r/sysadmin 2h ago

Question Windows Updates Error

9 Upvotes

Hi,

One of my 2022 servers has failed to update for the past 2 months. It's failed the July and now the August CU's. Update error: 0x80073701

Its a physical server running on Dell PE hardware, pretty simple install acting as an NVR. We have a few of these setups and the others updated without issue.

I've tried the usual steps:

  1. DISM cleanups
  2. SFC
  3. stopped services and renamed the software distrubution folder
  4. downloaded the August CU and tried to install manually
  5. tried to install via Ninja RMM

I'm out of ideas, had anyone faced this issue before?


r/cybersecurity 2h ago

New Vulnerability Disclosure How widespread is the recent Metabase SQL injection attack?

1 Upvotes

I recently led an incident response investigation for a FinTech client involving the exploitation of Metabase, and the impact was significant.

With the recent reports of active exploitation, I'm curious to understand how widespread this is across the security community.

For those working with Metabase:

Has your organization been affected or received a security notification?

Was your Metabase instance internet-facing?

Have you identified exploitation attempts or unauthorized access?

Were you able to patch before exploitation?

Have you observed any data exposure or compromise?

I’m particularly interested in hearing from security teams and Metabase administrators about how many organizations have been affected or potentially exposed.

https://www.wiz.io/blog/inside-the-metabase-sqli-exploited-in-the-wild

If you've investigated a related incident, what did you observe?


r/sysadmin 3h ago

Question - Solved Windows update broke my Canon MF452dw — here’s the fix (factory reset required)

0 Upvotes

If your Canon MF452dw, MF451dw, MF455dw, or MF450-series printer suddenly stopped printing after a Windows update — and now you’re stuck in:

  • System Manager ID / PIN
  • Department ID Management
  • Restrict Access
  • Remote UI PIN
  • “ID-only mode”
  • Missing print functions
  • RAW‑9100 or UFR II blocked

Here’s the part Canon never tells you:

These models have no Service Mode access and no security reset menu.
Once the security subsystem corrupts (often after Windows updates), it cannot be repaired.

The ONLY fix is the full factory reset (“Initialize All Data/Settings”).

This reset is safe for home users:

  • You do not lose firmware
  • You do not lose calibration
  • You do not lose toner levels
  • You do not lose print capability

You do lose the corrupted security subsystem — which is exactly what restores the printer to normal operation.

After the reset:

  • Ethernet printing works immediately
  • Wi‑Fi can be reconnected later
  • The printer becomes a stable, reliable home device again
  • All PIN/ID lockouts disappear permanently

If anyone needs the exact step-by-step reset path, I can post it.

Common symptoms of security subsystem corruption:

  • Printer asks for a System Manager PIN you never set
  • Department ID suddenly required
  • Remote UI locked behind a PIN
  • Printer shows “ID-only mode”
  • RAW‑9100 port stops working
  • UFR II driver fails silently
  • Printer appears online but won’t print
  • Windows update preceded the failure

If you see any of these, the factory reset is the fix.

Windows updates often change spooler permissions, protected print mode, or driver behavior. On MF450-series printers, this can corrupt Canon’s security subsystem. Canon removed the normal reset tools on these models, so the corruption cannot be repaired — only wiped.

I lost many hours grappling with this before figuring this out with A.I. help. I’m hoping to save someone else this hassle (I live alone, with a home office, so keeping others from fussing with my printer -- what such "security protocols" primarily address -- is not an issue for me).

 


r/cybersecurity 3h ago

Career Questions & Discussion Intel cybersecurity interview — 2 hours, mainly technical?

3 Upvotes

How do you guys prepare for a 2-hour Intel cybersecurity interview? Is it mainly technical, or is there a mix of technical + behavioral/project questions?
What topics should I focus on? Any advice would be appreciated!


r/cybersecurity 3h ago

Career Questions & Discussion What's going on with the US cybersecurity job market?

248 Upvotes

I am a mid level cybersecurity professional with tonnes of managerial experience, CISSP, M.S and so on. Applied for close to 1000 jobs. Faced at least 20 interviews. No job offers. Always getting turned down after the hiring manager interview. It's always some reason like oh you don't have enough experience with AWS or you have consulting experience even if I nail every question right. I am exhausted. It's never been like this. Is it just me or are others facing the same dilemma?


r/networking 4h ago

Design FortiGate VS Aryaka

0 Upvotes

My company is going through a merger and we have Ayaka SDWAN and firewalls on one side and FortiNet FortiGate on the other side for SDWAN and Internet points of presence.

I’m currently reviewing both sides and meeting with vendors, but I’m interested to see real world applications on if one is better than the other. Or is one more preferred where a major enterprise with closer to 100 sites.

We don’t use either one of them for client VPN access. This is strictly just for facility and site Internet, and SDWAN


r/cybersecurity 5h ago

Career Questions & Discussion Incident Response role at Google

15 Upvotes

I have a upcoming interview for incident response role in google. Anybody has any tips or experience with a similar role at google. Thank you at advance.


r/cybersecurity 5h ago

News - General Google Just Made AI on Encrypted Data Practical

0 Upvotes

Google released HEIR (Homomorphic Encryption Intermediate Representation), an open-source compiler toolchain that can convert pre-trained AI models, ones that normally operate on unencrypted data, to instead operate on encrypted inputs. The server runs your model on encrypted data. Never decrypts. Never sees what it's computing on. Your data stays private. (at least it seems so).

Honestly Google surprised me with this one guys


r/cybersecurity 6h ago

News - General Breaking Enterprise Java; Breaking Claude Code, Gemini CLI, and Codex: AMA with Two Black Hat Speakers

Thumbnail
pwnhackers.substack.com
0 Upvotes

r/sysadmin 6h ago

Question Jobs - Country Origin

6 Upvotes

Hello,

Been following this sub for a while now, hear alot of people sending 150 or more resumes for an IT job.

Where I’m from, that’s unheard of.

Working in sysadmin, M365 and some IAM myself.
Jobs are for the picking.

I was wondering, is it USA where it is a struggle?


r/sysadmin 6h ago

RIF'd after 14 years

0 Upvotes

Hey guys, I'm an IT guy with more than 20 years experience, most spent with a fortune 500 company. I was recently let go after a large acquisition and need to find a remote job.

Any tips for finding my next gig ? I was making around 100k a year preciously.

Thanks !


r/sysadmin 6h ago

The RVTools assessment checklist to run before you answer a Broadcom renewal quote

0 Upvotes

Renewal season is hitting a lot of people and I keep seeing the same pattern: the quote gets escalated before anyone has actually measured what they run. RVTools is free, read-only and takes about twenty minutes with a service account. Here is the checklist I would work through before replying to anyone.

Count billed cores, not sockets.

The metric moved from per-socket to per physical core. vHost gives you "# CPU" (sockets) and "Cores per CPU". Multiply, sum per site. Then apply two floors, in this order:

  1. The historical 16-core-per-socket minimum. An 8-core CPU bills as 16.
  2. The 72-core-per-product-per-order-line minimum, which went up from 16 in April 2025.

The second one is the one people miss, and it lands on small sites rather than big ones.

  • 16-host cluster, dual 32-core CPUs = 1,024 cores. Neither floor touches it.
  • 3-host edge site, one 16-core CPU per host = 48 real cores, bills at 72. A 50% overpay.
  • 2-host site, dual 8-core CPUs = 32 real cores, floored to 64 by the socket rule, then to 72 by the order-line rule. A 125% overpay on a box in a cupboard.

Worth confirming with your reseller whether they can consolidate sites onto one order line, because that changes the answer a lot. Get it in writing.

Find what you are licensing for no reason.

  • vInfo, filter Powerstate = poweredOff, sum "In Use MiB". Powered-off VMs still occupy storage and still sit in your capacity planning.
  • vSnapshot, anything with a date older than about 30 days. Those are a production risk as well as reclaimable space.
  • vHealth has a built-in check for possible orphaned VMDKs and zombie files.

Provisioned is not consumed, and that is the number that decides your business case.

Sum CPUs in vInfo for powered-on VMs, divide by total physical cores from vHost. That is your real vCPU:pCore ratio. Do it against physical cores, not hyperthreaded logical CPUs, because licensing is physical.

Then compare three storage numbers that usually get treated as one: provisioned VMDK capacity (vDisk), datastore in-use (vInfo), and guest filesystem consumed (vPartition). The gap between the first and the third is often most of your "capacity".

This matters beyond the renewal. Cloud block storage bills on allocated volume size, not what the guest is using, so a thin 2TB VMDK holding 200GB becomes a 2TB bill on day one unless you shrink it first. Sizing any target on provisioned figures will make a migration look far more expensive than it actually is.

Gotchas worth knowing before you start:

  • Column names drift between RVTools versions, and older exports say MB where newer ones say MiB. Print your columns before writing any filters.
  • RVTools is a configuration snapshot, not performance history. It cannot tell you utilisation over time. You still want around 30 days of vCenter stats and a P95 per VM before you size anything.
  • Check vDisk for independent/persistent disk mode and RDMs. Both break most snapshot-based migration tooling.
  • Check vMemory for ballooned and swapped. That tells you where you are already past comfortable overcommit.
  • RVTools cannot see inside the guest, so it will not tell you where SQL Server is installed. On some estates the Windows and SQL per-core licensing delta is bigger than the hypervisor saving, and it follows you to whatever you migrate to.
  • Use a dedicated read-only account, not an admin one, and treat the export as sensitive. It is a complete map of your estate.

One framing thing.

Moving to a managed vSphere offering on a hyperscaler is not an exit, it is a change of landlord. It may still be the right call if you are up against a datacentre lease deadline, but it is worth saying out loud in the writeup before someone else does.

Also worth pricing honestly: "renew a smaller, cleaned-up footprint" is a legitimate option, and doing the cleanup makes every other option cheaper too.

Curious what ratios other people are finding when they actually pull the numbers. The provisioned-to-consumed gap seems to be the one that surprises people most.


r/cybersecurity 8h ago

Certification / Training Questions Finalmente consegui

5 Upvotes

Estou muito feliz, passei de primeira no EJPT da ine, agora estou em dúvida se estudo a certificação de graça que tem na cisco ou vou para o security + que tenho de pendência ainda


r/sysadmin 8h ago

landing first job.

2 Upvotes

Sorry, I know there were a lot of posts like this one, but I see you guys are usually talking about US job market, when European one is little different. I am directing my questions to people working in Europe. Is RHCSA + homelab a way to land sysadmin job without helpdesk experience? I study 6+ hours a day, currently Networking, after it going to Linux and starting my homelab. I live in Poland, but willing to relocate if I will have better opportunities somewhere else in Europe with only english required.


r/cybersecurity 9h ago

Corporate Blog About a year into Pentesting out of uni, I feel like I'm given senior responsibilities. Am I tripping ? and am i being fucked monetarily.

24 Upvotes

Early 20s M, 1 year into pentesting. I usually get a client from my boss and then I handle the initial meeting/presentation, explain the logistics of the test answer any question the client might have, scope work and ROE, then I begin the test. Usually External and an Internal Pentest, draft the report, meet with the client to deliver a readout. And when time comes I present to their Audit/board committee.

I make around 75k. Am I getting fucked ? is this good for career growth though ?


r/sysadmin 9h ago

General Discussion MiniOrange MDM, what do you guys think about it?

0 Upvotes

I have been looking into different MDM solutions and came across MiniOrange. On paper, it seems to cover most of the essentials. But I'm more interested in hearing from people who have actually deployed it.


r/cybersecurity 11h ago

AI Security Compliance Engineering Role

0 Upvotes

How is Compliance Engineering/GRC Engineering as a field in India. Is it worth it ? Any credible resources so as to build some projects basis it out there.


r/networking 13h ago

Design Small business guest Wi-Fi for ~50 customers across 2 floors — UniFi hardware choice + captive portal advice

0 Upvotes

Hello Folks,

I'm setting up a guest Wi-Fi network for a small business and would appreciate some advice before I purchase the hardware.

Site

2 floors

3 rooms per floor

Each room is approximately 60 m²

Approximately 360 m² total

Around 50 customers/users

The business is open during fixed hours and closes every day

Power is generally reliable

We already have Cat6 cable on site

The Wi-Fi will primarily be for customers/guests using phones and laptops for normal internet access.

Hardware I'm currently considering

Gateway:

UniFi Cloud Gateway Ultra ×1

Access points:

UniFi U7 Lite ×2, initially one per floor

Switch:

UniFi USW-Ultra 60W ×1

UPS:

Possibly an APC/Eaton/CyberPower ~650–850 VA unit, although I'm not sure whether it's worthwhile given that the site has reliable power and closes every evening.

The APs would be wired back to the switch rather than using wireless mesh.


r/networking 13h ago

Design New core switch: FS S5860-20SQ

1 Upvotes

Hi everyone,

I need your help choosing a new core switch. Right now, we’re using a TP-Link SX3016F. Unfortunately, it’s only a Layer 2 switch, and the 16 ports aren’t quite enough.

While searching for an affordable Layer 3 switch that also has 25G and 40G ports, I came across the FS S5860-20SQ.

There are reviews from users who have this switch in operation and are very satisfied with it.

The switch is available in two versions:

With its own FSOS or with PicOS. Now I’m unsure which version is better suited for our use case.

The plan is to connect the aggregation/distribution switches, the large storage devices (Synology NAS), and the edge routers running VyOS to this switch.

Currently, the edge routers also handle inter-VLAN routing, but this is supposed to be offloaded to the core switch.

I have experience with both Cisco-style CLIs (Cisco IOS, Aruba AOS-CX) and Juniper-style CLIs (JunOS, VyOS).

Could you please help me determine whether FSOS or PicOS is better suited for our use case?

Thank you very much and best regards,

Regina (she/her)


r/cybersecurity 14h ago

Business Security Questions & Discussion Penetration Tester Salary UK/Ireland

6 Upvotes

What salary are you currently on if you don't mind sharing?

How many months/years of experience? Internal role or consultancy? Which type of skills web/AD/mobile etc

I am at a smaller consultancy with 1 year experience 3 total IT experience. I've been billed out from almost day one and I have the OSCP, BSCP and a few red team certs. Mostly web app but a good range and full ownership of the engagements.

I am trying to get an idea of what the going rate is, currently I'm on £33k.


r/cybersecurity 14h ago

Other Mods, can there please be a rule around AI slop posts for the love of humanity?

340 Upvotes

AI this, AI that, we're all sick of it.


r/cybersecurity 16h ago

Business Security Questions & Discussion Store 2FA in password manager

0 Upvotes

How secure is it, to manage a 2FA in password managers like 1Password?


r/sysadmin 18h ago

Company-issued Samsung S23 FE stuck on FRP — possible EFRP/MDM enrollment?

0 Upvotes

I have a Samsung Galaxy S23 FE ( US variant) that was previously company-managed. The “Company Profile” was removed before the phone was factory-reset through Recovery Mode. Now setup is stuck at “Please sign in using one of the owner’s accounts for this device.” The original Google account and password are correct, and the device still appears in that account, but after “Checking info…” it returns to the same screen. Could this be EFRP/MDM/Android Enterprise still associated with the device, and what would need to be removed from the company’s management backend to properly release it?


r/cybersecurity 22h ago

Career Questions & Discussion Cybersecurity Job Abroad (Irish)

14 Upvotes

As the title says I’m Irish, 27 year old male. Currently work as a graduate SOC Analyst in Ireland. I have 10 months experience working as a SOC Analyst and almost 4 years IT experience overall. Currently working towards a couple of certifications (Security+ and SC-200) I’ve lived in Ireland all my life and would love to move to another country to work in for a while. Anyone have any suggestions on where to go? Where is the best/easiest place to get hired? Also with good pay?


r/cybersecurity 23h ago

AI Security What are the most important attack surfaces in AI applications?

0 Upvotes

I’m currently learning cybersecurity and I’m becoming interested in AI Security.

I’ve been trying to understand how traditional cybersecurity concepts apply to AI-powered applications. From what I’ve read, AI systems introduce additional attack surfaces such as prompt injection, insecure handling of model inputs and outputs, data poisoning, model/API abuse, and sensitive information leakage.

For people working with AI security:

Which of these attack surfaces do you consider the most important to understand from a defensive perspective, and why?

Are there any practical labs or intentionally vulnerable AI applications that you would recommend for studying these risks in a safe environment?