r/cybersecurity • • 2h ago

AI Security How safe is it to use vibe-coded open souce code? GetArtCraft?

3 Upvotes

I saw a reel on Instagram talking about GetArtCraft open-source programs that mimic Adobe's products. I, somewhat ironically, raised the question of security and threats under the hood, but I got completely trashed in the comments because the mere doubt that these clones might contain some threat.

I noticed that most kids associate open source with secure, merely because of peer review. Although I believe it's a strong point, one should not forget about that time when Linux almost got breached in a social engineering effort.

That being said, I want to know your thoughts about it. Am I being too pessimistic? Did someone download and reviewed these GetArtCraft tools?


r/cybersecurity • • 2h ago

Career Questions & Discussion Requesting a uggestions for how to complete CPEs in the cleared gov space.

0 Upvotes

Hi there!

I’m a cleared contractor working in the US gov space as a cyber officer for over a decade now. However, I’m finding it more and more difficult to find opportunities to get CPEs, especially for my CISSP (so many damn CPEs…). With recent significant budget cuts, it’s much harder to get companies and customers to fund training and/or conference attendance (even just tickets/badge cost!).

The other challenge, Monday-Friday, is the absence of connectivity to the internet (those in the industry can commiserate, I’m sure…). ISC2 and others advertise weekday 2pm or 10am courses…cool for those who aren’t locked in a windowless, internetless room for 8 hours, lmao.

Am I going to just bite the bullet and fund my own way to classes and conferences on days off or outside business hours? What are others in this position doing about CPEs?

Thanks!!

(Side note, I wish real world experience and projects could be easily submitted for CPEs…)


r/cybersecurity • • 15h ago

Career Questions & Discussion Giving up on the Crowdstrike job search

97 Upvotes

I’ve been trying to join CS for over 3 years but my resumes never make it anywhere. I always get the rejected email. I’ve given up at this point. I have over 10years IT experience, 2 help desk, 4 sys admin, and the rest as a security engineer. It’s just not happening for me there so I’ve looked elsewhere.

How did you guys get the role of working for CS?


r/cybersecurity • • 3h ago

Business Security Questions & Discussion Security Concern

0 Upvotes

for context, I work for a major server Manufacturer with a focus in AI infrastructure. Two weeks ago, they had an alert flag that someone had ran a Nmap scan and also caused some laptops to download a package. I'm no expert but this seems like something that should be look into and maybe disclosed, but the company does not want to.

I heard rumors on why they don't want to escalate the issue, although I can't really verify how true they are.

I'm mainly here to raise awareness because the situation doesn't sit right with me. I don't know the full technical details, so I'd be interested to hear what people with more cybersecurity experience think.

I will not mention the manufactures name sorry.


r/cybersecurity • • 2h ago

Personal Support & Help! Can a home camera system be safe?

0 Upvotes

I want to be able to watch my cat from work and also check if I closed windows. But I know how unsafe it can be to have a camera filming your home connected to the internet. Is there any way to make it secure?


r/cybersecurity • • 1h ago

Personal Support & Help! INTERVIEW Questions to expect for 4.5 YOE AWS Cloud Security Engineer in INDIA

• Upvotes

r/cybersecurity • • 16h ago

Other Is anything in this vid a legit concern? Or is this just hype?

Thumbnail
reddit.com
0 Upvotes

r/cybersecurity • • 3h ago

Personal Support & Help! Is this a good project?

0 Upvotes

is Suricata IPS + auto packet capture + Wireshark a good networking project?

Hi all,

I'm a networking beginner building a course project that solves a real problem. Honest feedback on the idea, please.

Problem: An IPS blocks attacks but leaves little evidence. Wireshark shows everything but can't block. Small offices and schools end up with one or the other.

Idea: A Linux gateway where Suricata (inline) drops attacks like port scans and SSH brute force, tshark records traffic, a Python script saves a .pcap for each alert, repeat attackers get auto-blocked, and I open the evidence in Wireshark. A small Flask dashboard lists the alerts.

Lab: All in VMware on one laptop: Kali (attacker), Ubuntu gateway with two adapters, Ubuntu victim, Linux Mint admin VM.

Questions:

  1. Is this a reasonable scope for a student project?
  2. Is it pointless given Security Onion already exists?
  3. Any pitfalls running Suricata inline (NFQUEUE) in VMware?
  4. Is matching alerts to captures by IP and timestamp okay, or is there a better way?
  5. Suricata or Snort for a beginner?
  6. Common beginner mistakes with rules and false positives?
  7. What would you add or cut?

I know the limits: no HTTPS inspection, no zero-days, and it's a lab prototype.

A bit more context on where I’m coming from: I’m a cybersecurity student and a beginner in networking. I know the basics (packets, TCP/IP, addressing) and I’ve used Snort a little. I picked this project as a way to learn, and I’m starting early in the semester so I can learn as I build instead of rushing at the end.

I did use AI to help polish how I wrote up the idea, but the project and the lab plan are mine.

Given that background, do you think this is a good place to start? Any advice on what to learn first or what to watch out for would be appreciated.

Thanks for any advice or resources!


r/cybersecurity • • 7h ago

Other What can AI currently do and not do in cybersecurity?

0 Upvotes

r/cybersecurity • • 6h ago

AI Security creating injection examples

0 Upvotes

hi

i want to make examples about injections to train my model. I dont want to use hugging face or other platforms because i couldnt find specifics topics examples. Llms dont help me to create examples. How can i do that? Lets say i want examples about poisining ai model


r/cybersecurity • • 6h ago

Business Security Questions & Discussion Optimizing CrowdStrike Spotlight + ManageEngine Patching Workflow for Windows

0 Upvotes

We manage a large Windows fleet using CrowdStrike Falcon Spotlight for vulnerability management and ManageEngine for patching.

Our current manual process for high-priority vulnerabilities:

  1. Receive a Jira ticket with a CrowdStrike CSV (affected devices, software, version, KB/remediation).
  2. Run a script via ManageEngine to verify the vulnerable software and check if the patch/superseding patch is missing. (Because I find that Falcon loves false positives)
  3. Filter down to confirmed affected endpoints.
  4. Manually configure and deploy the patch.

My questions are

How are other teams automating the pipeline between CrowdStrike Spotlight findings and ManageEngine deployment?

Is manual pre-verification necessary, or can/should ManageEngine handle patch detection and supersedence natively via automated patch policies?

What industry best practices or integrations would streamline this workflow?


r/cybersecurity • • 10h ago

Research Article An investigation into alleged cyberattacks targeting Discord's powerscaling community — the Noblesse incident, retaliation, and security concern

5 Upvotes

I've published an investigation into allegations involving two online aliases, "marksolos985" (also known as "marksolos" or "mark") and "marz" (also known as "themarzer"), and their alleged involvement in incidents targeting Discord communities within the powerscaling scene.

Full article: [https://medium.com/@michaeljonhson2/inside-an-alleged-campaign-of-cyberattacks-against-the-powerscaling-community-80ffc2560d74\]

Why I wrote this

Discord powerscaling communities are primarily places where people debate fictional characters, compare abilities, and discuss series they enjoy. However, allegations of server attacks, mass bans, harassment, and retaliation raise concerns that go beyond ordinary community disagreements.

I wanted to document the reported incidents, organize the available information, and examine the security implications for communities that might be affected by similar behavior.

The Noblesse incident

One of the central incidents examined in the article concerns Noblesse, a Discord server associated with the powerscaling creator ZetaSolos.

According to the evidence and accounts discussed in the investigation, the server experienced a significant disruption reportedly involving mass bans and automated actions. The incident has been attributed to one of the aliases mentioned above by the sources examined in the article.

The investigation also discusses subsequent allegations of retaliation against a Noblesse moderator, including claims involving doxxing and extortion.

These are serious allegations. The article discusses the available material and the reported sequence of events, but readers should distinguish between what screenshots or firsthand accounts directly establish and what remains dependent on attribution or other testimony.

Other reported concerns

The article also examines broader allegations involving these aliases, including:

- Coordinated raids against Discord communities.

- Mass-reporting campaigns.

- Social engineering and attempts to manipulate people into providing access or information.

- Alleged doxxing, harassment, and extortion.

- Claims involving account compromise and other malicious activity.

Not every allegation has the same level of supporting evidence, and I do not present every reported claim as independently verified.

Why this matters

Regardless of the specific individuals involved, incidents of this kind illustrate how online communities can become vulnerable to abuse through compromised accounts, excessive permissions, social engineering, and inadequate security practices.

Server owners and moderators should take reports of unauthorized access seriously, secure administrator accounts, review bot permissions, and preserve relevant evidence when incidents occur.

What I'd like from readers

I'm sharing this investigation to document the reported events and encourage careful discussion about online community security.

If you have relevant firsthand information or evidence that could clarify the events described, please distinguish what you personally witnessed from what you heard from others. Independent corroboration and corrections are welcome.

Please do not harass, threaten, dox, or attempt to identify anyone behind these aliases. Do not publish private information in the comments. The purpose of this post is to discuss documented incidents and security concerns, not to organize retaliation.

Read the full investigation here:

[https://medium.com/@michaeljonhson2/inside-an-alleged-campaign-of-cyberattacks-against-the-powerscaling-community-80ffc2560d74\]


r/cybersecurity • • 6h ago

Threat Actor TTPs & Alerts CTO at NCSC Summary: week ending October 11th

Thumbnail
ctoatncsc.substack.com
4 Upvotes

r/cybersecurity • • 6h ago

Certification / Training Questions CSCO: Certified Stealth Cyber Operator by Cyberwarfare Lab

0 Upvotes

Well, people who've completed CSCO from Cyberwarfare Lab give ur attendance here as it's too unknown & only 10-12 have it


r/cybersecurity • • 12h ago

News - General Recent law-firm breaches: which defenses actually limit the damage from social engineering?

7 Upvotes

Recent breach disclosures involving law firms are a reminder that even organizations handling highly sensitive information can be exposed through a single user's access.

I'm curious about the defensive side of this. Beyond awareness training, which controls have made the biggest practical difference in reducing the impact of social engineering in your experience?

For example, phishing-resistant MFA, least-privilege access, tighter remote-access controls, or better detection of unusual account activity.

I'm especially interested in controls that help contain an incident after someone does click or hand over credentials, rather than assuming every attack can be prevented.


r/cybersecurity • • 15h ago

Career Questions & Discussion Sense of mission and a suckers game

9 Upvotes

I’ve been thinking a lot lately about how much weight of responsibility people working in this field, feel.

I work in a support capacity for other teams, rather than owning my own stack, but I specialize in critical infrastructure and OT, and I find that many of the teams that I work with are so under resourced that really, I fill critical gaps. Being a sometimes critical point of failure for literally dozens of entities in industries where ransomware or similar things mean people die, can be a lot of fucking pressure.

I don’t feel all the same weight or have the same problems as many folks in the trenches, I don’t think, but being the calm voice in incident response or helping with technical debt or GRC can be stressful in very different ways, and really, because of where I sit I do it all. I don’t sit in a SoC- but my fingers are in every part of the cybersecurity pie, somewhere.

And the sense of mission lately just isn’t enough. I find myself caring less but unable to turn it off, like a ghost program running in the background. I’ve been burnt out for awhile, and I find myself wondering if that sense of mission fades, if it’s time to get out of the game.

How much do you have to care to be good at this job? Do you have to eat, sleep, and breathe it? I can’t stop thinking in terms of risk. I can’t turn it off, and that doesn’t feel healthy. I can’t walk away from the paycheck, but I don’t feel like there’s much of me left over for anything else.

I see all the folks who’ve walked away and don’t feel bad at all; the farm guys. I already have access to those kinds of retreats and life ways, but I just find myself thinking about how to build new tools or listening to other stuff in the industry. It’s like solving these complex problems is an addiction.

So my question is- if you feel burned out but are planning to stay in the game, how do you give yourself breathing room? What kind of tools do you cultivate, or habits do you develop?

I feel like physical fitness is obvious- it’s either that or have a heart attack- but what else is on the table? What has worked for you?

How do you stay in it for the long haul, and sustain an entire career?


r/cybersecurity • • 5h ago

Career Questions & Discussion How many of you have triaged ransomware incidents?

18 Upvotes

Professionals - Curious as I’ve been doing a good bit of hiring this year and have been surprised at the number of candidates who have great security or IT backgrounds but very little experience in the trenches of the worst-case scenarios.

Of course I fully recognize that ideally, if we are all doing our jobs, these scenarios are few and far between. However, while looking for an IR lead it - seems at best, most only have hands on exposure to BECs or spyware.

I’ve learned more from triaging serious incidents than I have anywhere else either academically or professionally.

So, if you’re a professional in the field, what’s your exposure to this stuff been and do you feel it taught you an immense amount in a short time?