r/CyberSecurityAdvice

▲ 2 r/CyberSecurityAdvice+2 crossposts

Is Linux really more secure than main stream operating systems?

Linux can be misconfigured fatally, easier. Linux operating systems are specifically targeted malware families and botnets.

This is what I do not get when some people say, that most viruses target windows. It’s more nuanced than that. Most windows programs do not have a native linux port, so it’s not feasible for those types of viruses to make a linux port, especially since windows is used by the masses.

But Linux has its own security problems and easier misconfiguration, more open tooling and more services in some cases that can be exposed to the web.

So I don’t really get it when people say linux is more secure because, if an attacker breaks into a windows machine as the user account, they can’t really get to become the admin account unless they figure out the password. Meanwhile if an attacker breaks into a user account on linux, they have more escalation routes.

I might be misinformed on this but what stops a program or script containing a dropper or payload from running on a linux desktop?

reddit.com
u/minecrafter69_ — 1 day ago

CYS beginner

Hi, I'm starting my BS very soon in CYS and before that i want to work on my skills,

I'm a complete beginner and just downloaded Ubuntu version Linux on VM

Can you guys help me, what should i do now or where to start

reddit.com
u/Automatic_Fan744 — 1 day ago
▲ 6 r/CyberSecurityAdvice+3 crossposts

Being bombarded with Account Recovery Requests

I am being bombarded with Account Recovery requests. Bombarded may be overstating it a little bit, but I'm getting 3-10 requests a day and oftentimes 5 or 6 in a row. Of course I hit "No" every time it asks if it is me trying to recover.

I have Advanced Protection turned on. My phone set up as a passkey. I have an excellent password that is completely unique to Google. I also changed my password just to be safe. I've logged in and I recognize all of my connected devices.

I am pretty sure that I haven't been hacked, but I am being targeted. The messages that come along with the account recovery prompts state that my password hasn't been compromised, but the persistence of the hacker still worries me. It's been going on for about 2 weeks. I suppose the hacker is attempting to guess my passwords using old compromised ones bought off the web. I am mostly afraid of inadvertently hitting "Yes" to a prompt just one time and then I'm cooked. I don't THINK that completely opens me up, but I'm not 100% certain. I plan to get a physical security key, but I don't think that bypasses the Account Recovery prompts either.

Any thoughts or suggestions? Thanks.

reddit.com
▲ 155 r/CyberSecurityAdvice+95 crossposts

Most people who followed $CYDY remember March 30, 2021. The FDA publicly stated that CytoDyn's claims about leronlimab were "misleading and not supported by the data", no benefit was shown in COVID-19 treatment trials. The stock dropped 25%+ that day.

What happened afterward was a class action lawsuit covering investors who held $CYDY between March 27, 2020 and March 30, 2022.

A $500,000 settlement has been reached and terms are now submitted to the court for approval.

Who qualifies?

Anyone who held $CYDY during the class period and suffered losses from the alleged misrepresentations about leronlimab's effectiveness for HIV and COVID-19.

Can I still apply?

Yes, you can submit your application now and it will be processed once claims filing officially opens after court approval.

If you were damaged by this don't forget to check your eligibility. GL!

u/JuniorCharge4571 — 3 days ago

Really confused about where to start

I know this has been severely asked and I have gone through a lot of those answers but I am so confused over where to start. Like should I just start studying for a certificate or procure other skills in advance before that. I graduated as a bachelor in IT a month ago but obviously my college didn't really teach anything even close to cybersecurity. Please let me know any sort of starting first steps or guides you guys have.

reddit.com
u/Gammatizer — 2 days ago
▲ 2 r/CyberSecurityAdvice+1 crossposts

How to get a business email for any.run?

I'm trying to do a dynamic analysis on a phishing malware and don't want to go through the trouble of installing Remnux VM as I don't have enough space on my PC. I've tried using tempmail and even my personal email but all have been rejected. How do you sign up?

reddit.com
u/LeatherPen4962 — 2 days ago
▲ 37 r/CyberSecurityAdvice+31 crossposts

Updates for Getting Payment on the Rivian $250 million Settlement

Hey guys, if you missed it, Rivian settled $250 million with investors over claims that it failed to disclose the true cost of producing its vehicles. And, I just found out that they’re accepting claims even though the deadline has passed.

Quick recap: In 2022, Rivian was accused of misleading investors about its vehicle pricing and production costs. In short, the company promoted its R1T pickup and R1S SUV as competitively priced electric vehicles, but investors later alleged that Rivian was losing substantial amounts of money on each vehicle sold and failed to clearly disclose how severe the cost gap was. As supply-chain issues and material costs increased, Rivian announced major price hikes that sparked customer backlash and raised concerns about the company’s financial outlook.

Now, the good news is that the company agreed to settle $250 million with them, and even though the deadline has passed recently, they’re accepting late claims.

So, if you invested in $RIVN when all of this happened, you can still check the details and file your claim here.

Anyway, has anyone here invested in $RIVN at that time? How much were your losses, if so?

u/11thestate — 3 days ago
▲ 811 r/CyberSecurityAdvice+2 crossposts

About to ruin a 30+ year IT career because I can't spot a phishing simulation...

I'm a 30+ year network/systems admin/engineer and I feel like I've done a great job over the decades keeping up running and secure. I feel like I work as hard as anyone in the company and have a sense of ownership that is hard to teach. I've patched our servers every month on schedule for the past 17 years straight. I've used all the latest security tools to ensure safe authentication and protection against malicious activity. We always have stellar pen tests results. I'm a great troubleshoot. I take my security training and pass the tests with flying colors. I get exceeded expectations for my reviews. They even named the server from after me! All that and a bag of chips.

But...

I'm a freaking failure when it comes to phishing tests. I've failed two this year and three in the last three years. I've never actually fallen prey to real phishing. I know what that looks like and my tools don't let it near me. But I had to tell our email security gateway to allow those phishing simulations thru to our inboxes. And I keep falling prey to them. What is wrong with me!?! Why can't I learn?? I'm going to get fired because of this. We've got some employee handbook rules about not screwing up like this. Three strikes and all that.

All this good will and work and a career that I can feel great about going to be flushed down the drain and I'll retire a failure. Was hoping to retire in a few years and ride off into the sunset. Now I'm going to ride off a cliff into a ditch. I feel like shit today. Can't wait until Monday to get yelled at or maybe even fired.

Am I the only good sysadm to struggle like this? I hope it's not just me. Feel terrible.

reddit.com
u/etoptech — 5 days ago

TryHackMe should i try it?

I am a 3rd year btech student who is just starting Cybersecurity, i heard that tryhackme is very good for beginners so i wanted to purchase tryhackme premium as well, Btw what i am more intrested in is

SOC

IAM

GRC

CLOUD

TPRM

Malware

So should i get it? And what will i be able to learn from tryhackme and please guide me to get started in my cybersecurity career 😔

reddit.com
u/Weary-Nothing-4973 — 3 days ago

Hey guy I want to buy a laptop for cyber security

Here's Lenovo Thinkpad T16 gen 5 DDR 5 Ram 64gb, SSD 1Tb Ryzen Ai 7 pro 450 processor. I have seen m4 max in second market. But I am in doubt. Should I buy it?

reddit.com
u/Safe-Confidence-4907 — 4 days ago

My accounts are getting hacked someone help please.

It first started earlier this morning. I got a notification that someone was trying to get into my Apple ID account from Miami, while I'm located in Denver.
Then I got on X/Twitter, and for some reason, my name and profile picture had been changed to
"Vnltvna trobas" or whatever that is. I know I didn't do it, so I changed my X password, hoping that would help.
I also checked my email and got a message from Discord saying:
"Your account may have been compromised. This can happen if your Discord password is the same password used on another website and that website was hacked, or you accidentally gave your access token to someone else. Because of this, we've disabled your Discord account."
If anyone can please help me figure out what's going on, I would really appreciate it. I'm not sure if all of this is connected or what I should do next.

reddit.com
u/itsjusteliii — 3 days ago

How to remove claude watermark. Been searching for ways to do so. Also anybody transitioned here from GRC to Cloud Security / AI Security roles ?

Hi everyone, I am looking for ways that can be used to bypass the Claude Watermark as it makes my job of customising my work too hard. Also, anybody here can advice as to how to jump from GRC role to a tech role and which role would be better in cybersecurity to jump to ? And what skillsets need to be developed in order to land an entry level role there ?

reddit.com
u/DeluluDarkAngel — 4 days ago
▲ 4 r/CyberSecurityAdvice+1 crossposts

CCDL1 discount for students.

Hi, i lost my job this year and decide to change from software engineer to cibersecurity because its something that i always wanted but never got the time.
Now i completed some courses and i want to get into certs. Looking for reddit the CCDL1 seems to be the best option for me.
Is there a discount for students or people without a job outside the USA?
Thanks!

reddit.com
u/valeng5 — 3 days ago

Security Training targeted at old dogs who aren't good at learning new tricks!

Can anyone recommend some good security training for older Systems Administrators (50+) who need to rewire their brains to be suspicious of everything? Been on the job for 30+ years and my worst character defect is that I don't see things as suspicious. My understanding is younger generations have been taught to assume everything is the enemy, but I grew up in a world where you assumed everything was legit. This is now getting me in trouble as I'm failing phishing simulation tests at the office. I straight up need to have my brain rewired so every dang email, chat, text and prompt is an attack waiting to happen. I feel like i need to go to a training site where they shock you every time you choose the wrong option.

reddit.com
u/jwckauman — 4 days ago

AI Agents Are Becoming an Identity Security Problem

I've been thinking about something that doesn't seem to get enough attention when people talk about enterprise AI.

Everyone is talking about what AI agents can do.

They can read documents, access internal systems, create tickets, work with APIs, analyze customer information, write code, trigger workflows, and in some cases make decisions with very little human involvement.

But there's another question that seems just as important:

What identity does an AI agent actually use when it does all of this?

That's where things get interesting.

For years, we've spent a lot of time managing employee identities. We know who has access to a particular application, why they have it, and when their access should be removed.

AI agents make that model a lot messier.

Imagine giving an AI agent access to your company systems

Suppose a company creates an AI agent to help the support team.

It needs access to customer information, so someone gives it access to the CRM.

Later, the agent needs information from another system, so another permission gets added.

Then someone connects it to an internal API.

A few months later, nobody is quite sure what permissions the agent has anymore.

Sound familiar?

It's basically the same access-sprawl problem companies have dealt with for years, except now the "user" isn't a person.

And an AI agent can potentially operate much faster than a human.

That's why I think AI security isn't just about protecting the model.

It's also about controlling what the agent is allowed to do.

AI agents shouldn't automatically get broad access

One thing that seems pretty obvious to me is that AI agents should follow the same basic security principle we use for humans:

Give them only the access they actually need.

For example, if an AI assistant needs to read customer records, why should it also have permission to delete them?

If an AI coding agent needs access to a Git repository, does it really need production deployment access?

If an AI finance assistant can read invoices, should it be able to approve payments?

Probably not.

The more capable these systems become, the more important those boundaries become.

And then there's the identity problem

This is the part I find particularly interesting.

Organizations already have a huge number of non-human identities:

Service accounts.

API keys.

Applications.

Bots.

Workloads.

Machine identities.

Automated integrations.

Now we're adding AI agents to the list.

The problem is that these identities can sometimes end up with permissions that nobody is actively reviewing.

A security team might know exactly which employees have access to a database but have a much harder time answering:

Which applications, bots, APIs and AI agents can access that same database?

That's a serious visibility problem.

What I'd want to know about every AI agent

If I were responsible for securing an organization using AI agents, I'd want straightforward answers to a few questions:

  • Who owns this agent?
  • What identity does it use?
  • What systems can it access?
  • What permissions does it have?
  • Why does it need those permissions?
  • Can its access be revoked quickly?
  • Are its actions being logged?
  • What happens if the agent starts behaving unexpectedly?
  • What happens to its identity when the project is finished?

If those questions can't be answered easily, I'd consider that a warning sign.

This is where identity governance becomes interesting

I don't think every AI security problem can be solved by adding another security product.

But identity governance is becoming an important part of the conversation.

Platforms such as Infisign are working around this broader identity problem, including access governance, authentication and management of non-human identities.

What I find more interesting than the product itself is the underlying idea:

AI agents should be treated as identities, not just pieces of automation.

They need permissions.

Those permissions need to be controlled.

Their activity needs to be visible.

And someone needs to be accountable for what they can do.

I think this is going to become a much bigger issue

We're still relatively early in the adoption of autonomous AI agents.

Right now, many organizations are experimenting with them.

But imagine a company having 500 or 5,000 AI agents a few years from now.

At that point, manually keeping track of what each agent can access isn't going to work.

The organizations that think about identity and access early will probably have a much easier time scaling AI safely.

The question I'm curious about is:

How are companies actually handling AI agent identities today?

Are you creating separate identities for every agent?

Are you using service accounts?

Or are most AI agents simply inheriting the permissions of an existing user or application?

I'd genuinely like to hear how other security teams are approaching this.

u/Business-Cellist8939 — 3 days ago

Malware On resume

Hello guys,i’m a junior penetration tester and malware author and researcher, i’ve coded many malwares for the purpose of learning, never used except for testing on my own machine and never published publicly for anyone

i have also made my own hacking tools many which i haven’t put on my github simply because i dont want anyone using them for malicious use, a simple one just for demonstration would be an Ai assisted brute forcer that has features like delay, jitter and user agent rotation.

My first question is, should i upload these on a private repo on github just for the sole purpose to prove authenticity and credibility so employers can see that this was actually made by me?

my second question is, does that look good on a resume/portfolio, will an employer that has technical knowledge in the field ACTUALLY want to see a bit of malware and hacking tools that shows understanding of attacker methodology?

just a note: i’m not saying my resume would consist of ONLY malware’s and malicious hacking tools, although these are my most impressive to show, my portfolio will also include other projects.

reddit.com
u/Impressive-Day3049 — 5 days ago

I have a Bachelor's Degree in CyberSecurity and feel stuck

Not exactly sure how to start this, but as the title states, I have my degree and I've had it for over a year now and can not land any roles in the industry. I know certs are important, i just can't afford them at the moment. I feel like every day that goes by without me actually using my degree im losing what I learned and I fear that if I do get a job I am going to look like a clown that doesn't know anything. Is there any advice anyone can give me to help me out of this rut? I've applied everywhere at the most entry level jobs and cant get hits anywhere.

reddit.com
u/StatementPrimary9884 — 8 days ago

someone is a able to use my Gmail account to create new accounts (with verification)

I will first clear things up. The person is able to click and verify his accounts. I got 2 mails today from proton: one to verify account and one that confirmed it (4 minutes in btw). Which means he was able to click on the link of the first mail.

It’s not one of those situations where someone inserts mistakenly my email address. No, he is able to continue. As if he is also receiving the same the same mails that i did.

——————-
First a new dropbox account was created, then rockstargames and today proton.

I am a software developer (not security), and i thought i know I could find a solution to a problem like that, but this problem is on another level.

my gmail account is over 15 years old, I had always 2FA, I am using a password manager, passkey and i even keep changing the password around once a year.

my passkey is currently connected to my password manager. and yes, I also keep changing my password manager password.

Today, while someone created a proton account, i got the first mail to verifiy the email address. I was on my laptop and checked the loggedin devices. Nothing. only my laptop and phone.

I got another mail that confirmed the email address and the person was able to create an account.

someone is also using the same account as a recovery backup for another gmail account (title of mail i receive: Recovery phone was changed for your linked Google Account)

Where do i start?

reddit.com
u/BeeKayN32 — 5 days ago