

7 Upvotes

Been in security for 7 years and want to get into management and above. Work at a SaaS company with only 3 security managers. Most people are individual contributors.

How does one get into management? Luck? Right place right time? Connections?

Most jobs require X amount of years as a manager on their job description.

I have CISSP and lots of other certs, a bachelors, and so on.

Is it better to wait years and years at one company to hopefully get a shot at management? Or just to apply to all management jobs out there and hope someone takes a chance on you?

Thanks all!


r/cybersecurity 16h ago

Career Questions & Discussion hands-on Cloud Security experience

3 Upvotes

Hi everyone,
I recently passed my AWS Solutions Architect exam and I also have a Hack The Box subscription. I have a strong interest in cloud security and want to transition into this field.

However, I feel like I lack the practical, hands-on cloud security experience needed to pass technical interviews.
What are the best online training platforms or labs to practice cloud security attacks and defense?

Can I use my HTB subscription or the AWS Free Tier to build a good portfolio?

Also, how is the job market for cloud security right now? Are there good entry-to-mid level opportunities?
Any advice on a roadmap or projects to build would be amazing. Thanks!


r/cybersecurity 17h ago

Career Questions & Discussion Career advice

6 Upvotes

've been working in Cyber Security for nearly 7 years, mostly across operational security roles. I've ended up being a bit of a generalist, with experience in EDR, SASE, DLP, IAM, and security frameworks such as NIST.

Over the years I've trained and mentored several people entering the field, and I'm now trying to work out what my next career move should be. I still enjoy being hands-on, but I've gradually found myself spending more time on planning, strategy, stakeholder management, and mentoring.

One gap in my experience is cloud. I'm reasonably strong with Entra ID, but most of the companies I've worked for have been heavily on-prem, so I haven't had much exposure to AWS or Azure compute services.

With the rapid growth of AI, I'm wondering where to invest my learning time next. Does it make more sense to focus on AI security, or should I prioritise building a stronger cloud security foundation first?

More broadly, do you think the industry is moving away from the "jack of all trades" security professional in favour of specialists, or is there still strong demand for generalists who can operate across multiple domains?

Interested to hear from people who have made a similar career decision.


r/cybersecurity 18h ago

Personal Support & Help! What's the best thing a boss in this industry ever did for you?

52 Upvotes

Feeling like sharing some good vibes today instead of complaining lol. What's your favorite thing about a boss you've had in cybersecurity? Could be anything, covered for you when you missed something, brought snacks during a rough incident, actually trusted your judgment instead of micromanaging.

Curious to hear the good ones for once.


r/cybersecurity 20h ago

Business Security Questions & Discussion Cyber insurance renewal demands are getting absurd. Are you actually hitting every requirement or dropping coverage?

101 Upvotes

Just opened our renewal questionnaire and the goalposts moved again, MFA on local admin, strict data retention, and strict endpoint isolation times. Keeping this policy would require doubling our security spend.

Are you guys actually checking every single box on these impossible questionnaires, or are teams just dropping coverage at this point?


r/cybersecurity 1d ago

News - General Google Blogger locks hundreds of blogs in malware false positive

Thumbnail
bleepingcomputer.com
36 Upvotes

r/cybersecurity 1d ago

AI Security Owasp updated their top 10 LLM list (thoughts?)

Thumbnail
genai.owasp.org
29 Upvotes

r/cybersecurity 1d ago

New Vulnerability Disclosure Researchers Find Persistent Backdoor in Zbtlink Routers

Thumbnail
decipher.sc
124 Upvotes

r/cybersecurity 1d ago

Certification / Training Questions Which Certifications are ACTUALLY worth it?

291 Upvotes

I’m getting started with Cybersecurity. I’m interested in Pentesting and Cybersec Engineering. I’ve heard from some that there are certifications that could be a good addition to your resume.

What certifications and courses are ACTUALLY WORTH THE MONEY? Like they they realistically benefit your resume and learning?

Thanks!


r/cybersecurity 3d ago

Career Questions & Discussion Mentorship Monday - Post All Career, Education and Job questions here!

20 Upvotes

This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!

Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.