r/CyberSecurityAdvice 1h ago

Are these cybersecurity books still relevant in 2026? Looking for a roadmap to get into pentesting and bug bounty

Upvotes

Hey everyone,

I’m currently a beginner in cybersecurity and bug bounty, and I’m seriously interested in pursuing this field professionally. I’d really appreciate some advice from people who have been working in cybersecurity, penetration testing, AppSec or bug bounty hunting for a while.

I’m particularly interested in web application security, penetration testing and bug bounty hunting, and I’m trying to figure out the best way to build a strong foundation and progress from there.

I’m considering reading the following books:

  1. Real World Bug Hunting: A Field Guide to Web Hacking by Peter Yaworski
  2. Linux Basics for Hackers, 2nd Edition by OccupyTheWeb
  3. Penetration Testing: A Hands On Introduction to Hacking by Georgia Weidman
  4. Black Hat Python, 2nd Edition by Justin Seitz and Tim Arnold
  5. Web Hacking 101: How to Make Money Hacking Ethically by Peter Yaworski
  6. Hacking: The Art of Exploitation, 2nd Edition by Jon Erickson
  7. The Web Application Hacker’s Handbook, 2nd Edition by Dafydd Stuttard and Marcus Pinto
  8. The Basics of Hacking and Penetration Testing, 2nd Edition by Patrick Engebretson
  9. The Hacker Playbook 3: Practical Guide to Penetration Testing by Peter Kim
  10. OWASP Testing Guide 4.0 by the OWASP project
  11. The Hacker Playbook 2: Practical Guide to Penetration Testing by Peter Kim
  12. Hacking: Practical Guide for Beginners by Jeff Simon

My main question is: Are these books still relevant in 2026, and will the knowledge in them remain useful over the next few years?

I understand that some of these books are quite old, especially The Web Application Hacker’s Handbook, Hacking: The Art of Exploitation and the older Hacker Playbook editions. I’m not expecting books to teach me the latest tools or every modern vulnerability, but I’m wondering whether the underlying concepts are still worth learning.

If some of these are outdated or redundant, which ones would you recommend skipping? And are there newer books or resources that would be better choices?

A little about my background

I’m a Civil Engineering graduate, so I don’t come from a traditional CS background. However, computers, programming and technology have always been a huge interest of mine.

I’ve also worked as a freelancer for around 2 years, mainly in backend development and data science.

I already have some technical foundation:

• I can code in Python and JavaScript

• I have a basic understanding of networking

• I have some Linux knowledge

• I can read and understand code in languages such as C and C++, although I’m not equally proficient in all of them

Interestingly, around 4 years ago I actually found a bug in Udemy and reported it. Unfortunately, it was marked as a duplicate 😅. But that experience really got me interested in vulnerability research.

I’ve tried learning cybersecurity through Udemy courses and YouTube, but I’ve found that many courses spend a lot of time teaching extremely basic concepts and don’t go deep enough into practical understanding. I’m looking for something more hands on and structured.

I don’t want to simply memorize tools, follow tutorials or run automated scanners without understanding what’s actually happening underneath. I want to understand how systems work, why vulnerabilities exist, how to identify them manually and eventually develop the ability to find vulnerabilities myself.

So, if you were starting from my position, what would you learn and in what order?

For example:

  1. What fundamentals should I learn before seriously getting into penetration testing and bug bounty?
  2. Which areas of networking, Linux, programming, web technologies, databases, authentication, HTTP, etc. should I be comfortable with?
  3. Which of the books above are still worth reading in 2026?
  4. Which ones are outdated, redundant or not worth my time?
  5. Are there any newer books, labs, platforms or other resources you would recommend?
  6. At what point should I start doing CTFs, labs and actual bug bounty programs?
  7. What would a realistic learning roadmap look like for someone with my existing background?

I’m willing to put in the time. I’m not looking for shortcuts or a quick “become a hacker in 30 days” type of roadmap. I want to build solid fundamentals and genuine practical skills.

I’d really appreciate advice from people who have actually been through this journey. Especially interested in hearing from experienced pentesters, bug bounty hunters and security researchers about what they would learn differently if they were starting today.

Thanks in advance to anyone willing to share their experience or point me in the right direction!


r/CyberSecurityAdvice 2h ago

is it safe ?

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 8h ago

Someone who knew my name and last name, changed my user and name on it but it changed in seconds

3 Upvotes

I was arguing with someone in social media, i had my name and last name on it. And then when i changed tabs and went to my twitter, my name and username were changed on insults, i was shocked couldn’t believe how it happened because I didn’t open any link or make any call or anything like that.
Then i refreshed the page and it went to how it was before.
Should i be concerned or is there a trick someone can use in page source from chrome to someone’s twitter?


r/CyberSecurityAdvice 3h ago

Google Cert in Cybersecurity

Thumbnail
1 Upvotes

Do HR folks value the Google cert, and how does it compare with other certs?


r/CyberSecurityAdvice 5h ago

Is clicking "forward" on a suspicious email with an attachment dangerous

0 Upvotes

I got an email from an address I don't recognize with a PDF attached, which the sender is claiming is related to a project I'm working on. I did open the email in an Outlook web browser but didn't click on the attachment. However my initial (probably stupid) instinct was to forward the email to my supervisor and ask if it was legit. I clicked "forward" and when I saw the pdf attached to my draft email (duh) I got worried that maybe that somehow exposed me to some risk. Again, I didn't preview or download the pdf at all, just clicked forward. I deleted the draft with the forwarded email and just wrote to my supervisor separately, but should I be worried?


r/CyberSecurityAdvice 7h ago

Phishing attempt 245 notifications on Bitdefender.

1 Upvotes

Does anyone know what is causing this? I'm not able to figure out which program or add-on keeps causing this.

Bitdefender message below:

Phishing attempt detected

one minute ago

Feature:

Online Threat Prevention

We blocked this phishing page for your protection: http://188.126.89.75:8888/ping.txt Phishing pages attempt to obtain sensitive information such as login credentials or credit card details by disguising as trustworthy entities. The stolen data can be then used for financial gain.

Add to exceptions


r/CyberSecurityAdvice 20h ago

What certifications should I do to help get me an entry level job in Cybersecurity?

Thumbnail
3 Upvotes

r/CyberSecurityAdvice 1d ago

Feel completely lost at new job

18 Upvotes

For context, I'm 27 yo and just finished a master's degree in cybersecurity. I learned stuff, but nothing really in depth. I was lucky to get an internship in cryptography (certificates) and worked on Secure Boot for a while during school.

Having this experience, it allowed me to get a role in a big company as Senior Advisor in the crypto team (been there for a month). There are a lot of responsibilities that come with this job and I feel overwhelmed. There are countless of technologies to understand that I've not used before and when they explain some things, they seem to think I have way more context than I actually do. My boss expects me to get help when I can but I don't even know what I should be doing. I barely have all my accesses to do some basic stuff, yet, other colleagues expect me to respond to clients.

It feels like I know nothing and am in way over my head. I'm used to having someone tell me what to do and do it. I'm a very anxious person so reaching out to people is extremely difficult but my position kinda demands me to talk to everyone. Even asking questions is difficult cause I feel dumb and I feel like I should know already.

Any advice? Thanks


r/CyberSecurityAdvice 1d ago

My WordPress site was attacked by an actively exploited 0-day in a cookie consent plugin (10k+ installs) - full forensics, the one WAF rule that saved me, and how disclosure got it patched in 5 days

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 1d ago

Am I burned out or just lost? 20yo cybersecurity student feeling like I have no value

Thumbnail
0 Upvotes

r/CyberSecurityAdvice 1d ago

1.5+ YOE Java developer considering cybersecurity as a career switch — is it worth it?

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 2d ago

How safe are certified pre-owned devices from major dealers?

9 Upvotes

Whenever I look at buying a certified used phone, computer or other device, I get somewhat worried that the device might not have been fully wiped and that some previous malicious user might have placed some spyware on it. Do you think this is a real concern or should I not worry about it? The idea of someone having access to my entire phone or computer terrifies me lol.


r/CyberSecurityAdvice 2d ago

What I do to break in?

10 Upvotes

Hey everyone! I’m new to this subreddit and I’m in dire need of some advice.

Anyway let me give a bit of context about myself. I’m a Masters graduate in Cybersecurity. And I’ve been looking to break into the field ever since then. I graduated my masters in UK in 2023 and being in a country with no family or no help whatsoever I had to take care of myself financially and I was working in hospitality sector during the whole time. Both while doing my masters and also after I graduated. And this whole time I was working in hospitality I was actively applying for various positions in cybersecurity but no luck. Most of which was cause they had to sponsor me. But luckily my friend opened a new store and he hired me as IT support and for security for a while. So I had that but again that’s still limited. Although I still help him out, it’s nothing substantial.

And after all the relentless rejection while also working hospitality and helping my friend out, I decide to quit my hospitality job on Jan and I decided to move the Middle East and look for opportunities in the here but this time strictly in Cybersecurity and ever since then I’ve been jobless. I feel like I’ve done everything. During this time, I completed a certification from Comptia (because most positions ask for it as a requirement or a preference, also helped me get more knowledge so that’s a positive). I have also been spending my time creating home labs, doing projects, actively using platforms that help in Cybersecurity both for learning and also get more experience in what needs to be done but I’m still at a dead end. I haven’t received a single call back. There was a position I was short listed for but I’ve been trying to get in contact with them and then keep postponing it or ignoring me.

Tbh I haven’t even limited myself with one position. I’m actively applying for positions like SOC analyst, Cybersecurity analyst, IT security, IT support,etc. At this point I just want some sort of job to get into the field and the gradually make my way up (if that’s even possible)

I have a template for each of these positions and based on the JD I tweak it a bit and apply. I send cold DMs on LinkedIn, send email asking why they decided not to go with me, and a whole lot. I actually don’t know what I need to improve or do differently. Idk if I’m missing an angle I haven’t thought about or if my way of approaching it is wrong. Im here to take any and every advice. I’m also here to know if anyone’s working in cybersecurity and could guide me as what to do?

I know it’s an awfully long post but I had to, to express what I’m going through and what I’m doing. Thank you.


r/CyberSecurityAdvice 2d ago

Catching phishing clones on the device: page embeddings plus domain signals, with no URL sent to a reputation API

1 Upvotes

Disclosure first: I work at Olib AI and we ship this in our iOS app, so I have an interest here. The mechanics and the limitations are worth discussing on their own, which is why I am writing it up rather than just linking.

The problem with blocklists

A phishing page that went up four hours ago is not on a blocklist yet. Most of them never make it on at all, because the domain gets burned and rotated before anyone reports it. URL heuristics catch the obvious typosquats, paypa1 and the like, but a good clone today sits on a perfectly ordinary looking domain that has nothing to do with the brand it is imitating, and the page itself is a pixel-accurate copy of the login screen.

So the useful question is not "is this domain on a list" but "does this page claim to be a brand that this domain has no business being".

What we do instead

Two signals, combined into one score.

First, the page. We embed the rendered page locally and compare it against embeddings of known brand surfaces. A cloned login screen lands very close to the real brand's surface in that space while being served from a domain that is nowhere near it, and that mismatch is the flag. No page content and no URL is sent anywhere for this. The comparison runs on the phone.

Second, the domain. Cheap signals that correlate well with fresh phishing infrastructure:

  • domain age measured in days, not years
  • how many other domains resolve to the same IP
  • whether the domain is sitting behind a DNS provider commonly used to stand things up quickly

None of those is damning alone. A legitimate new startup trips all three. Combined with a brand-surface match on a domain that is not the brand, they stop being ambiguous.

A real block from our app looks like: three findings (domain registered 0 months ago, 100 domains share this IP, new domain on Cloudflare DNS), risk score 84, critical.

Why on-device is not just a slogan here

The conventional way to do this is to send every URL you visit to a reputation API. That works, and it also produces a log at a vendor of every page you opened, timestamped. For a feature whose entire job is protecting you, shipping your browsing history off the device to power it is a strange trade. Doing the comparison locally means the check costs you nothing in exposure.

Where it falls down, honestly

  • It catches imitation. A scam that invents its own brand has nothing to be close to, so the page signal contributes nothing and you are back to the domain signals alone.
  • Legitimate sites built from the same template family as a commonly cloned brand can score higher than they deserve.
  • Model size on a phone is a real constraint, so the brand coverage is finite, not the whole web.
  • It is a scoring system. It gives you a number and a reason, not a verdict.

Advice that holds regardless of what you run

Check the age of a domain before you type anything into it, whois is free. Let a password manager fill your credentials rather than typing them, since it will simply refuse to autofill on a domain that does not match, which is the cheapest anti-phishing control there is. Treat a padlock as evidence of encryption and nothing else. And be most suspicious when the page arrives with urgency attached, because that is the part of the attack that does not automate away.

The app is StealthOS, free with no account: https://apps.apple.com/us/app/stealthos-private-browser/id6756983634

If anyone here does detection work, I would like to hear what you weight domain age against, because we have gone back and forth on how much a fresh domain alone should move the score.


r/CyberSecurityAdvice 3d ago

Which job application platform is the most reliable for Cybersecurity? (Post Grad)

12 Upvotes

If you have suggestions, comment them down below. I know of Handshake, Indeed, LinkedIn, Dice, USAJobs, and applying directly on the website. If there's more comment those too


r/CyberSecurityAdvice 2d ago

is 24 gb ram good enough to power and start learning about cyber sec def field ( soc or incident responder ) I am on fedora workstation ???

1 Upvotes

r/CyberSecurityAdvice 2d ago

Getting an AI voicemail from myself

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 2d ago

Cyber Crime Survey

0 Upvotes

Can everyone take some time and fill out this survey. It is for a school project and I'll appreciate the help that I can get. Thanks in Advance!
https://docs.google.com/forms/d/e/1FAIpQLSeX47QxdGyRa7Y9nXZcYetiEwULV7SX5zjMxATPApwF6VuslA/viewform?usp=header


r/CyberSecurityAdvice 2d ago

EDPB just confirmed it: AI models are NOT automatically anonymous. Are we ready?

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 3d ago

Can anyone help me track down who's defamating my business

0 Upvotes

I recently received a review on all my platforms that is a fake review, I was just wondering if anyone could please help me track this person down I have their Google account name but of course the odds of that being real are slim to none but I got curious and clicked on all the reviews they left and just so happens they did it to two other businesses that Im actually friends with the owners outside of work but none of us can figure it out but its really going to hurt my businesses chances to being #1 Ranked business in my area like I have been for the last two years & I take this seriously I know some people would let it go but This is how I provide for my family & pay the bills & i just want to ask them whats the reason behind this or see if its a local competitor or what, I will pay for help finding out the identity of the person or a phone number email address anything that I can find to help identify this person. Please and thank you!


r/CyberSecurityAdvice 4d ago

2027 grad, or know one? Great opportunity with a great company.

6 Upvotes

If you're a Computer Science, Computer Engineering, Data Engineering, Information Systems, Industrial Engineering, Electrical Engineering, Mechanical Engineering, or other technical major graduating in 2027, please carefully consider applying to P&G's 2027 grad Digital team openings.

P&G, for those who may not know, is a F100 CPG company producing and distributing many of America's most recognizable consumer goods and products. More relevant to this subreddit, though, P&G has a strong technology stack both at its global offices in OH and MA, but also at its product supply sites across the continental U.S., including cybersecurity. These roles involve and include IT, OT/ICS, IAM, audit, network security, and GRC.

Typical new grad salary for all managerial/white-collar positions with the company is $85k to 115k PA, exclusive of bonuses or other rewards. This Band 1 role will typically last for 3-4 years, after which you may change roles, locations, or even Band.

The most relevant opening for this subreddit is going to be R000157910--Site Digital Leader. This includes Site Cybersecurity Leader roles, where you serve as the 'point man' for cybersecurity at your product supply sites, collaborating with local and central ITOT teams, and central cybersecurity resources. This is a fantastic opportunity with lots of room for internal growth and hands-on work on novel projects.

You must be a 2027 grad, and you must be open to relocating to a variety of locations across the U.S.--do keep in mind where plants and distribution centers are typically located. You must pass the logic/reasoning test after applying, and you must be a U.S. citizen or have other work authorization.

Please let me know if you have any questions. I am not a recruiter with the Company, but this is a great opportunity that I have personal experience with. I'm posting this because I think others deserve to know this awesome opportunity is out there.

(There is also R000157917, for OH-based cybersecurity roles--SOC, detection engineering, etc with the central teams)


r/CyberSecurityAdvice 3d ago

I might have bigger bite than I can chew, please advice.

0 Upvotes

Hi, I have been looking for a new oprtunities (currently I have 2 years intership and 1 year full time experience + degree, mostly fucusing on blue team+engineering). The thing is that I have managed to land a offer for a contractor role as CISO-as-a-Service for a company that "sell" contractors to other companies. Salary would be a bit more than 2x of my current salary, no need to relocate, BUT I have no experience with beeing a CISO. To be honest I view this as a massive oportunity to profesionaly grow, increase my income, network, BUT Im a bit scared cause liability of contractor in such position is not something you just shrug off. Could you please share you view on my situation, what else should I consider as decision factor, how to prepare for such job. I will be totaly honest - I want it but Im afraid that I fuck up something and the consequences would hit HARD.


r/CyberSecurityAdvice 4d ago

Question about BIA methodology / what constitutes a “Red” activity

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 5d ago

Certifications seem very important... and I can't get my unemployed spouse in Cybersec to understand why.

34 Upvotes

My husband is a cybersecurity engineer with 5 years of IT experience and 5 years and some change of Cybersecurity experience (edited for clarity!) that was laid off about three weeks ago. In that time he got his Security+ certification and is applying for jobs. For some background, he doesn’t have a college degree and has his GED. He’s been let go/laid off before (both because of mistakes he’s made / burnout affecting his PTO and project quality and things that were out of his control). He is insanely smart, just really bad at navigating traditional education systems. 

I’m having a difficult time coaxing him to continue looking at obtaining more certifications. It was like pulling teeth to get him to even consider getting his Security+ before he was laid off, and now that he passed it, it both boosted his confidence immensely… and now he seems to think that’s good enough for everything and anything. I don’t know much about cybersecurity, I’m in marketing, so I just rely on what I research on my own. From what I’ve seen, if you don’t have a degree, you essentially make up for it with certifications and experience. 

I believe he was laid-off this time because the place he worked needed to trim down the cost-centers of the business, and cybersecurity was one of the affected areas. He was able to get unemployment, the company said he could apply for other roles and he wouldn't be flagged, and they said he wouldn't have a black mark on his record when other employers contacted them for information on his work history. His team was full of people who had degrees and certs, and he was the only one with neither. I think he takes a lot of pride in the fact that he can do the job he does without having the education or certifications his peer group normally obtains. 

He’ll often brag / vaguely insult others that he considers “not as good” as him, and would complain about some of his co-workers “not being up to par” despite their education and certs… but from what I know they all still have jobs and he doesn’t. His lack of humility / braggadociousness seems to be a defensive mechanism against his own perceived inadequacies in his field (he has intense impostor syndrome despite how highly he sees his own skills), and I’m not sure how to break him out of that.

You can have all the experience in the world, but if you don’t have the piece of paper saying you can do the job, then you get skipped over for the job. It seems like a competitive market, and I don’t want him to fall into the same destructive pattern he's gone through before. Him being fired / laid off every 3-4 years has been exhausting and destabilizing for our family, and with AI affecting everything, I’m really worried about his future. 

Does anyone have any advice on how to encourage someone in this situation? We have the safety net for him to continue pursuing more certifications but now he’s essentially scoffing at the idea and wants to just jump right back into it. Is Security+ on its own enough anymore? What certifications should someone who wants to do Compliance / Security Administration aim for? I’m not really sure what a normal track should be for his field.

Any advice would be very appreciated. 

EDIT: updated his experience. He has 5 years of IT and 5 years of cybersecurity. So 10 years total, sorry for the confusion on that. Thank you so much for all the comments and input. I don't know much about the cybersecurity world so I'm not sure what level he should be at.

It definitely sounds like the CISSP or CISM should be his next move, now it's just a matter of actually getting him motivated to do it. If anything, this seems more like an emotional / maturity problem than an actual intelligence problem :| which sucks to hear as his wife. Guess it's time for another serious conversation with him about how the next several years will look.

Wish me luck.


r/CyberSecurityAdvice 5d ago

Is it better to go with a trusted white labeled solution or deploy from Replit?

4 Upvotes

It’s a simple SaaS application, includes e-signature and personal information storage as well as pdf upload… I cannot code, but I do know the risks of not repairing a security patch etc.
Should I bite the bullet and pay? Or are the no code tools like Replit more on top of the infosec than a 40 year old would assume?