Best of r/cybersecurity

@cybersecurity.page

Summarizes the hottest content on r/cybersecurity once per hour. Warning, the summaries are generated by an LLM and are not guaranteed to be 100% correct. Operated by @tweedge.net, open source @ https://github.com/r-cybersecurity/best-of-bot

Cyber insurance renewal demands are increasingly challenging, with requirements like MFA on local admin and strict data protocols. Meeting these could double security costs. Organizations face the dilemma of either adhering to every condition or dropping coverage. How are others handling this?

Cyber insurance renewal demands are getting absurd. Are you actually hitting every requirement or dropping coverage?

Just opened our renewal questionnaire and the goalposts moved again, MFA on local admin, strict data retention, and strict endpoint isolation times. Keeping this policy would require doubling our s...

reddit.com

For someone starting in cybersecurity with an interest in pentesting and cybersec engineering, look for certifications that add real value to your resume and enhance your learning. It's important to choose ones that are recognized in the industry and offer practical insights.

Which Certifications are ACTUALLY worth it?

I’m getting started with Cybersecurity. I’m interested in Pentesting and Cybersec Engineering. I’ve heard from some that there are certifications that could be a good addition to your resume. What ...

reddit.com

The poster shared their response to a recruiter's question about using AI-generated code, stating they prefer writing their own code for better debugging and reliability, especially in regulated environments. They worry they should have mentioned being open to AI in non-regulated environments.

How bad was this answer?

I had a call with a recruiter about a role I applied to and she asked me a few behaviorial-type questions about my experiences. One question was "when do you not use AI-generated code?" I said that...

reddit.com

The user has worked at four companies, each with a toxic manager displaying various issues like excessive control, micromanagement, inappropriate behavior, and backstabbing. This pattern makes the user question if cybersecurity is right for them or if it's a gender-related issue.

Different kind of issues in finding a job.

Worked at four companies now, and every single one has had a toxic manager. The first one was a control freak. He’d make us write pointless documentation just to “cover ourselves,” and had me send ...

reddit.com

An undergraduate with severe ADHD seeks advice on managing networking challenges for finding jobs and internships. They struggle with socializing and conversation in professional settings and ask how others with ADHD working in IT built connections, and if platforms like LinkedIn were helpful.

How do people with ADHD manage networking?

How do you function at your jobs or when starting out when you had ADHD? I’m an undergraduate with no experience yet, and that's why I'm a bit worried cause I don't have a job to start with. I keep...

reddit.com

The post asks if anyone has encountered a security incident caused by an AI coding agent, such as credential leaks or unauthorized data handling. It inquires about detection and changes post-incident, or if the absence of incidents is due to effective controls or oversight lapses.

Has anyone actually had a security incident caused by an AI coding agent yet?

Plenty of theory going around about agent risk, but I'm curious about actual cases. An agent that read or leaked credentials, executed something destructive, sent data somewhere it shouldn't, anyth...

reddit.com

A researcher accessed a C2 server, likely Chinese, attacking Brazilian government systems. It revealed AD credential theft, database exports, web shells, cryptominers, and more. The investigation unraveled malware, stolen data, and poor cybercriminal opsec before the server went dark.

Researcher accessed an active c2 server attacking the Brazilian government

tl;dr: got access to a (likely Chinese) C2 server actively attacking Brazilian government systems. Its files showed AD credential theft, database exports, web shells, cryptominers and persistence. ...

reddit.com

A cybersecurity professional with a master's degree, 5 years of IT experience, and Security+ certification is struggling to find work. Despite multiple interviews and recruiter interactions, they face rejections and are considering a career change. Seeking advice on securing a job in this market.

Difficulties Finding a Job

Hi everyone, I was laid off in late January of this year and I’ve been struggling to find a job in not just Cybersecurity, but even Help Desk and Support roles. For context, I have a masters degree...

reddit.com

A user struggles to justify Splunk costs to a CFO due to licensing and engineering time. They're considering managed SIEM as a solution but face unclear definitions of "managed" services and concerns about ownership of detection rules after leaving the service. Seeking insights from others.

Splunk costs are getting hard to justify. Looking at managed SIEM but cant figure out what im actually buying

New CFO asked me to justify our Splunk spend. About 400 endpoints, mostly AWS with some on-prem legacy, 2-person security team. Cant say more for obvs reasons. The licensing is one thing but honest...

reddit.com

A small security team supports 5,000 employees and faces criticism from a non-specialist CIO for phishing incidents. The CIO’s hindsight bias and lack of cybersecurity knowledge lead to micromanagement and blame-shifting, rather than collaboration. Is this dynamic common in the industry?

CIOs

I’m on a very small security team (fewer than 5 people) responsible for supporting ~5,000 employees. As you can imagine, phishing and social engineering incidents come up from time to time. The fr...

reddit.com

The user is wondering if Black Hat World, Def Con, and B Sides in Las Vegas are good for networking or job hunting. They mentioned that some conventions are recruiting-focused, like Black Hat's Business Hall, but they're unsure if this is accurate and seek more information.

Job hunting at Black Hat World / Def Con?

I transitioned from Software Engineering to Cybersecurity. I know of some Software Engineering conventions that basically double as job fairs. Big companies send recruiters every year specifically ...

reddit.com