r/cybersecurity

Cybersecurity books that actually changed how you think about security?

What books genuinely changed how you think about cybersecurity, rather than just teaching another tool or technique?

A few examples of the kind of books I mean:

  • Security Chaos Engineering - Kelly Shortridge: resilience, complex systems, testing security assumptions, and learning from failure.
  • Cybersecurity First Principles - Rick Howard: building security strategy around reducing material risk rather than accumulating controls and tools.
  • The Smartest Person in the Room - Christian Espinosa: why technical expertise alone isn't enough; communication, leadership, and business understanding matter.
  • Applied Network Security Monitoring - Chris Sanders et al.: approaching network security monitoring as a structured process of collection, detection, and analysis rather than simply generating alerts.
  • Offensive Countermeasures - John Strand & Paul Asadoorian: active defense, deception, honeypots, and making the environment hostile to attackers.

Books outside cybersecurity - systems thinking, SRE, risk, economics, failure analysis - count too.

reddit.com
u/athanielx — 1 day ago

Today I fucked up big.

I just want to vent out that this is my biggest fuck up in my career. I totally forgot an instruction relating a particularly high severity case and as I understand that fucked up the whole line (I’m in SOC btw). So now im waiting for any news if I still have a job in the coming days. Sorry but I can’t disclose any detail related to the incident.

For those who had experienced this, I really need your words and what will happen next in my career. Is this career ending?

fuck.

reddit.com
u/CyberSecWannaBe — 1 day ago

Friends to Learn with

I am someone who loves to study with friends. My friends are all in different fields. If you want to form a study group with me feel free to reach out.

reddit.com
u/Lanky_Anxiety2396 — 1 day ago

i have serious concern about corporate cybersecurity

is it just me or is the cybersecurity management in corporates are actually useless jobs ? i still didn't see a single ciso and his leadership advisors that actually prioritize fixing issues they all just ask "what tool should i purchase ", and in some jobs I've had the security leadership is doing actual unethical work by hiding issues from ciso because they don't want to be the bearer of bad news , cybersecurity job is full of delivering bad news that's just how it is and it drives me nuts when leadership doesn't understand that.

can someone please assure me and give me faith back in cybersecurity I've been working for more than 15 years and not a single CISO I've worked with actually pushs a roadmap towards fixing issues all i see is "what tool to change / what tool to add " meanwhile an smtp without authentication and whitlisted to bypass all security tools to avoid getting internal emails in spam and have a firewall with allow any/any is known for years but "too complicated to fix" ... my technical mind can't even start to understand the order of priorities in this , yes sure we want to expand the "build" of our scope , but shouldn't "what we need" be based on what are the areas we struggle in with risk on the "run" daily life ?

and if you are a CISO reading this can you tell me how are you making sure your direct reports are nto hiding bad news because they are afraid they wont get the promotion /bonus they wanted ?

reddit.com

Is anyone else finding that compliance is becoming a second security job?

I’m on the technical side of a growing company and one thing that’s starting to annoy me is how much time gets pulled into compliance requests. Someone needs evidence for a control, someone wants a screenshot, someone asks where a particular type of data lives, another person wants an access-control report, etc.

I understand why it’s necessary, but it feels like we’re spending a lot of engineering time proving that things exist rather than actually improving them. How are other teams handling this? Are you automating evidence collection/GRC stuff or do you just accept that this is part of the job?

reddit.com
u/Little_Face_639 — 1 day ago

Anyone else seeing shadow AI become worse than shadow IT used to be

Over the last couple months there seems to be way less talk about people using AI and way more discovery of agents nobody knew about.

One team builds an internal support agent. Someone connects an agent to Jira. Then another agent is pulling files from SharePoint straight into Slack.

And apparently nobody stopped to ask what these things can actually access.

None of it is necessarily malicious. People are just trying to save time. But shadow IT was already messy enough when people were installing random software. Now shadow AI can actually read, move and share information on its own.

Feels like this is going to get messy fast.

reddit.com
u/MasonCarter17 — 1 day ago

Kimi K3 is the first open-weight model that just succeeded on CyScenarioBench.

Irregular just showed that Kimi K3 can conduct cyber campaigns autonomously or near-autonomously. It's the first open-weight model that just succeeded on CyScenarioBench.

It trails closed frontier models with a ~6 month lag.

It was particularly effective at turning partial access into complete attack chains by adapting public exploit techniques to constrained environments, building custom tooling, diagnosing implementation failures, and validating each stage before proceeding.

While it's an expected trajectory, it's fascinating to see that you can get near frontier capabilities at 3x cheaper than Fable 5.

We can fast forward to a year from now and confidently predict that similarly to how we see vulnerability scanners checking for open ports and known issues, all publicly facing assets will be probed for pretty much any potential security issue.

reddit.com
u/DrKabanov — 1 day ago
▲ 74 r/cybersecurity+1 crossposts

analysis of a Stripe breach that just dropped, confirmed vendor leaks and claims of 20k compromised apis

*Headline clarification - the breach involves many Stripe vendors but does not necessarily indicates a Stripe breach!

On August 18th, 2026, a data release occurred on the illicit forum pwnforums. The threat actor known as Satanic published sensitive information extracted from hundreds of vendors utilizing the Stripe payment platform.

The initial dump released on August 18th contained detailed information pertaining to 669 specific vendors, alongside 1,033 compromised API keys. The volume of the data is reported as 33GB.

Hudson Rock researchers spoke to the threat actors minutes after the release of the data. During this exchange, they claimed that the released data represents only a fraction of their total haul. According to the actor, they possess approximately 20,000 compromised Stripe APIs, which they intend to release in subsequent batches.

infostealers.com
u/Malwarebeasts — 1 day ago

Is DevSecOps or Cloud security engineer a good career

Is DevSecOps or Cloud Security Engineering a good career choice. Whats the job like in 10 or 15 years. Is it diluted by low-skilled people and whats an entry level job for these jobs

reddit.com

Teams wanting to record all keystrokes from all apps on MacOS? WTF

Clean install of Teams on MacOS, why would it need access to your keystrokes from all apps, is this another MS fuckup or is this all just planned?

Teams was uninstalled after getting this message and I only use the web version now.

More MicroSlop?

reddit.com
u/BlackReddition — 1 day ago
▲ 7 r/cybersecurity+1 crossposts

Looking for a good real-world digital forensics case study

​

Hey everyone! I’m a student preparing a Digital Forensics / Computer Forensics practical presentation and I need to choose a real-world cybercrime case study.

I’m looking for a case that:

- Is not extremely common/popular (I want to avoid topics that many groups may choose)

- Has enough reliable information available online

- Has a clear digital evidence / forensic investigation angle

- Can be explained within 12–15 slides / 10–15 minutes

- Ideally involves things like hacking, gaming companies, Apple/iPhone, data theft, ransomware, website attacks, insider threats, digital evidence, or incident response

- Allows discussion of evidence acquisition, preservation, logs/artifacts, timelines, attribution, and/or legal issues

What real-world case would you recommend?

If possible, please share the case name and why you think it would work well for a student-level digital forensics presentation.

Thanks!

reddit.com
u/POTHAMM — 1 day ago

Why does this career have so many liars?

Context, I'm not seeking career advice. I have 10 years of experience and I've done everything from network engineering to managing a security program.

But is there any field out there with as much misinformation as this one? The cybersecurity community in general reminds me of the gaming community.

For example, someone may post "I'm looking to get into this field what should I learn?" And then someone will go on this long rant about how long they did was get a few certifications and they got a job. But they also omit key details like being drinking buddies with the CEO. Or their dad being the manager of the security department.

reddit.com
u/securityofus — 2 days ago
▲ 20 r/cybersecurity+1 crossposts

How would you protect 4–6 high-risk inboxes without breaking the bank?

We’re a small company with only 16 employees and currently use Microsoft Defender for email security. It works well overall, but a few of our executive accounts are targeted by phishing much more frequently, and one of them has been compromised in the past.

We’re looking for an extra layer of protection that we could apply to just a few users (around 4–6), rather than the whole organization.

Has anyone dealt with something similar? Any tools or solutions you’d recommend that work well alongside Defender and are cost-effective for such a small number of users?

reddit.com
u/Reasonable-Shoulder1 — 2 days ago

Am I thinking about IAM/PAM correctly, or am I missing something?

Had a conversation with an architect today about IAM, and I think we were talking past each other.
My background is systems/infrastructure, so when I think IAM I think AD users/groups, RBAC, MFA, privileged accounts, service accounts, and mapping access/rights into application based roles.
The way they described it made IAM sound like a much more separate/specialized discipline than I’m used to thinking of it.

For those who actually work in IAM: is the job mostly administering and governing who gets access to what, or are you actually hands-on configuring the applications and identity integrations themselves with SSO, group/role mappings, MFA, provisioning.

I’m trying to understand where IAM stops being “access administration” and becomes actual identity engineering.

reddit.com
u/solslost — 1 day ago

Is GRC the new wave in cybersecurity?

I’ve been noticing a pretty big uptick in GRC job postings lately, especially remote positions.

It feels like cybersecurity always has a “wave.” First it was everyone getting Security+, then it seemed like everyone was trying to break into SOC roles, and now I’m seeing GRC everywhere.

Is GRC becoming the new wave in cybersecurity? For those already working in GRC, are you seeing the field actually grow, or is it just getting more attention right now?

reddit.com
u/Main_Class8520 — 2 days ago

Passed CISSP Nov 2024. Sharing my free field manual here after positive reception in r/cissp

CISSP Field Manual - Free Download

Posted this in r/cissp earlier this week and got great feedback plus multiple suggestions to share it at r/cybersecurity for anyone on the CISSP path or considering it.

Quick context: passed November 2024 at 101 questions in ~80 minutes. After passing I spent 400+ hours turning my study notes into a proper field manual as a way to give back to the community that helped me get there.

91 pages, completely free. Covers all 8 domains, the manager mindset that trips up most technical people, test-day tactics, and a ranked breakdown of every resource I actually used with honest notes on which ones moved the needle vs. which ones I'd skip.

Hosted as a PDF so I can push updates as the exam evolves and as corrections come in from the community. Downloading always gets you the most current version.

Any feedback good, bad, or "you got X wrong on page Y" is genuinely appreciated. Comment here, DM me, or email (address is on the site).

Mods: if this link isn't allowed under sub rules, please let me know and I'll pull it. It goes straight to the free PDF, no paywall, no email gate, no upsell. Happy to repost without it if needed.

reddit.com
u/dummmyacccount — 1 day ago