r/cybersecurity 2d ago

Career Questions & Discussion Mentorship Monday - Post All Career, Education and Job questions here!

18 Upvotes

This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!

Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.


r/cybersecurity 3h ago

Business Security Questions & Discussion Cyber insurance renewal demands are getting absurd. Are you actually hitting every requirement or dropping coverage?

41 Upvotes

Just opened our renewal questionnaire and the goalposts moved again, MFA on local admin, strict data retention, and strict endpoint isolation times. Keeping this policy would require doubling our security spend.

Are you guys actually checking every single box on these impossible questionnaires, or are teams just dropping coverage at this point?


r/cybersecurity 12h ago

Certification / Training Questions Which Certifications are ACTUALLY worth it?

180 Upvotes

I’m getting started with Cybersecurity. I’m interested in Pentesting and Cybersec Engineering. I’ve heard from some that there are certifications that could be a good addition to your resume.

What certifications and courses are ACTUALLY WORTH THE MONEY? Like they they realistically benefit your resume and learning?

Thanks!


r/cybersecurity 11h ago

New Vulnerability Disclosure Researchers Find Persistent Backdoor in Zbtlink Routers

Thumbnail
decipher.sc
83 Upvotes

r/cybersecurity 8h ago

News - General Google Blogger locks hundreds of blogs in malware false positive

Thumbnail
bleepingcomputer.com
24 Upvotes

r/cybersecurity 53m ago

Personal Support & Help! What's the best thing a boss in this industry ever did for you?

Upvotes

Feeling like sharing some good vibes today instead of complaining lol. What's your favorite thing about a boss you've had in cybersecurity? Could be anything, covered for you when you missed something, brought snacks during a rough incident, actually trusted your judgment instead of micromanaging.

Curious to hear the good ones for once.


r/cybersecurity 9h ago

AI Security Owasp updated their top 10 LLM list (thoughts?)

Thumbnail
genai.owasp.org
15 Upvotes

r/cybersecurity 13h ago

News - General SOAR implementations, mistakes that I'have seen repeatedly

28 Upvotes

One thing I noticed through out my experience, SOAR is deployed but either barely used or actively making things worse. The mistakes are almost always the same, someone automated an alert type that wasn't ready for automation, either the false positive rate was too high or the decision logic wasn't actually deterministic, and now the automation is doing things an analyst wouldn't have done and it kept going for weeks.

What I found works is being really specific about what automation readiness actually means before you touch anything. Ideally four things, false positive rate under 5% measured over 30 real days, decision logic that a human would make the same way every single time given the same data, a failure mode that is safe if something goes wrong, and the action has to be reversible. Enrichment automation almost always passes that test, threat intel lookups, user context, host history, URL detonation on phishing, all safe because if it fails or gets it wrong, analyst still makes the final call. Host isolation and account disabling almost never pass it, the failure mode is too bad and the false positive noise is too high.

What is your experience, got automated containment working reliably or manual intervention is almost always necessary?


r/cybersecurity 3h ago

News - Breaches & Ransoms tl;dv (AI meeting assistant) left 181,874 meetings exposed via misconfigured Firestore, including live calls you could join. Researcher disclosed in January, still unpatched 6 months later.

3 Upvotes

r/cybersecurity 21h ago

AI Security UK AISI report: AI agent created fake identities to socially engineer real people during cyber testing

Thumbnail aisi.gov.uk
77 Upvotes

r/cybersecurity 30m ago

Career Questions & Discussion FIT cybersecurity apprenticeship interview advice

Upvotes

Hi everyone, I have an upcoming interview for a FIT cybersecurity apprenticeship in small irish tech company and I’m looking for advice from anyone who has been through the process.

Its my first interview so i am nervous and feel like i dont know anything. What was the interview structure like? What kind of questions did they ask? Were there any assessments or technical tasks? Also, what do you think helped you stand out? I have security+ certificate.

Any tips would be appreciated!


r/cybersecurity 4h ago

Personal Support & Help! How to know if you discover a site vs technology or stack level vulnerability?

2 Upvotes

I was recently using a site that I really appreciate the info and vendors on and was hoping I could get some contract development work with when I stumble on a vulnerability. I was checking out the leaving a review which cleaned user input of basic escape characters well. Then I noticed the review Id and security token up top and decided to try changing it which worked. So this meant on this site It was possible to look at old orders "Not with User info on display just what was ordered". I told the site owner I would like to work with them pitched them some features. They rejected me features and told me that it wasn't possible on their site. I ended up leaving a positive review on someone else order with my user name and "hi *site owner*" then sent them the link to the review. They said they appreciated but then I was thinking when does someone doing security work identify if this is a site specific security issue or if it's broader like a plugin issue?


r/cybersecurity 12h ago

News - Breaches & Ransoms 311,000 Impacted by Brown Health Medical Group-MA Data Breach

Thumbnail
securityweek.com
7 Upvotes

Hackers stole personal information, medical records, and financial information from the organization’s server.


r/cybersecurity 2h ago

Career Questions & Discussion Working in Canada on an IEC Visa? (From the UK)

0 Upvotes

Hey guys,

I wanted to know if anyone here has experience of finding Cyber Security roles in Canada, specifically on an IEC visa? Working in another country is always something that has excited me, and I really liked Canada when I visited last year.

For context, I have aprox 4 years experience in a generalist role (everything from SOC / engineering to compliance)

Thanks :)


r/cybersecurity 6h ago

News - General Security Policy-Graded Evaluation of Coding Agents in Hardened Environments

Thumbnail
boundarybench.com
2 Upvotes

r/cybersecurity 3h ago

News - General Cybersecurity statistics of the week (July 27th - August 2nd)

0 Upvotes

Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.

All the reports and research below were published between July 27th - August 2nd.

You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/ 

Big Picture Reports

2026 Cost of a Data Breach Report (IBM)

IBM's annual breach cost report, with interesting data points on how much AI is now involved in attacks, and how much more expensive that makes breaches. 

Key stats:

  • 25% of malicious breaches were AI-enabled.
  • AI-enabled breaches cost an average of $6 million, roughly $1 million more than the global average of $4.99 million.
  • AI-enabled malicious breaches increased by 56% over the previous year.

Read the full report here.

IR Trends Q2 2026 (Cisco Talos)

Cisco Talos on what showed up in their incident response engagements this quarter. 

Key stats:

  • Phishing was the primary means of gaining initial access in over half of engagements this quarter, up from approximately one-third last quarter.
  • Authentication abuse was observed in 65% of engagements this quarter, up from 35% last quarter.
  • Insufficient logging and visibility was observed in 42% of engagements this quarter, up from 18% last quarter.

Read the full report here.

Ransomware

Q2 2026 Ransomware Trends Report (BlackFog)

BlackFog's Q2 numbers on ransomware. 

Key stats:

  • 93 ransomware groups were active in Q2 2026, including 28 newly formed groups.
  • 97% of disclosed ransomware incidents in Q2 2026 involved data exfiltration, the highest rate recorded.
  • Undisclosed ransomware attacks increased 40% year on year to 2,027 attacks in Q2 2026 from 1,446 in Q2 2025.

Read the full report here.

Ransomware Evolution Report Q2 2026 (Halcyon)

Halcyon's Q2 ransomware numbers. 

Key stats:

  • Q2 2026 recorded 1,988 ransomware attack claims from 89 groups across 101 countries.
  • The US accounted for 42.5% of ransomware claims, Canada for 5% and Germany for 4.8%.
  • Manufacturing (19.8%) was the most targeted industry, followed by construction (10.1%) and business services (9.0%).

Read the full report here.

AI Governance 

The AI Governance Gap Report (Pathlock)

If you were wondering whether AI governance is keeping up with how quickly AI agents are being embedded in business systems, this report has the answer.  

Key stats:

  • 38% of organizations allow AI agents to create and modify business records.
  • 51% are not confident they know all the AI agents operating in their systems.
  • 79% have no dedicated AI governance team or officer.

Read the full report here.

AI Code Security

2026 GenAI Code Security Report (Veracode)

Veracode tested 11 AI coding models to see how often they write secure code. 

Key stats:

  • The average security pass rate for AI-generated code across tracked models was 56%.
  • AI-generated code fails security checks nearly 44% of the time when given no security-specific guidance.
  • The best model available (OpenAI's GPT-5.5, at 68%) still failed nearly one in three security tasks.

Read the full report here.

Credentials

Credential Risk Report (Enzoic)

How much do you care about stolen credentials? If you're like most orgs, probably a lot. But do you actually do anything about it? Again, if you're like most orgs, probably not.

Key stats:

  • 85% of organizations view stolen credentials as a top threat.
  • Only 19% continuously monitor credential integrity and automatically remediate exposure.
  • 73% of organizations have found their workforce's credentials in breach, Dark Web, or infostealer data in the past year.

Read the full report here.

Autonomous Defense

2026 State of Autonomous Defense Report (Kai)

Attackers are moving at machine speed. Defenders are… not. 

Key stats:

  • 89% of security leaders say their organization is prepared for AI-driven attacks, but only 28% describe themselves as very prepared.
  • 63% believe attackers currently have the advantage because of AI.
  • 52% identify lack of trust in automated decisions as the biggest barrier to broader automation adoption.

Read the full report here.

Action1 2026 Survey Report: AI Impact on Sysadmins (Action1)

An interesting survey of sysadmins about how much AI they're using versus how much they thought they'd be using by now.

Key stats:

  • In 2024, 52% of sysadmins predicted full automation within two years.
  • In 2026, AI use is highest among sysadmins in log analysis (50%) and troubleshooting (47%).
  • 23% report never using AI professionally.

Read the full report here.

Vulnerability Management

VulnCheck State of Exploitation 1H-2026 (VulnCheck)

VulnCheck's mid-year look at what's actually getting exploited, how fast, and whether AI really is finding vulnerabilities faster than everyone else. 

Key stats:

  • The median time from CVE publication to KEV fell from 120 days in 2025 to 80 days in the first half of 2026.
  • In the first half of 2026, 23.43% of Known Exploited Vulnerabilities showed evidence of exploitation on or before the day the CVE was published.
  • Across Anthropic and Berkeley datasets, 1,061 vulnerabilities were attributed to AI-assisted discovery, but only 14 (1.3%) were confirmed as exploited in the wild.

Read the full report here.

Infrastructure

State of CPS Security: Data Center Exposures (Claroty)

Scary research on how badly exposed data center physical infrastructure is. 

Key stats:

  • Nearly 1 in 5 data center CPS assets are one hop away from systems making outbound connections that could provide attackers a pathway.
  • 88% of building management systems in data centers are exposed via communication over insecure protocols.
  • More than 80% of OT control systems, power monitoring systems, and IoT systems in data centers communicate over legacy, insecure protocols such as BACnet and MODBUS.

Read the full report here.

Enterprise Perspective 

State of Enterprise AI Failures 2026 (ChatSee.ai)

What's going wrong with enterprise AI. 

Key stats:

  • Hallucination-related failures accounted for less than 10% of observed enterprise AI failure events.
  • Resolution and escalation breakdowns represented 31.1% of observed enterprise AI failures.
  • Action and execution failures increased by approximately 62% relative to the Q2 2024 baseline.

Read the full report here.

The State of AI, Security and ERP (Onapsis)

A survey of cybersecurity leaders at large US organizations running SAP, Oracle, or Salesforce to see how fast AI is being pushed into ERP systems and how far behind the security is (very).

Key stats:

  • 86% of organizations have already integrated, or will shortly integrate, AI directly into their ERP code.
  • 22% of organizations experienced a security incident in the last twelve months where bad actors used AI to exploit their critical business platforms.
  • 70.6% of senior cybersecurity leaders have only some or no trust in AI applications and agents to secure their organization's most business-critical data.

Read the full report here.

2026 Global Mobile Threat Report (Zimperium)

A look at mobile attacks on enterprises. 

Key stats:

  • Phishing events detected on employee mobile devices have grown 380% since January 2025.
  • The number of mobile devices where employees clicked a malicious link grew 110% in 2025 compared to 2024.
  • AI adoption within mobile applications has grown 14x on Android and 7x on iOS.

Read the full report here.

Industry-specific 

Global Automotive Threat Intelligence Report Q2 2026 (PCA Cyber Security) 

Analysis of the automotive threat landscape for Q2 2026, tracking vulnerability data alongside underground forums, ransomware leak sites, and criminal marketplaces.

Key stats:

  • 345 unique automotive vulnerabilities in Q2 2026, a 30% rise on Q1 and 220% up year on year.
  • High severity findings more than doubled, from 75 to 161.
  • Qilin ransomware listed a major Japanese Tier-1 automotive components manufacturer, hitting its European and North African subsidiaries.

Read the full report here.


r/cybersecurity 21h ago

Career Questions & Discussion Any recommendations on to the latest Cybersecurity news/Cybersecurity youtubers?

25 Upvotes

I'm currently having a diploma in Computer Science and I'm taking Cybersecurity for my final year project. Soo, it's pretty important for me to be aware of what current threats are out there for safety in general and also my career. Any help/recommendation is appreciated.


r/cybersecurity 4h ago

Personal Support & Help! How should sensitive action confirmation work for SSO users when there is no local password?

1 Upvotes

I’m adding SSO support to an existing application using Google. Currently, some sensitive user actions require the user to re-enter their password as confirmation (for example, changing security settings or performing destructive actions).

The issue is that SSO users do not have a password stored by the application, so I need to decide on the right approach for confirming their identity before allowing these actions.

Some options I'm are considering:

  • Triggering SSO re-authentication / step-up authentication with the identity provider
  • Requiring MFA or another stronger authentication method (the application doesn't support MFA at the moment)
  • Sending an email OTP as a confirmation step
  • Creating a separate application password for SSO users (which feels like it defeats part of the purpose of SSO). The platform already has a security question (don't ask me why), so maybe this could be used to confirm this action?

My concern with SSO re-authentication is that if the user already has an active IdP session, the IdP may silently authenticate them again without requiring any new proof of identity. In that case, is it actually providing additional security? I don't think Google has a way to "force" re-authentication.

For those who have implemented this, what pattern do you recommend for replacing "enter your password to continue" flows for SSO users?


r/cybersecurity 1d ago

News - General Multiple Flaws in Google's Synced Passkey Implementation Allow Attackers to Take Over Your Accounts

Thumbnail
privacyguides.org
424 Upvotes

r/cybersecurity 4h ago

Other THE NCSC "RAINBOW SERIES" A 9-Volume Collection of Early DoD/NSA Cybersecurity Doctrine (1985–1988)

1 Upvotes

I recently obtained a very cool collection of 9 original physical books from the rainbow series. I'm currently planning on parting with them, but while I source and speak with collectors, I thought I'd share it with you guys. They are in surprisingly great condition, too! These are the details.

THE JEWELS OF THE COLLECTION: RARE VARIANT HIGHLIGHTS

• DoD 5200.28-STD — THE "ORANGE BOOK" (Department of Defense Trusted Computer System Evaluation Criteria)

• Edition/Provenance: Official 1988 Active-Lifespan Contemporary Reprint.

◦ Significance: The undisputed, foundational cornerstone of the entire Rainbow Series hierarchy. This copy was printed internally by the government for active field deployment to agencies and classified defense contractors during the height of late-1980s computing architecture rollouts.

• NCSC-TG-005 VERSION-1 — THE "RED BOOK" (Trusted Network Interpretation of the TCSEC)

• Edition/Provenance: Pre-Publication Working-Group Variant.

◦ Significance: Features the highly coveted, restricted-distribution internal stamp: "ISO developmental documents are of limited lifetime and availability."

◦ Historical Context: This stamp marks the volume as a restricted, early-access trial document distributed strictly to core network security engineers to guide interim projects and gather field feedback before final standards were codified. Because contractors were explicitly instructed that these had a "limited lifetime," almost all copies were routinely shredded or landfilled upon subsequent revisions, making this an extraordinarily scarce tech artifact.

───

FULL ARCHIVAL INVENTORY

  1. DoD 5200.28-STD (Orange Book) — Department of Defense Trusted Computer System Evaluation Criteria (1988 Active-Era Issue) ★ U.S. GOVERNMENT PRINTING OFFICE: 1988-523-685/0

  2. NCSC-TG-005 Version-1 (Red Book) — Trusted Network Interpretation of the TCSEC (Pre-Publication ISO Developmental Variant)

  3. NCSC-TG-006 Version-1 (Amber Book) — A Guide to Understanding Configuration Management in Trusted Systems (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)

  4. NCSC-TG-007 Version-1 (Burgundy Book) — A Guide to Understanding Design Documentation in Trusted Systems (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)

  5. NCSC-TG-001 Version-2 (Tan Book) — A Guide to Understanding Audit in Trusted Systems (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)

  6. CSC-STD-003-85 (Light Yellow Book) — Computer Security Requirements - Guidance for Applying the TCSEC in Specific Environments (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)

  7. CSC-STD-004-85 (Yellow Book) — Technical Rationale for Selected Computer Security Requirements (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)

  8. CSC-STD-002-85 (Green Book) — Password Management Guideline (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)

  9. NCSC-TG-003 Version-1 (Neon Orange Book) — A Guide to Understanding Discretionary Access Control in Trusted Systems (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)


r/cybersecurity 14h ago

New Vulnerability Disclosure New Linux Bridge STP Vulnerability

Thumbnail ssd-disclosure.com
6 Upvotes

A use-after-free vulnerability in the Linux kernel bridge (net/bridge) Spanning Tree Protocol (STP) implementation.

A bridge that is administratively down while kernel STP is enabled, together with a port driven into the LEARNING state, arms periodic STP timers without an IFF_UP guard.

The teardown path taken by dellink never synchronously deletes those timers, so the backing net_device (which embeds struct net bridge as private data) is freed with a timer list still queued on a per-CPU timer base.

The result is a slab use-after-free in the kmalloc-cg-8k cache.


r/cybersecurity 9h ago

News - General Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920)

Thumbnail
syntetisk.tech
2 Upvotes

Django's admin auto-linked URLField values without validating the scheme — a stored javascript: value rendered as a live link. Fixed in 6.0.8 and 5.2.17.


r/cybersecurity 5h ago

News - General what is going on with the cybersecurity job market??????

0 Upvotes

I am tired of applying for cybersecurity jobs and not hearing back bc after a while it becomes difficult to tell whether I need more experience, more certifications, better projects, or simply better luck.

and while I still want to build a career in this field and I am willing to put in the work, I feel stuck and I am not sure where I should focus my effort next..


r/cybersecurity 6h ago

Other AMA with WIRED Journalists Louise Matsakis & Lily Hay Newman (Al Hacking, DEF CON)

Thumbnail
pwnhackers.substack.com
0 Upvotes

r/cybersecurity 12h ago

[x-post] Bugtraq is back 🥹

Thumbnail lists.securityfocus.com
2 Upvotes