Best of r/cybersecurity's Avatar

Best of r/cybersecurity

@cybersecurity.page.bsky.social

Summarizes the hottest content on r/cybersecurity once per hour. Warning, the summaries are generated by an LLM and are not guaranteed to be 100% correct. Operated by @tweedge.net, open source @ https://github.com/r-cybersecurity/best-of-bot

6,122 Followers  |  1 Following  |  4,948 Posts  |  Joined: 22.06.2023  |  1.6539

Latest posts by cybersecurity.page on Bluesky

SonicWall urges admins to disable SSLVPN amid rising attacks View post on Reddit.

SonicWall recommends disabling SSLVPN due to increasing attack threats to ensure better security for system administrators.

05.08.2025 15:42 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
How does non cybersecurity ppl get their CISSP validated? I saw in LinkedIn, a person who is in HR role but managed to get CISSP certified. How on earth that person gets the cert? Don’t you need relevant IT security job experience to get validated in orde...

The post questions how someone in an HR role obtained CISSP certification, doubting how it was validated given the requirement for relevant IT security experience. The poster feels this devalues the CISSP certification.

05.08.2025 14:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
What's the best threat intelligence software out there these days? Hey evryone, I’m trying to find a solid threat intel tool for our security stack. Our team’s not huge, but we’re looking for something that actually adds value - early threat detection & decent enr...

Looking for a threat intelligence tool for a small security team with a focus on early detection and enrichment. Considering options like Recorded Future, Crowdstrike Falcon, and Anomali, but unsure of hype vs. utility. Seeking recommendations from midsize organizations.

05.08.2025 02:42 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Cybersecurity bootcamps - don't do them I drank the kool-aid for this bootcamp stuff. Hey yall, this is for anyone who may be thinking about doing any cybersecurity bootcamp. Don't do it. I've done all the tests and went to all the lesso...

The author warns against enrolling in cybersecurity bootcamps, describing them as scams, based on their own experience with the expensive EDX bootcamp by the University of Denver, which provided little value. They suggest using free online resources and focusing on certifications instead.

04.08.2025 22:42 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
How many Cybersecurity Firms are just running automated scans and charging an arm and a leg for it? So my boss is fielding calls from a few Cybersecurity companies, to provide Cybersecurity for us, and we share an office. Something I have noticed, is it feels like a lot of these Cybersecurity Fir...

The post discusses skepticism about cybersecurity firms charging high fees for what seems to be simple automated scan services, possibly even using open source tools. The author suggests these services may exploit clients' ignorance and fear, emphasizing their boss's poor IT decision-making history.

04.08.2025 21:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Microsoft Used China-Based Engineers to Support Product Recently Hacked by China View post on Reddit.

Microsoft used engineers based in China to support a product that was recently hacked by Chinese actors, sparking concerns about internal security challenges and the company's oversight of its global workforce.

04.08.2025 18:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
What’s is your company doing with AI Hey everyone, I'm really curious to move past the marketing buzz and hear about the practical, hands-on ways your companies are using AI or machine learning to genuinely boost security or improve e...

A Reddit user is seeking insights into how companies are using AI or machine learning practically to enhance security or efficiency, beyond just purchasing AI tools. They are interested in genuine projects or implementations that have proven to be game-changers.

04.08.2025 17:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Does anyone know which scanner covers the most CVEs? My company is looking for a new scanner. There are over 300,000 CVEs. QualysGuard only scans for 110,000 CVEs. Fortra's Alert Logic scans for 256,000 CVEs. I can't find one that has more than 256,0...

A user is seeking information on vulnerability scanners with the widest CVE coverage. They note that QualysGuard covers 110,000 CVEs and Fortra's Alert Logic 256,000 CVEs but haven't found a scanner with higher coverage than Alert Logic. They distrust Tenable due to perceived low ethics.

04.08.2025 16:42 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Building a startup`s network infra in 2025. what would you not do anymore? aiming for fully cloud based setup, zero trust principles, and as little physical hardware as possible. anything you`d steer clear of?

When building a startup's network infrastructure with a focus on cloud-based, zero trust principles, and minimal physical hardware, it's wise to avoid traditional on-premises setups and any outdated security approaches that conflict with zero trust.

04.08.2025 15:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Mentorship Monday - Post All Career, Education and Job questions here! This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cyb...

Mentorship Monday - Post All Career, Education and Job questions here!

04.08.2025 14:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
PSA: If you’re a business (etc), don’t use VNC for remote support If this doesn’t fit onto this subreddit, feel free to remove. Here’s a little rant about cybersecurity. TL;DR: Donβ€˜t use TightVNC for remote access if your business has terribly-secured public faci...

Businesses should avoid using TightVNC for remote access, especially in environments with poorly secured public kiosks, like those in airports and fast food restaurants. TightVNC is insecure with limited password protection, making systems vulnerable to exploitation.

04.08.2025 13:42 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
How to present a short 2-month tenure on LinkedIn? Hey everyone, I recently left EY after a short 2-month stint. It was a big name and seemed like a great opportunity on paper, but once I joined, I quickly realized it wasn’t the right fit for me, s...

How to present a short 2-month tenure on LinkedIn?

04.08.2025 01:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Will job market get better? I keep hearing that market is rough now, freshers don't get hired, even experienced are facing unemployment rn. Does it have any chance to improve in future or will it remain same???

The job market is currently tough, with both freshers and experienced professionals facing unemployment. The post questions whether there is a chance for improvement or if the situation will remain the same.

04.08.2025 00:42 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
We're talking a lot about cutting edge stuff. I wanna know about the most ancient things you've encountered. Now that even the most change-averse parts of our company get win11 whether they like it or not, I keep seeing more and more interesting detections from USB drives being plugged in before PCs get u...

A Reddit user reflects on encountering outdated tech in cybersecurity, noting how upgrading to Windows 11 has led to detecting interesting USB drive incidents. They mention finding a conficker binary on an old external drive. They ask others about incidents that felt like uncovering digital relics.

03.08.2025 23:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Leading phone repair and insurance firm collapses after paying crippling ransomware demand β€” Cutting 100+ employees to just eight wasn’t enough View post on Reddit.

A phone repair and insurance company has been severely impacted by a ransomware attack. Despite reducing its staff from over 100 to just eight employees, the firm couldn't avoid collapse after paying a crushing ransom demand.

03.08.2025 03:42 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Is BEEF still a thing? Or has it become completely obsolete against modern browsers? Edit. Including the link to the project here to avoid confusion: https://github.com/beefproject/beef

The user is asking if the BEEF security tool is still relevant or has become obsolete against modern browsers, and includes a GitHub link to the project for clarity.

03.08.2025 02:42 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Is a Masters in Cyber Security the way to go? I’ve been in IT security a couple of years and I just graduated with a bachelors in IT management. I’m currently an ISSO and I’d like to make more money and open more opportunities do you guys and ...

Considering a Master's in Cyber Security could help open more opportunities and increase your earning potential, especially since you already have several certs and experience as an ISSO. It could be a beneficial investment for your long-term career growth.

03.08.2025 01:42 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
How do you keep up to date with Cyber Security? What are some news sources that you use to stay up to date ? Other than reddit ofcourse, reddit's recommendation algorithm is so shitty.

To stay updated on cybersecurity, users suggest sources like security blogs, online forums, podcasts, newsletters, and websites like Krebs on Security, Ars Technica, and CyberScoop, avoiding Reddit due to its poor recommendation algorithm.

02.08.2025 15:42 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Undocumented USB Worm Discovered – Possibly the First Public Record of This Self-Replicating Malware Hi everyone, While conducting a forensic inspection of an old USB flash drive, I came across a previously undocumented and highly unusual USB worm. The malware was stored under a misleading filenam...

A forensic inspection of an old USB drive led to the discovery of a previously undocumented USB worm that replicates itself in the "Downloads" folder on a Windows 11 system. It uses obfuscation and privilege escalation techniques. A full analysis is available online for collaboration.

02.08.2025 03:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
If there were a way to fully secure company data on a user’s personal laptop (no installing heavy agents, no managing the whole device, no invasion of their privacy)... would you consider BYOD? Curious what others think

The post is asking if people would consider implementing a BYOD (Bring Your Own Device) policy if there was a way to fully secure company data on personal laptops without heavy software or invading privacy. The user is curious about others' opinions on this approach.

02.08.2025 00:42 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Cybersecurity Analyst vs Cybersecurity Engineer I was hired for my current contract as cybersecurity analyst and I manage the siem, some operational stuff because its a military organization, and acas. I also monitor the firewalls and update the...

Cybersecurity Analyst vs Cybersecurity Engineer

01.08.2025 22:42 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Suspicious MS account login despite strong password + 2FA. Trying to understand how this happened. So I was going through my Microsoft account’s recent activity page and noticed a login from an unexpected location. What’s odd is that I use a long, complex password and have 2FA enabled via the Au...

Suspicious MS account login despite strong password + 2FA. Trying to understand how this happened.

01.08.2025 21:42 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Ontario city facing full $18.3M cyberattack bill after insurer denies claim | Globalnews.ca As both a taxpayer and an IT professional - this one really hurts.

An Ontario city must cover an $18.3 million cyberattack bill because their insurer denied the claim, causing frustration for taxpayers and IT professionals alike.

01.08.2025 20:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Tea App Hack: Disassembling The Ridiculous App Source Code View post on Reddit.

A Reddit user reviews the poor coding practices of the Tea App, highlighting its vulnerabilities by disassembling its source code and providing insight into how such flaws can be exploited.

01.08.2025 17:42 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Am I being too optimistic with landing a job in China as an American? (background) Hey guys, hope everyone is well. Some background - I've worked in Cybersec for close to 5 years now with GRC/Incident Response (SOC). Love my job, but gonna have to relocate soon for family matters...

An American with 5 years in Cybersecurity, focusing on GRC/Incident Response, is relocating to Shanghai for family reasons. Despite a tech BA, a Masters in cybersecurity, and certifications, they're finding few American companies and are seeking insights on job prospects in China.

01.08.2025 10:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Rapid7 Layoffs? Rapid7 just rescinded my written offer the same week as acceptance, citing lack of headcount. Are their prospects looking bleak, and has anybody else heard of similar things happening?

Rapid7 rescinded a user's job offer due to a lack of headcount after they accepted it, raising concerns about the company's prospects. They're asking if others have experienced anything similar.

01.08.2025 00:42 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
How are people securing payment portals without a big IT team? We use Stripe and a few third-party tools for collecting payments. Just wondering what security measures are worth adding when you don’t have an internal tech/security team?

Consider implementing measures like regular software updates, strong password policies, two-factor authentication, and data encryption to secure payment portals. Additionally, rely on trusted third-party tools with built-in security features and seek occasional security audits or consultancy.

31.07.2025 22:42 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Finding a job in a different country, what is the smartest move? I'm currently working in France as a cybersecurity analyst, I do incident response and digital forensics investigation when it's required. I hold 2 years of experience in cybersecurity and 5 years ...

Considering a cybersecurity position abroad, the post highlights concerns including visa requirements, job market demand, experience level, and language barriers. It questions whether to switch to pentesting with broad opportunities or specialize in DFIR, given potential security clearance issues.

31.07.2025 16:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Will Proton no longer be safe? Hello, I am a normal person who is outside this whole cybersecurity world, but after learning about the Edward Snowden leaks, I decided to purchase Proton's services. Not just the VPN, but also Pro...

A concerned Proton user is worried about potential changes in Swiss privacy laws, fearing Switzerland might adopt heavy surveillance measures. They seek insights on whether these changes will affect Proton's safety and ask about alternative countries with strong privacy protections.

31.07.2025 14:42 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
How do you prep for cybersecurity compliance without hiring a full-time CISO? We’re a growing business and starting to think about ISO and SOC 2 compliance. We don’t have a full security team in-house, so I’m wondering, how do small businesses handle the prep and documentati...

Consider appointing an internal security champion or a part-time consultant to guide your team. Use frameworks and tools tailored for small businesses to streamline the process. Prioritize documentation and training to ensure compliance readiness.

31.07.2025 04:42 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@cybersecurity.page is following 1 prominent accounts