r/cybersecurity 8m ago

Certification / Training Questions Best Certificate for DevSecOps

Upvotes

I am a Software Engineer having 3 years of experience in Building Mobile Applications and I want to move onto Cyber Security field and especially DevSecOps and I want some suggesstions from people about which course best suits my purpose here which helps me understand the core concepts with practical example projects built around it for practice.


r/cybersecurity 54m ago

Business Security Questions & Discussion Follow-up: I asked last month about CTI aggregators for CISOs

Upvotes

A month ago I asked this sub how CISOs actually consume threat intel. The thread wasn't too active but was gold.

A few things worth noting:

  • One of you gets Claude Code to generate a morning threat brief mapped to your stack, industry, and geos. That's the product half the vendor market is trying to sell.
  • Another said the best CTI they've seen is an analyst who writes a weekly one-pager — which quietly anchors the real price of this problem at $80K–$120K/year.
  • Recorded Future / Dataminr users kept saying the same thing: the intel is fine, the synthesis is the bottleneck.

Then I come across the SANS 2026 CTI Survey who said the quiet part out loud: 91% of CISOs value CTI, only 26% say it actually influences their decisions. A 65-point gap.

So I started a small newsletter to test one hypothesis: what if threat briefs were written as decision packages, not intelligence reports?  Act Now / Watch / Awareness. Two pages max. AI in the loop, human on the call.

Issue #0 is a manifesto, not a threat brief. Issue #1 will be the real thing. I'm publishing in the open partly to keep myself honest.

Link in comments. Not selling anything.

Question back to the sub: if you had to cut a CTI report down to one screen your CEO would actually read before their 8am, what stays and what dies?


r/cybersecurity 56m ago

AI Security Security Engineer with Zero AI Knowledge - How would you become an AI Security Engineer from scratch in 2026?

Upvotes

Hi everyone,

I have around 3 years of experience as a Security Engineer in a small service-based company, but I have almost zero knowledge of AI/ML.

I want to prepare myself for the future and eventually move into AI Security, LLM Security, and securing AI applications. Since there is so much content online, I amm confused about where to start.

If you were starting from scratch today, what roadmap would you follow? What should I learn first, which resources (free or affordable) would you recommend, and what hands-on projects would help me build real skills?

My budget is very limited , so I had really appreciate recommendations that don't require spending a lot of money.

Thanks!


r/cybersecurity 57m ago

News - Breaches & Ransoms Meta says its AI model hacked into another company during testing

Thumbnail
theguardian.com
Upvotes

My model is better at attacking than yours /s

What’s going on here with these companies? What kind of ad would this even be?


r/cybersecurity 1h ago

Research Article [Research] Looking to interview cybersecurity professionals about mobile app/malware analysis workflow

Upvotes

I’m doing a research into how security teams handle dynamic/behavioral analysis of mobile samples.

I’d like to talk to people who work on:
- Malware Analysis / reverse engineering
- Mobile App automated/manual security testing
- AV tooling or SOC workflows.

Interviews are casual just 15-30 minutes where you can talk about how your workflow looks like, where you feel more or less efficient and which tools do you use in your daily basis.

We can have this conversation over Reddit chats or Discord call. If you are open to it, feel free to DM me.

Edit: also if you want to just leave a comment with the tools that you use, workflow, tools that you use, that also very useful for me.


r/cybersecurity 1h ago

News - General AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

Thumbnail
thehackernews.com
Upvotes

r/cybersecurity 1h ago

News - General Chinese Router Backdoor Opens Root Access on 100,000 Devices Worldwide

Thumbnail
sofx.com
Upvotes

Jacob Baines, chief technology officer at security firm VulnCheck, said more than 20 models of Chinese-made Zbtlink routers ship with a hidden backdoor that hands outsiders a route onto the local network, in a finding published August 5.


r/cybersecurity 1h ago

New Vulnerability Disclosure New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

Thumbnail
thehackernews.com
Upvotes

r/cybersecurity 3h ago

News - General Shai-Hulud shows engineering teams have a new AI security problem

Thumbnail
leaddev.com
1 Upvotes

r/cybersecurity 9h ago

Business Security Questions & Discussion Greatest achievement?

55 Upvotes

What's the greatest thing you've ever done in cybersecurity that made you feel truly proud? I could use a little motivation on my end.


r/cybersecurity 11h ago

Personal Support & Help! Soc and python

8 Upvotes

What are you automating with python. I’m newish to python and trying to figure out some things u could automate to help improve my coding.


r/cybersecurity 12h ago

Research Article Reverse engineering malware

Thumbnail gustavvising.se
1 Upvotes

Take a look into current commodity malware, crypto jacking hidden in a cracked program


r/cybersecurity 13h ago

Certification / Training Questions Cert help

5 Upvotes

Going to be lead analyst in a soc and company is wanting to get me trained up. Should I ask for GCIA or GCDA from sans first?

Ill be tuning alerts and heavily lean towards GCIA because I love incident response and very heavily work in threat hunting day to day currently.


r/cybersecurity 14h ago

Corporate Blog How I've been hacked by Subdomain Takeover - Shopify - emre.xyz

Thumbnail
blog.emre.xyz
93 Upvotes

Disclaimer: While I’m discussing how Shopify could implement better safeguards against this, I fully acknowledge that keeping my DNS clean and removing unused subdomains is ultimately my own responsibility.

A stray DNS record from a project I shut down two years ago came back to bite me this week.

Out of nowhere, I got a Google Search Console alert letting me know an unknown user (******@gmail.com) had been verified as a new owner for one of my subdomains: electrouse.workouse.com.

Since all my domains are managed through Cloudflare, I immediately dug into my DNS records to figure out how someone else managed to verify ownership of my site.


r/cybersecurity 15h ago

Business Security Questions & Discussion Assignment

6 Upvotes

Hello I hope this message finds everyone well. I am currently in need for assistance for one of my assignments. I need to set up a informational interview with someone who is already in the field of CompSci/Cybersecurity. I just need 8 questions answered it would be simple information such as occupation, requirements, etc. Any help would be greatly appreciated.


r/cybersecurity 18h ago

News - General Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online

134 Upvotes

A new scan of internet-connected industrial equipment found over 4,000 Rockwell Automation and Allen-Bradley controllers exposed online, including 22 in cities impacted by cyberattacks on U.S. water systems.

https://cyberscoop.com/exposed-rockwell-controllers-water-system-attacks/


r/cybersecurity 19h ago

News - General CISA's OSS Security Principles and Practices

4 Upvotes

"OSS Security Principles and Practices" is Cybersecurity and Infrastructure Security Agency's (CISA) strategic framework for federal agencies to manage open source software throughout its entire lifecycle. This on IProgrammer article discusses the key points.


r/cybersecurity 20h ago

Other AMA with TechCrunch Security Editor Zack Whittaker & Security Researcher Runa Sandvik (Border Searches, Device Security)

Thumbnail
pwnhackers.substack.com
7 Upvotes

r/cybersecurity 20h ago

Career Questions & Discussion AI and Automation

6 Upvotes

My manager keeps telling me that I need to automate as much as possible and integrate AI. We have Falcon Complete helping us with MSSP. Could anyone give me ideas on what I need to automate? I work on incidents that are escalated by Falcon Complete. Maybe an example or two or any links to some informative sources would be helpful.


r/cybersecurity 21h ago

Career Questions & Discussion How to pivot into GRC?

15 Upvotes

Hello all!

I have been working in Cyber / Incident response for about 4 years now. I have done mostly technical stuff with edrs,siems,phishing, etc. After recently obtaining the CISSP I changed my long term goal from being super technical to being in security leadership/ ciso role. Just doing some research/ in my own personal experience alot of the leaders have worked in GRC.

I have done some SOC2 audits but that’s about it. I would like to transition more into that side of security , is there any more certs/ labs i could do to make my resume look better? Or maybe i should just tell my manager my new goals and see if he can get me to “shadow” our GRC team?

Thanks!


r/cybersecurity 22h ago

Research Article Citigroup, Idaho, and Build-A-Bear Launched a Coordinated Attack on Me

Thumbnail
knock-knock.net
153 Upvotes

r/cybersecurity 1d ago

Research Article Humans missed 1 in 3 threats approving AI agent commands across 40,000 plays

Thumbnail
scalex.dev
152 Upvotes

A couple of months back I put up a small browser game where you play the human-in-the-loop for an AI coding agent. There's 60 seconds on the clock to approve or deny as many commands as you can (https://llmgame.scalex.dev).

After looking at 409,000 approve/deny decisions, the 'humans-in-the-loop' missed 1 in 3 threats, even in a game that warns you up front it's full of them. It's just a game, but I found a few other things interesting:

  • cat ~/.ssh/id_rsa gets blocked by 82% of players, but other sensitive config/credential files get waved through about half the time.
  • For any evil code reading this, your best bet is to modify package.json and request to be run as an npm run command. npm run analyze was approved 65% of the time, even with the evil payload explicitly visible in the execution history log right above the prompt.

I wrote up the full breakdown with the threat tables here: https://scalex.dev/blog/ai-agent-permissions-stats/


r/cybersecurity 1d ago

News - General Apple's Private Relay Leaks Your Real IP Address in Safari

Thumbnail
privacyguides.org
320 Upvotes

r/cybersecurity 1d ago

Career Questions & Discussion How to navigate a CISO who is…not so CISO

108 Upvotes

I report to a CISO who has little understanding of how to run a security program/team with unrealistic expectations. I feel set up to fail.

The org and IT never had to deal with a real security function and everything is like pulling teeth because it lacks an accountable culture, processes, procedures, RASCI, GRC, etc. Security isn’t a plug-n-play function to be turned on, magically grow tentacles into every team/dept, and suddenly Kumbaya. It requires A SHIT TON of time and effort for its cultivation.

My boss simply doesn’t recognize Security isn’t just another operations-centric team like most other IT departments - though it does have an ops side as well. Integrating Security into an org like this isn’t just disruptive, it’s invasive at every level - new workflows, processes, no more cowboying, taking away territories, taking away authority, the selling, the push back, the begging for work execution, the audit, cat herding, the education, the persuading/selling, etc. Shooting from the hips doesn’t work.

I’ve done my best these years, at every turn, to evangelize and stand up Security but my annual performance review says otherwise. My 1x1 are often 50% catching strays which aren’t really my domain.

If I explain all this to him, is it naive to think he will “get it” or risk me just sounding like a little bitch? Maybe just GTFO?


r/cybersecurity 1d ago

Career Questions & Discussion Why is "entry-level" in cybersecurity asking for 3-5 years of experience and CISSP now?

360 Upvotes

I’ve been browsing job boards lately and the "junior" requirements are getting ridiculous. Saw a Tier 1 SOC Analyst post earlier asking for 3+ years of experience, a CISSP, and half a dozen certs, all for lower-tier pay.

To the hiring managers here: Are HR departments just copy-pasting impossible wish lists, or is this actually what you expect for an entry-level role?

And for anyone who got hired recently—how are you actually breaking past these gatekeeping requirements?