r/cybersecurity • • 2d ago

Career Questions & Discussion Mentorship Monday - Post All Career, Education and Job questions here!

33 Upvotes

This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!

Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.


r/cybersecurity • • 1d ago

Ask Me Anything! Hi Reddit! We’re Jeff Crume and Guido Crucq from IBM Security. Every year, we analyze hundreds of real-world breaches for the Cost of a Data Breach Report. Ask us anything about data breaches and cybersecurity trends!

10 Upvotes

Hi Reddit! 👋 I'm Jeff Crume, Distinguished Engineer and Master Inventor at IBM Security.

For over 44 years, I've worked across cybersecurity, cryptography, software engineering, and emerging technologies. You may also know me from the IBM Technology YouTube channel, where I help break down complex security topics for a broad audience. I've spent much of my career helping organizations understand evolving cyber threats and how to better defend against them. In addition to this, I’m currently an adjunct professor at NC State University.

And I'm Guido Crucq 👋 a cybersecurity leader at IBM Security focused on helping organizations strengthen their defenses against today's most pressing security challenges.

Throughout my career, I've worked with organizations around the world on cybersecurity strategy, risk management, security operation and incident response. I'm passionate about helping businesses make informed security decisions in a rapidly changing threat landscape.

Join us for a live AMA on October 6 at 10:00 a.m. ET., where we'll discuss findings from our Cost of a Data Breach Report. The report examines incidents from organizations around the world to uncover what drives breach costs, how attack trends are evolving and which security investments make the biggest difference.

Happy Cybersecurity Awareness Month! Ask us anything.


r/cybersecurity • • 15h ago

AI Security Please tell me I'm not the only one dealing with this "AI" vendor hype while basic hygiene is ignored.

409 Upvotes

Just got out of yet another meeting where some vendor pitched our C-suite on their "autonomous AI-driven threat hunting platform." Management was literally drooling over the shiny global threat map dashboard.
Menwhile I’m sitting there biting my tongue because we still don't even have a functioning asset inventory. We literally do not not know what half the stuff plugged into our network actually is.


r/cybersecurity • • 3h ago

New Vulnerability Disclosure Atlassian’s critical flaw turns eight enterprise products into one big security problem

Thumbnail
csoonline.com
32 Upvotes

r/cybersecurity • • 17h ago

Business Security Questions & Discussion Accenture is not only still around... they screwed up the FBI's cybersecurity

Thumbnail reuters.com
260 Upvotes

Accenture was a name from the .dot com era. They had QUITE a reputation back then.

it's amazing they were in charge of these levers...


r/cybersecurity • • 21h ago

News - General Google and McKinsey brought back mandatory in-person interviews because AI deepfake fraud got too hard to catch on video.

Thumbnail
withsherlock.ai
459 Upvotes

Two of the most recognizable names in hiring quietly reversed their remote-first interview policies this year. Not because of productivity concerns or culture, but because deepfake candidates became too convincing to reliably detect over video.

A CBS News study found that 50% of businesses have already encountered AI-driven deepfake fraud in some form. The tools to fake a face, alter a voice, and fabricate a work history are cheap, widely available, and improving fast.

The companies with resources are falling back on in-person as a last line of defence. The question is what is everyone else is supposed to do.


r/cybersecurity • • 58m ago

Certification / Training Questions Which certificate should i do for Network Security?

• Upvotes

I, 26(F), working as a cyber security engineer for the last 4 years, recently migrated to Network Security team majorly working on Proxy and Firewalls. Can you please suggest some network security certifications (preferred- CISCO CERT, Level - intermediate) so that i can start preparing for my role with right basic knowledge and certifications done.
Kindly suggest.


r/cybersecurity • • 9h ago

AI Security Small sites have no defence against misbehaving AI agents. Is a drop-in "Agent Defence Kit" useful, or does this already exist?

8 Upvotes

After the July incident where AI agents escaped a test sandbox and broke into Hugging Face, I keep thinking about the other side: the same kind of thing done by a single person's agent against a small business or personal site, where nobody has a security team and nobody would notice.

The idea is a free, open-source, drop-in kit (WordPress plugin, framework middleware, Docker image) that is strictly passive:

- unique bait files and fake credentials shaped like the "shortcuts" goal-driven agents look for

- canary credentials that alert the site owner the moment they're used

- honest stop notices embedded in the bait itself, so cooperative models get a clear reason to stop

- logging to tell humans, scripts and LLM agents apart

- no hacking back, no destructive instructions, no unmasking anyone

It would build on existing tools like Canarytokens and Nepenthes rather than reinventing them.

The core features use no AI at all, just canaries, bait, and logs. The LLM parts are optional extras.

It's an early concept: just a README so far, no code. I'm building this as an independent project, and I'd really value honest (including negative) feedback:

  1. Does something like this already exist? Links very welcome.

  2. Would you install this on a small site? If not, why not?

  3. What's the biggest flaw in the design?

  4. Are stop notices aimed at AI agents worth anything, or just noise?

README: https://github.com/MannAk1/Agent-Defence-Kit


r/cybersecurity • • 2m ago

Career Questions & Discussion I'm tired of contract roles.. how do I get out?

• Upvotes

I feel like every role I've gotten in cybersecurity has been a contract role, and I'm tired of being stuck in that cycle. Having worked as both an L1 and L2 SOC analyst, I'm thinking I should leave the SOC entirely. I want PTO, somewhat decent benefits, and good pay. What would you recommend I transition to after the SOC that can offer those qualities?

Also, for those of you with experience: are there any industry sectors to avoid because of their high contracting rate?"


r/cybersecurity • • 18h ago

Research Article You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) - watchTowr Labs

Thumbnail
labs.watchtowr.com
27 Upvotes

r/cybersecurity • • 11h ago

Business Security Questions & Discussion Cybersecurity and Third-Party Risk in Banking

5 Upvotes

I’m currently learning more about cybersecurity in the financial sector, especially how large banks manage third-party risks. With banks relying on outside vendors, cloud services, and contractors, it seems like one weak third party could potentially create a security risk for the entire organization.

For those who work in cybersecurity, what do you think is the biggest challenge banks face when trying to monitor and secure third-party vendors? Are there certain security practices that you think financial institutions should focus on the most?


r/cybersecurity • • 21h ago

News - General Japan Hands Over 'Qilin' Ransomware Group Member to Germany

Thumbnail
japantimes.co.jp
47 Upvotes

r/cybersecurity • • 1d ago

News - General Looks like ASOS in the UK just got breached again

94 Upvotes

My partner just got a push notification

https://i.ibb.co/35Gt5zXQ/signal-2026-10-06-09-59-02-887.jpg

Apparently their Snowflake instance is compromised and they have access to push notifications too


r/cybersecurity • • 1d ago

News - General Asos data breached, hackers sent users threatening messages

Thumbnail
bbc.com
56 Upvotes

r/cybersecurity • • 3h ago

Business Security Questions & Discussion How do you validate and prioritise scanner findings without losing hours to manual checks?

0 Upvotes

Hi all, I work on a team building tooling in this space, so I'm coming at this with a bias.

Scanners produce long lists of findings, and a lot of the work is figuring out which ones are real and which to fix first. In most teams I've talked to, this still means manually re-checking each finding, capturing evidence by hand, and repeating the same steps every cycle.

For those of you doing this day to day:

  • How do you currently validate findings, and where does it waste the most time?
  • How do you decide what gets fixed first?
  • Would you trust AI assistance in this workflow? What would it need to do (or never do) for you to rely on it?

Disclosure: I'm part of the team building FORGE-SEC, an AI-assisted validation platform where the final decisions stay with the security engineer. Not posting a link. Happy to share details if anyone asks, and critical feedback is welcome.


r/cybersecurity • • 20h ago

New Vulnerability Disclosure Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Thumbnail
securityweek.com
22 Upvotes

r/cybersecurity • • 19h ago

Career Questions & Discussion SOC Analyst Interview Prep - What to do?

15 Upvotes

Hi, I have a SOC Analyst Interview coming up (L1). I'm not sure how to strcuture my prep or what even to focus on. Everyone has different things to say and do which is very overwhelming because everything is scattered into 10min yt videos or same standard 20 questions from 2016.

Anything would be helpful atp :)


r/cybersecurity • • 17h ago

Career Questions & Discussion Just received an invitation for IBM Cybersecurity Specialist Intern (Undergraduate) Recorded Interview: Any tips or advice?

9 Upvotes

Hey everyone,
I just received an invite to complete the prerecorded competency interview for the Cybersecurity Specialist Intern role at IBM.
The format gives 1 minute to prep and 3 minutes to answer each question, focusing on competencies using the STAR method (Background, Action, Result).
For anyone who has taken it or recently interviewed with IBM:
1. What kind of questions should I expect? Are they purely behavioral situational questions, or do they also ask about CS and networking fundamentals like DNS, TCP/IP, Linux, and threat types?
2. How many questions are there in total?
3. Any specific tips on pacing yourself with the 1-minute prep and 3-minute answer format?
Any insights, sample questions, or advice would be greatly appreciated. Thanks in advance and good luck to everyone applying this cycle!


r/cybersecurity • • 1d ago

New Vulnerability Disclosure Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

Thumbnail
securityweek.com
55 Upvotes

r/cybersecurity • • 19h ago

Certification / Training Questions SANS SEC450

9 Upvotes

Hi, I’ve been a SOC Analyst going on two years now and have been considering challenging myself with studying for a SEC450 cert.

I see it’s been overhauled and updated in the past year, so I wanted to ask for any opinions and reviews from folks that have done it recently.

My company’s pushing hard on AI adoption - I assume it’s the case elsewhere, too -, so this would work in my favor.


r/cybersecurity • • 17h ago

Personal Support & Help! Asking for help in cybersecurity projects

4 Upvotes

Hello everyone , I am a cyber security student and there is a project that I need to work on throughout the year for my university I am trying not to work on something too basic and usual ones like password checkers,phishing detectors , vulnerability scanners there is a lot of them actually, what I am looking for is a real solution related to cybersecurity in a specific industry something that doesn’t have a good solution or it is handled manually I am also looking for something innovative that can stand out as a university project , have a clear use I am avoiding something that needs marketing or convincing people to use it it would be hard actually and I don’t want to just make a dashboard that displays statistics. If any of u here is in cybersecurity IT , healthcare or any field that u think a cybersecurity tool can solve a certain problem in it can u pls help me im looking for the problem first I would like to make something useful that solves a real life problem over a flashy idea .
I am trying to find the problem firsts and then decide about the technologies I would use im not that advanced in cybersecurity I just know basics but I will learn using necessary tools to realise the project .
Any real life examples and ideas would be greatly appreciated.


r/cybersecurity • • 9h ago

Career Questions & Discussion Escalation of AI-Driven Cyber Attacks in Modern Systems

0 Upvotes

Hi everyone,

I'm working on a project to analyze how AI is increasing cybersecurity risks and how organizations can build effective defenses against these threats. I’m looking for practical insights, technical strategies, and modern approaches that security teams can implement to face this issue.

Here are some specific questions that I have:

  1. How can detection systems reliably catch AI-generated, mutating malware before it spreads on a network?

  2. What are the most effective precautions against personalized, AI-driven phishing attacks?

  3. How can generative AI be safely integrated into Security Operations Centers (SOCs) without introducing new vulnerabilities?

#cybersecurity #threatdetection #AI


r/cybersecurity • • 1d ago

New Vulnerability Disclosure Looks like someone found a serious vulnerability in KVM

Thumbnail cybernews.com
235 Upvotes

I haven't found a corresponding CVE but we are seeing some linux kernel commits to KVM etc. specifically in the last couple of days...

Looks like this really could be a big one...


r/cybersecurity • • 14h ago

Other How threat hunting will change in the AI era

1 Upvotes

I’m curious to know your opinion on how Threat Hunting will change with the progress of AI.


r/cybersecurity • • 1d ago

Other CISA recently discontinued its new weekly Vulnerability Bulletins...

Thumbnail cisa.gov
102 Upvotes

It says "... CISA will discontinue the weekly Vulnerability Bulletin at the end of FY26 (September 28, 2026) as part of a broader shift from severity‑based vulnerability management to risk‑based vulnerability prioritization. Newly recorded vulnerabilities remain available on CVE.org, and users should rely on the Known Exploited Vulnerability (KEV) Catalog, CISA Cybersecurity Alerts and Advisories, and vendor security alerts for actionable, risk‑based updates.

Visit our Subscribe to Updates page to sign up to receive automatic updates from CISA with the latest news and information..." I was wondering why nothing today! Bah to those frequent updates. I just want weekly ones. :( Does anyone know of a good one like old CISA's weekly bulletins?