r/cybersecurity 2d ago

Career Questions & Discussion Mentorship Monday - Post All Career, Education and Job questions here!

22 Upvotes

This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!

Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.


r/cybersecurity 6h ago

Career Questions & Discussion What is actually expected from a cybersecurity manager at a FAANG-level company?

41 Upvotes

Beyond technical skills, what does success look like for a cybersecurity manager at a FAANG-scale organization?


r/cybersecurity 12h ago

Career Questions & Discussion Will the rush into security ever slow down or is this the new normal?

62 Upvotes

Now that we have been in this security “boom” for a few years now it’s got me thinking about the long term implications of the field. We’ve constantly hear that about people “rushing” to the field, wages getting suppressed (along with entry roles dwindling), and people established in the field struggle to move and grow all because AI

So my question to the sub is this, have your opinions changed about the field at all? Are we still in a boom and it will eventually subside (even if it takes longer than expected) or is this the new normal and we need to start accept this field will continue act closer to medicine, or finance where you gotta suffer more to get more?


r/cybersecurity 17h ago

New Vulnerability Disclosure China-linked campaign targets high-value networks, critical infrastructure

Thumbnail
scworld.com
115 Upvotes

r/cybersecurity 3h ago

Research Article Don’t Let Abliteration Abliterate Your Bug Hunting: Discovering Verdict Bias in Uncensored Models

Thumbnail
clearbluejar.github.io
7 Upvotes

r/cybersecurity 12h ago

Business Security Questions & Discussion Is docusign sufficiently secure? Does this example raise any security concerns?

33 Upvotes

Apologies if this is meant for r/cybersecurity_help, it felt like a general question that concerns the overall security of a product rather than just my personal experience, so I thought this sub would be the right place. Let me know if not, I can move it.

My employer sent me a document to sign via docusign which has a button called "Review documents" which leads to the following URL:

https://eu.docusign.net/Signing/EmailStart.aspx?a=<some_hash>&etti=<some_int>&acct=<some_hash>&er=<some_hash>

I've annonimized any ids or hashes in the above url as you can see.

Upon opening it (even in an incognito session), I can see the document they want me to sign, but I also see the signature I used months ago to sign a different document. All I need to do to re-use that signature and sign the new document is to click on the signature field and it's immediatelly applied on the document.

There is no additional authentication, I do not need to re-draw my signature, I do not need to enter a password to use it or login to any account. In fact, I have never registered an account with docusign at all.

In other words, my signature is stored in docusign's backend and the authentication to use it on any document is self-contained within the URL and likely associated with my email address. The email comes directly from docusign and my employer is not CCed on it so in theory only I should have access to the URL and auth, however it's still an employer provided email address and inbox.

This authentication and signing method makes me feel uncomfortable. Should it? Is it considered normal and secure in this space?

  • Signature stored by docusign indefinitely
  • URL sufficient for authentication (works even in incognito session)
  • I have no account or direct relationship with them (I assume employer is data controller)
  • Stored signature can be used freely just using the auth link sent to my email address

Thanks

EDIT

Missed to mention that I tried deleting all cookies and the signature was still loading.

It was also loading in a new incognito session in the browser, as long as I use the same link.

Another user in their own community subreddit claims "When you sign without an account, an recipient is created to store the signature, but no account is ever opened, it's basically just to hold the signature, tied to the name and email address that the sender used.", which tracks with my observations, this is likely the method.


r/cybersecurity 11h ago

Personal Support & Help! Tired and Feel Stuck

21 Upvotes

Hi everyone,

I’ve been in working in the general sector of IT for about 3 years now and have always enjoyed studying cybersecurity. I got my B.S. in Cybersecurity, along general certs (8) such as
CompTIA CySA+ and others. I get ppl are normally in IT for 5-7 years with moving up to a network admin or system admin and then try to pivot into cyber. I understand that a degree and labs are only a small piece to the overall process.

There is zero cybersecurity jobs where I live and if there is an opening it’s normally for a senior role and remote (ex. senior software engineer for cybersecurity company). The only MSP in my city has help desk roles but I don’t want to move jobs getting paid 15K less doing the same thing I’ve done before.

I don’t think moving from help desk to help desk would be good. I get the next step could be trying to find a system admin role but I don’t want to patch servers and do things I have absolutely no interest in as I would rather do what I do now which is help desk over that.

Where I currently work there is a huge IT team cover different areas like software engineering, networking, etc. However, the person who is thrown everything cybersecurity related tasks I’ve asked multiple times on being including on things and he won’t give me the time of day to shadow or anything when my boss approved me to do this.

I also have a lot of health issues which some of which have yet to be resolved (meaning me being diagnosed.)

I feel miserable and obviously 8 years ago I didn’t know that later on I would be feeling stuck in help desk and get major health issues I deeply want to work remotely and be in cyber dealing with something like SOC 1 work. I can’t afford to move and have my specialists in town doctor wise so moving 4 hours away to try to get a cyber job and probably not financially make it doesn’t seem realistic.

I feel stuck and hate this feeling. I’ve had deep depression of this entire situation for months and it’s hard for me to go into work at times. I feel like a fraud for going into IT only to learn the cybersecurity market has been horrible the past 5 years and to get a “we have gone with someone more experienced” on internships and SOC 1 roles while applying each week for the past 6 months.


r/cybersecurity 8h ago

Business Security Questions & Discussion Regarding cybersecurity and documentation, are you expected to reinvent the wheel?

8 Upvotes

So I'm under the impression that in terms of cybersecurity, employers care more about skill than degrees, and one of those ways to show skill is projects and documentation

The thing is though, is that what could someone like me possibly document or make a project of in an industry that has seemingly been fully covered by other people? Like, if I practice attacking and defending in cybersecurity or practice analyzing, what could a noob like me possibly offer that others haven't

Am I expected to reinvent the wheel? Like what could someone like me possible document or make a project of that hasn't been done before?


r/cybersecurity 4h ago

FOSS Tool What would make a dedicated DFIR and authorized security-testing Linux distribution worth using in 2026?

4 Upvotes

I’m the developer of T-PHANTOM, a Linux distribution I’ve been building around DFIR and authorized security testing.

I’m not posting this as a launch announcement. I’m genuinely interested in how practitioners here judge whether a dedicated security distribution is actually worth keeping installed instead of simply using Kali/Parrot or building their own toolkit.

When you evaluate a distro like this, what matters most to you?

  • Reproducible and verifiable builds?
  • A strong update and package-maintenance model?
  • Better DFIR workflows and evidence handling?
  • Tool isolation and safer defaults?
  • Documentation and repeatable procedures?
  • Hardware compatibility?
  • A smaller, carefully validated toolset rather than hundreds of bundled tools?

I’m particularly interested in feedback from people working in DFIR, incident response, forensic acquisition, or authorized penetration testing.

What would make you actually trust and use a dedicated distribution like this in real work — and what would make you immediately avoid it?

Disclosure: T-PHANTOM is my own project. I’m looking for technical criticism more than promotion.


r/cybersecurity 12h ago

News - General Five Venezuelans plead guilty to ATM jackpotting attacks in US

Thumbnail
bleepingcomputer.com
16 Upvotes

r/cybersecurity 15h ago

Career Questions & Discussion I am new to GRC, recommended resources?

23 Upvotes

Hi, I am joining a GRC software company very soon as their US/EU AE and Im looking to learn more about the space and compliance and frameworks.

Where do you think I should start?


r/cybersecurity 15h ago

Research Article Content debt is now an engineering problem

Thumbnail
leaddev.com
20 Upvotes

As AI pulls content from anywhere and everywhere, and when success with AI relies on unified, accurate data, organizations struggle to decide who is in charge of that data.


r/cybersecurity 5h ago

Other Breaking Down Appsec

2 Upvotes

I started a blog series to provide free insights into appsec. I do have a company but I will not be shilling anything there. It’s mainly to breakdown what application security is all about. It’s mainly targeted towards beginners and startups, so take it as you will.

Just want to teach every one interested in appsec my perspective on it from my experience in big tech. If you all are interested, I start with my first post here:

https://pigeonsec.substack.com/p/what-really-is-application-security

I can dive into any topic anyone is interested in. Just let me know what sort of topic you’d like me to dive deeper into. Thanks!


r/cybersecurity 11h ago

Career Questions & Discussion Detection Engineering Basics

7 Upvotes

I want to understand how can one learn the basics of detection engineering. What are the prerequisites to detection engineering. I think there are no fixed steps to create detection and tuning rules but even a rough roadmap would be helpful.


r/cybersecurity 1d ago

Corporate Blog The Hugging Face Incident Is Not an AI Story

Thumbnail
uphack.io
546 Upvotes

r/cybersecurity 12h ago

News - General AI-driven cyber risk is top concern for global financial stability, watchdog says

Thumbnail reuters.com
7 Upvotes

r/cybersecurity 9h ago

Other Owning the Secure Sandbox

Thumbnail
joinpwn.com
2 Upvotes

r/cybersecurity 3h ago

Personal Support & Help! Graduating in December — internship ended after 10 months, what should I do next

1 Upvotes

I’m graduating this December with a degree in cybersecurity, and I’m trying to figure out what I to the next few months to put myself in the best position to land a full-time job.
I had an IT internship from September 2025 through July 2026. Going into it, I was hoping there would be an opportunity to extend the internship and potentially transition into a full-time position after graduation. I felt like I was doing well throughout the internship. I never received any negative feedback from my manager/boss or coworkers that I worked, so I was a little disappointed when it ended without an extension or full-time opportunity.
At this point, I’m trying not to dwell on that and instead figure out the best path forward.
I currently have Sec+, Net+, and I’m working toward RHCSA. I’m interested in cybersecurity, but I’m also open to IT/networking/Linux roles that could eventually help me move further up.
For people already working in the industry and that have experience, what would you recommend I focus on between now and graduation?
Also, with roughly 10 months of internship experience, Security+, Network+, and eventually RHCSA, what level of positions would you consider realistic for a new graduate?
I’m already applying for jobs that’s been a bit rough I’ve applied to about a little over a 100 in the past month in the central New York area as that’s where I live but most of the time I’ve been ghosted or get the usual hr automated response, but I’d really appreciate advice from people who have been in a similar position or who hire entry-level IT/cybersecurity candidates.


r/cybersecurity 1d ago

Other Why are hacker group names so stupid?

273 Upvotes

Golden Chickens. Aquatic Panda. Lemon Sandstorm. Sure, they're easier to remember than TA1508, but it feels like it's gone too far, every vendor has their own set of names for the same groups, and it's impossible to keep straight. Does it bother anyone who works with this stuff daily, or do you just get used to it?

Disclosure: It was scratching our brain, so we made a doc on exactly this and interviewed Dmitri Alperovitch, who now calls his own naming scheme a mistake. We respect the rules of self promotion but if anyone's interested - we can provide you with the link. Cheers!


r/cybersecurity 19h ago

New Vulnerability Disclosure PaperCut issues emergency patches as threat actors target chained vulnerabilities

Thumbnail cybersecuritydive.com
16 Upvotes

r/cybersecurity 1d ago

Other Are cybersecurity professionals often off grid/Luddites off the clock?

152 Upvotes

My team at my org is funny like that. At the risk of playing to stereotypes, the India team has a lot of gamers and people who are online all the time even when not working, whereas the US team including myself has a lot of people who are into camping, trekking, hunting etc and likes to disconnect completely when not on the clock. A lot of us lives in super outdoorsy places like Colorado and such. It’s almost like the stuff we learn at work makes us want to hide out in a cabin in the woods “can’t hack me HERE!” Of course not counting all the smart gear and gadgets that some of us like. But yeah when my husband (also in cyber) and I go on our one shared vacation together we specifically choose a cabin with no cell service and no WiFi, and ideally no Starlink either.


r/cybersecurity 1d ago

Business Security Questions & Discussion What Software do you use to check email links or downloads?

49 Upvotes

Specifically is there a good way to download and check something from an email without having to download it in a sandbox? Otherwise what sandbox vm would you use?


r/cybersecurity 7h ago

Research Article cybersecurity research

1 Upvotes

I'm enthusiastic about research and recently got in touch with a student writing his own paper. Now my topic is dynamic datasets for cybersecurity intrusion detection in UAV networks in dense environments. As someone new to these terms, help me out, seniors: where should I start, and how should I start writing it ? What should be my design process? How to collect resources and materials, etc?


r/cybersecurity 16h ago

News - General Anatomy of a scam campaign, from the point of view of a link shortener

5 Upvotes

I run a small URL shortener as a side project. Last week’s abuse sweep turned up a destination that had taken 89,826 clicks in 48 hours across three short links — more than everything else on the platform combined.

My scanner had scored it zero. The destination was an ordinary .com with a numeric path. Nothing to pattern-match on. I only found it because I sorted the database by click count instead of by suspicion score, which I’d never thought to do.

The destination cloaked on user agent:

Fetched with Response
Desktop browser 963 bytes, redirect to google.com
Data-centre IP Redirect to yahoo.com
Android, Facebook in-app browser 42,748 bytes of machinery

That payload checked for Selenium/Puppeteer fingerprints, checked for an ad blocker, sampled 80 mouse positions to confirm a human, and fingerprinted GPU/screen/battery/timezone. If any check failed it played a success animation and then did nothing, so you never learn you were caught. I never reached the final page — it kept classifying me as not-a-victim.

I assumed the destination was the valuable thing, so I blocked it. Four hours later they were back with the same three short links, now pointing at two new domains that forwarded to the same place.

Fix: purged slugs are now reserved rather than released, and the reservation is written before the delete.

Full writeup with the timeline and telemetry: https://casparwre.de/blog/anatomy-of-a-scam-campaign/


r/cybersecurity 8h ago

Certification / Training Questions Getting Iso 27001 LA certified.

0 Upvotes

Hi, I'm looking to get ISMS LA certified and I'm confused which vendor should I pick. A senior analyst at my firm who is certified told me that the more reputable your certification vendor is the better. I have seen a lot of people getting certified from

BSI

Tuv Sud

PECB

IRCLASS

Mastermind

And I'm not sure which on to opt for. Money is a factor for me but i want to get the best bang for buck. Mastermind afaik isnt cqi irca certified so the certificate from them means little as compared to other. I'm an Indian if it matters while getting best vendor.

Please reachout if you have any advices or comment!