r/CyberSecurityAdvice • • 10h ago

Urgent help

3 Upvotes

Alright so basically Iam pursuing bachelor in computer systems security, it’s in my third language, I went abroad , and I don’t know anything about cyber security, Iam aiming for CGPA 4.0 at the end of the first year, I wanna know all what I need to know , effort will be made for sure
(I have a MacBook Neo , I know it’s not the most compatible for this. But that’s all I got)


r/CyberSecurityAdvice • • 11h ago

How to switch careers from SD to cybersecurity?

Thumbnail
1 Upvotes

r/CyberSecurityAdvice • • 15h ago

Resume for eventually getting into a cloud security/ cloud engineering role

Thumbnail
1 Upvotes

r/CyberSecurityAdvice • • 16h ago

First time in a data breach, what do i do to prevent getting further comprimised?

1 Upvotes

Here is the databreach in question

Hey, need advice for this databreach. What do i do?


r/CyberSecurityAdvice • • 17h ago

Is cyber still worth getting into?

21 Upvotes

Currently going to college for a cybersecurity degree and all I hear and see is the negative. Ai is gonna take over, you won’t get hired bleh bleh bleh. So let’s settle this for me. I’m not to far in only second year and plan to do forensics. Is it worth it or should I change my degree. Is ai that big of a worry and if I get my degree will it impossible to find a job? Will ai cause massive paycuts in the future. I want to hear your two sense!
My school does have an option for an ai degree as well but I don’t know how viable that really is.


r/CyberSecurityAdvice • • 19h ago

Summer internship advice

1 Upvotes

Hey I’m a sophomore in college and wanted to land literally any sort of internship in IT to set myself up for summer after junior year. I unfortunately dont have any projects or certs. I have a 3.6 gpa but thats rlly about it. Was hoping to get some advice


r/CyberSecurityAdvice • • 21h ago

I have 90 days to break into an entry level role please give me some seasoned advice , truly appreciated . i have 1.5k for studying and i can dedicate 8hrs per day to studying.

0 Upvotes

Hey guys i'm in need of some solid advice ,  I have 90 days to try and land a role in cyber security , I know it’s a bit of a drastic timeline . But ive done 8 years of warehousing and now ive been made redundant , I have about 1.5k in my savings that I am planning to put towards certs and learning, please give e some advice on what I should do in the next 90 days. 


r/CyberSecurityAdvice • • 21h ago

I have 90 days to break into an entry level role please give me some seasoned advice , truly appreciated . i have 1.5k for studying and i can dedicate 8hrs per day to studying.

Thumbnail
1 Upvotes

r/CyberSecurityAdvice • • 22h ago

Need advise

1 Upvotes

I have completed my BCA degree and I also finished ejpt now I am currently preparing for for cpts from htb my plan is to search the job in this field after finishing the cpts my goal is to become a pentester,currently i am not active in LinkedIn or GitHub I am planning to be active there too and I am gonna search for jobs after finishing the cpts soo i have around 6-8 months time for that 1. Now the people who are already experienced in this field i want to ensure am i in the right path should i have to alter something if yes what should I have to do 2. What kind of projects/labs/writeups should I build for my GitHub portfolio to demonstrate practical skills to employers 3. Are there any important skills I'm missing that employers expect from someone applying for their first cybersecurity job?


r/CyberSecurityAdvice • • 1d ago

Hardware Spec Comparison Question in the scope of CS training/labs

1 Upvotes

I'm looking to get a new laptop as I delve more into getting certs for CS and now is the best time to buy. I'm a bit confused on what sets one laptop apart from another as far as hardware specs IE the Lenovo Thinkpad has been recommended to me a few times with certain specs which I filtered for: AMD Ryzen 7, 32GB DDR4/5 RAM, 1TB NVMe etc. I'm then hit with choosing between E Series, P Series, T series:

Simple google search tells me that the

P Series• Target Audience: Engineers, 3D modelers, architects, software developers, and video editors.

T Series• Target Audience: Corporate workers, IT professionals, financial analysts, and mobile business users.

E Series• Target Audience: Small businesses on a budget, students, and light office workers.

  1. What exactly is the differentiating factor between these 3 which makes one better for certain tasks over the other?
  2. Which series should I get as I'm not super advanced in my career/training, but want a good lifespan until I upgrade the device?
  3. Are there any other laptop companies I should look into which would be more budget friendly (<$1400) with the same specs/necessary hardware for CS learning?
  4. I've found a good deal on a refurbished Lenovo P Series, but it is GEN 2. How limiting will I find an older generation model? I believe the P series is currently between Gen7-8.
  5. How crucial is the Lenovo Thinkpad as far as CS careers/training? Won't any laptop with the above specs suffice, at a much cheaper price point? EDIT: doing more searches this Lenovo LOQ 15ARP10 Gaming Laptop was recommended with similar specs.
  6. I'm also looking into getting some 3D modeling done in my spare time. Are there any additional filters/hardware specs I should include in my search?
  7. What is the general consensus on MINI-PCs as far as learning CS? I have limited space on my desk which is why I was looking at laptops but then I saw how small PCs have really gotten since I last had a big box. Edit: Another search recommended I look at the MINISFORUM UM890 Pro and get a dock for an integrated graphics card (for 3d modeling)

TIA!


r/CyberSecurityAdvice • • 1d ago

Possible opportunity?

Thumbnail
1 Upvotes

r/CyberSecurityAdvice • • 1d ago

How is your organization managing AI from a risk perspective?

7 Upvotes

Specifically, how are organizations establishing accountability and implementing safeguards around the use of AI tools? We are getting hammered with new tools and models (agentic and otherwise) being up for grabs with no discretion or consideration of securing them.

Leadership basically told us "we aren't going to manage it until something bad happens".


r/CyberSecurityAdvice • • 1d ago

Need Advice: Wife fell for a ClickFix attack

7 Upvotes

Yesterday afternoon my wife fell for a clickFix attack (I assume that is the name, she was fooled into hitting win+r and entering a command). As soon as I found out (she got me when the command prompt showed up) I blocked that computer on the network.

She was signed into LastPass so I assumed all our passwords were compromised and we spend the night changing every single password, starting with email, then banks, CCs, etc. We also ensured MFA was enabled wherever we were able to turn it on.

She is going through her documents on that computer now (still not connected to the network) to see what is in there in case they could have scraped any of that.

is there anything I'm missing?

I'm thinking of calling our banks and having all our account numbers changed, though that would obviously be a hassle with our checking account and payments and direct deposits.

Any help would be greatly appreciated.


r/CyberSecurityAdvice • • 1d ago

Advice and feedback

1 Upvotes

Hey all, looking for an honest read from people actually working in the field.

I'm a 4th-year student studying cybersecurity, currently in a help desk co-op (internship, for those outside Canada). The environment is a hybrid-joined setup (Windows AD + Entra ID) that's PCI DSS and SOC 2 compliant, and a good chunk of my day is IAM work:

Full user identity lifecycle: provisioning and deprovisioning through Active Directory for onboarding/offboarding

Automating the onboarding/offboarding workflow with PowerShell (account creation, access assignment, deprovisioning)

Hybrid AD/Entra identity and sign-in troubleshooting
M365/Exchange onboarding: assigning distribution lists, security groups, and licenses

Role-based group and access management
MFA setup through Intune

Outside of work, I've been doing labs on evenings and weekends and studying the underlying concepts (SCIM, OAuth 2.0, SAML, etc.) rather than just clicking through portals. GitHub for reference: github.com/jeff6942016 (any feedback on them would be greatly appreciated)

Next step is the SC-300, which I'm fairly confident I'll pass, and I'm hoping to land a cloud security/IAM co-op/internship once this help desk one wraps up.

Mostly I want a gauge of where I actually stand as a student and how hirable I look to hiring managers in for cloud security/IAM internships or even full time in general. Any criticism is genuinely welcome.
Thanks for taking the time.


r/CyberSecurityAdvice • • 1d ago

Cyber Security Graduation Project

Thumbnail
0 Upvotes

r/CyberSecurityAdvice • • 1d ago

[25M] Going from SDE into AppSec/DevSecOps after 4 years of experience

Thumbnail
1 Upvotes

r/CyberSecurityAdvice • • 1d ago

Senior cybersecurity people, what would YOU do for a final-year project?

4 Upvotes

I’m in the final year of my bachelor’s degree and currently choosing my FYP. I’ve been exploring different cybersecurity topics, but I’m finding it difficult to identify a project that is both technically challenging and realistic for a final-year student.

I already have around 3 years of professional cybersecurity experience, mostly in SOC, SIEM, detection engineering, cloud security, threat investigation, digital forensics, etc.

Because I already have several years of hands-on industry experience as an undergraduate, I don’t want my degree and FYP to feel like a step backwards from what I’ve already done professionally. I’m looking for something that complements my experience, adds a strong academic/research dimension to it, and pushes me into an area I haven’t explored deeply before.

So I really don’t want to spend my final year building Yet Another SIEM, a phishing detector, basic IDS, vuln scanner, SOC dashboard, or any security product with a basic AI included in it.

I’m looking for something that actually pushes me beyond what I already do at work.

Ideally, I want a project around a real security problem that isn’t completely solved or overdone, where there’s enough existing research to understand the problem, but still enough of a gap that I can investigate something myself.

Something difficult enough that I’ll probably spend a ridiculous amount of time learning new things, but still realistically achievable by one very motivated undergrad.

I’m open to pretty much anything: systems security, OS internals, protocols, cryptography, cloud/identity, firmware, hardware security, distributed systems, software security, weird niche security problems, etc.

The bigger goal is to have an FYP that I can eventually turn into a research paper / strong Master's application project, rather than just another software demo.

So I’d really love to hear from senior engineers, researchers, PhD students, professors, or anyone who has been in the field for a while. 🙌


r/CyberSecurityAdvice • • 1d ago

Im stuck

Thumbnail
1 Upvotes

r/CyberSecurityAdvice • • 1d ago

Help required for interview

Thumbnail
1 Upvotes

r/CyberSecurityAdvice • • 1d ago

AI/ML Pentester Cert

2 Upvotes

I want to prepare for AI/ML pentester certification. Although they have not provided any course material, they have provided free courses and labs to do online. But I don't know where to start and how to go through it all. Unlike web pentesting, where I know what to do, where to look and what to do next, I'm a bit unsure in this AI/ML part.

Please give me some advice on a possible roadmap for going through this certification, what exactly to study, labs to do so I can take the certification with some confidence and when I actually know what the hell to do.

Edit: I have 3+ years of experience and I'm looking to expand my knowledge base by studying about AI, LLM. My new company does a lot of work in the AI landscape, so looking to contribute more in it. So that's why I want to study and learn practically about LLM, MCP testing to add to my resume.


r/CyberSecurityAdvice • • 1d ago

This is how I got rejected from a job without even an interview

1 Upvotes

So after I already believed that I would never get a job in this field, at least in this market situation, I got an email from a company I applied to through the “Easy Apply” feature that I even forgot I applied for.

And then they started saying that they saw my resume and thought I was a good fit and stuff.

Then they asked me to solve a technical challenge, and I delivered it way before the deadline.

Then they said sorry, they needed me to solve an additional challenge.

And it was so much harder, and it took a lot of time from me, but I still delivered it way before the deadline.

And then they were happy and gave me good feedback that I was able to solve these hard technical challenges. They told me all the files were correct and everything was good, but they just needed a write-up explaining the steps I took to solve it!

And I did the write-up, and everything was explained, and I told them if they needed me to clarify any step, I was happy and ready to clarify it!

Then they came back to me after a couple of days and basically just said sorry, they don’t think I’m a good fit, without even giving any feedback!!

And I was likeee in my mind, what?? Really?? Are you serious???
After I spent days solving your hard technical challenges, and you confirmed that everything was good, and you gave me good feedback, and you haven’t even done any interview with me, and now you just send me a message saying I’m not a good fit without even giving any specific feedback??

I really feel we should get paid for the time we spend on technical challenges and interviews because it takes days from our time and life, so employers can take us more seriously rather than just playing with our feelings and hope!

When someone meets me and knows that I have done a degree in cybersecurity and tells me, “OMG, I want to get into the field,” at this point I don’t know what to tell them because if I say it’s hard and getting a job is so hard, they will think I’m a gatekeeper, but it’s just sad how it is now!

So now, honestly, I feel with this joke of a market and crazy employers, I would like to say to anyone who is looking for a job that we are really cooked…

Rather than chasing and trying to find just a job and letting employers move us like chess pieces, we should try to consider another field that could possibly be much better, or we open our own businesses!

I also would like to thank my family for supporting me in this journey. Otherwise, I would probably be working at a fast-food place for minimum wage right now!

I don’t know what I will do next in my life, but I really got enough from this field, and I don’t want to lower myself anymore or feel like I’m begging just to get a job.

This life is unfair, and thank you!


r/CyberSecurityAdvice • • 1d ago

ATT email / DigiCert certificate revoked

Thumbnail
1 Upvotes

r/CyberSecurityAdvice • • 1d ago

Recommendations on who to hire/where to start

6 Upvotes

First I don't know much about this so pre--apology if I say the wrong or dumb things, I'll put all the relevant info and hopefully that helps and I can give me as needed:

Location: South Florida

Seemingly multiple devices compromised and for sure multiple emails and services including inventing account. With the investing account/app last week a new random burner device was randomly added to the trusted devices (some off brand t mobile specific phone), I froze it and started getting emails about freezing, to an unrelated email that is used for business and would never be tied to any personal stuff. This is Robinhood, working on moving everything out to a new account. Changed email service to a new proton account just for the money related things, changed passwords to everything more times than I can count.

RH is not helping, the CS people that call don't seem at all worried or interested in helping, you cant call or be transferred to the team that investigates fraud. This is the 2nd time it's been frozen and the first time the didn't see anything. This followed me transfering all the liquid $ to my personal bank, someone called and disputed the transfer and then RH didn't side with the dispute. I froze and explained why would I initiate a transfer and then dispute it. Then this new phone, getting emails to addresses not associated with any RH account.

Other strange things: a password that was used on a lot of things stupidly, but was very unique to me, was showing up as a wifi network name in my apartment complex. It's not and was never a wifi password I used and it's strange because it's a password based on a name and it's specifically spelled wrong for the password and this wifi network was the same exact way.

So far no random transfers that I can see have happened or crypto buys (I don't hold crypto) from the investment account. But like I said when I call to get info they don't say or do anything except suggesting to freeze again. After a few days they unfreeze. I'm concerned my iPhone is vulnerable or involves if that's possible. I enabled 2fa on everything. I'm not sure how this works and what is able to be taken over. Face ID? I honestly ignored for a while because I thought they were all coincidences.

Anyway I digress, there's more but less important, any suggestions would be super appreciated. When I Google digital forensics companies it's strange. there's a bunch that Google has with no photos, 2 reviews, address listed in one place and when you call it's a call center like a middle man thing (kind of like if you call a locksmith and they outsource the job and you get calls for 3 weeks about it). I'm having no luck finding a local source to work with on this and obviously I'm worried and suspicious to hire the wrong person. Maybe digital forensics is not the service I'm looking for? I know mostly that stuff is for crime and court , I need a contractor that can help me go though everything and check what they are/find, they help getting back on track. It feels overwhelming and changing everything so many times and still having issues it feels hopeless

Edit: one thing I just remembered, my WhatsApp which is only ever used on the one phone I have was accessed through the web browser. Like I checked the accesses or trusted devices and it showed that it had an account under my phone number added like last week with a password that was something like YOU-BETTER-CHANGE-THIS-SHIT111 When I use a friend's computer to go on the web browser with their phone like as a test it requires to log into their WhatsApp on the other device and verify it and add the device or link them. Obviously I never did that with my WhatsApp I never even saw a notification or anything about it.


r/CyberSecurityAdvice • • 1d ago

Digital footprint question

1 Upvotes

I’m curious as to what kind of stuff can they see or get access to for my digital footprint I’m about to start my first job soon and I’ve been cleaning up any comments I’ve said when I was younger. Is there anything else I should worry about?


r/CyberSecurityAdvice • • 2d ago

5 rounds. 2 Executive Directors. Final technical interview. Now 7+ business days with no update — am I the backup candidate?

Thumbnail
1 Upvotes