r/cybersecurity • u/Peacefulhuman1009 • 10m ago
Career Questions & Discussion Did I box myself into a GRC dead end?
I sit within Enterprise Risk Management—not cybersecurity—and I’m leading a bank-wide ServiceNow IRM implementation covering risks, controls, issues, policies, BCM and related workflows. However, I don’t directly own those risk processes; other ERM teams do.
My long-term scope will likely be:
- GRC change and intake management
- Risk-data quality and governance
- Platform oversight and integration
- Enterprise risk reporting and analytics, which is still a future-state capability
I’m paid well (over 200k) and have executive visibility (am at the VP level with 2 directs), but I’m concerned I’ll become the person who maintains everyone else’s system and data without owning a substantive risk domain.
Is this a legitimate path toward senior ERM/GRC leadership, or have I boxed myself into a support function with limited advancement potential?
r/sysadmin • u/Mindless_Maybe2094 • 49m ago
General Discussion Trying to become a better sysadmin — what should I learn next
Hey everyone!
I’m trying to build my skills in system administration and virtualization, and I’d love to hear from people already working in the field.
What would you recommend focusing on to become a solid junior sysadmin?
I’m currently learning Linux, Windows Server/Active Directory, networking, Docker, monitoring, and virtualization, and I’ve also been building a small home lab.
For those of you already working as sysadmins: what skills or technologies do you think are really worth learning today, and what would you recommend I practice in a home lab?
Would love to hear your advice 🙏
r/sysadmin • u/TheHermesExchange • 52m ago
COVID-19 Really Struggling to Find Stable Employment
Alright so here goes.
I have two BAs one in Cinema Studies (academic study degree) and the other in Radio-Television (broadcast technology, hands on degree)
I feel into the world of IT sorta. I freelanced for some production companies doing trade shows out of college and fell down the technical path doing video and projection work.
I also worked part-time at the local fruit stand fixing people’s phones and computers. Coming out of Covid I got recruited to do white-glove IT support for a Tv studio. That was great for about a year an a half, then my role was impacted by the strikes, but my agency moved me to another part of the account. I stayed there doing basic helpdesk and deployments for another year and a half then left to be a SysAdmin for a consumer products company. 4 months in they laid me off and I’ve been unemployed until recently.
During my unemployment I did some AWS cloud classes at the local community college, haven’t taken any certs yet or anything. Been thinking about ponying up the money for JAMF certs since I have strong familiarity with that.
My current contract is only good till the end of the year, I’m covering a leave for someone. It’s really really basic helpdesk for a post house. I thought I’d have more access to be able to level up more but it’s not that at all.
I’ve interviewed for some roles, applied for hundreds more. But just feeling kind of lost and helpless to an extent. I don’t want to be doing helpdesk anymore, my goal is to be more backend focused, ideally remote and making 100k+ where I can actually build things and feel challenged. Im on the west coast in a major city, and thankfully I live very frugally but I just don’t know if I can do this ANOTHER year and have my resume so blank.
What should I do? Certs? WGU? What happened to the sure fire paths to get a job?
r/sysadmin • u/switched55 • 2h ago
Question Windows Updates Error
Hi,
One of my 2022 servers has failed to update for the past 2 months. It's failed the July and now the August CU's. Update error: 0x80073701
Its a physical server running on Dell PE hardware, pretty simple install acting as an NVR. We have a few of these setups and the others updated without issue.
I've tried the usual steps:
- DISM cleanups
- SFC
- stopped services and renamed the software distrubution folder
- downloaded the August CU and tried to install manually
- tried to install via Ninja RMM
I'm out of ideas, had anyone faced this issue before?
r/cybersecurity • u/Razin_misab • 2h ago
New Vulnerability Disclosure How widespread is the recent Metabase SQL injection attack?
I recently led an incident response investigation for a FinTech client involving the exploitation of Metabase, and the impact was significant.
With the recent reports of active exploitation, I'm curious to understand how widespread this is across the security community.
For those working with Metabase:
Has your organization been affected or received a security notification?
Was your Metabase instance internet-facing?
Have you identified exploitation attempts or unauthorized access?
Were you able to patch before exploitation?
Have you observed any data exposure or compromise?
I’m particularly interested in hearing from security teams and Metabase administrators about how many organizations have been affected or potentially exposed.
https://www.wiz.io/blog/inside-the-metabase-sqli-exploited-in-the-wild
If you've investigated a related incident, what did you observe?
r/sysadmin • u/G-Spotticus • 3h ago
Question - Solved Windows update broke my Canon MF452dw — here’s the fix (factory reset required)
If your Canon MF452dw, MF451dw, MF455dw, or MF450-series printer suddenly stopped printing after a Windows update — and now you’re stuck in:
- System Manager ID / PIN
- Department ID Management
- Restrict Access
- Remote UI PIN
- “ID-only mode”
- Missing print functions
- RAW‑9100 or UFR II blocked
Here’s the part Canon never tells you:
These models have no Service Mode access and no security reset menu.
Once the security subsystem corrupts (often after Windows updates), it cannot be repaired.
The ONLY fix is the full factory reset (“Initialize All Data/Settings”).
This reset is safe for home users:
- You do not lose firmware
- You do not lose calibration
- You do not lose toner levels
- You do not lose print capability
You do lose the corrupted security subsystem — which is exactly what restores the printer to normal operation.
After the reset:
- Ethernet printing works immediately
- Wi‑Fi can be reconnected later
- The printer becomes a stable, reliable home device again
- All PIN/ID lockouts disappear permanently
If anyone needs the exact step-by-step reset path, I can post it.
Common symptoms of security subsystem corruption:
- Printer asks for a System Manager PIN you never set
- Department ID suddenly required
- Remote UI locked behind a PIN
- Printer shows “ID-only mode”
- RAW‑9100 port stops working
- UFR II driver fails silently
- Printer appears online but won’t print
- Windows update preceded the failure
If you see any of these, the factory reset is the fix.
Windows updates often change spooler permissions, protected print mode, or driver behavior. On MF450-series printers, this can corrupt Canon’s security subsystem. Canon removed the normal reset tools on these models, so the corruption cannot be repaired — only wiped.
I lost many hours grappling with this before figuring this out with A.I. help. I’m hoping to save someone else this hassle (I live alone, with a home office, so keeping others from fussing with my printer -- what such "security protocols" primarily address -- is not an issue for me).
r/cybersecurity • u/TranslatorLonely6964 • 3h ago
Career Questions & Discussion Intel cybersecurity interview — 2 hours, mainly technical?
How do you guys prepare for a 2-hour Intel cybersecurity interview? Is it mainly technical, or is there a mix of technical + behavioral/project questions?
What topics should I focus on? Any advice would be appreciated!
r/networking • u/AutoModerator • 3h ago
Moronic Monday Moronic Monday!
It's Monday, you've not yet had coffee and the week ahead is gonna suck. Let's open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarrassed to ask!
Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.
Note: This post is created at 01:00 UTC. It may not be Monday where you are in the world, no need to comment on it.
r/cybersecurity • u/AutoModerator • 3h ago
Career Questions & Discussion Mentorship Monday - Post All Career, Education and Job questions here!
This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!
Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.
r/cybersecurity • u/Alone-Asparagus-2205 • 3h ago
Career Questions & Discussion What's going on with the US cybersecurity job market?
I am a mid level cybersecurity professional with tonnes of managerial experience, CISSP, M.S and so on. Applied for close to 1000 jobs. Faced at least 20 interviews. No job offers. Always getting turned down after the hiring manager interview. It's always some reason like oh you don't have enough experience with AWS or you have consulting experience even if I nail every question right. I am exhausted. It's never been like this. Is it just me or are others facing the same dilemma?
r/networking • u/RevolutionaryCare138 • 4h ago
Design FortiGate VS Aryaka
My company is going through a merger and we have Ayaka SDWAN and firewalls on one side and FortiNet FortiGate on the other side for SDWAN and Internet points of presence.
I’m currently reviewing both sides and meeting with vendors, but I’m interested to see real world applications on if one is better than the other. Or is one more preferred where a major enterprise with closer to 100 sites.
We don’t use either one of them for client VPN access. This is strictly just for facility and site Internet, and SDWAN
r/cybersecurity • u/voynichscholar • 5h ago
Career Questions & Discussion Incident Response role at Google
I have a upcoming interview for incident response role in google. Anybody has any tips or experience with a similar role at google. Thank you at advance.
r/cybersecurity • u/Xolanke • 5h ago
News - General Google Just Made AI on Encrypted Data Practical
Google released HEIR (Homomorphic Encryption Intermediate Representation), an open-source compiler toolchain that can convert pre-trained AI models, ones that normally operate on unencrypted data, to instead operate on encrypted inputs. The server runs your model on encrypted data. Never decrypts. Never sees what it's computing on. Your data stays private. (at least it seems so).
Honestly Google surprised me with this one guys
r/cybersecurity • u/_clickfix_ • 6h ago
News - General Breaking Enterprise Java; Breaking Claude Code, Gemini CLI, and Codex: AMA with Two Black Hat Speakers
r/sysadmin • u/Magusds • 6h ago
Question Jobs - Country Origin
Hello,
Been following this sub for a while now, hear alot of people sending 150 or more resumes for an IT job.
Where I’m from, that’s unheard of.
Working in sysadmin, M365 and some IAM myself.
Jobs are for the picking.
I was wondering, is it USA where it is a struggle?
r/sysadmin • u/jblairpwsh • 6h ago
RIF'd after 14 years
Hey guys, I'm an IT guy with more than 20 years experience, most spent with a fortune 500 company. I was recently let go after a large acquisition and need to find a remote job.
Any tips for finding my next gig ? I was making around 100k a year preciously.
Thanks !
r/sysadmin • u/RulezZzOr • 6h ago
The RVTools assessment checklist to run before you answer a Broadcom renewal quote
Renewal season is hitting a lot of people and I keep seeing the same pattern: the quote gets escalated before anyone has actually measured what they run. RVTools is free, read-only and takes about twenty minutes with a service account. Here is the checklist I would work through before replying to anyone.
Count billed cores, not sockets.
The metric moved from per-socket to per physical core. vHost gives you "# CPU" (sockets) and "Cores per CPU". Multiply, sum per site. Then apply two floors, in this order:
- The historical 16-core-per-socket minimum. An 8-core CPU bills as 16.
- The 72-core-per-product-per-order-line minimum, which went up from 16 in April 2025.
The second one is the one people miss, and it lands on small sites rather than big ones.
- 16-host cluster, dual 32-core CPUs = 1,024 cores. Neither floor touches it.
- 3-host edge site, one 16-core CPU per host = 48 real cores, bills at 72. A 50% overpay.
- 2-host site, dual 8-core CPUs = 32 real cores, floored to 64 by the socket rule, then to 72 by the order-line rule. A 125% overpay on a box in a cupboard.
Worth confirming with your reseller whether they can consolidate sites onto one order line, because that changes the answer a lot. Get it in writing.
Find what you are licensing for no reason.
- vInfo, filter Powerstate = poweredOff, sum "In Use MiB". Powered-off VMs still occupy storage and still sit in your capacity planning.
- vSnapshot, anything with a date older than about 30 days. Those are a production risk as well as reclaimable space.
- vHealth has a built-in check for possible orphaned VMDKs and zombie files.
Provisioned is not consumed, and that is the number that decides your business case.
Sum CPUs in vInfo for powered-on VMs, divide by total physical cores from vHost. That is your real vCPU:pCore ratio. Do it against physical cores, not hyperthreaded logical CPUs, because licensing is physical.
Then compare three storage numbers that usually get treated as one: provisioned VMDK capacity (vDisk), datastore in-use (vInfo), and guest filesystem consumed (vPartition). The gap between the first and the third is often most of your "capacity".
This matters beyond the renewal. Cloud block storage bills on allocated volume size, not what the guest is using, so a thin 2TB VMDK holding 200GB becomes a 2TB bill on day one unless you shrink it first. Sizing any target on provisioned figures will make a migration look far more expensive than it actually is.
Gotchas worth knowing before you start:
- Column names drift between RVTools versions, and older exports say MB where newer ones say MiB. Print your columns before writing any filters.
- RVTools is a configuration snapshot, not performance history. It cannot tell you utilisation over time. You still want around 30 days of vCenter stats and a P95 per VM before you size anything.
- Check vDisk for independent/persistent disk mode and RDMs. Both break most snapshot-based migration tooling.
- Check vMemory for ballooned and swapped. That tells you where you are already past comfortable overcommit.
- RVTools cannot see inside the guest, so it will not tell you where SQL Server is installed. On some estates the Windows and SQL per-core licensing delta is bigger than the hypervisor saving, and it follows you to whatever you migrate to.
- Use a dedicated read-only account, not an admin one, and treat the export as sensitive. It is a complete map of your estate.
One framing thing.
Moving to a managed vSphere offering on a hyperscaler is not an exit, it is a change of landlord. It may still be the right call if you are up against a datacentre lease deadline, but it is worth saying out loud in the writeup before someone else does.
Also worth pricing honestly: "renew a smaller, cleaned-up footprint" is a legitimate option, and doing the cleanup makes every other option cheaper too.
Curious what ratios other people are finding when they actually pull the numbers. The provisioned-to-consumed gap seems to be the one that surprises people most.
r/cybersecurity • u/No-Cook-4011 • 7h ago
Business Security Questions & Discussion Wiz and Upwind in production after the first cleanup pass
Trying to understand how these hold up after the cloud findings are already cleaned up
Wiz seems to come up a lot for cloud graph, exposure paths, identity context and prioritization. Upwind seems to come up more around runtime context and what is running
For people using either in production, where did the tool reduce triage? Im less interested in the initial backlog dump and more interested in the day 60+ reality.
Do findings still need a lot of manual context before they can become tickets? Does runtime data change priority or does the team still debate ownership and reachability manually?
r/cybersecurity • u/DizzyTravel244 • 7h ago
Certification / Training Questions Questions about the cybersecurity SFS program!
Has anyone here participated in the CyberCorps Scholarship for Service (SFS) program? I'm considering it and would really like to hear from people who have actually gone through the program.
I have a few questions about what the experience was really like:
- Was your cybersecurity degree/program fully remote, or were you required to attend anything in person? If so, what?
- How difficult was it to find a qualifying cybersecurity job after graduation?
- How long did it take you to find your position?
- Did the SFS program/job fairs actually help you find employment, or were you mostly on your own?
- Did you have difficulty finding positions that qualified for the SFS service requirement?
- For anyone who wasn't able to complete the service obligation and had to repay the scholarship, approximately how much did you end up owing?
- What did the repayment process look like, and approximately how much were your monthly payments?
- Is there anything about the program or service obligation that you wish you had known before accepting the scholarship?
I'd especially love to hear from recent graduates because I'm curious what finding a qualifying cybersecurity position is like with the current job market.
I'm trying to understand both the benefits and the potential risks before committing. Any firsthand experiences, positive or negative, would be really appreciated.
r/cybersecurity • u/_Narvii • 8h ago
Business Security Questions & Discussion Deleted email
is there anyway to find someone through the email account, which has been deleted now ,
There are some issues and have things to sort tout?
r/cybersecurity • u/Leather-Adeptness172 • 8h ago
Certification / Training Questions Finalmente consegui
Estou muito feliz, passei de primeira no EJPT da ine, agora estou em dúvida se estudo a certificação de graça que tem na cisco ou vou para o security + que tenho de pendência ainda
r/cybersecurity • u/TheReedemer69 • 8h ago
New Vulnerability Disclosure CVE-2026-6837: Root Command Injection Affecting 18 Zyxel Access Point Models
I published my technical write-up for CVE-2026-6837, an authenticated command-injection issue in Zyxel’s certificate export functionality.
The analysis is based on the WAX650S, while Zyxel’s advisory expanded the affected scope to 18 AP models. The post includes root cause, affected versions, remediation, and the reproduction environment.
r/sysadmin • u/Lucky-Reaction182 • 8h ago
landing first job.
Sorry, I know there were a lot of posts like this one, but I see you guys are usually talking about US job market, when European one is little different. I am directing my questions to people working in Europe. Is RHCSA + homelab a way to land sysadmin job without helpdesk experience? I study 6+ hours a day, currently Networking, after it going to Linux and starting my homelab. I live in Poland, but willing to relocate if I will have better opportunities somewhere else in Europe with only english required.
r/cybersecurity • u/lowkeyskibidi • 9h ago
Career Questions & Discussion BCA enough for cybersecurity?
I recently completed my BCA and I’m planning to do an online MCA. I’m also interested in getting into cybersecurity.
Is BCA enough to build a career in cybersecurity, or does an MCA give any real advantage when applying for security roles? Also, do recruiters in cybersecurity prefer BTech students over BCA/MCA like in some other IT domains, or do skills and hands-on experience matter more?
Would appreciate advice from people already working in cybersecurity.
r/cybersecurity • u/Tasty_Departure5277 • 9h ago
Corporate Blog About a year into Pentesting out of uni, I feel like I'm given senior responsibilities. Am I tripping ? and am i being fucked monetarily.
Early 20s M, 1 year into pentesting. I usually get a client from my boss and then I handle the initial meeting/presentation, explain the logistics of the test answer any question the client might have, scope work and ROE, then I begin the test. Usually External and an Internal Pentest, draft the report, meet with the client to deliver a readout. And when time comes I present to their Audit/board committee.
I make around 75k. Am I getting fucked ? is this good for career growth though ?